// TRACK RECORD & EMPIRICAL MANDATES

Anonymous Advisory Scenarios & Measurable Value Delivered

Real-world executive mandates de-identified to protect client confidentiality under professional legal privilege. Highlighting balance sheet impact, operational resilience, and cyber risk governance outcomes achieved across Private Equity, FTSE 250 boards, regulated FinTech, and critical national infrastructure.

£18M+
CAPEX & Software Drag Averted
100%
Client Privilege Maintained
72-Hour
Rapid Recon Delivery SLA
0%
Vendor Resale or Reseller Bias
JUMP TO SCENARIO: 01 // M&A Due Diligence 02 // FTSE 250 Board Governance 03 // CNI Zero Trust NIS2 04 // FinTech FinOps & Cloud 05 // Sovereign Legal AI 06 // Ransomware Crisis Response
// SCENARIO 01 PRIVATE EQUITY & M&A
10-DAY PRE-LOI SPRINT [CONFIDENTIAL // ANONYMOUS]
CLIENT CONTEXT: UK Mid-Market Private Equity Sponsor (£45M Enterprise SaaS Target)

Pre-Acquisition Technical Due Diligence & Technical Debt Remediation

#TechnicalDueDiligence #BuruOpsRecon #ValuationDefense
01 // THE PROBLEM

Hidden Monolithic Debt & RCE Vulnerability Masked as Modern Architecture

Target leadership presented their software as a cloud-native microservices platform with high gross margins. Standard financial and legal audits raised no alarms.

  • Core architecture was a 14-year-old monolithic DB with extreme query latency.
  • Single-person dependency on two founding engineers who held all root credentials.
  • Exposed admin gateway harboring active Remote Code Execution (RCE) flaw.
02 // OUR ADVISORY ROLE

Empirical 10-Day Attack Surface & Codebase Interrogation

Mtengwa Strategic Advisory conducted an independent investigation combining external reconnaissance with architectural artefact review.

  • Zero-touch perimeter mapping via BuruOps tools discovering leaked credentials.
  • Stress-tested database sharding ceilings and calculated true cost per query.
  • Authored an unvarnished Investment Committee Memo quantifying balance-sheet risk.
03 // VALUE DELIVERED

£3.8M Valuation Reduction & £1M Indemnity Escrow Secured

£3.8M
Valuation Cut
£1.8M
Remediation Modeled
  • Prevented day-one post-acquisition financial insolvency shock.
  • Provided sequenced 100-Day Engineering Value Creation Plan.
"Prevented the sponsor from overpaying by £3.8M for mischaracterized legacy software, delivering actionable 100-day engineering leadership."
// SCENARIO 02 FINANCIAL SERVICES & BOARD RISK
6-WEEK BOARD REVIEW [CONFIDENTIAL // ANONYMOUS]
CLIENT CONTEXT: FTSE 250 Board Audit & Risk Committee / Group CISO

FTSE 250 Boardroom Cyber Governance & £2.4M Tooling License Avoidance

#NCSC_CAF #MSSP_Governance #ToolRationalization
01 // THE PROBLEM

Contradictory Metrics & Unwarranted £2.4M SIEM Overhaul

Internal IT reported low cyber risk, while the incumbent MSSP claimed the firm was indefensible without an unbudgeted £2.4M SIEM replacement.

  • MSSP alert queue generated 4,200+ monthly false positives.
  • Proposed replacement duplicated capabilities already owned under Microsoft E5.
  • Audit committee non-executive directors lacked independent verification.
02 // OUR ADVISORY ROLE

Independent Vendor-Neutral Audit & Telemetry Re-Engineering

Engaged by the Non-Executive Audit Chair to establish the ground truth of detection capabilities against MITRE ATT&CK.

  • Discovered 82% of alert noise was caused by 4 misconfigured firewall parsers.
  • Audited existing software licenses proving replacement was unnecessary.
  • Established an objective Board Risk Scorecard aligned to NCSC CAF.
03 // VALUE DELIVERED

£2.4M Expenditure Averted; 68% Alert Noise Reduction

£2.4M
Spend Averted
68%
Noise Slashed
  • Zero additional software purchased; existing tools tuned to peak performance.
  • Restored board confidence and fulfilled UK Corporate Governance code.
"Eliminated £2.4M in vendor-driven software bloat by proving existing tools were sound but poorly tuned, restoring board clarity."
// SCENARIO 03 CRITICAL INFRASTRUCTURE
4-MONTH MANDATE [CONFIDENTIAL // ANONYMOUS]
CLIENT CONTEXT: Executive Board of Regulated Energy Distribution Provider

Critical National Infrastructure Zero Trust & OT Isolation (NIS2 / DORA)

#ZeroTrust #NIS2_Article21 #SCADA_Isolation
01 // THE PROBLEM

Permeable IT/OT Boundary Under Threat of €10M NIS2 Sanctions

Corporate IT networks maintained unsegmented jump-box routing into operational SCADA substation controls, risking widespread grid shutdown upon a single phishing breach.

  • Shared root credentials utilized across 40+ electrical substations.
  • Online backups lacked immutable air-gap protection for control logic.
  • Imminent NIS2 Article 21 compliance audit with up to €10M fine exposure.
02 // OUR ADVISORY ROLE

Purdue Model Modernization & Zero Trust Boundary Blueprinting

Architected a resilient Zero Trust isolation framework that satisfied national security regulators without causing operational power disruptions.

  • Severed direct L3 routing, inserting ephemeral protocol-breaking identity brokers.
  • Engineered an isolated, immutable tape & object storage vault for SCADA logic.
  • Defended the architecture directly before the National Competent Authority.
03 // VALUE DELIVERED

100% Regulatory Clearance; Zero Operational Downtime

100%
Audit Clearance
Zero
Downtime Min
  • Verified containment stopping ransomware lateral traversal into substations.
  • Eliminated €10M fine risk under NIS2 Article 21 and UK CAF guidelines.
"Hardened vital energy delivery systems against nation-state traversal, clearing national audits with zero interruption to power delivery."
// SCENARIO 04 FINTECH & CLOUD ARCHITECTURE
8-WEEK OPTIMIZATION [CONFIDENTIAL // ANONYMOUS]
CLIENT CONTEXT: European Payment Institution & FCA-Regulated Neo-Bank

Regulated FinTech FinOps & Multi-Region Cloud Modernization

#CloudFinOps #FCA_FG16 #MultiRegionKubernetes
01 // THE PROBLEM

180% Cloud Cost Escalation & 800ms Transaction Latency

Rapid customer growth led engineering teams to over-provision Kubernetes clusters and unindexed cross-region databases without unit-cost accountability.

  • Annual AWS and Azure cloud spend surged past £2M with zero unit-cost visibility.
  • Core payment APIs experienced 800ms latency spikes under peak settlement hours.
  • Audit by FCA flagged inadequate failover testing across multi-region clusters.
02 // OUR ADVISORY ROLE

Architectural Refactoring & FinOps Forensic Instrumentation

Embedded alongside the CTO and Head of Engineering to restructure cloud economics and stabilize core transactional throughput.

  • Rightsized over-allocated compute tiers and eliminated orphaned cloud storage snapshots.
  • Redesigned data replication topologies utilizing local read-replicas with Redis caching.
  • Built automated cost-per-transaction telemetry connecting engineering to the CFO.
03 // VALUE DELIVERED

42% Recurring Cloud OPEX Reduction; 42ms P99 Latency

£840K/yr
OPEX Saved
42ms
P99 Latency
  • Achieved permanent £70,000/month reduction in recurring cloud hosting costs.
  • Fully cleared FCA operational resilience criteria with validated 3-minute failover.
"Transformed runaway cloud expenses into a predictable unit-cost model while slashing transactional latency by 95%."
// SCENARIO 05 AI & DATA SOVEREIGNTY
6-WEEK MANDATE [CONFIDENTIAL // ANONYMOUS]
CLIENT CONTEXT: International Commercial Law Firm (750+ Fee Earners)

Enterprise Legal Sovereign AI & Private Retrieval-Augmented Generation

#DataSovereignty #LegalPrivilege #PrivateRAG
01 // THE PROBLEM

Shadow AI Adoption Jeopardizing Legal Professional Privilege

Associates and partners were pasting sensitive client briefs into public commercial LLMs, risking catastrophic waiver of client privilege and SRA disciplinary action.

  • Zero data retention guarantees from public vendor API endpoints.
  • Managing partners immobilized between client confidentiality and AI productivity demands.
  • Vendors pitched black-box "Legal AI" suites costing £600K/yr without IP indemnities.
02 // OUR ADVISORY ROLE

Sovereign Private Enclave Blueprinting & AI Governance Charter

Designed an isolated, single-tenant private RAG topology with mathematical verification that zero client training data ever leaves the firm's sovereign cloud.

  • Authored firm-wide AI Governance Charter adopted by the Senior Management Committee.
  • Engineered cryptographic matter isolation ensuring ethical walls across client files.
  • Negotiated vendor API agreements to ensure zero training and strict UK data residency.
03 // VALUE DELIVERED

100% Legal Privilege Retained; 3.2x Contract Review Acceleration

100%
Privilege Preserved
3.2x
Review Velocity
  • Safeguarded multi-billion pound M&A transaction documents from public LLM ingestion.
  • Avoided £600K recurring vendor lock-in by leveraging sovereign open weights.
"Enabled fee earners to unlock generative AI productivity without risking client privilege or violating legal regulatory mandates."
// SCENARIO 06 INCIDENT GOVERNANCE & RESILIENCE
ACTIVE CRISIS RESPONSE [CONFIDENTIAL // ANONYMOUS]
CLIENT CONTEXT: Global Freight & Logistics Operator (£180M Turnover)

Ransomware Crisis Governance & Clean-Room Greenfield Identity Rebuilding

#CrisisCounsel #RansomRefusal #CleanRoomRebuild
01 // THE PROBLEM

Full Enterprise Encrypted & £4.5M Double-Extortion Demand

Threat actors executed simultaneous ransomware encryption across 600+ virtual servers, corrupting on-premises backup catalogues and halting port freight operations.

  • Entire Active Directory forest compromised with golden ticket persistence.
  • Insurers urged consideration of £4.5M bitcoin ransom payment to resume operations.
  • Executive committee paralyzed by conflicting technical claims between IT and MSSP.
02 // OUR ADVISORY ROLE

Direct Boardroom Crisis Counsel & Isolated Identity Reconstruction

Advised the Chairman and Board to reject ransom extortion, leading an emergency recovery architecture in an isolated clean-room cloud tenant.

  • Advised refusal of £4.5M ransom by proving decryptor flaws and double-cross risk.
  • Architected a fresh greenfield Entra ID tenant with zero trust federation.
  • Coordinated forensic isolation, insurer communications, and ICO regulatory notices.
03 // VALUE DELIVERED

Zero Ransom Paid; Freight Restored in 96 Hours

£0 Paid
Extortion Preserved
96 Hours
Critical Restoration
  • Preserved £4.5M balance-sheet capital and avoided sanction-busting legal liabilities.
  • Rebuilt enterprise upon modern zero-trust architecture immune to initial infection path.
"Guided the board through active extortion crisis, preserving £4.5M in capital and executing a 96-hour clean-room identity reconstruction."
// STATEMENT OF CLIENT PRIVILEGE & TECHNICAL VERACITY

All advisory scenarios published herein are drawn from actual client engagements conducted by Mtengwa Strategic Advisory. In strict accordance with Non-Disclosure Agreements, professional legal privilege, and SRA/ICO compliance standards, all identifying markers—including company names, specific financial metrics, domain records, and staff identities—have been anonymized or mathematically perturbed. Technical architectures, failure modes, diagnostic methodologies, and governance outcomes accurately reflect the empirical reality of each mandate.

[+] LIMITED RETAINED MANDATES // DIRECT PRINCIPAL COUNSEL

Facing an Acquisition, Audit, or Architecture Crisis?

Mtengwa Strategic Advisory operates under strict portfolio discipline. We accept limited retained mandates each fiscal cycle to ensure direct, uncompromised principal attention from Engr. Burhani Mtengwa.

🛡️ 100% Principal Led ⚡ Zero Junior Delegation 🔒 Strict Privilege & NDA
[+] EXECUTIVE COMMUNICATIONS PROTOCOL

Direct Principal Channels & Retained Advisory Intake

SURREY, UK • SERVING UK & INTERNATIONAL CLIENTS
VIRTUAL SWITCHBOARD 24/7 GREETING
+44 1483 928037

Professional automated executive reception and priority message routing for prospective advisory mandates.

MOBILE & WHATSAPP DIRECT DESK
+44 7459 190198

Direct messaging channel for urgent confidential inquiries, board scheduling, and bilateral follow-ups.

Burhani Mtengwa
PRINCIPAL INBOX
DIRECT
principal@mtengwa.co.uk

Direct inbox for Principal Advisor Burhani Mtengwa. For board scoping, strategic reviews, and bilateral NDAs.

OFFICE & REGISTRY D&B REGISTERED
Surrey, United Kingdom

Mail Address: Surrey, UK (Not Registered Office)
Registered Office: 61 Bridge Street, Kington, HR5 3DJ, UK
Registered with Dun & Bradstreet

WHATSAPP BRIEFING +44 7459 190198