All systems operational London · UK
Mon–Sat 10:00–18:00 ☎ 0207 096 0936
← Case studies
Case study · Community care provider

Passing a security audit for a community care charity

An external audit flagged 20+ security gaps ahead of a Cyber Essentials assessment. Our team closed them out on a single onsite visit — MFA, enforced encryption, locked-down remote access and more.

MFA enabled across every Microsoft 365 account, including shared mailboxes
BitLocker encryption enforced via admin so users can't disable it
Unattended remote access to an unsecured data PC shut off
Windows 10 machine upgraded to Windows 11 at no extra cost

The challenge

A community care charity providing support services across South London was working towards Cyber Essentials accreditation. As part of that, an external security consultant carried out a full audit of their systems — and came back with a list of more than twenty findings.

Individually some were small; together they painted the picture of an office that had grown organically without a security baseline. Multi-factor authentication was only on the admin account, not staff. BitLocker encryption was switched on but not enforced, so a user could turn it off. Mailboxes shared a single password. A “hidden” PC storing data could be reached over remote-access software with no prompt for credentials, from a desktop that sat permanently unlocked. Some machines were still on Windows 10, weeks from end-of-life.

For an organisation handling sensitive data about vulnerable people, this was exactly the sort of list that needed closing — quickly, and with evidence.

What we did

Our team went through the auditor’s findings and remediated them on a focused onsite visit:

  • MFA everywhere — enabled multi-factor authentication on every Microsoft 365 account, not just the admin. Individual accounts were linked to each user’s own phone; shared mailboxes (careline, accounts, team and others) were set up through the Microsoft Authenticator app on a nominated manager’s phone.
  • Enforced encryption — BitLocker was enforced through an admin account so staff can no longer disable it from their own login, closing the gap the auditor found.
  • Locked-down remote access — the unattended remote-access connection to the unsecured “data” PC was switched off, so it can now only be reached when access is manually approved each time.
  • Automatic screen locking — every laptop set to lock after ten minutes of inactivity, so an unattended machine isn’t an open door.
  • End-of-life remediation — a desktop still running Windows 10 was upgraded to Windows 11, at no extra cost, before support ran out.

Crucially, we did all of this without changing a single password — because MFA now protects every account, existing logins kept working, so there was no disruption to staff who “have little time for learning new systems.”

The result

The charity went back to its auditor with the actionable findings closed off and a clear account of what had been done — a solid step towards Cyber Essentials and a materially more secure environment for the sensitive data they hold. What had been a long list of red flags became a short, documented list of fixes.

Honest about who did the work

This work was delivered by our team. We’ve anonymised the client out of respect for their privacy — but the audit, the fixes and the outcome are real. If you’re preparing for Cyber Essentials, or an audit has handed you a list you’re not sure how to close, it’s the kind of thing we handle as part of cyber security and managed IT support.

Services we used

Free · no obligation

Got a project like this?

Tell us what you're trying to fix and we'll come back with a clear, no-obligation plan and price.