Skip to content

Drupal Hub · Case Studies

What actually happens once you sign the contract

Not a highlight reel. Four scenarios across government, education, healthcare and media — the real constraints (no downtime, no content loss, an unpatched version already exposed), the decisions we made, and what changed by the end.

A note on these examples: details below are anonymised composites built from typical engagement patterns, not attributed to one identifiable organisation. We publish named, client-approved case studies once written sign-off exists — ask us directly for references in your sector.

Government · Saudi Arabia

Migrating a government ministry off Drupal 7 without losing a decade of published content

Client:
A GCC government ministry (anonymised)
Services:
Drupal 7-to-10 migration, in-Kingdom hosting, security hardening
Timeline:
5 months
Status:
Live, on a maintenance agreement

The challenge

  • • A public-facing ministry portal had run on Drupal 7 for close to a decade — over 10,000 published items across multiple departments, each with its own approval chain.
  • • The version was past end-of-life: no security patches, and a pending IT-governance audit had flagged it as a compliance risk.
  • • Editors across departments had no appetite for retraining on an unfamiliar system, and nothing could go offline during a migration.

What we did

  • • A fixed-price discovery phase audited the content model department by department before any migration code was written.
  • • Migrations were rehearsed against a staging copy of the full dataset, with published counts reconciled department-by-department against the live site.
  • • The new build preserved every department's existing approval workflow rather than imposing a single generic one.
  • • Deployment moved to an in-Kingdom cloud region with documented data flows for the compliance team's sign-off.
  • • Editor training ran in Arabic and English before cutover, so no department was learning the system live.

The result

MetricBeforeAfter
Known unpatched vulnerabilitiesMultiple open, no fix availableZero — current supported release
Content migrated without loss100% of published items reconciled
Editor retraining timeUnder one week per department

Technology: Drupal 10, in-Kingdom cloud hosting, single sign-on integration, Arabic/English bilingual publishing.

Higher Education · Saudi Arabia / UAE

Bringing a university's dozen faculty sites under one governed Drupal platform

Client:
A GCC public university (anonymised)
Services:
New Drupal build, multi-site architecture, Arabic-English publishing
Timeline:
6 months
Status:
Live, phase 2 (admissions integration) in progress

The challenge

  • • A dozen faculties and research centres each ran a different, inconsistently maintained website — no shared branding, no central security ownership, several on outdated software.
  • • University communications had no way to enforce a consistent editorial or accessibility standard across departments.
  • • Content needed to exist properly in Arabic and English, not as an English site with a translated summary bolted on.

What we did

  • • A Drupal multi-site architecture gave each faculty its own editorial space and branding flexibility inside one centrally maintained, centrally secured platform.
  • • A shared content model and component library kept every faculty site consistent without forcing identical page layouts.
  • • Mirrored Arabic-English publishing with independent editorial workflows per language, so translation was never a bottleneck.
  • • Central IT retained one security and update surface instead of a dozen separately-managed installations.

The result

MetricBeforeAfter
Separately maintained CMS installations121 governed platform
Sites meeting a consistent accessibility/branding standardA minorityAll faculty sites
Security patchingInconsistent, per-facultyCentralised, on a defined schedule

Technology: Drupal 10 multi-site, shared component library, bilingual RTL/LTR templates, central SSO.

Healthcare · Saudi Arabia

Rebuilding a hospital network's patient-facing platform to a higher security bar

Client:
A GCC private hospital group (anonymised)
Services:
New Drupal build, security hardening, systems integration
Timeline:
4 months
Status:
Live, on a maintenance agreement

The challenge

  • • A multi-facility hospital group needed a patient-facing site handling appointment enquiries and health information, held to a materially higher security and privacy bar than a typical corporate site.
  • • The existing platform had no formal update cadence and limited integration with the group's internal patient-management systems.
  • • Content needed sign-off from clinical, legal and marketing stakeholders before anything published — three separate approval chains, not one.

What we did

  • • Role-based editorial workflows were built to route content through clinical, legal and marketing review in the correct order, with a full audit trail.
  • • Security hardening followed a documented checklist mapped to the controls the group is assessed on, with monitoring and a defined patch cadence agreed up front.
  • • Enquiry and appointment-request flows were integrated with the group's internal systems via Drupal's API layer rather than left as disconnected web forms.

The result

MetricBeforeAfter
Formal patch/update cadenceNoneDefined schedule with monitoring
Content approval trailInformal, email-basedAuditable, in-platform workflow
Appointment enquiries reaching internal systems directlyManually re-enteredIntegrated via API

Technology: Drupal 10, hardened hosting configuration, role-based clinical/legal/marketing workflow, systems integration.

Media & Publishing · United Arab Emirates

Scaling a bilingual news platform through national-event traffic spikes

Client:
A GCC regional media group (anonymised)
Services:
Drupal 9-to-10 migration, performance tuning, headless delivery
Timeline:
3 months
Status:
Live, ongoing support

The challenge

  • • A regional newsroom's Drupal 9 platform was approaching end of support and had never been load-tested against the traffic spikes national news events produced.
  • • The editorial team needed faster turnaround between filing a story and it being live in both Arabic and English.
  • • Marketing wanted a headless option to eventually feed the same content into a mobile app without duplicating editorial work.

What we did

  • • The migration to the current Drupal release was paired with a caching and CDN strategy specifically tuned for concurrency spikes, not just average-day traffic.
  • • Drupal's built-in web-services layer was enabled so the same content could serve both the website and, later, other channels headlessly without a second editorial system.
  • • Editorial workflow was streamlined per language, cutting the manual handoff steps between filing and publishing.

The result

MetricBeforeAfter
Handles national-event traffic spikesNot load-tested, occasional slowdownsLoad-tested and cached for peak concurrency
Time from filing to bilingual publishMaterially reduced through workflow changes
Ready for a headless mobile-app feedNoYes, via the existing content model

Technology: Drupal 10, decoupled/headless-ready API layer, CDN + caching layer, bilingual editorial workflow.

Continue exploring

See the reasoning behind these patterns onwhy enterprises and governments choose Drupal, get answers to specific questions in theDrupal FAQ, or start back at the Drupal hub.

See your situation in one of these?

Tell us where you're stuck — a clear, costed point of view lands within one business day.

Speak to a specialist

Tell us what you're trying to achieve

Share your goal — more leads, a new platform, a market entry — and a senior consultant will come back within one business day with a clear point of view on how to get there. No obligation, no sales script.

Prefer email?hello@voxgcc.com

Your details are used only to respond to this enquiry, in line with UAE and Saudi data protection law (PDPL). No mailing lists, no resale.

Call usWhatsApp us