The weaknesses were known, the number was not
Glasgow’s own people already understood where the institution was exposed. Knowing it was never going to move a funding committee on its own. A committee funds a case it can measure, and a catalogue of technical concerns, however accurate, gives it nothing to measure against.
From a measured gap to a funded plan
CyPro gauged where the University genuinely sat against recognised security frameworks, agreed a target state the institution was comfortable defending, and turned the distance between the two into a roadmap that gave every step an order, a price and an owner. It was written for both readers: enough technical substance for the teams delivering it, and a plain enough case for the committee footing the bill. The committee said yes, releasing several million pounds to strengthen how the University secures its systems and infrastructure.
Why measurement is what frees the budget
The same shape recurs at any scale, and it applies squarely to cloud and infrastructure security. A large institution runs a sprawling estate of systems, services and, increasingly, cloud accounts, and the teams accountable for it seldom lack awareness of the weak points. What they lack is an up-to-date, credible measurement that non-specialists can act on. That is the job of an assessment against a recognised benchmark. A scoped review that ends in a ranked list of findings, each mapped to the risk it poses and the effort required to fix it, hands a budget holder a decision they can defend. Glasgow’s engagement was a cyber security roadmap rather than a dedicated cloud security assessment, yet the standard it demonstrates, exposure measured and turned into a costed, sequenced case, is exactly what CyPro’s consultants bring to an assessment of an AWS, Azure or GCP estate. Findings are only done when someone can fund them, close them and show the exposure has gone.