From fragmented IT responsibility
to a more secure digital foundation.
A Danish humanitarian NGO had developed an increasingly interconnected IT landscape across infrastructure, digital platforms and ERP. With several suppliers involved, responsibility could become unclear when systems interacted, while growing digital dependence increased the need for stronger protection of business-critical data. The work focused on creating clearer IT responsibility and strengthening identity, access and device security across the organisation.
The challenge
The organisation's IT environment had evolved across several suppliers responsible for different parts of infrastructure, digital platforms and ERP. This model could work when systems were isolated, but became more difficult to manage as the organisation grew and the systems increasingly depended on one another.
When a problem crossed several systems, responsibility was not always obvious. The organisation risked becoming the coordinator between suppliers instead of having a clear owner responsible for understanding the wider environment.
Security requirements were also changing. Employees increasingly depended on laptops, smartphones, tablets and digital services to access information and perform their work. This increased the importance of controlling who could access business-critical systems and from which devices.
The challenge was therefore not simply to introduce more security technology. It was to create stronger control and clearer responsibility across an IT landscape that needed to remain practical for the people using it every day.
The approach
The work began with a review of the existing IT landscape. The purpose was not to replace systems that already worked, but to understand the current environment, identify where security requirements were already covered and determine where additional controls would create value.
Identity and access security became an important focus. Login procedures were strengthened and multi-factor authentication was introduced for access to relevant systems, adding another layer of protection beyond passwords alone.
Device security was strengthened as well. The organisation introduced greater validation of the devices used to access business-critical infrastructure and systems, making it possible to restrict selected access to approved and registered devices.
The broader IT setup was considered as one connected environment rather than a collection of isolated systems. Infrastructure, digital platforms and ERP therefore formed part of the same operational discussion, helping create clearer responsibility when technical issues or future changes crossed traditional supplier boundaries.
The objective was not maximum technical complexity. It was to strengthen the controls that mattered while creating an IT environment that remained manageable for both the organisation and its users.
The impact
The organisation gained a more coordinated foundation for managing IT across security, infrastructure and business-critical systems. When responsibilities crossed technical areas, the organisation had a clearer point of ownership instead of having to coordinate between several suppliers itself.
Security around user access was strengthened through multi-factor authentication and improved login controls, while stronger device validation created greater control over which devices could access selected systems and infrastructure.
The broader setup also created a more coherent relationship between cybersecurity and the systems the organisation depended on every day. Security, infrastructure, digital platforms and ERP could be considered as connected parts of the same operating environment rather than separate technical projects.
The case reflects SR Konsul's approach to cybersecurity: security should not exist as an isolated technical layer. It should be designed around the organisation's systems, users, data and operational reality.
Have a similar security challenge?
Tell us briefly what needs to work better. We'll determine the right next step.