An enterprise-wide data protection assessment — clear enough to act on alone


An enterprise-wide data protection assessment — clear enough to act on alone
Case Study — Enterprise Data Protection Assessment | Small Robot

Customer Case Study · Data Protection

An enterprise-wide data protection
assessment — clear enough to act on alone

How Small Robot assessed the data protection posture of a leading Australian telecommunications provider across its entire enterprise, in a report clear enough for the client's own team to implement without further support.

Client name and logo withheld at the customer's request
Client
Leading Australian telecommunications provider
(name withheld)
Sector
Telecommunications
Engagement
Enterprise-wide data protection assessment
Duration
Approximately four weeks
Delivery
Recommendations self-implemented by the client

The starting point

A national telecommunications provider, holding customer data at a scale few sectors match, wanting a clear-eyed view of its data protection posture.

The client is one of Australia's leading telecommunications providers — a business that holds customer, billing and network data across millions of accounts, under privacy and telecommunications-sector obligations that make data protection a standing regulatory concern, not a one-off project.

Rather than assume existing controls and policy were keeping pace with the business, the client engaged Small Robot to assess its data protection posture across the entire enterprise — not a single business unit or system, the whole organisation.

The challenge

An enterprise-wide view is hard to get — and hard to act on once you have it.

Scale and fragmentation

A telecommunications enterprise of this size spans many systems, business units and data flows. An assessment scoped to "the whole enterprise" has to actually cover that ground, not sample a convenient slice of it.

Findings senior leadership would actually act on

An assessment is only useful if its findings are credible enough, and clear enough, for senior leadership to back — and specific enough for the client's own team to execute without needing the assessor back in the room.

What Small Robot did

Four weeks, enterprise-wide, three lenses on the same question.

  • Document and policy analysis. Reviewed data protection policies, standards and governance documentation against what the business's own obligations actually require.
  • Technical controls and configuration analysis. Assessed how data protection controls were actually configured and operating in practice, across the enterprise rather than a single system or team.
  • Senior and technical stakeholder interviews. Spoke with both executive stakeholders and technical staff, to understand where documented policy, technical reality and everyday practice agreed — and where they didn't.

The output was a single report of key findings and prioritised recommendations, covering the client's entire enterprise rather than a subset of it.

Delivered in one engagement

A single, defined assessment — not the start of an ongoing remediation programme.

WEEKS 1–2 Document & policy analysis WEEK 2–3 Technical controls & configuration analysis WEEK 3–4 Senior & technical stakeholder interviews WEEK 4 Report & recommendations DELIVERED. IMPLEMENTED BY THE CLIENT'S OWN TEAM.

Phase boundaries are illustrative of a typical four-week enterprise assessment.

The results

A report senior leadership backed — and the client's own team could run with.

4 weeksto assess data protection posture across the entire enterprise
Enterprise-widescope — the whole organisation, not a single business unit or system
Self-implementedrecommendations were clear and specific enough for the client's own team to execute directly
AreaBeforeAfter
Enterprise visibility No consolidated, independent view of data protection posture across the whole business Single enterprise-wide assessment covering policy, technical controls and practice
Leadership confidence Assumed adequacy of existing controls, untested independently Findings well received by senior leadership, with clear backing to act on them
Path to remediation No prioritised, actionable set of recommendations Recommendations specific enough for the client's own team to implement without further external support

Why this engagement looks different

Unlike a follow-on remediation engagement, Small Robot's role here ended at the report. That's not a gap in the story — the recommendations were actionable enough, and clear enough, that the client's own team took them from there.

Where things stand today

The assessment is complete and the report has been actioned by the client's own team. This was a defined, single engagement rather than an ongoing programme — a clean example of an assessment doing exactly what it was meant to do: give leadership a credible view of the real state of play, and give the team enough clarity to act on it themselves.