The gaps were understood, the money was not
Glasgow’s own people already knew where the institution’s weak spots lay. Knowing it, though, was never going to shift a funding committee on its own. A committee backs a case it can measure, and a catalogue of technical worries, accurate as it may be, offers nothing to measure it against.
From a measured gap to a funded plan
CyPro gauged where the University truly sat against recognised security frameworks, agreed a target state the institution was comfortable defending, and turned the distance between the two into a roadmap that gave every step an order, a price and an owner. It was written with both audiences in mind, carrying enough technical substance for the teams delivering it and a plain enough case for the committee footing the bill. The committee said yes, releasing several million pounds to strengthen how the University secures its systems and data.
Why measurement is what frees the budget
The same shape recurs at any scale of organisation, and it applies to data protection just as squarely as to security. A university holds personal data on tens of thousands of students, staff and research participants, and the teams accountable for it seldom lack awareness of their weak points. What they lack is a current, believable measurement that non-specialists can act on. That is the job of an assessment against a recognised framework. A scoped review closing with a prioritised set of findings, each tied to the risk it creates and the work needed to close it, hands a budget holder a decision they can defend. Glasgow’s engagement was a cyber security roadmap rather than a data protection project, yet the standard it demonstrates, measurement turned into a costed and sequenced case, is exactly what CyPro’s consultants bring to a GDPR gap analysis or audit. Findings are only done when someone can fund them, close them and show the gap has gone.