The firm ran one shared email password across its operations desk, had no multi-factor authentication anywhere, and owned a backup drive nobody had checked since it was installed. A supplier-impersonation attempt had already reached the finance inbox. We ran a four-day review, closed the eleven highest-risk findings over three weeks, and moved them onto the monitoring tier.
“We had assumed someone was handling it. Now someone is, and I can show a client exactly what that looks like.”
- 31 → 0
- Accounts without MFA
- 27% → 4%
- Phishing simulation click rate, 90 days
- 38 min
- Full restore, tested quarterly
Client named on request. Figures from the engagement close-out report.