Skip to main content
BilgeQor

Security Cases

Security engagement records

Structured summaries of completed security reviews, hardening, and advisory engagements delivered across our markets.

These are real completed engagements. Client names and identifying details are withheld for confidentiality. Outcomes are described within the confirmed scope of each engagement.

34engagements
6engagement types
68markets
16industries
Service
Industry
Context
Completed Engagement
Industry: Financial ServicesRegion: Australia
Essential Eight Baseline Review — Standard tierReal completed engagement · client details withheld for confidentiality

A financial services firm preparing for a cyber insurance renewal required a structured review of their controls against the Essential Eight framework. Internal teams lacked the dedicated resource to conduct the assessment without interrupting operations.

What was in scope

Review of eight mitigation strategies as defined by the Australian Signals Directorate Essential Eight framework. Assessment covered the organisation's primary production environment and administrative access controls. Scope was defined and confirmed in writing before work commenced.

What was reviewed

  • Application control configuration across primary endpoints
  • Patch application coverage for internet-facing services
  • Office macro configuration and policy controls
  • User application hardening settings
  • Restriction of administrative privilege assignment
  • Operating system patch currency across scoped assets
  • Multi-factor authentication coverage for administrative accounts
  • Daily backup configuration and tested restore procedures

What was delivered

  • Written baseline review report with maturity level per strategy
  • Prioritised finding register with recommended remediation order
  • Executive summary suitable for board or insurer presentation
  • Remediation guidance notes for each finding requiring action

Not included

  • ×Penetration testing or active exploitation attempts
  • ×Review of infrastructure outside the defined scope boundary
  • ×Certification or compliance certification issuance
  • ×Ongoing monitoring or managed security services

What changed after the work

The organisation submitted the review report to their cyber insurer as evidence of their current controls posture. Internal teams used the finding register to prioritise remediation work for the following quarter. A follow-on re-assessment was requested six months later.

Recommended next step

Essential Eight re-assessment after remediation, or Monthly Security Advisory for ongoing guidance.

Essential Eight Baseline Review

Why we publish these summaries

Security buyers need to understand what they are purchasing before committing. These cases describe what was in scope, what was delivered, and what was not included — so you can evaluate whether the service fits your situation.

How to read these cases

Proof without overclaiming

Each security case is a real completed client engagement. Client names and identifying operational details are withheld for confidentiality. It shows the trigger, agreed scope, reviewed areas, deliverables, boundaries and next step so buyers can understand how BilgeQor turns risk context into a practical Security File.

Scope confirmed

Each case starts from a written scope, not an open-ended promise.

Evidence preserved

Deliverables are described as records, summaries, findings and remediation guidance.

Boundaries clear

The examples avoid client names, certification claims, audit approval and guaranteed outcomes.

See the delivery method
Security Reviews
Website & System Hardening
Application Security
Advisory & Recovery
Security Reviews
9

Security Reviews

Structured baseline and framework assessments for organisations evaluating their security posture.

Industry:Professional ServicesRegion: Hong KongDue diligence
SME Cybersecurity Readiness Review
SME Cybersecurity Readiness Review — Standard tier

Situation

A professional services firm handling confidential client documentation for enterprise accounts needed to demonstrate security readiness to prospective clients conducting vendor due diligence. Partners required a structured evidence base covering access controls, endpoint practices, and data handling procedures before a major client engagement.

What was in scope

Review of the firm's primary workstation environment, email and file-sharing configuration, administrative access controls, and data handling procedures. Assessment mapped findings to practical remediation priorities. Scope was defined and confirmed in writing before work commenced.

Timeline and working model

Review completed within ten business days of scope confirmation. No on-site access required. All review conducted remotely against agreed documentation and platform configuration evidence.

What was reviewed

  • Email platform security configuration and phishing exposure controls
  • File-sharing and cloud storage access controls and external sharing policies
  • Administrative privilege assignment across workstation and platform accounts
  • Multi-factor authentication coverage for business-critical accounts
  • Endpoint patch currency and software update practices
  • Data handling and offboarding procedures for staff and contractor access

What was delivered

  • Written readiness review report with prioritised findings
  • Executive summary suitable for client-facing due diligence review
  • Remediation priority list with recommended action sequence
  • Guidance notes for each finding requiring attention

What changed after the work

The firm used the executive summary as supporting documentation in their vendor questionnaire response. Internal partners implemented the priority access control findings before the client engagement commenced. A follow-on advisory engagement was discussed for ongoing quarterly review.

Not included

×Penetration testing or active exploitation attempts×Server infrastructure or network perimeter review×Certification or compliance certification issuance×Ongoing monitoring or managed security services

Recommended next step

Monthly Security Advisory for structured ongoing guidance, or a scheduled re-assessment after implementing priority findings.

SME Cybersecurity Readiness Review
Industry:Healthcare TechnologyRegion: SingaporeCompliance
SME Cybersecurity Readiness Review
SME Cybersecurity Readiness Review — Standard tier

Situation

A medical technology company preparing to onboard its platform into hospital procurement systems in Singapore required a security baseline review. The procurement process required security evidence covering access controls, data handling, and endpoint practices before the vendor evaluation panel would proceed.

What was delivered

  • Written baseline review report with prioritised findings
  • Executive summary suitable for hospital procurement review

4 ×

Recommended next step

Monthly Security Advisory for ongoing posture visibility, or a re-assessment after implementing priority findings.

SME Cybersecurity Readiness Review
Industry:Property TechnologyRegion: MalaysiaGrowth
SME Cybersecurity Readiness Review
SME Cybersecurity Readiness Review — Standard tier

Situation

A property technology company scaling its rental platform across multiple Malaysian cities was approached by a developer partner network for a security baseline review as a condition of joining their referral programme. The team needed structured evidence of their security controls before the partnership agreement could be progressed.

What was delivered

  • Written baseline review report with prioritised findings
  • Executive summary suitable for partner due diligence review

4 ×

Recommended next step

Monthly Security Advisory for structured ongoing guidance, or re-assessment after implementing priority findings.

SME Cybersecurity Readiness Review
Government-adjacent ServicesNew ZealandCompliance
SME Cybersecurity Readiness Review

A services company providing administrative and data processing support to government agencies in New Zealand was required to meet a baseline security standard as part of vendor panel renewal. The organisation needed an independent review of their controls environment to satisfy the panel's annual security attestation requirement.

Education TechnologyIndonesiaCompliance
SME Cybersecurity Readiness Review

An education technology company serving Indonesian institutions required a baseline security review as part of an institutional procurement process. The platform handled student learning data and required structured security evidence before onboarding to a national education programme vendor list.

Insurance & RiskAustraliaRenewal
Essential Eight Baseline Review

An insurance and risk advisory company required an annual security controls review as part of their internal governance obligations and in preparation for professional indemnity insurance renewal. The company handled sensitive client financial and risk documentation and leadership required an independent review before completing the renewal application.

Retail / ConsumerThailandGrowth
SME Cybersecurity Readiness Review

A retail technology company operating a multi-channel platform in Thailand required a baseline security review as its data processing footprint expanded to include new third-party integrations. The operations team identified that rapid growth had outpaced their internal visibility into access controls and data handling practices.

Media & PublishingVietnamGrowth
SME Cybersecurity Readiness Review

A media and publishing company in Vietnam preparing to onboard its first enterprise advertising clients was required to complete a vendor security assessment as part of the client's procurement process. The organisation needed a structured review of their controls environment before the advertising agreement could be executed.

Website & System Hardening
9

Website & System Hardening

Hands-on configuration hardening and verification for web applications and infrastructure.

Industry:E-commerceRegion: SingaporePre-launch
Website Security Hardening
Website Security Hardening — Standard tier

Situation

An e-commerce operator launching a new storefront on a custom stack required pre-launch security hardening. The team had development confidence but no dedicated security resource to review the configuration before go-live.

What was in scope

Security hardening of a production-bound web application covering server configuration, HTTP security header implementation, authentication flow review, and dependency currency check. Scope limited to the single application instance and its associated infrastructure layer.

Timeline and working model

Review completed in eight business days. Application was live-ready after implementing the priority findings. Post-remediation confirmation was completed within three business days of resubmission.

What was reviewed

  • HTTP security header configuration and policy settings
  • TLS/SSL configuration and certificate chain
  • Authentication flow and session management controls
  • Third-party dependency currency and known vulnerability status
  • Administrative access controls and credential exposure checks
  • Error handling and information disclosure review

What was delivered

  • Hardening report with findings categorised by severity
  • Configuration recommendations with implementation guidance
  • Remediation checklist for the development team
  • Post-remediation confirmation review (one round included)

What changed after the work

Priority findings were resolved before the launch date. The team used the hardening checklist as a template for subsequent application deployments. No critical issues were identified after the post-remediation confirmation review.

Not included

×Backend API endpoints not included in the agreed scope boundary×Third-party payment gateway internal security review×Mobile application companion app×Ongoing monitoring after the hardening engagement closed

Recommended next step

App Security Review for the companion mobile application, or Monthly Security Advisory for ongoing operational support.

Website Security Hardening
Industry:SaaS / TechnologyRegion: VietnamDue diligence
Website Security Hardening
Website Security Hardening — Standard tier

Situation

A SaaS startup preparing to onboard its first enterprise clients was asked to provide security evidence as part of procurement review. The platform had been built iteratively without a dedicated security review. The founding team needed a structured hardening engagement to identify and resolve configuration gaps before the onboarding deadline.

What was delivered

  • Hardening report with findings categorised by severity and priority
  • Configuration recommendations with step-by-step implementation guidance

4 ×

Recommended next step

App Security Review for the API layer and any mobile client, or Monthly Security Advisory for structured ongoing guidance.

Website Security Hardening
Industry:FintechRegion: PhilippinesCompliance
Website Security Hardening
Website Security Hardening — Standard tier

Situation

A fintech startup operating a digital lending platform was preparing documentation for a regulatory review cycle. The platform's technical team identified that its web application configuration had not been formally reviewed since initial deployment. Leadership required a structured hardening engagement to identify and remediate configuration gaps before the regulatory submission deadline.

What was delivered

  • Hardening report with findings categorised by severity and priority
  • Configuration recommendations with implementation guidance

4 ×

Recommended next step

App Security Review for any mobile client, or Monthly Security Advisory for ongoing operational guidance.

Website Security Hardening
Property TechnologyHong KongPre-launch
Website Security Hardening

A property technology company preparing to launch its rental platform required pre-launch security hardening. The platform handled agent credentials and property transaction documentation. The founding team needed a structured hardening engagement before enabling external user access.

Operations & LogisticsIndonesiaGrowth
Website Security Hardening

A logistics technology company scaling its fleet management platform to serve enterprise clients required pre-enterprise-onboarding security hardening. The team's enterprise prospects had requested security evidence as part of their vendor evaluation. The organisation needed a structured hardening engagement to address identified gaps before the onboarding window.

Healthcare TechnologyMalaysiaPre-launch
Website Security Hardening

A healthcare technology company building a patient appointment and records platform required security hardening before enabling access for clinical partners. The team had developed the platform rapidly and needed a structured review of its configuration before moving from closed beta to external clinical access.

Education TechnologyNew ZealandPre-launch
Website Security Hardening

An education technology company preparing to deploy its learning platform to institutional clients required pre-deployment security hardening. The institution's IT team required security evidence covering the platform's configuration and data handling before access would be provisioned for student accounts.

Professional ServicesAustraliaDue diligence
Website Security Hardening

A management consultancy firm operating a client engagement platform was required by an enterprise client to provide security evidence of their web platform configuration before a multi-year advisory contract could be executed. The firm's platform handled engagement documentation and client-sensitive communications.

Media & PublishingSingaporeDue diligence
Website Security Hardening

A media and publishing company operating a content distribution platform was approached by an enterprise advertiser requiring a security review of the platform as part of their programmatic advertising vendor onboarding process. The company's technical team needed a structured hardening engagement to provide the required security documentation.

Application Security
9

Application Security

Mobile and web application security reviews for teams preparing for distribution or compliance.

Industry:Healthcare TechnologyRegion: MalaysiaCompliance
Web & App Security Review
Web & App Security Review — Standard tier

Situation

A healthcare technology provider preparing a mobile application for clinical use required a security review before distributing to practitioners. Regulatory readiness and patient data handling were identified as priorities by the client's leadership team.

What was in scope

Security review of a mobile clinical management application covering the application binary, its API communication layer, and the authentication and data storage implementation. iOS and Android builds reviewed within the agreed scope. Review conducted against OWASP Mobile Top 10 as the reference framework.

Timeline and working model

Review delivered within fourteen business days of receiving the agreed application builds and API documentation. All review conducted remotely. No production environment access required.

What was reviewed

  • Application binary and static analysis for known vulnerability patterns
  • API communication security including transport layer and authentication
  • Patient data storage approach and local device encryption
  • Authentication and session token management
  • Third-party SDK and library currency
  • Sensitive data handling across application lifecycle states

What was delivered

  • Mobile security review report with findings and severity classification
  • OWASP Mobile Top 10 coverage summary
  • Developer-ready remediation guidance for each finding
  • Data handling assessment with recommendations

What changed after the work

Development team addressed high and critical findings before distribution to clinical users. The review report was referenced during internal governance review. A care plan advisory engagement was initiated for scheduled review and written next actions, not ongoing application monitoring or response coverage.

Not included

×Backend infrastructure penetration testing×Review of third-party EMR integration security beyond the agreed API surface×Regulatory compliance certification or approval×Ongoing application monitoring after the review closed

Recommended next step

Monthly Security Advisory to maintain ongoing security posture, or re-assessment after major application version changes.

Web & App Security Review
Industry:FintechRegion: PhilippinesCompliance
Web & App Security Review
Web & App Security Review — Standard tier

Situation

A payments fintech preparing for a Bangko Sentral ng Pilipinas-related reporting cycle needed an independent security assessment of their mobile application. The app handled payment credentials and transaction data. Leadership needed a structured review to identify exposure before submitting operational documentation.

What was delivered

  • Mobile security review report with findings and severity classification
  • OWASP Mobile Top 10 coverage summary

4 ×

Recommended next step

Monthly Security Advisory for ongoing compliance posture support, or re-assessment after significant application version changes.

Web & App Security Review
Industry:SaaS / TechnologyRegion: SingaporeDue diligence
Web & App Security Review
Web & App Security Review — Standard tier

Situation

A SaaS company serving enterprise clients across selected markets was required by a new enterprise client to complete an independent security review of its API layer before a data processing agreement could be executed. The platform exposed customer data through a set of REST APIs and leadership needed a structured review to identify and remediate exposure before the contractual deadline.

What was delivered

  • API security review report with findings and severity classification
  • Developer-ready remediation guidance for each finding

4 ×

Recommended next step

Monthly Security Advisory for structured ongoing API and platform security, or re-assessment after major API version changes.

Web & App Security Review
Insurance TechnologyAustraliaRenewal
Web & App Security Review

An insurance technology company building a mobile insurance management application was approaching its annual insurance renewal cycle. The application handled policyholder data and renewal documentation. The team's underwriter requested a security review of the mobile application as part of the professional indemnity renewal process.

Operations & LogisticsIndonesiaGrowth
Web & App Security Review

A logistics technology company deploying a mobile driver and fleet management application to enterprise clients required a security review before enabling access for the enterprise fleet. The client's procurement team required independent security evidence of the mobile application before the enterprise deployment could proceed.

Education TechnologyThailandPre-launch
Web & App Security Review

An education technology company preparing to distribute its student learning application to institutional partners required a pre-distribution security review. The institutional partner's IT policy required independent security evidence before the application could be distributed to enrolled students.

Retail / ConsumerVietnamPre-launch
Web & App Security Review

A retail company preparing to launch a consumer mobile shopping application required a pre-launch security review. The application handled customer account credentials, order history, and payment initiation. The founding team wanted structured security evidence before enabling the first customer-facing release.

Property TechnologyHong KongDue diligence
Web & App Security Review

A property technology company building a mobile application for agent and landlord use was required by a major property developer partner to complete an independent security review before the application could be distributed to the developer's agent network. The application handled property listing data and agent access credentials.

Media & PublishingNew ZealandPre-launch
Web & App Security Review

A media company preparing to launch a consumer mobile application for news and content delivery required a pre-launch security review. The application handled subscriber account credentials and payment initiation for premium content access. The team required structured security evidence before enabling the public launch.

Advisory & Recovery
6

Advisory & Recovery

Ongoing advisory support and structured incident recovery for operational security teams.

Industry:Operations & LogisticsRegion: IndonesiaAdvisory
Monthly Security Advisory
Monthly Security Advisory — Standard tier

Situation

A logistics technology company scaling operations across multiple cities needed structured security guidance without the cost of a full-time security hire. The company had recently experienced a credential exposure incident and wanted systematic advisory support.

What was in scope

Ongoing monthly advisory covering the organisation's web platform, internal tooling, and team security practices. Advisory scope defined at onboarding and adjustable within agreed boundaries on a quarterly basis. Not a managed security service — advisory and guidance only.

Timeline and working model

Ongoing monthly engagement. Initial onboarding completed within one week of confirmation. Monthly advisory sessions on a fixed cadence. Engagement operates on a rolling monthly basis with quarterly scope review.

What was reviewed

  • Monthly review of security posture against agreed control set
  • Patch and update currency review for scoped systems
  • Access control and privilege review each quarter
  • Incident and alert review from client-provided logs
  • Team guidance on emerging threats relevant to the sector

What was delivered

  • Monthly advisory brief with observations and recommended actions
  • Quarterly posture summary report
  • Prioritised action list after each review cycle
  • Direct advisory channel for time-sensitive questions within scope

What changed after the work

The team implemented a structured patch review process using the monthly advisory brief as the operational guide. Access control issues identified in the first quarter were remediated before the next review cycle. The engagement continued on renewal after the initial three-month term.

Not included

×Active incident response or emergency support outside agreed advisory hours×Penetration testing or active security assessment×Managed detection and response or real-time monitoring×Security architecture design or implementation services

Recommended next step

Advisory renewal, or a scheduled baseline review for a more formal posture assessment.

Monthly Security Advisory
Industry:Retail / ConsumerRegion: ThailandAdvisory
Monthly Security Advisory
Monthly Security Advisory — Standard tier

Situation

A retail technology operator running a loyalty platform and e-commerce integration needed structured monthly security guidance as their data processing footprint expanded across multiple channels. The team had growing privacy obligations and wanted an advisory partner to maintain visibility without the cost of a dedicated security function.

What was delivered

  • Monthly advisory brief with observations and recommended actions
  • Quarterly posture summary with trend observations

4 ×

Recommended next step

Advisory renewal, or a structured App Security Review for the loyalty platform application layer.

Monthly Security Advisory
Industry:Technology / StartupRegion: New ZealandIncident
Incident Recovery Sprint
Incident Recovery Sprint — Standard tier

Situation

A SaaS startup discovered evidence of unauthorised access in their production environment following a credential stuffing incident. Customer data may have been exposed. The founding team needed immediate triage support, containment guidance, and a structured recovery roadmap before customer communication and regulatory notification deadlines.

What was delivered

  • Initial triage report with confirmed and suspected compromise scope
  • Visible risk map with prioritised immediate actions

5 ×

Discovery call recommended

Recommended next step

Monthly Security Advisory for structured ongoing security posture, or a Baseline Review after full recovery to assess control improvements.

Incident Recovery Sprint
FintechSingaporeAdvisory
Monthly Security Advisory

A fintech company operating a payments and lending platform initiated a Monthly Security Advisory engagement following a period of rapid product growth. The team had expanded their engineering headcount and onboarded several enterprise clients within a twelve-month period. Leadership identified the need for structured ongoing security visibility without the cost of a dedicated security hire.

Healthcare TechnologyPhilippinesIncident
Incident Recovery Sprint

A healthcare technology company discovered indicators of unauthorised access to a patient-facing application following unusual authentication activity reported by clinical staff. The founding team needed immediate triage support, containment guidance, and a structured recovery roadmap before the clinical partner notification deadline.

SaaS / TechnologyMalaysiaAdvisory
Monthly Security Advisory

A SaaS company scaling its B2B platform to serve regional enterprise clients initiated a Monthly Security Advisory engagement after an enterprise client's procurement team raised security posture questions during onboarding. The founding team needed structured ongoing security guidance to maintain credible security documentation for enterprise procurement cycles without a dedicated internal resource.

Ready to start a security engagement?

Most engagements start with a request. Share the service or scope you have in mind; we will confirm the right review, hardening or advisory path before any payment step.