// Case Studies

Outcomes, not slideware.

Customer-identifying details redacted under NDA. Metrics representative of engagements delivered. Detailed write-ups available in your discovery call.

Customer names redacted under NDA. Quotes attributed by role, not by person. Metrics representative.
01 / recurring validation

Tier-2 European bank found a critical IDOR before its annual audit.

European fintech · Tier-2 bank · ~600 employees · regulated under DORA

// challenge

A scheduled Argus validation run picked up an IDOR in the customer transfer endpoint introduced in a feature release the bank shipped two weeks prior.

// solution

Single argus engagement against the transfer surface (authenticated, scope-locked to the affected endpoints). Senior engineer review on the finding within 4 hours of detection. Fix proposed alongside the finding, customer remediation deployed within 48 hours, free retest within 30 days confirmed closure.

// results

  • Critical IDOR detected 4h after release, closed in 48h
  • 73% reduction in exploitable findings over 90 days of quarterly coverage
  • DORA Article 25 (ICT-related operational resilience testing) evidence captured automatically

We had a clean external pentest in March. argus found a critical that shipped in May. That's what continuous means.

Head of Security, Tier-2 European bank
02 / compliance readiness

Regional healthcare provider went from a six-month NIS2 readiness estimate to 8 weeks.

Regional healthcare provider · ~1,200 staff · HIPAA + NIS2 obligations · operating in two EU member states

// challenge

Initial in-house gap analysis flagged 18 NIS2 controls as 'unclear' or 'missing' and projected six months of remediation. Internal team had no NIS2-specific lead and was already at capacity on EHR migration.

// solution

Single Compliance Readiness Assessment for NIS2 — gap assessment, evidence collection where appropriate, policy and procedure review, and expert validation of the provider's clinical-IT evidence.

// results

  • 18 control gaps identified and remediated in 8 weeks (vs 6-month internal estimate)
  • Audit-ready dossier with full traceability matrix at week 8
  • 70% of available evidence mapped for the subsequent ISO 27001 readiness work, reducing duplicate evidence collection

The traceability matrix is what saved us. Our auditor closed the conformity assessment two weeks earlier than scheduled.

CIO, Regional healthcare provider

Outcomes, not slideware.

Detailed engagement write-ups available under NDA in your discovery call.

Start scoping
Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU