Finding out where member data was actually at risk — then fixing it


Finding out where member data was actually at risk — then fixing it
Case Study — Data Protection & DLP Uplift | Small Robot

Customer Case Study · Data Protection

Finding out where member data was
actually at risk — then fixing it

How Small Robot assessed and is uplifting the data protection and data loss prevention capability of a leading Australian superannuation provider — turning a four-week assessment into an active remediation programme.

Client name and logo withheld at the customer's request
Client
Leading Australian superannuation provider
(name withheld)
Sector
Superannuation & financial services
Engagement
Data protection & DLP assessment and uplift
Assessment
Four weeks, completed
Remediation
In progress — 8+ weeks and ongoing

The starting point

A fund holding sensitive member data at scale, wanting an honest, independent view of how well it was actually protected.

The client is one of Australia's leading superannuation providers — an organisation that holds long-term financial and personal data for a large member base, under regulatory obligations that treat data protection as a standing requirement, not a project. That combination makes data loss prevention (DLP) a genuinely high-stakes capability: the cost of getting it wrong is measured in regulatory exposure and member trust, not just remediation effort.

Rather than assume its existing controls were adequate, the fund engaged Small Robot to independently assess its data protection and DLP posture — and to help close the gaps that assessment found.

The challenge

Understand the real state of data protection before deciding what to fix.

No independent baseline

Policy documents, technical controls and day-to-day practice don't always agree with each other. Without an independent assessment, the fund had no reliable way to know where its actual DLP exposure sat — only where policy said it should sit.

Strategic and tactical gaps, tangled together

Some issues were quick configuration fixes. Others were structural — the kind of gap that needs a programme of work, not a setting change. Both had to be identified and correctly separated before remediation could be prioritised sensibly.

What Small Robot did — the assessment

Four weeks, three lenses: what's written down, what's configured, and what people actually do.

  • Document and policy analysis. Reviewed the fund's data protection and DLP policies, standards and governance documentation against what good practice — and the fund's own regulatory obligations — actually require.
  • Technical controls and configuration analysis. Assessed how DLP and related data protection controls were actually configured and operating, not just how they were meant to work on paper.
  • Senior and technical stakeholder interviews. Spoke with both executive stakeholders — for direction, ownership and risk appetite — and technical staff — for how controls really get used day to day. The two views rarely match perfectly, and the gap between them is often where the real risk lives.

The output was a report of key findings and recommendations, structured so the fund could clearly separate quick wins — tactical fixes deliverable in weeks — from strategic recommendations — structural changes that would take longer and need sustained investment.

What Small Robot did — the remediation

An engagement that is still running, by design.

The findings report was the start of the work, not the end of it. Remediation has been underway for more than eight weeks and continues today, split deliberately into two tracks:

Quick wins & tactical recommendations — implemented Strategic recommendations — in progress
WEEKS 1–4 Assessment & report Remediation Quick wins & tactical fixes Complete Strategic recommendations ongoing → Week 8+ still in progress ASSESSMENT DONE. REMEDIATION CONTINUES.

Timeline reflects the described phases — a four-week assessment followed by an ongoing, two-track on-going remediation programme.

The results so far

4 weeksto complete the full assessment — policy, technical and stakeholder-based
8+ weeksof remediation delivered so far, with strategic work still underway
Enterprise-wideclearer direction and expectations for how data is handled and protected
AreaBeforeAfter
Independent baseline No independent view of DLP posture — reliant on internal assumptions Comprehensive baseline established via document, technical and stakeholder-based assessment
DLP detection & response Gaps in detection and response identified during the assessment Materially improved following quick-win implementation Complete
Direction & expectations Inconsistent understanding of data-handling expectations across the business Clearer direction and expectations now set, enterprise-wide Complete
Strategic controls Structural gaps identified in the assessment report Remediation underway In progress

Being clear about what's finished

The tactical work is done and already showing results. The strategic work is not — it is still being delivered and will be ongoing for some time, which is expected for an organisation of this size and structure.

In their words

“We are impressed with the outcomes produced by the team and our internal team are looking for more opportunities for us to work together.”

[Title only, no name] — Risk & Data Protection

Where things stand today

Quick wins and tactical recommendations are implemented and already delivering better DLP detection and response. Strategic remediation continues, more than eight weeks in, with Small Robot still engaged alongside the fund's own team to see it through. This is an active engagement, not a closed case study.