Cybersecurity is about small, targeted moves: 20% of the right actions prevent 80% of the risk. Find your 20%: assess your exposure →

Case studies

Critical infrastructure, delivered

Banking, government, industry, SMBs and non-profits: an anonymized look at our work.

Banking

Zero Trust segmentation of a national banking network

Context

A flat network core carried twenty years of growth: one compromised endpoint could reach the payment systems.

Engagement

Full flow mapping, trust-zone definition, then a wave-by-wave cutover with validated rollback windows at every step.

Results
Payment systems isolated
Full traceability of cross-zone access
Audit file delivered to the regulator
0 service interruptions during migration
Government

Multi-site WAN migration for a public agency

Context

Heterogeneous links, end-of-life carrier contracts and no central visibility on actual site availability.

Engagement

A single target WAN architecture, site-by-site migration outside public service hours, central monitoring deployed ahead of cutover.

Results
Link costs reduced
Unified monitoring across all sites
No interruption to citizen services
40+ sites migrated in 9 months
Industry

High-density Wi-Fi and OT/IT convergence in a plant

Context

Connected forklifts and production terminals dropped their link in heavily steel-framed zones, causing line stoppages.

Engagement

On-site coverage survey, access-point resizing, then OT network segmentation and a full connected-asset inventory.

Results
Network-related line stoppages eliminated
OT networks isolated from office IT
Industrial asset inventory kept current
99.9% coverage across the entire site
SMB

Full RISS 360 rollout: manufacturer, 85 employees

Context

No formal security policy, untested backups, and compliance requirements discovered during a client tender.

Engagement

Assessment, activation of security features already included in their existing licences, org-wide MFA, supervised backups and a processing register.

Results
Law 25 compliance documented
Disaster recovery tested
Client tender won
4 months to reach Law 25 compliance
Non-profit

Technology standards upgrade

Context

Aging equipment, a fixed grant-funded budget and no internal IT resource to run the upgrade.

Engagement

Replacements prioritized by risk, equipment chosen for controlled total cost, and knowledge transfer to an internal owner.

Results
Endpoints and network renewed
Self-sufficient internal owner
Granted budget respected in full
100% of the granted budget respected
Banking

AIOps intelligent monitoring on critical infrastructure

Context

Thousands of daily alerts drowned the real signals; incidents were reported by users before IT teams saw them.

Engagement

Automated event correlation, dynamic thresholds learned from actual network behaviour, and service-oriented dashboards.

Results
Alert noise sharply reduced
Detection ahead of user impact
Incidents down 35% year over year
-35% incidents in one year

Work in environments where downtime is expensive

The projects below are anonymized at our clients' request, but the scopes, constraints and results are real. They share one trait: in each, a service interruption or a data leak would have carried a major direct, regulatory or reputational cost.

We systematically document the initial state, the architecture decisions and the measured results. That is what lets our clients justify their investments to a board, an auditor or a regulator.

Key points

  • Six documented engagements: banking, public sector, industry, smaller businesses and non-profits.
  • Anonymised at our clients' request, in sectors where the engagement itself is sensitive.
  • Each case states the initial state, the architectural decisions and the measured result.
  • Named references are provided on request, confidentially.

Why are your case studies anonymised?

Because in the banking and public sectors, disclosing that an organization has run a security programme is itself exploitable information. Anonymisation is our clients' requirement, not commercial reticence. The scopes, constraints and results remain accurate.

That reserve has a consequence we accept: at this stage of your thinking, you have to take our word for it. This is why we provide named references on request, confidentially, at an advanced stage of discussion, and why we arrange introductions to a comparable client when that client consents.

The figures in these cases come from our own engagement measurements. They are assertions by RISS Canada, verifiable with the clients concerned under a confidentiality agreement, and not data published by an independent third party. We prefer to say so rather than let the opposite be assumed.

How do you document an engagement?

In three systematic parts: the initial state as found, the architectural decisions with their trade-offs, then the measured results. This structure is not a communications exercise: it is what lets a client justify their investment to a board, an auditor or a regulator.

  • The initial state. A factual survey of the environment before intervention, including the assets the organization did not know it was exposing. Without that baseline, no result is demonstrable afterwards.
  • The architectural decisions. What was chosen, what was ruled out, and on what grounds. We document the options not taken, because that record is what prevents the debate reopening in two years with no memory of the constraints of the time.
  • The measured results. Compared against the initial state, on indicators defined before work started rather than chosen at the end to flatter the outcome.

What have you delivered in the banking sector?

Two engagements. A Zero Trust segmentation of a national network core carrying twenty years of growth, delivered without service interruption. And AI-assisted monitoring on critical infrastructure where incidents were reported by users before the technical teams noticed them.

  • Zero Trust segmentation of a national banking network. A flat network core where one compromised endpoint could reach the payment systems. Complete flow mapping, definition of trust zones, then a wave-by-wave cutover with a validated rollback window at every step. Result: payment systems isolated, full traceability of cross-zone access, audit file delivered to the regulator, no service interruption during the migration.
  • AIOps monitoring on critical infrastructure. Thousands of daily alerts were drowning the real signals. Automated event correlation, thresholds learned from actual network behaviour, service-oriented dashboards. Result: alert noise sharply reduced, detection ahead of user impact, incidents down 35% year over year.

And in the public sector and industry?

A multi-site WAN migration for a public agency, carried out outside public service hours. And an OT/IT convergence in a plant, where production terminals were losing their link in heavily steel-framed zones and causing line stoppages.

  • Multi-site WAN migration for a public agency. Heterogeneous links, end-of-life carrier contracts, no central visibility on actual site availability. A single target architecture, site-by-site migration outside service hours, central monitoring deployed ahead of cutover. Result: link costs reduced, unified monitoring, no interruption to citizen services, more than 40 sites migrated in 9 months.
  • High-density Wi-Fi and OT/IT convergence in a plant. Connected forklifts and production terminals were dropping their link in metal-framed zones. On-site coverage survey, access-point resizing, OT network segmentation and a full connected-asset inventory. Result: network-related line stoppages eliminated, OT networks isolated from office IT, industrial asset inventory kept current, 99.9% coverage across the site.

What do these methods produce for a smaller business or a non-profit?

The same principles, at a different scale and under a tighter budget constraint. In both cases below, the main gain came not from a purchase but from enabling what already existed and prioritising by real risk.

  • Full RISS 360 rollout at an 85-employee manufacturer. No formal security policy, untested backups, compliance requirements discovered during a client tender. Assessment, activation of security features already included in existing licences, organization-wide multi-factor authentication, supervised backups, processing register. Result: Law 25 compliance documented, disaster recovery tested, client tender won.
  • Technology standards upgrade at a non-profit. Aging equipment, a fixed grant-funded budget, no internal IT resource. Replacements prioritised by risk, equipment chosen for controlled total cost, knowledge transfer to an internal owner. Result: endpoints and network renewed, a self-sufficient internal owner, granted budget respected in full.

Sources

The results on this page are internal measurements by RISS Canada Inc., taken on real engagements and compared against a documented initial state. They describe what was achieved in a given context and constitute neither a guarantee nor a forecast for any other context.

Frequently asked questions

Yes, on request and confidentially, at an advanced stage of discussion. We do not publish names because in the banking and public sectors, disclosing the existence of a security programme is itself sensitive information, and our clients ask for that reserve. It is a frequent and legitimate request from a buyer: we handle it systematically before contracting, though never before understanding your context.

Yes, when the client concerned consents and your context is comparable in sector and size. It is often more useful than a list of logos: an executive at a manufacturing business gets answers from a counterpart that no brochure will give, particularly about how the work actually unfolded and what was difficult. We arrange these conversations without attending them where that is preferable.

It varies widely, deliberately. At one end, a one-off assessment for an organization of about fifteen people. At the other, a network core segmentation running several months with negotiated cutover windows. What our engagements have in common is not their size but their criticality: in each, a service interruption or a data leak would carry a direct, regulatory or reputational cost far exceeding that of the work.

No, and we say so plainly. These are our own engagement measurements, compared against an initial state surveyed before intervention. They are verifiable with the clients concerned under a confidentiality agreement. We do not present these results as data published by an independent body, and we extrapolate no promise from them: your context will produce its own results, which we will define with you before starting.

It depends on the engagement. Some concluded with a full knowledge transfer to internal teams, with documentation and training, which was the agreed objective. Others continue as managed monitoring or on-call coverage on critical components. Both outcomes are successes from our point of view: an architecture only the firm that built it can operate is a dependency, not a security improvement.

Is your infrastructure ready for the next threat?

An initial assessment, free and without commitment, to evaluate your security posture.

Home Expertise RISS 360 PME Assess