Talsoft TS

Outcomes in context

Cybersecurity cases that result in operable capabilities.

Public and anonymized experiences across maturity, evidence and technical validation. Each case shows the initial pressure, the work performed and what remained operational afterward.

Rivkin Securities · Australia · 6 months

Featured public case

Rivkin Securities · Australia · 6 months

Public case · Maturity program

Rivkin Securities: from an existing structure to a governed and measurable posture.

Talsoft supported the Australian fintech in formalizing its cybersecurity program and connecting governance, risk, response, monitoring and technical validation.

Client
Rivkin Securities
Region
Australia
Duration
6 months
Work
ISMS, risk, monitoring and PenTest

Initial pressure

Enhance and formalize the existing security structure with a shared view for leadership, technology and third parties.

Work performed

A coordinated and documented program aligned with ISO 27001, ASIC cyber resilience good practices and the Australian Privacy Act.

Progress across assessed controls

Approximate comparison between the initial assessment and the end of the six-month engagement.

Overall control compliance
Initial 27%Final 70%
Controls marked non-compliant
Initial 44%Final 17%
Compliance among high-risk controls
Initial 26.7%Final 83.3%

Approximate percentages for controls included in this assessment. They describe this project, not a certification or a guaranteed outcome for other organizations.

Capabilities left operating

  • ISMS and control model
  • Live risk register
  • Incident response
  • Centralized monitoring
  • External PenTest and remediation

Original CTO testimonial

“Leandro and the team did a great job enhancing and formalising our existing security structure. The engagement was well-organised, consistently documented, and delivered to a high standard.”
CTO · Rivkin Securities

Case published with authorization and limited scope. It does not imply certification or regulatory approval; architecture, vendors, findings and sensitive data are omitted.

Discuss a similar program

Other entry points

Two anonymized cases for recognizing common situations.

Identity is protected, while the context, applied judgment and resulting capability remain concrete.

Anonymized case · B2B SaaS / services

From scattered controls to operable maturity

Pressure
Enterprise-customer pressure and distributed evidence without clear owners.
Engagement
GAP, 3-6-12 month roadmap, risk register and evidence map.
Outcome
A defensible way to explain posture, gaps and next steps.
View ISMS / Maturity case

Anonymized case · SaaS / fintech / services

From isolated PenTest to remediation decisions

Pressure
Validate technical exposure without accumulating findings disconnected from the business.
Engagement
Controlled scope, technical validation, executive reading and prioritized backlog.
Outcome
Risks translated into owners, remediation sequence and external evidence.
View PenTest / Technical risk case

One shared criterion

Different projects, the same value sequence.

  1. 01

    Understand the pressure

    Business context, assets, third parties, incidents and available evidence.

  2. 02

    Prioritize and execute

    Gaps organized by risk, owners, dependencies and real capacity.

  3. 03

    Operate and demonstrate

    Controls, evidence and follow-up that remain after delivery.

Selected social proof

What teams value after the work.

Three references connected to clarity, action and technical quality. Every project outcome depends on its scope and context.

“Their assessment was sharp, detailed, and refreshingly easy to act on. We came away more secure and far better informed. Exactly the expertise we were hoping for.”
Esteban SolerCTO, CrossCHQ
“The action plan made the security audit useful and effective.”
Casimiro Félix Toyos e Hijos S.A.Client company
“They carried out a penetration testing activity professionally.”
EMM S.A.Client company

Confidentiality without losing clarity

Anonymized cases never publish names, domains, IPs, screenshots, payloads or contractual data. They do show the business problem, approach and resulting capabilities.

Questions about the cases

Why are some cases anonymized?

Security work involves architecture, exposure and sensitive decisions. We publish context, approach and capabilities without revealing exploitable or contractual information.

Do these cases imply certification or guaranteed compliance?

No. They show concrete work and capabilities within a defined scope, but do not guarantee certifications, external approvals or the absence of incidents.

How do I know which case resembles our situation?

Customer or audit pressure usually points toward maturity and evidence. Technical uncertainty may call for a PenTest. A short conversation helps validate the right entry point.

Do you recognize a similar situation?

In a 30-minute conversation we can frame the current pressure and decide whether to begin with a GAP, PenTest, readiness or an ongoing program.