Helping IHRP gain clearer visibility into its cybersecurity posture

For IHRP, cybersecurity was not being overlooked. The challenge was gaining sufficient visibility into the organisation's cybersecurity posture to prioritise action, support internal reporting, and evidence its controls for external assessment under the CSA Cyber Essentials Mark (CEM).

As a lean organisation, IHRP had limited resources for continuous monitoring and independent risk validation. The team needed a more structured way to benchmark its existing policies, identify gaps, and assemble the evidence base required for CEM certification, without significantly expanding internal capabilities.

StrongKeep helped IHRP run a gap analysis across its cybersecurity policy framework, adopt a tailored set of policy templates, and organise the evidence trail required for CEM assessment.

Start StrongKeep for free!
James Wang, IHRP
James Wang Manager, Digital & Technological Operations, IHRP
5
Key cybersecurity areas reviewed
12
Customised policy templates adopted
Certified
Cyber Essentials, Dec 2025

The Problem

IHRP understood the importance of cybersecurity, but visibility across its overall posture was limited. Without a clear and independent view, it was difficult to determine which risks required attention, where policy gaps existed, and which controls were already documented to assessor standards.

"Prior to using StrongKeep, one of the main challenges was limited visibility into our overall cybersecurity posture. As a lean organisation, resources for continuous monitoring and independent validation of potential risks were constrained."

This created uncertainty around the organisation's potential exposure to cybersecurity risks, and added friction when preparing for compliance and certification cycles.

"It resulted in some uncertainty around potential exposure to risks, and made it harder to evidence our controls when needed."

IHRP needed a more structured approach to reviewing cybersecurity. One that could surface the right issues, produce policy documentation aligned to recognised frameworks, and remain practical for a lean team to manage.

The Solution

StrongKeep provided IHRP with a practical framework for reviewing its cybersecurity environment and closing documentation gaps against the CEM control set.

Rather than approaching cybersecurity as one broad and complex area, the engagement focused on several key domains: asset management, system protection, patching, backup practices, and incident preparedness. These are the same areas covered by the CEM requirements.

"StrongKeep's gap analysis benchmarked our existing policies and surfaced where we needed to strengthen documentation. We adopted twelve customised policy templates covering incident response, data backup, access control, asset management, secure configuration, and related areas, and put each through our internal review and approval process."

The platform's compliance module then helped organise the evidence collection required by the assessor, mapping controls to artefacts in a structured way.

"The organisation was exploring options to better understand its cybersecurity environment and identify risks in a more structured manner, without significantly expanding internal capabilities."

For IHRP, StrongKeep offered the right balance between external perspective and practical guidance, helping the organisation strengthen its approach without adding unnecessary operational complexity.

The Outcome

StrongKeep helped IHRP move from uncertainty towards a clearer, more organised view of its cybersecurity posture, and to a tangible certification milestone.

"With StrongKeep's support, IHRP achieved the CSA Cyber Essentials Mark in December 2025. It provided greater clarity on existing gaps and areas for improvement, and gave us a documented baseline we can return to as our cybersecurity needs evolve."

With clearer visibility into gaps and improvement areas, cybersecurity discussions became more grounded and actionable. The organisation was better placed to consider what needed attention, what could be improved, and how risks should be communicated internally and to the board.

"StrongKeep offers a structured approach to reviewing and improving cybersecurity practices, with an emphasis on identifying and addressing potential risks."

Looking ahead, IHRP is preparing for its CEM renewal cycle in 2027, which will expand scope to cover delta requirements around AI, operational technology (OT), and cloud security. The documented baseline established through the StrongKeep engagement provides a starting point for that next cycle, rather than a blank page.

For organisations with limited in house cybersecurity resources, IHRP shared:

"It may be relevant for organisations that are looking for additional external perspectives on their cybersecurity posture, particularly where in-house resources are limited."

For IHRP, StrongKeep helped turn cybersecurity from a broad area of concern into a more structured, visible, and certifiable process.

Company Profile

  • Organisation: IHRP (Institute for Human Resource Professionals)
  • Website: ihrp.sg
  • Industry: Human Resources / Professional Body
  • Objective: Achieve CSA Cyber Essentials Mark certification and establish a documented cybersecurity baseline
  • Challenge: Limited visibility into overall cybersecurity posture and documentation gaps for assessor grade evidence
  • Internal context: Lean organisation with constrained resources for continuous monitoring and independent risk validation
  • Areas reviewed: Asset management, system protection, patching, backup practices, and incident preparedness

Results with StrongKeep

  • Achieved CSA Cyber Essentials Mark certification in December 2025
  • Adopted twelve customised cybersecurity policy templates covering the CEM control domains
  • Established a documented and assessor ready evidence base through the compliance module
  • Gained greater clarity on existing cybersecurity gaps and areas for improvement
  • Established a more organised approach to managing cybersecurity processes
  • Supported more informed internal discussions around cybersecurity risks and controls
  • Added an external perspective without requiring significant internal capability expansion
  • Built a documented baseline to support the 2027 CEM renewal, including delta scope for AI, OT, and cloud security

Hackers aren't waiting. Protect your business before it's too late!

Get Started