All case studies
ConsultingRepresentative engagement

Turning a Compliance Deadline Into a Programme

A representative engagement, drawn from the environments ITBuilders works in across the Kingdom.

The context

Regulatory scope in the Kingdom has widened, and the number of organisations holding formal cybersecurity obligations has grown accordingly. Many are meeting a structured control framework for the first time. The common failure is not technical incapacity. It is treating a framework as a list of defects to be repaired rather than an operating model to be adopted.

An organisation subject to NCA ECC-2:2024 requirements had received its assessment findings and had a remediation deadline. The internal response had been to assign each finding to a technical owner and request a fix. Six months later, progress reporting showed most items in progress and few closed.

The cause was structural. A significant share of the findings were not technical problems. They were governance problems expressed in technical language — absent ownership, undocumented process, no defined review cycle — and they had been assigned to engineers who could not resolve them from where they sat.

The approach

ITBuilders re-scoped the work as a programme rather than a remediation list. The first step was classification: which findings required technical implementation, which required documented process, which required a governance decision, and which required all three in a specific order. Roughly a third of open items were blocked behind a decision that had never been escalated, because it had never been recognised as a decision.

Ownership was then assigned at the level capable of resolving each item, with technical implementation sequenced after the governance decisions it depended on. This reordering closed several items within weeks that had been open for months.

A control baseline was established covering the full regulatory scope, mapped to the organisation's actual environment rather than a generic framework, so that each control had a named owner, a defined evidence source and a review cycle. Where controls were partially implemented, the gap was documented specifically rather than marked as in progress, because a vague status is indistinguishable from no status during an audit.

The remediation roadmap was sequenced by risk and dependency, with realistic effort estimates, and presented to the executive committee in terms of residual risk per quarter rather than item counts. This changed the funding conversation.

Alongside remediation, the programme established the operating rhythm the framework assumes exists: periodic control review, defined change governance, and an evidence process that produces audit material continuously rather than in a scramble before each assessment.

What changed

The organisation met its remediation deadline on the items carrying regulatory consequence, with documented evidence for each. More usefully, it now runs a compliance function that maintains its own position rather than rebuilding it before every review.

Continuity of operation

ITBuilders remains engaged through the review cycle — maintaining the control baseline as the environment and the regulatory scope change, supporting evidence production, and advising at the governance level where a control's owner sits above the technical team. Compliance is a position that has to be held continuously, and the organisations that struggle most are the ones that treated the first audit as the finish line.

Your next step

Facing a similar challenge?

Talk to ITBuilders about the constraints, priorities and operating requirements of your environment.

Start a conversation