CAIRNCYBER ADVISORY

Work

Security review of an enterprise analytics platform

Sector
Financial services
Scale
Enterprise analytics platform, large and varied data estate

Situation

A large analytics platform was coming up to production. Given the size of the data estate it ran over, it needed an architectural security review and regulatory assurance before it could go live.

Constraints

The delivery timeline was live, so the review had to keep pace with it. The data estate was large and varied. The regulatory obligations had to be evidenced rather than asserted, which is a higher bar than it sounds.

Approach

I led the review. That meant threat modelling the platform, assessing the design against both enterprise standards and the regulatory requirements that applied to it, and then setting out the conditions it had to meet before it could proceed.

Outcome

The platform went to production with an evidenced compliance position and an agreed set of mitigations, rather than a general assurance that it looked sound.

Frameworks: NIST CSF v2 · Regulatory compliance · Threat modelling

Discuss similar work →

Start a conversation

Send an outline of the problem and the timescale. I reply to every enquiry that is a plausible fit, usually within one working day.