<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Resilience | InConsult</title>
	<atom:link href="https://inconsult.com.au/case-study-category/cyber-resilience/feed/" rel="self" type="application/rss+xml" />
	<link>https://inconsult.com.au</link>
	<description>Helping you confidently take risks</description>
	<lastBuildDate>Wed, 24 Jun 2026 06:53:46 +0000</lastBuildDate>
	<language>en-AU</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://inconsult.com.au/wp-content/uploads/2021/06/cropped-favicon-3-32x32.jpg</url>
	<title>Cyber Resilience | InConsult</title>
	<link>https://inconsult.com.au</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Third Party Risk Management Assurance for Major Insurer</title>
		<link>https://inconsult.com.au/case-study/third-party-risk-management-assurance-for-major-insurer/</link>
		
		<dc:creator><![CDATA[William Makdessi]]></dc:creator>
		<pubDate>Tue, 04 Nov 2025 00:56:11 +0000</pubDate>
				<guid isPermaLink="false">https://inconsult.com.au/?post_type=case_study&#038;p=14288</guid>

					<description><![CDATA[<p>InConsult strengthened a multinational insurer's third party risk program — delivering passive vulnerability scanning, bespoke vendor assessments aligned to APRA CPS 234/230, and year-on-year cohort reporting to support executive and regulatory oversight.</p>
The post <a href="https://inconsult.com.au/case-study/third-party-risk-management-assurance-for-major-insurer/">Third Party Risk Management Assurance for Major Insurer</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<h1><span style="color: #0092c5;">Case Study: Facilitating Third Party Risk Management for Insurer Regulatory Assurance</span></h1>
<hr />
<h2>THE CHALLENGE</h2>
<p data-start="211" data-end="749">A large multinational insurer engaged InConsult to strengthen its third party risk management (TPRM) program and gain a transparent, year-on-year view of vendor information security capability, modern slavery obligations and operational risk management processes. Key drivers included: clearer alignment with prudential regulation expectations for service-provider oversight (APRA CPS 234/230), better evidence collection aligning with auditing standards and to provide sufficient assurance, and external visibility of vendors’ exposed attack surface through vulnerability assessments.</p>
<p data-start="751" data-end="832">The existing process included basic questionnaires and some attestations, but lacked:</p>
<ul data-start="833" data-end="1142">
<li data-start="833" data-end="912">
<p data-start="835" data-end="912">independent passive vulnerability / external attack-surface visibility,</p>
</li>
<li data-start="913" data-end="999">
<p data-start="915" data-end="999">bespoke assurance questionnaires tuned to different vendor tiers and services,</p>
</li>
<li data-start="1000" data-end="1064">
<p data-start="1002" data-end="1064">consistent evidence trails for control verification, and</p>
</li>
<li data-start="1065" data-end="1142">
<p data-start="1067" data-end="1142">comparative reporting showing cohort trends and year-on-year changes.</p>
</li>
</ul>
<h2>OUR APPROACH</h2>
<p data-start="1162" data-end="1303">We delivered a comprehensive, evidence-based third party risk management uplift including the complete end-to-end facilitation of the program to truly define supply-chain risk:</p>
<ul>
<li data-start="1307" data-end="1723"><strong data-start="1307" data-end="1347">Program Design &amp; Standards Alignment: </strong>Mapped the insurer’s TPRM processes to APRA CPS 234 (information security, including third parties) and CPS 230 (operational risk and service providers), and considered international supply-chain standards (e.g. ISO/IEC 27036) to structure controls, evidence and assurance activities.</li>
<li data-start="1307" data-end="1723"><strong data-start="1727" data-end="1768">Third Party Ecosystem, Tiering &amp; Bespoke Assessments: </strong>Confirmed vendor details, services, data sensitivity and criticality, assigned tiers and set tier-based assessments combining questionnaires, workshops, external scanning and targeted evidence requests (e.g., ISO 27001 certificates, penetration test reports, backup/MFA configurations).</li>
<li data-start="1307" data-end="1723"><strong data-start="2184" data-end="2244">Passive Vulnerability Scanning of External Attack Surface: </strong>Performed non-intrusive scanning to identify exposed services, weak configurations and stale assets for in-scope vendors, aligned with the Open Worldwide Application Security Project (OWASP) vulnerabilities database. Findings fed into each vendor’s risk profile and remediation recommendations.</li>
<li data-start="1307" data-end="1723"><strong data-start="2569" data-end="2605">Bespoke Assurance Questionnaires: </strong>Built tier-specific questionnaires leveraging prudential standard requirements that the insurer is required to comply with internally and across their supply chain. Designed scoring and an easy-to-follow risk rating matrix for identified weaknesses.</li>
<li data-start="1307" data-end="1723"><strong data-start="2905" data-end="2952">Facilitated Workshops &amp; Evidence Collection: </strong>Ran multi-hour workshops with high-dependency vendors to validate responses, walk through configurations, and agree remediation timelines. Collected artefacts to create defensible audit-quality workpapers mapped to each control and risk theme.</li>
<li data-start="1307" data-end="1723"><strong data-start="3291" data-end="3330">Reporting, Scoring &amp; Trend Analysis: </strong>Issued a customised report to each vendor and a portfolio summary report for the insurer showing cohort performance, heat-maps, trend lines versus prior years, and prioritised recommendations. Prioritised residual risks based on severity, regulatory implications, costs, time to rectify and our experience as risk management experts.</li>
</ul>
<h2>OUTCOMES &amp; BENEFITS</h2>
<p data-start="2025" data-end="2055">As a result of our engagement:</p>
<ul>
<li data-start="3677" data-end="3937">
<p data-start="3679" data-end="3937"><strong data-start="3679" data-end="3723">Enterprise-Wide View of Third-Party Risk</strong><br data-start="3723" data-end="3726" />A consolidated view and summary report covering all vendors with tier-based grades, material issues, and remediation status, supporting executive and audit/risk committee oversight.</p>
</li>
<li data-start="3938" data-end="4190">
<p data-start="3940" data-end="4190"><strong data-start="3940" data-end="3975">Independent External Visibility</strong><br data-start="3975" data-end="3978" />Passive scanning surfaced misconfigurations and exposed services missed by self-attestations, enhancing remediation and reducing time-to-detect for vendor weaknesses.</p>
</li>
<li data-start="4191" data-end="4436">
<p data-start="4193" data-end="4436"><strong data-start="4193" data-end="4226">Stronger Evidence &amp; Assurance</strong><br data-start="4226" data-end="4229" />Complete workpapers tied to recognised supply-chain standards to give internal audit and regulators confidence in the control assessments.</p>
</li>
<li data-start="4437" data-end="4627">
<p data-start="4439" data-end="4627"><strong data-start="4439" data-end="4469">Year-on-Year Comparability</strong><br data-start="4469" data-end="4472" />Vendor and cohort trend analysis showed measurable improvement against the previous year, with risk-based sequencing of “next best” actions per vendor.</p>
</li>
<li data-start="4628" data-end="4818">
<p data-start="4630" data-end="4818"><strong data-start="4630" data-end="4653">Trusted Partnership</strong><br data-start="4653" data-end="4656" />The structured, transparent approach strengthened the insurer’s confidence in InConsult as a trusted provider for ongoing third party risk management assurance and uplift initiatives.</p>
</li>
</ul>
<p>Would you like to know more about our cyber resilience services? <a title="Contact Us" href="/contact-us/">Contact us</a> today.</p>
<p><em>This case study is drawn from a real-life engagement/project between InConsult and our client. While client details are not disclosed for commercial and confidentiality reasons, this case study is based on a real engagement and reflects genuine results and outcomes. Specific client references and project details can be shared with prospective clients during the proposal process.</em></p>The post <a href="https://inconsult.com.au/case-study/third-party-risk-management-assurance-for-major-insurer/">Third Party Risk Management Assurance for Major Insurer</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Essential Eight Auditing in Local Government</title>
		<link>https://inconsult.com.au/case-study/essential-eight-auditing-in-local-government/</link>
		
		<dc:creator><![CDATA[William Makdessi]]></dc:creator>
		<pubDate>Mon, 03 Nov 2025 21:54:59 +0000</pubDate>
				<guid isPermaLink="false">https://inconsult.com.au/?post_type=case_study&#038;p=14282</guid>

					<description><![CDATA[<p>InConsult delivered the first comprehensive Essential Eight audit for a NSW council serving 40,000+ residents — confirming ASD Maturity Level One compliance and providing a clear remediation roadmap aligned to Cyber Security NSW guidelines.</p>
The post <a href="https://inconsult.com.au/case-study/essential-eight-auditing-in-local-government/">Essential Eight Auditing in Local Government</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<h1><span style="color: #0092c5;">Case Study: Applying the Cyber NSW Cyber Security Guidelines for Local Government</span></h1>
<hr />
<h2>THE CHALLENGE</h2>
<p>A NSW Local Government agency serving more than 40,000 residents within a high-density region wanted independent assurance over its cyber posture and a clear, evidence-based path to reach its targeted Essential Eight (E8) Maturity Level One as set out in its Information Security Strategy. The agency needed an audit aligned to the <strong data-start="619" data-end="690">Cyber Security NSW – Cyber Security Guidelines for Local Government</strong> and to be assessed against the Australian Signals Directorate (ASD) Essential Eight assessment guidelines, so executives and auditors could rely on the results for planning and reporting.</p>
<p>For the Local Government agency, this was the first ever comprehensive E8 audit that would reveal any potential shortfalls after many months of uplift and late nights.</p>
<h2>OUR APPROACH</h2>
<p data-start="1347" data-end="1565">InConsult delivered a structured audit and assessment program combining workshops, technical validation and comprehensive documentation:</p>
<ul data-start="1567" data-end="3033">
<li data-start="1567" data-end="1833">
<p data-start="1569" data-end="1833"><strong data-start="1569" data-end="1592">Scoping &amp; Alignment: </strong>Defined the audit scope against the Cyber Security NSW – Local Government Guideline control set and mapped each control to the ASD Essential Eight maturity criteria and assessment methods.</p>
</li>
<li data-start="1835" data-end="2399">
<p data-start="1837" data-end="1994"><strong data-start="1837" data-end="1873">Facilitated Multi-Hour Workshops: </strong>Ran detailed, multi-hour workshops with IT Operations to:</p>
<ul data-start="1997" data-end="2399">
<li data-start="1997" data-end="2255">
<p data-start="1999" data-end="2255">Validate current state for the eight mitigation strategies (application control, patching applications/OS, Microsoft Office macro settings, user application hardening, restricting admin privileges, MFA, and backups).</p>
</li>
<li data-start="2258" data-end="2348">
<p data-start="2260" data-end="2348">Elicit evidence paths, data sources and system configurations for each target control.</p>
</li>
<li data-start="2351" data-end="2399">
<p data-start="2353" data-end="2399">Agree on required evidence, sampling volumes and special terms for review of highly sensitive content.</p>
</li>
</ul>
</li>
<li data-start="2401" data-end="2845">
<p data-start="2403" data-end="2845"><strong data-start="2403" data-end="2442">Evidence-Based Testing &amp; Workpapers: </strong>Executed ASD-aligned assessment procedures (configuration reviews, sample-based testing, artifact walkthroughs and spot checks). Produced complete audit workpapers directly aligned to ASD’s Essential Eight Assessment Process Guide, including test steps, results, screenshots and residual risk notes, creating a robust audit trail from requirement to evidence.</p>
</li>
<li data-start="2847" data-end="3033">
<p data-start="2849" data-end="3033"><strong data-start="2849" data-end="2880">Findings, Ratings &amp; Roadmap: </strong>Issued an audit report with clear control ratings, maturity mapping, and remediation recommendations prioritised by risk, effort and dependencies.</p>
</li>
</ul>
<h2>OUTCOMES &amp; BENEFITS</h2>
<p data-start="2025" data-end="2055">As a result of our engagement:</p>
<ul>
<li data-start="2059" data-end="2215"><strong data-start="3062" data-end="3117">Target Achieved: Essential Eight Maturity Level One: </strong>The agency achieved E8 Maturity Level One, meeting its strategic target with documented, repeatable evidence aligned to ASD guidance, providing confidence to executives, audit &amp; risk committee members and external stakeholders.</li>
<li data-start="2059" data-end="2215"><strong data-start="3386" data-end="3424">Assurance Over Guideline Alignment: </strong>Verified alignment to the Cyber Security NSW – Local Government Guideline, strengthening their policy-to-control traceability and reporting confidence.</li>
<li data-start="2059" data-end="2215"><strong data-start="3634" data-end="3663">Clear, Actionable Remediation: </strong>Prioritised remediations sharpened focus on near-term controls (e.g., admin privilege management, MFA coverage and backup processes).</li>
<li data-start="2059" data-end="2215"><strong data-start="3891" data-end="3919">Strengthened Partnership: </strong>The quality of our workpapers, facilitation and practical recommendations enhanced our standing as a trusted provider, setting the foundation for ongoing advisory and periodic reassessments.</li>
</ul>
<p>Would you like to know more about our cyber resilience services? <a title="Contact Us" href="/contact-us/">Contact us</a> today.</p>
<p><em>This case study is drawn from a real-life engagement/project between InConsult and our client. While client details are not disclosed for commercial and confidentiality reasons, this case study is based on a real engagement and reflects genuine results and outcomes. Specific client references and project details can be shared with prospective clients during the proposal process.</em></p>The post <a href="https://inconsult.com.au/case-study/essential-eight-auditing-in-local-government/">Essential Eight Auditing in Local Government</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
