Identity
Expanded stronger authentication, reviewed dormant external identities and addressed specific hybrid-directory risks.
RACF-CC in practice
A worked example of how targeted, resource-aware improvements produced measurable control change in a low-resource hybrid environment—even when headline assessment scores concealed some of the progress.
Operating context
The organisation depended on cloud services and on-premises infrastructure to support care delivery. A small technology function had to balance security work with service continuity, legacy dependencies, limited specialist capacity and constrained budgets.
The assessment used configuration evidence, platform telemetry and repeatable before-and-after measurements. Work was prioritised where existing tools and licensing could reduce credible risk without creating disproportionate operational disruption.
These results come from one environment. Figures have been rounded and identifying operational details omitted. They illustrate an approach, not a performance benchmark or a guarantee that another organisation will achieve equivalent outcomes.
Prioritised action
The programme combined preventative controls with better visibility, governance and evidence. Improvements were phased rather than presented as a single technology deployment.
Expanded stronger authentication, reviewed dormant external identities and addressed specific hybrid-directory risks.
Used existing management and protection capabilities to increase verified coverage of high-value hardening controls.
Applied supported-system patching and configuration remediation while recording residual legacy risk.
Enabled health reporting and compared like-for-like findings instead of relying only on aggregate maturity scores.
Measured outcomes
The public figures below are intentionally rounded. Each describes a defined control measure rather than an overall claim that the environment had become secure.
Expanded authentication capability substantially reduced the measured gap, although further identity work remained.
The review targeted guests with no recorded successful sign-in or extended inactivity, reducing unnecessary standing access.
The measure reflects verified protection coverage for this specific technique—not generic protection against every form of WMI abuse.
The improvement was sustained while the reporting population increased, demonstrating the value of enabling health telemetry before assuming policy effectiveness.
This was a like-for-like comparison across the same server cohort. It counts finding instances, not distinct vulnerabilities or affected organisations.
Rule-level evidence showed improvements to long-lived trust and certificate-template exposure even though the headline domain-risk score did not move.
The central finding
Aggregate assessments remained useful for direction-setting, but they did not provide a complete account of change. Assessment models evolved, licensing-dependent controls affected attainable scores and some tools retained severe headline ratings after individual attack paths had been reduced.
RACF-CC therefore treats headline scores as assurance inputs—not definitive measures of security maturity. Decision-makers also need control-level evidence, consistent comparison groups and an account of what remains unresolved.
Progress is better demonstrated by evidence that a control changed exposure than by a maturity score viewed in isolation.
RACF-CC case-study lesson
Residual risk
Some older operating systems, applications and specialist platforms could not be patched or replaced immediately.
Some controls remained in audit or report-only states, and systems outside modern management platforms required separate assurance.
Useful signals existed across several tools, but review and correlation still depended heavily on limited staff capacity.
Evidence review, exception ownership and residual-risk decisions needed to become a recurring operational cycle.
Transferable lessons
Apply the learning
Explore the eight RACF-CC domains or use the prioritisation tool to compare proposed improvements consistently.