info@p2pnetworkdesign.co.uk London, United Kingdom
ISO 27001  ·  PCI DSS  ·  Cyber Essentials  ·  UK GDPR
Our Work

Case studies & client projects

Home  /  Case Studies
Delivery Track Record

The kinds of outcomes we deliver

Case studies are published with client permission and anonymised where requested. If you'd like to discuss similar outcomes for your organisation, book a free assessment.

Compliance — ISO 27001

ISO 27001:2022 certification for a UK SaaS provider

A 45-person B2B SaaS company needed certification to satisfy enterprise procurement — with no documented ISMS, no risk register, and limited policies. We delivered the full implementation from gap analysis to UKAS-accredited certification.

SaaS / Technology45 employees5 months
  • Certification achieved first attempt
  • 25-policy library authored and approved
  • 47-risk register with documented treatment
  • 3 enterprise contracts unlocked post-certification
Cybersecurity — Penetration Testing

Web application pen test for a fintech platform

A London fintech processing payment data needed annual testing for PCI DSS and an enterprise client's security questionnaire. We delivered a grey-box web application test covering OWASP Top 10 and business logic.

Financial Services5 days testingPCI DSS
  • 2 critical IDOR vulnerabilities found and fixed
  • Authentication bypass in reset flow resolved
  • Evidence accepted by QSA
  • Clean retest of all critical/high findings
Compliance — Cyber Essentials Plus

CE Plus for an NHS supply chain member

A healthcare technology company was required to achieve Cyber Essentials Plus as a condition of NHS framework membership — with unmanaged admin accounts and inconsistent patching. We remediated and prepared them for the audit.

Healthcare Technology6 weeksNHS Supply Chain
  • Cyber Essentials Plus achieved
  • Admin separation across 3 offices
  • Documented, enforced patch process
  • NHS framework membership renewed on schedule
DevSecOps & Cloud

Pipeline transformation for a startup engineering team

A 12-engineer team had no security gates in GitHub Actions — secrets had been committed to git three times and containers shipped unscanned. We integrated SAST, secrets scanning, container scanning, and IaC policy checks.

Technology Startup12 engineersGitHub Actions
  • Zero credential exposures since rollout
  • Container CVE rate down 80% in 3 months
  • Snyk + SonarQube + Trivy across all pipelines
  • HashiCorp Vault for secrets management
Cybersecurity — Incident Response

Ransomware response for a professional services firm

A 30-person law firm suffered ransomware encrypting 60% of their file server, with potential exfiltration of client matter data. We provided emergency response, forensics, ICO notification, and post-incident hardening.

Legal ServicesEmergency responseICO Notification
  • Contained and eradicated within 48 hours
  • ICO notified inside the 72-hour deadline
  • Forensic report supported the insurance claim
  • EDR, MFA, and hardened backups deployed
Cloud Infrastructure & Security

Secure AWS landing zone for an e-commerce business

A UK e-commerce company processing cardholder data ran a flat AWS account — no segmentation, overpermissive IAM, unencrypted S3. We designed and deployed a CIS-aligned, PCI-ready landing zone.

E-commerceAWSPCI DSS
  • CDE fully segmented behind WAF
  • All S3 encrypted; public access blocked by policy
  • 94% IAM permission reduction on service accounts
  • CIS Benchmark score: 23% → 91%

Want results like these for your organisation?

Every project starts with a free thirty-minute assessment — your gaps, your priorities, and a realistic fixed-fee approach.