Client story

GLXG: building the security foundations for a growing healthcare business.

The job was not to arrive with a pile of policies. It was to understand how the organisation worked, identify where security needed to develop, and build a sensible foundation for the next stage of growth.

Engagement summary
OutcomeClear security picture + practical priorities
EngagementSecurity review + ongoing improvement
SectorHealthcare diagnostics and life sciences

The situation.

Global Lab eXpert Group (GLXG) connects patients and practitioners with advanced diagnostic testing, including genomics, microbiome analysis, and complex disease investigation. As the organisation developed, security requirements naturally grew more complex across devices, cloud services, suppliers, people, and sensitive health information.

GLXG wanted a clearer view of its security position and a more structured way to manage the risks associated with continued growth. The objective was not to impose a heavy framework or unnecessary bureaucracy, but to build something proportionate to the organisation and practical to maintain over time.

Process & Methodology

From complexity to a clearer security position

01UNDERSTAND
Establish the baseline

YDC first built a clearer picture of GLXG's environment across people, technology, devices, cloud services, suppliers and the information being handled.

02PRIORITISE
Bring risk into focus

The engagement introduced a structured approach to identifying and managing information security risk, with clear ownership and priorities so effort could be focused where it mattered most.

03STRENGTHEN
Build practical controls

The work then focused on practical improvements including device management, access, data handling, staff awareness and a more controlled Microsoft 365 environment.

Security areas addressed
DevicesAccessDataCloudSuppliersRiskPeople
Practical foundations

What the engagement involved.

First: understand the environment01
Building the baseline

We started by working through how the business actually operated — people, technology, devices, cloud services, suppliers and the information being handled. This established a practical baseline and helped separate areas that needed real change from areas that mainly needed clearer structure or documentation.

Second: governance02
Risk and governance

We introduced a structured approach to identifying and managing information security risk, with clear ownership and actions. This gave the leadership team a better view of where the organisation was exposed, which risks mattered most and where security effort should be focused.

Third: controls03
Building the foundations

We worked through the practical controls needed to strengthen GLXG's security position — including device management, access, data handling, staff awareness and the move towards a more controlled Microsoft 365 environment. The focus was on making sensible improvements in the right order rather than trying to change everything at once.

The outcome.

GLXG now has a much clearer view of its security position and a structured way of managing the risks associated with continued growth. Security is easier to understand, priorities are clearer and there is a defined route towards further assurance — including Cyber Essentials where it makes commercial sense.

Clearer position

A practical baseline of GLXG's security environment.

Clearer priorities

A structured view of risks, ownership and where effort should be focused.

Next-stage readiness

A defined route towards further assurance, including Cyber Essentials where commercially appropriate.

Most organisations do not need more security activity for the sake of it. They need to understand what matters and what to do next. That was the focus here.

Global Lab eXpert Group (GLXG) — healthcare diagnostics and life sciences

Questions & answers

Frequently asked questions.

Usually by understanding what is already there. Growing organisations naturally accumulate technology, suppliers, working practices and exceptions over time. A proper baseline makes it much easier to decide what actually needs attention and in what order.

Similar situation?

Security gets more complicated as businesses grow — we help organisations understand where they are and what to do next.

We help organisations understand where they are, what matters and what to do next — without adding process for the sake of it.

Cyber Essentials support

Further resources

Related reading.

Understand the baseline requirements, scope, and practical steps to achieve certification.

Assess your team's governance, documentation, and technical controls before an audit.

How Desucla built practical risk governance and secured independent validation.