The Background
Kardinia International College has an outstanding reputation in the local and international education community. Catering to years K-12, Kardinia has several locations across Victoria and an international campus in Northern Thailand.
The Goal
Kardinia International College (KIC) had taken considerable steps to protect their IT infrastructure with several security controls in place, however, it was difficult for them to be sure how their security compared to industry and other schools. Security has always been high on their agenda, but they thought it prudent to get specialist and independent assistance with road-mapping their future program of security controls. During a time when the Notifiable Data Breach (NDB) legislation was a hot topic across all industries, Kardinia International College also wanted to demonstrate a proactive approach to information security with an independent review of their systems.
“When we heard about the changes in legislation around data breaches, we talked a lot about the security systems and processes we already had in place and discussed how to best measure the effectiveness. We started talking about undertaking a security audit, so we could show that we take security seriously and in doing so take a proactive approach. We thought it was really important to have someone independently review our systems. We value our partnerships with our existing partners, and although some had the capability to undertake a review, we felt their investment in our school did not provide the level of transparency we were looking for.” - Diana Murase, ICT Manager, Kardinia International College
The Selection
KIC sought an IT partner; not a consultancy to simply point out their flaws. They needed a partner with extensive experience and one they could trust to provide guidance on an ongoing basis. Referred through Hewlett Packard Enterprise (HPE), KIC approached us at The Missing Link.
“We got some advice from a colleague at HPE, who had talked to some others and came back to us with a couple of different companies that were recommended. Throughout discussions with the different companies, The Missing Link stood out as they were willing to customise a solution that met our needs and also budget. We appreciated the time taken to understand our environment and our priorities, and then designing a solution to our specific needs.” - Diana Murase, ICT Manager, Kardinia International College
The Solution
After we conducted a robust Security Control Review, our team suggested a combination of 13 Projects and products that would improve Kardinia’s overall level of Security Maturity, these consisted of the following:
- Enabling additional features on already purchased controls
- Developing additional policies and procedures
- Device Hardening
- Discovery projects to understand the school’s location and use of Data
As we worked through our process with KIC we made the necessary upgrades, clarified several areas where they were succeeding in their information security and developed a program of security controls for the future.
The Relationship
“We liked that The Missing Link focused their expertise on the audit and then as a follow up made some suggestions on solutions based on our environment. This made us comfortable that the audit was the focus, not the selling of specific products. We weren’t too sure heading into the review what to expect, and there were a few of our staff that felt a bit exposed. But the process was really simple and pain-free. They had two staff on-site and others working remotely, they quickly built a good rapport with our staff, and got the trust of those who were concerned quickly, through their professionalism and the way they shared information throughout the process.” - Diana Murase, ICT Manager, Kardinia International College
The Difference
This project has given Kardinia International College renewed confidence in their security controls and made them compliant with the new NDB legislation. In addition, they gained valuable clarity on their maturity compared to others in their industry and importantly, they have a clear view of what areas of security to work on in the future.
“We were also really pleased with the way the results were shared with us. We had lots of discussions around the report and from there it allowed us to set a clear and prioritised action plan. It was great to know what was working well and where we needed to do some work. This is where I think the independence of the review was particularly important. The report was easy to understand and allowed us to present to senior leadership a healthy report card. From this, we have had a couple of meetings to discuss solutions that will take us to the next level. Sales staff were again great in working with us to present options that met our needs and budget.
In looking at our experience with The Missing Link, we were certainly impressed with the technical service provided, but more importantly it was the way they were able to work with us to understand our needs and customise a solution specifically for our school.” - Diana Murase, ICT Manager, Kardinia International College
We were thrilled to assist Kardinia International College in this project and remain a trusted IT partner, working with them to implement ongoing risk, governance and various IT projects.