Secure & Patched — Post-Incident Hardening Case Study
Secure & Patched: A Post-Incident Hardening Case Study
What does it take to harden a large statutory public entity after a ransomware attack? Between December 2021 and March 2022, Dataproof delivered a four-pillar hardening programme that took a 109,905-vulnerability estate down to just 30,301 — a 72% reduction in five weeks — with zero security incidents across the entire engagement.
“We cut 109,905 vulnerabilities to 30,301 in five weeks — 75,653 remediated — with zero incidents across 2,530 endpoints.”
The Stats at a Glance
- 109,905 vulnerabilities identified → 30,301 in 5 weeks (72% reduction)
- 75,653 remediated (~70% of medium/high/critical)
- 2,530 endpoints protected (1,949 workstations + 581 servers)
- 512 of 643 production servers patched across 16 server groups
- 45/45 test servers patched — 100% CAB-approved
- Zero security incidents during the engagement
The Four Pillars
This engagement delivered four integrated capabilities: SOC (real-time detection and response), Malware Protection (endpoint defence), Patch Management (disciplined remediation at scale), and Vulnerability Management (continuous discovery and prioritisation). Remove one pillar and the structure weakens.
Read the Thought Leadership Series
- Post 1 — The Wake-Up Call: Your vulnerability backlog is the real threat
- Post 2 — The 4-Pillar Approach: Why monitoring alone isn’t enough
- Post 3 — Legacy Systems: What to do when you can’t patch
- Post 4 — Governance-First: CAB-approved audit-ready defence
- Post 5 — The 90-Day Model: From scan to remediated estate
Get Your Free 14-Day Vulnerability Assessment
Want to see where your organisation stands? We’re offering a free, no-obligation 14-day Vulnerability Assessment — the same starting point we used for this engagement.
* Case study anonymised per client confidentiality requirements. All figures are factual and verified.