TerraQuest

Case Study

TerraQuest is a trusted organisation renowned for its expertise in providing innovative and cost-effective data management solutions to the public and private sectors. TerraQuest delivers bespoke, flexible, and efficient services through a process-oriented delivery structure. They pride themselves on strong customer relationships, evidenced by a high proportion of referrals and repeat business.

The Challenge

Established over 50 years ago, TerraQuest is a trusted organisation renowned for its expertise in providing innovative and cost-effective data management solutions to the public and private sectors. TerraQuest delivers bespoke, flexible, and efficient services through a process-oriented delivery structure. They pride themselves on strong customer relationships, evidenced by a high proportion of referrals and repeat business.

As an ISO 27001:2022 certified business, TerraQuest already has a well-embedded Information Security Management System and operates a Secure by Design approach to all internal and client-facing projects. With most of its services hosted in the cloud and managed by its in-house DevOps team, the need for a more innovative approach to security was identified. Traditional boundaries needed to be challenged to enhance further TerraQuest’s security posture in an ever-changing security landscape.

TerraQuest required a cybersecurity partner who could work closely with their business to provide technical and information assurance support and help build a robust governance framework to support current and future initiatives.

The Solution

Aristi was selected as TerraQuest’s partner to provide Cyber Security as a Service (CSaaS) over a multi-year period.

Aristi’s service was tailored to TerraQuest’s specific needs and included:

  • Continuous vulnerability and penetration testing to provide a holistic view of the security posture of the target systems
  • Physical security assessments to help identify and manage physical security risks
  • Social engineering assessments to support user awareness of attacks such as phishing
  • Cyber resilience exercises to assess and help improve security incident response processes
  • Business continuity assessments to assess and help improve business resilience
  • Information Assurance guidance for ISO 27001, GDPR, and risk management
  • Aristi subject matter experts attending TerraQuest’s internal Security Design Authority meetings to help embed good security practices and build a security governance framework

A dedicated delivery team was established, and a delivery plan and a Ways of Working process were created. These included secure data sharing and monthly technical and service reviews.

The Outcome

Aristi and TerraQuest operate as a collaborative team, and the two businesses have built an excellent working relationship. Several benefits have already been realised, including:

  • A comprehensive, up-to-date view of the security posture is now available to TerraQuest, allowing for more effective remediation. In comparison, the traditional approach of annual testing left a window of 11 months before knowing if any new security vulnerabilities existed within the IT estate
  • Ongoing access to Aristi’s team of NCSC-assured cybersecurity experts complements TerraQuest’s in-house technical expertise
  • Aristi consultants are supporting TerraQuest’s in-house activities, such as risk management training for the board, helping with the transition to the new ISO 27001 standard, as well as client-facing activities, such as being part of TerraQuest’s delivery team as independent security advisors
  • Cybersecurity is becoming the norm. The culture of the business is changing, and security is becoming part of business as usual

Testimonials

"Aristi’s independent consultancy has been instrumental in supporting the complex needs of our clients. The level of assurance they provide to us, and our clients is a testament to their understanding and commitment to ethical considerations and our business.

Aristi has shown a solid commitment to working with our team and ensuring that we maintain the high standards they adhere to. Their contributions have been invaluable to collaborative projects, enhancing our team dynamics and security stance. Aristi's ability to communicate complex technical issues clearly and effectively has allowed us to quickly identify and resolve critical vulnerabilities."

Adam Masters
Information Security Manager
TerraQuest

Telephone
0121 222 5630
E-mail
info@aristi.co.uk

Got an enquiry? Please don't hesitate to contact us.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Our Services

Cyber Security

We support public and private sector organisations to reduce their cyber exposure.

To find out more, click the read more button below. Or, alternatively please get in touch.

Our Services

Managed Security

We can manage your cyber security and data protection for you.

To find out more, click the read more button below. Or, alternatively please get in touch.

Our Services

Training

We provide training courses for key roles and general user security awareness.

To find out more, click the read more button below. Or, alternatively please get in touch.