Skip to content

Red team against a client portfolio portal

Red team against a client portfolio portal

Red team against a client portfolio portal

A wealth management firm wanted to know how its defences held against a patient, targeted adversary rather than a checklist. The objective was set narrowly: reach the client portfolio data, quietly, and show the path.

Client

Wealth management firm

Industry

Wealth management

Service

Red team & code review

Severity

CRITICAL

A vault door standing slightly open at the end of a dark corridor, its gap lit in blue

01

The challenge

The challenge

The challenge

The firm had invested in endpoint detection and a monitored perimeter, and against noisy, generic attacks that investment works. A targeted adversary does not bring noisy, generic attacks. The gap this exercise probed was not a missing product; it was the assumption that detection tuned for commodity attacks also covers a slow operator who blends into normal traffic and never touches the patterns the tooling is looking for.

Once a foothold exists, the interior of most networks is more permissive than the perimeter suggests. Credentials left on one machine reach another. A path from an ordinary user to a system administrator exists because the internal segmentation was designed for convenience and reviewed less often than the edge. None of this is exotic. It is the ordinary interior of a network that has spent its budget facing outward.

02

The approach

The approach

The approach

The engagement ran as an adversary simulation with a defined objective and rules of engagement agreed in advance, so the exercise measured the firm’s resilience rather than improvising scope. We favoured legitimate tooling and existing access over anything that would announce itself, because the point was to test what the defenders would actually see.

  • Establish a foothold through a realistic initial vector and confirm what, if anything, was detected

  • Move through the interior using existing credentials and administrative tooling rather than custom code

  • Reach the portfolio data along the shortest defensible path, and stop at demonstrated access

  • Reconstruct, with the defenders afterward, which steps were visible and which were not

The value was not the access. It was the timeline: where detection fired, where it should have, and the exact distance between the two.

03

The path

The path

The path

01

Established a quiet foothold

02

Moved using existing credentials

03

Reached the client portfolio portal

04

Retuned detection, replayed the path

A dark office floor under dormant sensors with a blue line running beneath them

04

The outcome

The outcome

The outcome

Detection was retuned for the slow, low-signal behaviour the exercise used, hardware-backed multi-factor was required for administrative access, and the interior was re-segmented so a single foothold no longer reaches the portfolio layer. The engagement’s real deliverable was a defender’s map of what had been invisible.

We replayed the key steps after remediation to confirm they were now detected or blocked. Reported as CRITICAL in 2025. Retest included in the engagement.

CRITICAL

CRITICAL

Severity

Severity

2025

2025

Disclosed

Disclosed

Included

Included

Retest

Retest