Skip to main content
ITSIGNSolutions
Case studies

Work we can show

Real engagements, written so you can see the problem, the work and the outcome. Client names appear only when we have permission.

ManufacturingIncident Response

Confidential client

Restoring production in 14 hours after a ransomware incident

A mid-sized manufacturer lost access to its ERP and file infrastructure overnight. We contained the incident, restored from isolated backups, and rebuilt identity controls to close the entry point.

Time to production restore
14 hrs
Ransom paid
$0
Data loss window
< 1 hr
Read the case study
Professional ServicesCloud and Microsoft 365

Confidential client

Stopping a six-figure wire after a lookalike invoice

Accounts payable received a familiar invoice from a long-standing vendor — on a domain one character off. The callback rule we had just written caught it before the wire left the trust account.

Payment stopped
$186k
Mailboxes with MFA
100%
Later attempts that reached a wire
0
Read the case study
Financial ServicesGRC Services

Confidential client

Turning a declined cyber renewal into a bindable application

The broker came back with four fails: MFA coverage, backup isolation, EDR alerting, and no pentest in two years. We evidenced what was already true, closed the rest in six weeks, and the policy bound.

Weeks to bindable evidence
6
Application fails closed
4/4
Exclusion applied
None
Read the case study
HealthcareIncident Response

Confidential client

Containing a clinic mailbox breach before notification became the story

A clinic manager clicked a Microsoft 365 notice. We revoked the session, hunted inbox rules, and gave counsel a fact pack the same day so the PHIPA conversation was about facts, not panic.

Time to cut forwarding
< 1 hr
Days of undetected forwarding
11
Staff on MFA after the week
70/70
Read the case study
Retail and E-commerceCloud and Microsoft 365

Confidential client

Cleaning a retail tenant before Black Friday, not after it

Guest links, leftover contractor accounts and an IMAP leftover from a 2019 migration. We locked the tenant in three weeks so peak season was not the week identity failed.

Stale accounts removed
47
Weeks to lock-down
3
Anonymous share links closed
120+
Read the case study
Public Sector and EducationPenetration Testing

Confidential client

A municipal pentest that became a closed ticket list, not a PDF

Council had asked for a pentest. The last one sat unread. We scoped the systems residents actually use, ranked the paths, and retested the highs before the next council packet.

High findings at retest
0 open
Weeks from kickoff to retest
11
Resident-facing outage
None
Read the case study

Have a similar problem?

Tell us what you are dealing with. If we have solved it before, we will say so.