Example Engagements

Real outcomes. Anonymized for trust.

A snapshot of typical Cyberactics engagements across MDR, infrastructure, Microsoft 365, SIEM, and vulnerability programmes - with the problem, approach, and measurable results behind each.

  • Healthcare MDR & Email Security

    Healthcare Provider (HIPAA-aligned), 100 users

    Scope
    12-week project + ongoing managed service
    Engagement Model
    Secure Tier

    Problem

    Legacy email gateway with no threat analysis and no endpoint detection on clinical workstations, leaving the practice exposed to ransomware targeting healthcare providers.

    Solution

    Advanced MDR with behavioral analysis across 70 clinical and 12 admin endpoints; email gateway replacement with sandboxing and URL rewriting; phased rollout designed around patient-care operations.

    Outcomes

    • 87% reduction in phishing incidents within 90 days
    • 99.2% SOC uptime SLA for threat detection
    • Regulatory readiness for annual HIPAA audit
    • Healthcare
    • MDR
    • Email Security
    • HIPAA
  • Multi-Site Firewall & VPN Standardization

    Manufacturing SMB, 5 sites (KSA + UAE), 150 users

    Scope
    8-week project + ongoing firewall management
    Engagement Model
    Complete Tier

    Problem

    Three different firewall vendors, no centralized policy enforcement, poorly documented VPN rules, and a compliance audit flagging shadow-IT risks across regional offices.

    Solution

    Unified FortiGate-based perimeter across 5 sites with single-pane policy management, site-to-site IPsec with auto-failover, and audit log streaming into a central SIEM with documented change control.

    Outcomes

    • 40% reduction in firewall rule overhead
    • 100% policy consistency across all sites
    • Failover recovery improved from 2 hours to 15 minutes
    • Manufacturing
    • Firewall
    • VPN
    • KSA
    • UAE
  • Microsoft 365 Hardening & Cloud Backup

    Financial Services SMB (KSA), 75 users

    Scope
    2-year ongoing engagement
    Engagement Model
    Secure Tier

    Problem

    Basic Microsoft 365 defaults with no enforced MFA, no immutable backup for ransomware recovery, and a prior data-loss incident from SharePoint oversharing.

    Solution

    Identity-first Zero Trust model with FIDO2/Windows Hello MFA, risk-based conditional access, SharePoint external sharing governance, Exchange DLP mail flow rules, and immutable Azure backup with 30-day retention.

    Outcomes

    • 100% MFA adoption within 2 weeks
    • Zero data-loss incidents over 18 months
    • 4-hour ransomware recovery capability demonstrated
    • Passed SAMA/NCA-aligned regulatory security review
    • Finance
    • Microsoft 365
    • Zero Trust
    • SAMA
    • NCA
  • SIEM Deployment & 24/7 SOC Integration

    Energy Sector Enterprise, 400 users (Regional HQ + 3 sites)

    Scope
    6-month project + managed 24/7 SOC
    Engagement Model
    Complete Tier

    Problem

    No centralized logging, security events scattered across systems, CISO-reported blind spots in threat visibility, and audit findings on log-retention compliance.

    Solution

    Cloud SIEM ingesting logs from firewalls, servers, endpoints, and cloud services; 24/7 SOC monitoring with escalation playbooks; CVSS-based risk dashboards and monthly executive reporting on incident trends, dwell time, and remediation velocity.

    Outcomes

    • 24-hour mean dwell time (industry average 200+ days)
    • 100% log-retention audit compliance
    • 70% reduction in analyst false positives via automated enrichment
    • 60% faster incident response
    • Energy
    • SIEM
    • SOC
    • Executive Reporting
  • Risk-Based Vulnerability Management

    Telecom SMB (UAE), 200 users + 40 servers

    Scope
    18-month ongoing managed service
    Engagement Model
    Secure Tier

    Problem

    Ad-hoc patching with no prioritization framework, CVSS-only scoring treating everything as urgent, manual remediation tracking with no accountability, and an audit deadline six months out.

    Solution

    Weekly authenticated internal and edge scans with live asset inventory sync; risk prioritization combining CVSS, exploit availability, and asset criticality; automated remediation ticketing with SLA tracking; targeted patch-testing labs for critical systems.

    Outcomes

    • Critical remediation time reduced from 120 days to 18 days
    • 94% scan coverage (from 60%)
    • Medium/low backlog eliminated
    • Audit passed with exception-based remediation policy approved
    • Telecom
    • Vulnerability Management
    • UAE
    • Audit