Skip to content

Quriosity

A working archive of the engagements behind the practice.
The three case studies below are drawn from engagements delivered by NirVyn principals and senior partners in prior corporate and consulting roles. Client identifiers, methodology specifics, and proprietary findings are withheld throughout. The intent is not to showcase: it is to give a serious prospect a clear picture of the kind of problem we have spent careers solving, and the manner in which we go about it.
Each case follows the same structure the situation as the client saw it, where it got complicated, the approach taken, what followed, and the broader point.
SECTOR · MANUFACTURING / GEOGRAPHY · INDIA, MULTI-STATE

Security risk assessment across a national manufacturing footprint

Twenty-three sites, six weeks, one comparable posture.
Engagement delivered by a NirVyn senior partner in a prior corporate role. Client identifiers, methodology specifics, and proprietary findings are withheld. Detail available under NDA.
The Situation: A multinational manufacturer with India operations had grown by acquisition and organic build‒out into a footprint of more than twenty plants spread across several states. Each site had its own security organisation, its own vendor relationships, and its own assessment history some recent, some years old, none mutually comparable. The Group CSO inherited the question every CSO eventually faces: where, across the entire footprint, is the next rupee of security spend most likely to obviate the next loss event?
Where it got complicated: Three things compounded the problem. First, the window. The Group wanted physical visits, efficacy testing, and final reporting inside six weeks quick enough to inform the next budget cycle, not so quick that the assessments lost depth. Second, the variation. Sites ranged from large continuous‒process operations to small finishing units; risk exposure varied not only by geography but by what the site actually did. A single template would either flatten the nuance or fail to fit half the sites. Third, the comparability requirement. The Group did not want twenty individually‒good reports. It wanted a posture map it could read across.
The approach: We applied the 5T's framework Team, Technology, Throughput, Tactics, Tests as the consistent lens at every site. Each site was scored under the same five heads, with site‒specific evidence captured underneath. Four parallel field teams ran the physical assessments under a central quality node that held the scoring discipline and resolved ambiguities the same way at every site. The reporting template carried the site nuance in the body and the comparable posture in the header.
What followed: The Group received its first enterprise-level comparable posture map across all sites — not just a stack of site reports. Several urgent findings were closed during the engagement itself, before the final report was signed off. More usefully, the Group's central security function gained a recurring framework to re-score against on a defined cadence; the assessment stopped being a one-time event and became an instrument.
The point: For a multi‒site enterprise, the value of a security assessment is rarely in the findings at any single site. It is in the comparability across sites. A risk score that does not sit on a comparable scale tells you nothing about where to spend the next rupee. The discipline is to fix the scale first, and only then look at the scores.
SECTOR · MULTI-SECTOR CONGLOMERATE / GEOGRAPHY · INDIA, MULTIPLE OPERATING SITES

Insider fraud and supply‒chain integrity at a Tier‒1 conglomerate

When the leak is inside the building.
Engagement delivered by a NirVyn senior partner in a prior corporate role. Client identifiers, methodology specifics, and proprietary findings are withheld. Detail available under NDA.
The Situation: A Tier‒1 Indian multi‒sector conglomerate was bleeding at the seams of its supply chain. Material was disappearing between vendor despatch and plant receipt. Procurement records showed patterns that did not match physical inventory. Internal audit had flagged the symptoms; vendor switches had been tried; new SOPs had been issued. The bleeding continued. What the leadership did not have and badly needed was a clear sight of who, how, and through which entry points.
How do you investigate an actor who already sits inside?
Where it got complicated: Three things made the standard playbook insufficient. First, the suspects if there were suspects were embedded in the operation. Anything visible (more audits, a louder vendor review) would alert them. Second, the data was scattered: procurement system in one place, vendor master in another, biometric access logs in a third, CCTV nowhere correlated. No single function could see the whole picture. Third, the timeline. Disruption to ongoing operations was not an option; the investigation had to run quietly alongside production.
The approach: We applied SIRA Suspicion Indicators Recognition & Assessment as the analytical frame. Three workstreams ran in parallel. An OSINT layer mapped vendor and counterparty digital footprints, surfacing relationships and ownership patterns the client could not see from its own records. A discreet ground layer validated digital signals through field observation and triangulation against transactional data. An integration layer correlated biometric access logs, CCTV timestamps, procurement entries, and despatch records through a remote analytical node producing the cross‒functional picture no single team could assemble on its own.
What followed: The actors and the mechanism were identified. The worst exposures were closed during the engagement window. Procurement and supply-chain controls were restructured to remove the entry points the mechanism had used. Equally importantly, the analytical framework was institutionalised: the client retained a recurring discipline for surfacing insider commercial risk before it became a loss event, rather than after.
The point: Insider commercial risk is rarely a single bad actor. It is a system of small signals that no single function in the organisation sees in full. The value of SIRA is not in any one signal it surfaces — it is in the cross-functional discipline of having a frame that surfaces signals at all. The endeavour is to design that frame before the incident, not after.
A network of crossing pathways with one highlighted route traced through it — signal found in noise
Deciphering the signals in the noise
SECTOR · DIVERSIFIED ENTERPRISE / GEOGRAPHY · INDIA, SINGLE HIGH-FOOTFALL SITE

Unifying a fragmented security ecosystem at a high‒footfall enterprise

Designing the workflow before the technology.
Engagement delivered by a NirVyn senior partner in a prior corporate role. Client identifiers, methodology specifics, and proprietary findings are withheld. Detail available under NDA.
The Situation: A diversified enterprise operated a high‒footfall site that had grown, like most such sites do, by accretion. Staff, vendors, contractors, and visitors moved through the site in volumes that exceeded what the original security design had been built to handle. The security stack reflected the same pattern: access‒control system from one vendor, CCTV from another, visitor management from a third, none of them in conversation with one another. Procedures had drifted into staff discretion. Oversight was, in practice, oversight of whichever system was speaking loudest on a given day.
Where it got complicated: The instinct rip and replace was not available. Operational continuity could not be interrupted; the budget for a full replacement did not exist; and large parts of the legacy stack still worked perfectly well in isolation. The real problem was not the technology. It was that the workflows around the technology had never been designed as a system. Adding more technology to a workflow that was already underspecified would have produced more shelfware, not better security.
The approach: We started with a deep‒dive into the workflows as they actually ran on the ground not the workflows as the SOPs described them. Where staff had drifted into discretion, we asked why; the answers were almost always practical, and the redesign respected them. From that workflow baseline, we built a phased transformation roadmap that dovetailed the legacy stack into a unified ecosystem rather than replacing it: app‒based access control where it added value, automated gate control at the choke points, video analytics layered over the existing CCTV, AI‒monitored cameras at the perimeter, all integrated through a remote command node. Behavioural change ran alongside the technical work the people using the system were treated as part of the system from day one.
What followed: The site moved from a fragmented operation to a unified‒control ecosystem on a phased timeline that preserved continuity throughout. Staff adoption was the quietest part of the project, because the transition had been designed for them rather than at them. Oversight that had been impossible before cross‒system compliance reporting, anomaly detection across logs became routine.
The point: Most security technology fails the way a transplant rejects a host not because the tissue is wrong, but because the system around it was not prepared. The discipline is to design the workflow before the technology, not after. Hence the deep‒dive into how things actually run, not how the SOPs say they should.
Image of a modern glass-and-steel office tower against a dusk sky
Selected engagements, beyond the three above. Each entry is a brief summary of a piece of work delivered by NirVyn principals and senior partners in prior roles — the same authorship and confidentiality conventions apply.