VERIGATE IT & COMPLIANCEExplore case studies ↓
GRC & CYBERSECURITY ASSURANCE LAB

Risk visibility. Practical controls. Clear decisions.

Explore five practical, simulated governance, risk, and compliance engagements illustrating how VeriGate approaches evidence review, risk identification, control gaps, remediation planning, and executive reporting.

Demonstration portfolio: All organizations, evidence, findings, and outcomes shown here are fictional or synthetic. These projects are not representations of completed customer audits, certifications, or regulatory determinations.
SELECTED WORK

Assessment case studies

CASE STUDY 01 / SIMULATED

NIST CSF 2.0 Gap Assessment

Assess governance, inventory, access protection, incident response, and recovery against selected CSF 2.0 outcomes.

Scenario

ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.

Evidence

Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.

Risk & Control Gap

Unclear accountability; No approved cybersecurity RACI.

Recommendation & Remediation

Approve security RACI and annual review. Action: Assign CISO delegate; approve matrix.

Findings snapshot

IDReferenceControl gapSeverityRemediation
VG-01-01GV.RRNo approved cybersecurity RACIHighAssign CISO delegate; approve matrix
VG-01-02ID.AMIncomplete SaaS asset inventoryHighReconcile monthly
VG-01-03PR.AAMFA missing on 8 privileged accountsCriticalEnroll admins and verify logs
VG-01-04DE.CMNo centralized alert triageHighEnable logging and weekly review
VG-01-05RS.MAIncident playbook untestedMediumDocument findings and retest

Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.

Download synthetic findings CSV ↗
CASE STUDY 02 / SIMULATED

HIPAA Security Risk Assessment

Evaluate safeguards for electronic protected health information using selected HIPAA Security Rule standards.

Scenario

ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.

Evidence

Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.

Risk & Control Gap

Undetected threats to ePHI; No documented enterprise ePHI risk analysis.

Recommendation & Remediation

Perform thorough risk analysis. Action: Assign owners and track treatment.

Findings snapshot

IDReferenceControl gapSeverityRemediation
VG-02-01164.308(a)(1)(ii)(A)No documented enterprise ePHI risk analysisCriticalAssign owners and track treatment
VG-02-02164.312(a)(1)Shared EHR account in billing teamHighRemove shared account; provision named users
VG-02-03164.312(b)EHR audit log retention unverifiedHighTest audit reporting monthly
VG-02-04164.308(a)(7)Restore testing not evidencedHighRecord RTO/RPO and test results
VG-02-05164.312(e)(1)Vendor file transfer not assessedMediumObtain technical evidence

Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.

Download synthetic findings CSV ↗
CASE STUDY 03 / SIMULATED

Third-Party Vendor Risk Assessment

Assess the proposed healthcare billing vendor before onboarding and handling ePHI.

Scenario

ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.

Evidence

Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.

Risk & Control Gap

Unverified control environment; Vendor cannot supply current assurance report.

Recommendation & Remediation

Request SOC 2 report or alternative evidence. Action: Conditional approval pending review.

Findings snapshot

IDReferenceControl gapSeverityRemediation
VG-03-01SOC 2 reportVendor cannot supply current assurance reportHighConditional approval pending review
VG-03-02BAAHealthcare data processor has no executed BAACriticalLegal review and signature
VG-03-03SSO/MFAAdmin access lacks enforced MFAHighObtain configuration evidence
VG-03-04BCP/DRNo recovery test resultsMediumAdd remediation deadline
VG-03-05Vendor inventorySubprocessor list missingMediumUpdate vendor inventory

Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.

Download synthetic findings CSV ↗
CASE STUDY 04 / SIMULATED

SOC 2 Readiness Review

Perform a limited readiness review of selected security-related Trust Services Criteria.

Scenario

ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.

Evidence

Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.

Risk & Control Gap

Unauthorized access persists; Quarterly access reviews not documented.

Recommendation & Remediation

Institute documented access certification. Action: Run and sign quarterly reviews.

Findings snapshot

IDReferenceControl gapSeverityRemediation
VG-04-01CC6.1Quarterly access reviews not documentedHighRun and sign quarterly reviews
VG-04-02CC8.1Emergency changes lack approval trailHighSample tickets monthly
VG-04-03CC7.2Security alerts not assignedHighMeasure response SLAs
VG-04-04CC3.2Risk register not approvedMediumQuarterly governance meeting
VG-04-05CC9.2Critical vendors not reviewedMediumCollect evidence and track gaps

Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.

Download synthetic findings CSV ↗
CASE STUDY 05 / SIMULATED

Access Governance and RBAC Review

Review fictional employee roles, privileged access, and least-privilege exceptions.

Scenario

ClearPath Health Solutions, a fictional 250-person healthcare technology provider, is preparing for a security and compliance review.

Evidence

Synthetic records, mock logs, fictional questionnaires and simulated policy extracts. No real patient or customer data.

Risk & Control Gap

Bulk data disclosure; Billing analyst can export full patient dataset.

Recommendation & Remediation

Limit export to approved roles. Action: Remove permission; test access.

Findings snapshot

IDReferenceControl gapSeverityRemediation
VG-05-01Least privilegeBilling analyst can export full patient datasetCriticalRemove permission; test access
VG-05-02Privileged accessHelp desk has permanent global adminCriticalRemove standing privilege
VG-05-03DeprovisioningFormer contractor account active for 21 daysHighDisable account; reconcile HR feed
VG-05-04Segregation of dutiesClinical user can edit billing ratesHighReassign role and validate
VG-05-05Credential governanceService credential has no rotation ownerMediumVault secret and rotate

Executive summary: This illustrative assessment identified five selected control weaknesses. Management should assign accountable owners, validate the evidence, prioritize remediation by risk, and retest control effectiveness before representing the gaps as closed.

Download synthetic findings CSV ↗
PORTFOLIO METHOD

How to interpret these demonstrations

Each case study is an educational, limited-scope simulation. A real engagement requires written scope, authorized access, interviews, verified evidence, applicable control criteria, risk acceptance decisions, and independent validation of remediation. SOC 2 readiness is not a SOC 2 examination; HIPAA risk analysis examples do not establish legal compliance.

VeriGate IT & Compliance, LLC | Governance, Risk & Compliance | Cybersecurity advisory