A client project we're proud of

Getting security under control in a fast-growing Mortgage Platform

How we helped a mortgage provider assess cyber maturity, close control gaps and achieve Cyber Essentials certification.

A fast-growing mortgage platform provider needed its cyber security to keep pace with rapid business expansion. Broadgate, part of Ortecha, assessed their security operations against Cyber Essentials, identified control gaps and built a practical remediation roadmap. The result was stronger governance, clearer risk management and successful certification. 

Project snapshot

Scope: 

  • Cyber security operational assessment
  • Benchmarking against Cyber Essentials
  • Policy and process gap analysis
  • Security tooling review
  • Remediation roadmap design
  • Certification support 

Impact:

  • Achieved Cyber Essentials certification
  • Established structured security governance
  • Clear, prioritised remediation roadmap
  • Improved visibility of security risk
  • Stronger foundation for future growth  

Growth started to outpace security control

The business was growing fast with new clients, more activity and more complexity. 

But security maturity hadn’t kept up. 

Processes had evolved organically. Policies existed, but weren’t always consistent or fully embedded. Controls were in place, but not always aligned to a clear standard. Leadership knew there was risk building, but didn’t have a structured view of where exposure sat or what needed fixing first. 

In a regulated sector, that uncertainty matters. Growth without control creates risk that compounds quietly. 

The organisation needed a clear baseline. Not theory. A practical view of how security actually operated day to day. 

Why they brought us in

This wasn’t about buying more tools or running another generic audit. 

They needed an independent, practitioner-led view of their security operations. Someone who could cut through documentation and assess what was really happening. 

We were brought in to: 

  • provide a clear, evidence-based assessment
  • benchmark against a recognised standard
  • translate findings into practical actions 

The goal was simple. Understand the real position. Fix what matters. Build something that can scale. 

How we assessed security and built the roadmap

We grounded the work in a recognised benchmark. In this case, Cyber Essentials. 

That gave the organisation a clear, external standard to measure against and a practical route to certification. 

Step 1. Assess how security actually works 

We reviewed policies, processes and controls across the organisation. Not just what was written down, but how things worked in practice. 

Where controls were inconsistent or unclear, we flagged it. Where processes existed but weren’t embedded, we challenged it. 

This created a clear, evidence-based view of current maturity. 

Step 2. Identify and prioritise the gaps 

Not all gaps matter equally. 

We worked with the client team to assess where risk was highest and where controls needed to be strengthened first. This avoided blanket fixes and focused effort where it would have the biggest impact. 

Step 3. Review the supporting security stack 

We carried out a high-level review of the technology supporting security controls. 

The focus was simple. Are the tools aligned to the controls? Are they being used effectively? Are there gaps or overlaps? 

Step 4. Build a practical remediation roadmap 

We translated findings into a clear, prioritised roadmap. 

This wasn’t a long-term strategy document. It was a working plan the organisation could act on. Clear actions. Clear ownership. Clear sequencing. 

Step 5. Support certification 

Once key gaps were addressed, we supported the organisation through the Cyber Essentials assessment process. 

Making sure the controls weren’t just in place, but evidenced and understood. 

What changed for the client

The organisation moved from uncertainty to control. 

Clear view of risk

Security gaps were no longer hidden or assumed. The business had a structured understanding of where exposure existed and what needed attention. 

Stronger governance and processes

Policies and processes were aligned to a recognised standard and embedded more consistently across the organisation. 

Focused improvement, not blanket change

Effort was directed where it mattered most. This reduced unnecessary disruption and accelerated progress. 

Certification achieved

The organisation successfully achieved Cyber Essentials certification. A clear signal of improved security maturity to clients and stakeholders. 

A foundation that can scale 

Most importantly, security is now structured to grow with the business, not fall behind it. 

Why this matters

This is a something we see all the time in high-growth financial services firms. 

Security doesn’t usually fail because nothing exists. It fails because controls grow unevenly, processes drift and no one has a clear, shared view of risk. Left unchecked, that creates exposure just as the business is scaling fastest. 

What makes the difference is clarity meaning: a clear baseline, a recognised standard, a practical roadmap. 

That’s how you move from reactive security to controlled, credible operations. And that’s what allows growth to continue with confidence. 

About the client

A UK-based mortgage platform provider operating in the financial services sector. The organisation was scaling quickly, onboarding new clients and expanding operations in a regulated environment. 

Ortecha Team

Picture of John Vincent

John Vincent

Partner, Technology Transformation

Picture of Richard Gale

Richard Gale

Partner, Technology Transformation

Ready to achieve similar results?