Home/Case studies/Financial services
Financial services

A JSE-listed financial services provider cut critical exposure by 71%

Client anonymised at their request
9-month programmeVulnerability managementQuarterly assurance
71%
Reduction in critical findings
4.2d
Median time to remediate
3
Frameworks mapped
9mo
To board-defensible posture
01The challenge

A merger left a fragmented, unmeasured estate

Following the acquisition of a smaller competitor, the group inherited two overlapping technology estates with inconsistent controls, duplicated internet-facing services and no unified view of vulnerability. The board’s risk committee was being asked to sign off on a posture nobody could actually quantify.

An annual penetration test had become the only measure of security, a once-a-year snapshot that was stale within weeks. Critical findings recurred between tests, remediation was untracked, and there was no way to demonstrate progress to regulators or the audit committee.

02Our approach

From point-in-time testing to continuous assurance

We replaced the annual snapshot with a continuous programme, anchored to a single risk register the board could read.

  • A
    Unified the attack surfaceConsolidated and de-duplicated all internet-facing assets across both estates into one authoritative inventory.
  • B
    Continuous vulnerability managementStood up scheduled scanning with senior-tester validation, so real exploitable issues were separated from scanner noise.
  • C
    Prioritised, tracked remediationEvery finding was risk-rated, assigned an owner, and tracked to closure in a live register mirrored to the board dashboard.
  • D
    Quarterly independent assuranceEach quarter we re-tested and issued a board-ready report mapped to the group’s control frameworks.
03The outcome

A defensible posture in three quarters

Within nine months the group had a measurable, improving posture, and a risk committee that could finally see it.

  • 71% fewer critical findings across the consolidated estate, quarter on quarter.
  • Median remediation time down to 4.2 days for critical issues, from an unmeasured baseline.
  • A single board-ready dashboard the risk committee now reviews every quarter.
  • Clean evidence trail for regulators and external auditors, mapped to control requirements.
“For the first time, we could show the board exactly where we stood, and prove it was getting better every quarter.”
Chief Information Security Officer · JSE-listed financial services group
04Frameworks

Mapped to the standards that matter

Every quarterly report was framed against the group’s regulatory and control obligations, so assurance and compliance drew on the same evidence.

PCI DSS 4.0 Req. 11.4ISO 27001 A.8.8 / A.8.29POPIA §19 safeguards

This case study is anonymised at the client’s request. Sector, scope, methods, frameworks and outcomes are described as delivered; identifying details have been generalised to protect the client’s security posture.

Want an outcome like this?

Start with a baseline assessment. We’ll show you where you stand today and map the path to a posture your board can trust.

A JSE-listed financial services provider cut critical exposure by 71% | Resilitech case study · Resilitech