Case Studies

Real engagements. Specific outcomes. Every case study below describes work GarrisonOne has done for small and mid-size organizations — with details adjusted to protect client confidentiality.

8
Published Case Studies
4
Service Areas Covered
10–140
Employee Range
6
Industries Represented

Recent Engagements

All IAM Pentest Cloud Assessment
IAM Implementation

Regional Accounting Firm

100%
Individual accounts
MFA
All systems
Zero
Shared credentials

35 employees. Shared credentials across financial apps, no MFA, manual offboarding. Full IAM framework + secure Microsoft 365 migration.

Read Case Study
Healthcare IAM & HIPAA

Independent Medical Practice

100%
Individual EHR accounts
HIPAA
Risk analysis done
MFA
Clinical systems

7 providers. Shared EHR logins, no audit trail, HIPAA risk analysis never completed. Role-based access + HIPAA documentation.

Read Case Study
Web Application Pentest

E-Commerce Retailer

3
Critical findings
SQL
Injection found
30d
Full remediation

22 employees. In-house platform, never tested. SQL injection, unauthenticated admin panel, 3 vulnerable plugins. Vendor requirement satisfied.

Read Case Study
Network Assessment & Pentest

Regional Law Firm

3
Ghost accounts found
1
RCE vulnerability
3
Client requirements met

45 employees. Former employee accounts still active, RCE vulnerability on live server, no network segmentation. Attestation letter produced.

Read Case Study
AWS Cloud Security

SaaS Startup

4
Critical findings
Zero
Public S3 buckets
2
Deals unblocked

18 employees. Public S3 buckets, wildcard IAM roles, no CloudTrail. Two enterprise procurement reviews stalled on security docs — both closed.

Read Case Study
Security Assessment Program

Building Materials Distributor

19
Gaps found
16
Closed in 90 days
1st
Security policy ever

48 employees. No formal security program, 10-year-old environment, no backup testing. First-ever security assessment and 90-day remediation program.

Read Case Study
Identity Governance & JML

Multi-Site Specialty Clinic Group

75%
Faster onboarding
50%
Fewer tickets
Auto
Offboarding

90 employees, 3 locations. Manual onboarding, dormant accounts, HIPAA audit findings. Automated JML, RBAC, privileged access controls.

Read Case Study
SSO & MFA Modernization

Regional Retail & E-Commerce Co.

65%
Fewer helpdesk tickets
12+
Apps under SSO
Zero
Lingering contractor access

140 employees. 12+ disconnected apps, phishing wave in progress, contractors with lingering access. SSO, MFA, and automated contractor lifecycle.

Read Case Study