RMI’s cybersecurity maturity journey revealed foundational risks in:
Inconsistent onboarding/offboarding across regions
Shadow IT and unauthorized app use (e.g., Google Drive, Splashtop)
Manual MFA setup and poor adoption
Limited visibility and enforcement of access rights, license assignments, and device preparation
Onboarding was often driven by email and local discretion, exposing the organization to data leakage, unrevoked access, and noncompliance with frameworks like Cyber Essentials and ISO 27001.
Benchmarked implemented end-to-end SOPs, MFA controls, and secure device setup protocols, structured into three key areas:
Developed detailed SOPs for onboarding and offboarding field, office, and contractor staff:
Microsoft 365 account creation
Role-specific license assignment (F3, Business Premium, Adobe, OneLogin)
Device setup with Cynet EDR, Adobe, and endpoint encryption
Aligned global procedures across UK, US, and offshore teams
“By bringing structure to something as fundamental as user access and device setup, we closed gaps we didn’t even know we had.”
— RMI IT Ops Manager
Processes were inconsistent across regions, relying on email instructions and local discretion. This led to unrevoked access, misconfigured devices, and shadow IT exposure.
By deploying OneLogin Protect and Microsoft Authenticator, creating SOPs, and delivering hands-on training, 100% of users across all regions adopted MFA, ensuring secure logins for critical apps.
Benchmarked introduced a Windows 11 build standard, offline installation, local admin configuration, Edge-hardening, and EDR installation. All devices are now compliant with patch, encryption, and antivirus policies.
A centralized ticketing system was implemented (RMI-IT-SOP-002) with SLA-based responses. Automated ticket creation via Acronis ensures onboarding, device issues, and access requests are tracked efficiently.
Standardized onboarding/offboarding prevents unrevoked access
MFA enforcement blocks unauthorized logins
Endpoint hardening and EDR protect devices from malware and unauthorized apps
Centralized monitoring provides visibility for compliance and incident response
Yes. SOPs, MFA, and endpoint baselines are aligned across UK, US, and offshore teams, providing a repeatable, auditable framework suitable for continued growth and regulatory compliance.
Benchmarked combines practical deployment, user enablement, and governance to implement controls that are secure, scalable, and sustainable — reducing risk while enabling business operations.
We embed ourselves in your operations, implement the changes with you, and guide your team through what matters, what to prioritize, and where the trade-offs lie—so compliance actually improves your security, not just your paperwork.
IT cost optimization isn’t about cutting corners — it’s about making sure every dollar spent serves a purpose.
Chief Executive Officer, Sidra Medicine
QHSE Manager
Sales Director (B2B)
Many thanks Mat. Really appreciate your team's hard work over the last few months. This has not been an easy task.
RMI being ISO 27001 and 14001 certified. These certifications are a testament to the hard work, dedication, and collaborative efforts of everyone.
Thank you for your outsdanding work without any setbacks.
Gap Analysis & Readiness Review
Policy Development & Documentation
Infrastructure Review & Hardening
Staff Training & Awareness
License & Vendor Optimization
Quick Wins (low-effort savings initiatives)