For strategic technology, cybersecurity, data protection, infrastructure, and governance initiatives across A&One Precision Engineering.
This dashboard provides a live management view of MIS-led initiatives across governance, cybersecurity, infrastructure, customer assurance, and operational technology planning. It is intended to give leadership a clear overview of work completed, current focus areas, emerging priorities, and execution progress.
In Progress
Shared Drive Governance & Operational Control
Ref to Slide 3
Advance security control uplift, infrastructure planning, and policy adoption
The current focus is to strengthen the company's technology governance, cybersecurity posture, data protection controls, infrastructure planning, and document management practices.
Meaningful progress has already been made in improving the handling of confidential customer information, updating key policies, supporting shared drive governance, coordinating AMAT remediation work, and strengthening data lifecycle practices for audit readiness.
The current priority is to convert these foundational improvements into stronger operational discipline, staff adoption, and scalable control structures.
Key policies updated and core control areas are being strengthened.
Remediation activities continue in support of AMAT expectations.
Shared drive governance and document lifecycle practices remain a key focus area.
Identity controls, infrastructure upgrades, vendor governance, and policy adoption.
The following initiatives represent completed or materially advanced deliverables led by the MIS function.
Each item includes a summary, business impact, and defined next step.
Implemented OneDrive for handling AMAT confidential information, replacing email-based file transfers.
Impact: Improves control, traceability, and protection of customer-sensitive data.
Next Step: Reinforce correct usage through staff education and adoption monitoring.
Updated Incident Response, Data Classification, and Encryption Management policies.
Impact: Strengthens governance clarity and the policy foundation for secure operations.
Next Step: Translate policy into operational understanding through targeted awareness training.
Provided structured consultancy on shared drive governance and document control practices.
Impact: Improves file organization, access governance, version control, and obsolete document handling.
Next Step: Continue detailed review of ownership, access rights, naming discipline, and archive logic.
Served as primary liaison coordinating AMAT cybersecurity and data protection remediation work.
Impact: Creates a clearer response structure and supports coordinated remediation execution.
Next Step: Continue closing identified gaps and ensuring improvements are practical and sustainable.
Supported the definition of data lifecycle practices to improve ISO audit readiness.
Impact: Strengthens control over how data is disposed with a workflow
Next Step: Align practices with operational ownership and formal governance processes.
The following workstreams represent the active operational and strategic priorities currently under execution by the MIS function.
Intent: Review and improve folder structure, ownership, version control, access permissions, and obsolete file handling.
Why It Matters: This is the core governance workstream needed to improve control, consistency, and audit readiness.
Intent: Educate affected staff on correct OneDrive usage for AMAT confidential information and reduce reliance on email transfer.
Why It Matters: Secure controls are only effective when consistently adopted in daily operations.
Intent: Continue remediation work aligned to AMAT expectations with focus on practical risk reduction and control strengthening.
Why It Matters: Supports customer assurance, risk reduction, and long-term compliance maturity.
Intent: Further define how information should be classified, retained, archived, and disposed.
Why It Matters: Supports ISO audit readiness, operational consistency, and long-term governance discipline.
Intent: Review and renew the organization’s cyber security insurance coverage to ensure it remains aligned with the current threat landscape, business operations, customer expectations, and incident response needs. This includes assessing coverage scope, exclusions, claim triggers, and the adequacy of support services provided during a cyber incident.
Why It Matters: To ensure the organization has appropriate financial protection and access to specialist support in the event of a cyber breach. This helps reduce the financial impact of incidents, supports business recovery, and strengthens overall resilience against cyber and data-related risks.
The following items represent the next wave of planned initiatives. Each is scoped, sequenced, and aligned to the company's operational and security improvement objectives.
Assess and implement Entra AD Premium capabilities including Conditional Access to strengthen identity security and support geo-based access protection.
Review current internet performance and business requirements by July 2026. Current observations indicate line speed and stability are sufficient; no immediate need for a dedicated line.
Plan firewall upgrades at Loyang and Tuas to strengthen security posture, improve resilience, and support future infrastructure requirements.
Prepare for migration from the current Azure Gateway setup to the AZ Series, ensuring continuity, compatibility, and improved long-term reliability.
Review and refine the vendor cybersecurity management program so that policy expectations are clearer, more practical, and realistically implementable for all suppliers.
Assess whether cyber whitelisting should be formalized into a documented process, including approval workflow, ownership, review frequency, and exception handling.
Review the current SharePoint structure and identify opportunities to redesign the intranet for clearer navigation, ownership, collaboration, and document governance.
Conduct targeted policy briefings and implementation training for relevant Heads of Department so governance requirements are understood and consistently applied.
A consolidated view of the current state across all MIS-led workstreams, providing leadership with a single-pane status read at a glance.
Delivered or materially advanced
Currently in execution
Planned and scoped
Identified and being managed
In Progress — active execution across all workstreams
Governance, Cybersecurity, and Operational Control
Shared drive governance and secure information handling
Strengthening foundational controls and embedding adoption
Policies and controls require stronger operational embedding across departments
Progress infrastructure planning, conditional access review, vendor governance refinement, and HOD policy adoption
A visual status overview of all active and planned MIS initiatives. Status reflects current execution state.
Completed
Implemented to train
In Progress
In Progress
In Progress
In Progress
Planned
Planned
Planned
Planned
Planned
Planned
The following risks and control gaps have been identified. Each is actively monitored and managed. The tone here is constructive — these items are raised to ensure leadership visibility and appropriate resourcing.
Staff may continue using older habits such as email-based transfer of confidential information unless secure alternatives are reinforced through communication and consistent practice.
Shared drive improvements may not be fully effective unless ownership, naming standards, access controls, and obsolete file handling are clearly enforced and maintained.
Policy updates alone will not deliver results unless departments understand their responsibilities and consistently apply the defined controls in day-to-day operations.
Vendor and supplier cyber requirements may remain weak if expectations are not practical, clearly documented, and realistically implementable across the supply base.
Infrastructure improvements must be sequenced carefully to strengthen security posture without introducing operational instability during transition periods.
A&One MIS Workplan Progress Dashboard