The organisation operated across three separate business entities, with identities and data fragmented across three Google Workspace environments and one Microsoft 365 tenant. There was no single source of truth for users, groups, or access entitlements, and unified governance, standardised access controls, and consistent identity protection policies were absent.
Multi Factor Authentication was not consistently implemented or enforced across the group, increasing exposure to both cyber and insider threats. The absence of centralised security management limited visibility and monitoring capability, while the decentralised structure created operational complexity and elevated overall security risk.