<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Case Studies on Thompson InfoSec</title>
    <link>https://thompsoninfosec.com/case-studies/</link>
    <description>Recent content in Case Studies on Thompson InfoSec</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>© 2026 Jonathan Thompson</copyright>
    <lastBuildDate>Sat, 28 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://thompsoninfosec.com/case-studies/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Google Workspace Security Assessment</title>
      <link>https://thompsoninfosec.com/case-studies/google-workspace-security-assessment/</link>
      <pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate>
      
      <guid>https://thompsoninfosec.com/case-studies/google-workspace-security-assessment/</guid>
      <description>&lt;div style=&#34;display: grid; grid-template-columns: repeat(auto-fit, minmax(150px, 1fr)); gap: 1rem 2rem; padding: 1.5rem 1.75rem; margin: 1.5rem 0; background: rgba(34, 211, 238, 0.04); border-top: 3px solid #22d3ee; border-radius: 0.5rem;&#34;&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Industry&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;Public Technology Company&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Scope&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;89 CIS controls + extended checklist&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Framework&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;CIS Google Workspace Foundations&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;div style=&#34;margin: 0 0 2.5rem; padding: 1.25rem 1.75rem; background: linear-gradient(160deg, #0a1628 0%, #1b2d4f 50%, #1e3a5f 100%); border-radius: 0.5rem;&#34;&gt;&#xA;  &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.5rem;&#34;&gt;The Outcome&lt;/div&gt;&#xA;  &lt;div style=&#34;color: #ffffff; font-size: 1.0625rem; line-height: 1.55;&#34;&gt;33 prioritized findings (5 critical, 11 high, 17 medium) with a tiered remediation roadmap covering OAuth hygiene, admin sprawl, DMARC enforcement, and AI controls.&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;The Challenge&#xA;    &lt;div id=&#34;the-challenge&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#the-challenge&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;A publicly traded technology company had never had an independent security review of its Google Workspace environment. The tenant had grown organically: administrators were added as needed, third-party applications were connected without formal approval, and configuration decisions were made reactively rather than against a security baseline. The company needed a clear picture of its exposure and a prioritized path to remediation.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>ISO 27001 Certification From Disarray to First-Try Pass</title>
      <link>https://thompsoninfosec.com/case-studies/iso-27001-certification/</link>
      <pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate>
      
      <guid>https://thompsoninfosec.com/case-studies/iso-27001-certification/</guid>
      <description>&lt;div style=&#34;display: grid; grid-template-columns: repeat(auto-fit, minmax(150px, 1fr)); gap: 1rem 2rem; padding: 1.5rem 1.75rem; margin: 1.5rem 0; background: rgba(34, 211, 238, 0.04); border-top: 3px solid #22d3ee; border-radius: 0.5rem;&#34;&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Industry&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;Regulated Technology&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Engagement&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;6 months&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Frameworks&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;ISO 27001, SOC 2, HIPAA, HITRUST&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;div style=&#34;margin: 0 0 2.5rem; padding: 1.25rem 1.75rem; background: linear-gradient(160deg, #0a1628 0%, #1b2d4f 50%, #1e3a5f 100%); border-radius: 0.5rem;&#34;&gt;&#xA;  &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.5rem;&#34;&gt;The Outcome&lt;/div&gt;&#xA;  &lt;div style=&#34;color: #ffffff; font-size: 1.0625rem; line-height: 1.55;&#34;&gt;First-try ISO 27001 pass with zero major nonconformities. SOC 2 and HIPAA completed on the same timeline. Policy library consolidated from 45 to 25.&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;The Challenge&#xA;    &lt;div id=&#34;the-challenge&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#the-challenge&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;A regulated technology company found itself without dedicated GRC staff, six months before a scheduled ISO 27001 certification audit. The ISMS had fallen into disarray: governance meetings had gone dormant, policies had proliferated without coherence, evidence collection processes had broken down, and several required technical controls were either missing or incomplete.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>Multi-Site Network Security Assessment</title>
      <link>https://thompsoninfosec.com/case-studies/network-security-assessment/</link>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate>
      
      <guid>https://thompsoninfosec.com/case-studies/network-security-assessment/</guid>
      <description>&lt;div style=&#34;display: grid; grid-template-columns: repeat(auto-fit, minmax(150px, 1fr)); gap: 1rem 2rem; padding: 1.5rem 1.75rem; margin: 1.5rem 0; background: rgba(34, 211, 238, 0.04); border-top: 3px solid #22d3ee; border-radius: 0.5rem;&#34;&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Industry&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;Regulated Technology&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Scope&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;3 continents · multi-site firewalls · colo + AWS&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;  &lt;div&gt;&#xA;    &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.25rem;&#34;&gt;Drivers&lt;/div&gt;&#xA;    &lt;div style=&#34;font-size: 0.95rem; font-weight: 500;&#34;&gt;First independent network review · upcoming compliance&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;div style=&#34;margin: 0 0 2.5rem; padding: 1.25rem 1.75rem; background: linear-gradient(160deg, #0a1628 0%, #1b2d4f 50%, #1e3a5f 100%); border-radius: 0.5rem;&#34;&gt;&#xA;  &lt;div style=&#34;color: #22d3ee; font-size: 0.7rem; font-weight: 700; letter-spacing: 0.12em; text-transform: uppercase; margin-bottom: 0.5rem;&#34;&gt;The Outcome&lt;/div&gt;&#xA;  &lt;div style=&#34;color: #ffffff; font-size: 1.0625rem; line-height: 1.55;&#34;&gt;First unified view of network security risk across all environments. Top two findings actionable within days. Full 6-month remediation roadmap aligned to operational capacity.&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;The Challenge&#xA;    &lt;div id=&#34;the-challenge&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#the-challenge&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;A regulated technology company with operations across three continents had grown its network infrastructure organically over several years. The environment included next-generation firewalls at several office locations, a colocation data center, and an AWS account supporting cloud-hosted security appliances and remote analyst access. The company had no recent independent review of its network security posture and needed an assessment ahead of upcoming compliance requirements.&lt;/p&gt;</description>
      
    </item>
    
  </channel>
</rss>
