A wealth management firm wanted to know how its defences held against a patient, targeted adversary rather than a checklist. The objective was set narrowly: reach the client portfolio data, quietly, and show the path.
Client
Wealth management firm
Industry
Wealth management
Service
Red team & code review
Severity
CRITICAL

01
The firm had invested in endpoint detection and a monitored perimeter, and against noisy, generic attacks that investment works. A targeted adversary does not bring noisy, generic attacks. The gap this exercise probed was not a missing product; it was the assumption that detection tuned for commodity attacks also covers a slow operator who blends into normal traffic and never touches the patterns the tooling is looking for.
Once a foothold exists, the interior of most networks is more permissive than the perimeter suggests. Credentials left on one machine reach another. A path from an ordinary user to a system administrator exists because the internal segmentation was designed for convenience and reviewed less often than the edge. None of this is exotic. It is the ordinary interior of a network that has spent its budget facing outward.
02
The engagement ran as an adversary simulation with a defined objective and rules of engagement agreed in advance, so the exercise measured the firm’s resilience rather than improvising scope. We favoured legitimate tooling and existing access over anything that would announce itself, because the point was to test what the defenders would actually see.
Establish a foothold through a realistic initial vector and confirm what, if anything, was detected
Move through the interior using existing credentials and administrative tooling rather than custom code
Reach the portfolio data along the shortest defensible path, and stop at demonstrated access
Reconstruct, with the defenders afterward, which steps were visible and which were not
The value was not the access. It was the timeline: where detection fired, where it should have, and the exact distance between the two.
03
01
Established a quiet foothold
02
Moved using existing credentials
03
Reached the client portfolio portal
04
Retuned detection, replayed the path

04
Detection was retuned for the slow, low-signal behaviour the exercise used, hardware-backed multi-factor was required for administrative access, and the interior was re-segmented so a single foothold no longer reaches the portfolio layer. The engagement’s real deliverable was a defender’s map of what had been invisible.
We replayed the key steps after remediation to confirm they were now detected or blocked. Reported as CRITICAL in 2025. Retest included in the engagement.
Case Studies


