Case Studies

Real-world examples of how organisations have transformed their risk management with Acuity.

Defence contractor uses STREAM® to strengthen cyber GRC and operational security processes

Defence
Defence
Cyber GRC
NIST 800-53
MITRE ATT&CK

Challenge

A defence contractor needed to demonstrate a rigorous, evidence-based cyber risk management approach to a public sector customer, including continuous oversight of risk levels across key technology assets in multiple environments.

Solution

STREAM® supported a Cyber GRC solution based on NIST 800-53, with MITRE ATT&CK configured as the threat library. The solution supported current risk-level oversight using data rather than relying only on periodic assessment snapshots.

Results

  • Evidence-based Cyber GRC aligned to NIST 800-53
  • MITRE ATT&CK configured as the threat library
  • Current, data-led oversight of risk levels across key technology assets
  • Relationship extended in 2026 with consultancy supporting a fully integrated risk management framework
  • Expansion of STREAM® use into broader operational security processes, including joiner and leaver requests

Medical device business uses STREAM® to support product compliance and ISO certification

Medical Devices
Medical Devices
Product Compliance
ISO Certification
Risk Management

Challenge

A medical device business that develops complex medical devices and supporting hardware products, operating across multiple regions and regulated sectors, needed to track regulatory requirements, product risks, controls and compliance evidence during product development. Late identification of compliance gaps can be especially expensive for hardware products, because design changes become harder and more costly once development has progressed.

Solution

STREAM® supported a risk and compliance management system for medical device development, helping the organisation track risks and controls with reference to ISO, NIST and SCF methodologies and maintain visibility of design-stage compliance decisions.

Results

  • Structured tracking of regulatory requirements, product risks, controls and compliance evidence
  • Risks and controls referenced to ISO, NIST and SCF methodologies
  • Greater visibility of design-stage compliance decisions
  • Support for the organisation's ISO certification process

A Leading B2C E-commerce Company

E-commerce / Retail
E-commerce
VMH
Supplier Risk
Compliance

Challenge

With a legacy, largely manual tool being decommissioned, the company needed a more robust approach to supplier risk compliance—without disrupting business operations.

Solution

The company adopted VMH to introduce a consistent operating model for risk compliance as part of supplier onboarding and due diligence, automating assessments and improving data quality.

Results

  • Materially improved speed-to-onboard while strengthening governance
  • Built-in risk scoring and clearer evidence trails for faster, more informed decisions
  • Better prioritisation of mitigations
  • Greater confidence in meeting legislative and policy requirements

Midland States Bank

Financial Services
Financial Services
GRC
Integration

Challenge

In the past, Midland States Bank managed its governance, risk, and compliance practices using a mix of different programs, spreadsheets, and systems. This approach made it difficult to track, measure, and report on GRC issues for different stakeholders.

Solution

Midland States Bank implemented STREAM® to create a centralized platform for all its risk management and compliance activities. The platform acts as the bank's GRC hub, collecting data from various sources to create complete reports that match their needs.

Results

  • Implemented a system that brings together information from multiple sources for a clearer view of risks
  • Improved ability to detect and address security issues by connecting risk data with security monitoring systems
  • Automated compliance with various regulatory standards
  • Generated detailed compliance reports quickly
  • Provided executive management with clear risk insights

Carl Zeiss AG

Manufacturing
Manufacturing
Global Compliance
Customization

Challenge

Carl Zeiss AG needed to improve their information security management and ensure compliance across their global business units by consolidating data on a single platform.

Solution

The company implemented STREAM® for a centralized approach to managing information security across its global operations. This provided a consistent method for identifying, assessing, and addressing information security risks.

Results

  • Successfully configured to match in-house standards
  • Centralized view of risks and controls across all sites
  • Enabled different visibility levels based on hierarchy
  • Created a consistent approach to risk management
  • Improved efficiency through automated workflows

European Data Hub

Data Center Services
Data Center
ISO 27001
Risk Management

Challenge

European Data Hub faced the challenge of managing numerous compliance requirements for its high-security data center while dealing with the complexities of modern IT environments.

Solution

By implementing STREAM, European Data Hub was able to align its information security practices with the ISO 27001 standard and create a structured approach to understanding and managing risks.

Results

  • Complete transparency in all risk management processes
  • Increased efficiency in risk assessment and mitigation
  • Better decision-making through risk-based approach
  • Improved ability to demonstrate compliance to clients
  • Enhanced overall security posture

ATPI

Travel Management
Travel Industry
ISO 27001
Risk Management

Challenge

ATPI needed a solution to improve their ISO 27001 certification process and better manage their IT security risks.

Solution

ATPI selected STREAM to streamline their information security management system, enabling them to effectively monitor and manage their security controls and risks.

Results

  • Successfully achieved ISO 27001 certification
  • Improved visibility and management of security issues
  • Enhanced ability to demonstrate compliance to clients
  • Streamlined auditing processes
  • Better overall risk management and security posture