RACF-CC in practice

An anonymised care charity case study

A worked example of how targeted, resource-aware improvements produced measurable control change in a low-resource hybrid environment—even when headline assessment scores concealed some of the progress.

Operating context

Improvement within real constraints

The organisation depended on cloud services and on-premises infrastructure to support care delivery. A small technology function had to balance security work with service continuity, legacy dependencies, limited specialist capacity and constrained budgets.

The assessment used configuration evidence, platform telemetry and repeatable before-and-after measurements. Work was prioritised where existing tools and licensing could reduce credible risk without creating disproportionate operational disruption.

How to interpret this case study

These results come from one environment. Figures have been rounded and identifying operational details omitted. They illustrate an approach, not a performance benchmark or a guarantee that another organisation will achieve equivalent outcomes.

Prioritised action

Controls were treated as one connected system

The programme combined preventative controls with better visibility, governance and evidence. Improvements were phased rather than presented as a single technology deployment.

01

Identity

Expanded stronger authentication, reviewed dormant external identities and addressed specific hybrid-directory risks.

02

Endpoints

Used existing management and protection capabilities to increase verified coverage of high-value hardening controls.

03

Exposure

Applied supported-system patching and configuration remediation while recording residual legacy risk.

04

Evidence

Enabled health reporting and compared like-for-like findings instead of relying only on aggregate maturity scores.

Measured outcomes

Meaningful change at control level

The public figures below are intentionally rounded. Each describes a defined control measure rather than an overall claim that the environment had become secure.

Identity Approximately 50%

reduction in users relying on single-factor authentication

Expanded authentication capability substantially reduced the measured gap, although further identity work remained.

External identities More than 450

dormant guest accounts disabled following review

The review targeted guests with no recorded successful sign-in or extended inactivity, reducing unnecessary standing access.

Endpoint hardening Below 1% → above 80%

confirmed protection against WMI event-subscription persistence

The measure reflects verified protection coverage for this specific technique—not generic protection against every form of WMI abuse.

Data assurance Approximately 48% → 15%

reporting devices with an outdated OneDrive client

The improvement was sustained while the reporting population increased, demonstrating the value of enabling health telemetry before assuming policy effectiveness.

Vulnerability management Approximately 13%

reduction in critical vulnerability instances

This was a like-for-like comparison across the same server cohort. It counts finding instances, not distinct vulnerabilities or affected organisations.

Hybrid identity Specific risk reduced, score unchanged

targeted directory weaknesses were remediated

Rule-level evidence showed improvements to long-lived trust and certificate-template exposure even though the headline domain-risk score did not move.

The central finding

Headline scores can conceal meaningful improvement

Aggregate assessments remained useful for direction-setting, but they did not provide a complete account of change. Assessment models evolved, licensing-dependent controls affected attainable scores and some tools retained severe headline ratings after individual attack paths had been reduced.

RACF-CC therefore treats headline scores as assurance inputs—not definitive measures of security maturity. Decision-makers also need control-level evidence, consistent comparison groups and an account of what remains unresolved.

Progress is better demonstrated by evidence that a control changed exposure than by a maturity score viewed in isolation.

RACF-CC case-study lesson

Residual risk

Improvement did not mean completion

Legacy dependencies remained

Some older operating systems, applications and specialist platforms could not be patched or replaced immediately.

Coverage was not universal

Some controls remained in audit or report-only states, and systems outside modern management platforms required separate assurance.

Telemetry remained fragmented

Useful signals existed across several tools, but review and correlation still depended heavily on limited staff capacity.

Governance required repetition

Evidence review, exception ownership and residual-risk decisions needed to become a recurring operational cycle.

Transferable lessons

What another resource-limited organisation can adapt

  1. Measure before changing.Enable trustworthy reporting and define a baseline before claiming that a policy or product is effective.
  2. Prioritise exposure, not appearance.Choose work by likely risk reduction, delivery burden and service impact—not by which dashboard score is easiest to raise.
  3. Use existing capability well.Configuration and governance improvements can remove real exposure without requiring an enterprise-scale programme.
  4. Compare like with like.Record denominators, reporting coverage and assessment changes so that before-and-after results remain intellectually defensible.
  5. Report residual risk openly.Show what remains unresolved, who owns it and what interim safeguards or decisions are required.
Case-study limitation. This page summarises one applied evaluation in an anonymised, resource-constrained care environment. Outcomes were shaped by its technology, licensing, people, risks and starting position. RACF-CC should always be adapted through local assessment and appropriate governance.

Apply the learning

Move from evidence to prioritised action.

Explore the eight RACF-CC domains or use the prioritisation tool to compare proposed improvements consistently.