A high-profile event management company handling VIP data for financial institution clients. First Arab Bank required ICC compliance before the relationship could continue. The audit had to find and close every gap — with a fixed deadline and absolute reputational stakes.
BLS Events managed guest lists, personal details and sensitive information for high-profile banking events hosted by First Arab Bank. When the bank’s security team reviewed the arrangement, they flagged gaps in how VIP data was stored, transmitted and accessed by event staff.
ICC compliance was the threshold — without it, the contract would not continue. The deadline was fixed, and a surface-level audit report would not survive the bank’s internal review.
The uncomfortable part of this class of engagement is that the client is paying you to find things that are expensive for them to fix, on a deadline, while a third party grades the result.
We conducted a full penetration test and vulnerability assessment across web applications, internal network, data storage practices and access control systems — going well beyond automated scanning to manually verify privilege escalation paths, encryption in transit and at rest, API authentication, and physical access controls at event venues.
Every point where VIP personal data touched an external system or third-party integration was mapped, because that boundary is where this kind of data actually leaks.
Findings were delivered as a severity-tiered remediation roadmap with named owners and verification checkpoints — structured so the bank’s security team could audit the remediation, not just read a claim of it.
All critical and high-severity findings were remediated within the compliance timeline. ICC certification was achieved, the bank’s security team signed off on the audit report, and the client relationship continued.
Beyond compliance, the engagement produced architectural improvements the client kept: unified access logging, encrypted event data export workflows, and a formal data retention and destruction schedule that had not previously existed.
Compliance isn’t paperwork when
the contract depends on it.
Your largest client’s security team
will audit you eventually.