The context
Control frameworks applied across the Kingdom have changed what organisations are required to prove. It is no longer sufficient to hold security products. An entity must be able to name each control, identify its owner, produce its evidence, and demonstrate that it is enforced. Most security estates cannot answer those questions, because they were accumulated rather than designed.
A mid-sized financial services group had spent six years buying security products one incident at a time. A phishing wave produced an email gateway. A regulatory finding produced a data loss tool. A new CISO produced an endpoint platform to replace the one before it. None of it was wrong on its own. Together it had become unmanageable.
The symptom that forced a decision was not a breach. It was an audit. Preparing evidence for a regulatory review took the security team eleven working days, because no two systems reported in the same format and nobody could produce a single answer to a simple question: which controls are actually enforced, on which assets, right now.
The approach
That question is the real starting point. ITBuilders began with an inventory of enforced controls rather than purchased ones — the difference between the two is usually where the risk sits. In this environment the gap was wide. Three separate consoles held overlapping endpoint policy, two of them in monitor-only mode after a performance complaint from the business two years earlier. Nobody had turned them back on.
The first phase was assessment against a defined control baseline, mapped to the applicable regulatory domains so findings could be discussed in language the regulator and the board already shared. This matters more than it sounds. Security debt described in technical terms rarely gets funded. The same debt described as a named control gap, with a named owner, tends to move.
Architecture came next. The design principle was reduction: fewer enforcement points, each doing more, with policy defined once and applied consistently. Network segmentation was rebuilt around function and data sensitivity rather than the historical VLAN layout, which had been inherited from an office move. Identity became the primary control plane, with privileged access separated from daily-use accounts across both the on-premises estate and the group's cloud workloads.
Migration ran in overlap. Legacy controls stayed live while replacements were tuned against real traffic, with each cutover reversible until the security team signed off on detection parity. That extends the project. It also means the business never discovers a gap on the organisation's behalf.
The measurable change was not in threat volume. It was in time. Evidence for the following audit cycle came from a single reporting layer. Control ownership was documented and assigned. New applications now enter a defined onboarding path with security requirements attached at the start rather than discovered at go-live.
What changed
The less visible change was cultural. A security team that had spent its time reconciling consoles started spending it on risk reduction.
Continuity of operation
ITBuilders continues to maintain the control baseline, run the review cycle, and support evidence production at each audit. Consolidation is reversible. The same pressure that produced six years of point purchases still exists, and the only thing that prevents a return to it is a maintained architecture with an owner and a defined route for new requirements.



