Establishing the position
The work began with understanding the existing arrangements and the concerns that had prompted the review. The aim was to give the company a clear account of what needed attention.
Agreeing priorities
The advice put the weaknesses in context, considering their significance and the order in which they should be addressed. This gave those responsible a basis for discussing the work with their IT provider.
Providing a roadmap
The roadmap set out a considered route to improvement, with attention to responsibility and oversight. The focus was on helping the company make informed decisions about its security and the work required.