Outcomes

What the work looks like in practice.

All engagements are anonymized. Industries and details are described with enough specificity to be useful — not enough to identify clients.

Adversary Simulation Financial Services — Regional Bank, ~$4B AUM

Threat actor had domain admin in under four hours.

The security team had no alerts.

The situation

The client had completed a penetration test six months prior. It came back mostly clean — a handful of medium-severity findings, all remediated. Leadership wanted assurance that the security program was functioning as intended before a regulatory exam.

What we found

Using an initial access vector that replicated a spearphishing email — the same technique used by the threat actor group most likely to target institutions of this type — we established a foothold on an endpoint within the first hour. From there, the path to domain admin was unobstructed.

The environment had strong perimeter controls and excellent patch discipline. It had almost no lateral movement detection. A contractor account with legacy VPN access had never been deprovisioned. NTLM relay was viable across four subnets. The SOC had zero alerts across the entire four-hour operation.

What changed

The client implemented network segmentation between their core banking systems and the rest of the environment, deployed deception assets on three high-value subnets, and ran a purple team exercise six weeks later to validate their new detection content. The regulatory exam finding on network architecture was addressed before the exam date.

Outcome

Domain admin in 3h 47m. Zero SOC alerts. Full detection program overhaul completed before regulatory review.

Assumed Breach Healthcare — Multi-Site Specialty Practice, ~1,200 employees

The breach path went through the EHR vendor's support portal.

No one had thought to look there.

The situation

Following a near-miss ransomware incident at a peer organization in the same specialty, the client's CISO wanted to know how far an attacker with internal access could get before anyone noticed. Budget constraints meant a full red team was off the table. An assumed breach exercise — starting from a position of internal access with a standard user account — was scoped instead.

What we found

Starting from a single compromised workstation in the billing department, we mapped the internal environment and identified a path to their Electronic Health Record system within 90 minutes. The path ran through a vendor support account that had been granted persistent access to their EHR platform for troubleshooting — access that had never been reviewed or scoped down.

That account had read access to every patient record in the system. It had write access to scheduling and billing. It authenticated without MFA. The vendor was not aware the account was configured this way.

What changed

The vendor support account was revoked and replaced with a time-limited, scoped access process with full logging. Third-party access was added to their annual access review cycle. Detection content was developed for lateral movement patterns consistent with the techniques used in the exercise.

Outcome

PHI access path identified in 90 minutes. Vendor access remediated. Third-party access review program established.

Incident Response + Ransomware Negotiation Manufacturing — Industrial Equipment, ~600 employees

Ransomware hit on a Friday night. Production was down by Saturday morning.

The threat actor had been inside for 22 days.

The situation

The client called at 11pm on a Friday. A ransomware variant had encrypted their manufacturing execution system, their ERP, and three file shares. OT systems were isolated as a precaution, halting production. They had no IR retainer, no backups that weren't also encrypted, and a ransom note demanding $2.1M in cryptocurrency.

What we did

We were on-site within six hours. The first 48 hours were triage and containment — identifying the threat actor, scoping the blast radius, and preserving forensic evidence. Forensics confirmed the initial access had occurred 22 days prior via a phishing email targeting their CFO's executive assistant. The attacker had moved slowly and deliberately, spending three weeks mapping the environment and staging for maximum impact before detonating.

Negotiation ran in parallel with technical remediation. The threat actor's initial demand was $2.1M. Through structured negotiation — demonstrating we understood their tooling, their timeline, and their operational costs — we reached a settlement that was materially lower, with a decryption key that worked. Technical remediation proceeded alongside, so the client was not solely dependent on the decryptor.

What changed

Full production resumed in 11 days. Post-incident, the client implemented an IR retainer, offline backup architecture, and MFA across all remote access. The executive assistant's account was found to have had overly broad access inherited from a previous role — that access model was redesigned across all EA and administrative accounts.

Outcome

Production resumed in 11 days. Ransom negotiated down significantly from initial demand. Decryptor functional. Forensic root cause identified.

Executive Advisory / Fractional CISO Technology — B2B SaaS, Series B, ~180 employees

The board wanted a CISO. The company needed one. The budget didn't support a full-time hire.

The answer was a different kind of engagement.

The situation

A Series B SaaS company processing financial data for enterprise clients was facing increasing security due diligence from prospects and their own board. Enterprise sales cycles were stalling on security questionnaires. Two large prospects had asked for SOC 2 Type II as a condition of signing. The Head of Engineering was handling all security questions on top of his primary job. The CEO needed someone who could speak to the board and to enterprise procurement teams — not a junior analyst, and not a consulting firm sending a different person every quarter.

What we did

We engaged as fractional CISO over a 12-month period. The first 90 days focused on a security program assessment, identifying the gaps between their current posture and the enterprise requirements they were selling into. We built a board-ready security roadmap — not a technical document, a business risk document — and presented it directly to the board.

Concurrent with the roadmap work, we scoped and managed their SOC 2 Type II audit engagement, coordinating with their engineering team without pulling the Head of Engineering into every conversation. We also developed their vendor security program and rewrote their security questionnaire response process so the sales team could handle tier-one questions without escalation.

What changed

SOC 2 Type II audit completed in month eight. Two enterprise deals that had been stalled on security diligence closed within 60 days of the report being issued. The board shifted from asking "do we have a CISO?" to having a quarterly security briefing they could speak to with confidence. By month twelve, the company was ready to hire a full-time security leader — and they hired someone strong because they knew what to look for.

Outcome

SOC 2 Type II completed. Two stalled enterprise deals closed. Board security program established. Full-time CISO hire completed at end of engagement.

Start a Conversation

Every situation is different. Tell us about yours.

These engagements started with a conversation about what the client was trying to learn or solve. That's how all of our engagements start. There's no standard scope here — just a genuine look at your situation and an honest answer about what we can do and whether it's the right fit.

Tell Us About Your Situation →