Enter Password

CASE STUDY /

Securing a Historic Legacy with Cyber Essentials

Photograph credit: Alex Beattie

gorange
CLIENT The Carnegie Dunfermline and Hero Fund Trust
SERVICE USED Cyber Essentials Certification and Annual Renewal
LOCATION Dunfermline, Scotland

About the Trust

The Carnegie Dunfermline and Hero Fund Trust is an endowment trust established by philanthropist Andrew Carnegie in 1903 to enrich the lives and environment of the Dunfermline community where he was born and raised.

One of more than 20 Carnegie foundations worldwide, it is governed by a Royal Charter and a Board of twenty Trustees.

Today, the Trust brings together three charitable purposes under one organisation. The Dunfermline Trust awards grants to local charities and organisations across arts, education, sport and community projects. The Hero Fund recognises civilian acts of bravery across the UK, and the Trust also runs the Andrew Carnegie Birthplace Museum, preserving the legacy of one of Scotland’s most influential philanthropists.

The Challenge

With responsibility for sensitive data and GDPR compliance, the Trust aimed to strengthen its cyber security posture and reduce the risk of cyber attacks.

Trustees also wanted to minimise the organisation’s exposure to cyber risk and qualify for lower cyber insurance premiums by completing the accreditation.

Although the Trust already partnered with Grant McGregor for day-to-day IT support, Cyber Essentials initially felt complex for a small internal team. They needed a clear, supported route to certification that would improve security without adding pressure.

Our Solution

Grant McGregor provided a guided, clear route to Cyber Essentials certification and annual renewal:

  • One-to-one guidance from an experienced consultant, translating requirements into clear, actionable steps.
  • Policy and documentation support to align existing practices with the scheme.
  • Practical security improvements, including a password manager, multi-factor authentication (MFA) and structured software and device updates.
  • User awareness training with phishing simulations and regular tips to build everyday vigilance.
  • Renewal support each year, explaining question set updates and highlighting areas needing attention.

Our Approach and Results

The process was designed to be straightforward and supportive, raising security standards while keeping the workload manageable for a small team.

Improved Security

Stronger policies, a password manager and enforced updates on all devices used for work.

Better IT asset management

Retiring devices at end of warranty or support to reduce vulnerabilities and unexpected costs.

Remote Work Enabled

Reliable access supports hybrid and flexible working

Staff Empowerment

Tailored training increased confidence with new systems

Less IT Pressure

More efficient support freed up internal teams

Future-Ready Foundation

Strong digital base to support long-term growth

In Their Words

Moving to Azure has given us a new level of security and flexibility. Our team had limited technical understanding, but the support we received, especially the training from X, helped us overcome that. We've improved security, restructured how we work and our staff are now much more confident with the systems. Working with Grant McGregor has been a hugely positive experience. It’s opened the door to future digital improvements.

image-default

Job Title


Name Surname