Work we can show
Real engagements, written so you can see the problem, the work and the outcome. Client names appear only when we have permission.
Confidential client
Restoring production in 14 hours after a ransomware incident
A mid-sized manufacturer lost access to its ERP and file infrastructure overnight. We contained the incident, restored from isolated backups, and rebuilt identity controls to close the entry point.
- Time to production restore
- 14 hrs
- Ransom paid
- $0
- Data loss window
- < 1 hr
Confidential client
Stopping a six-figure wire after a lookalike invoice
Accounts payable received a familiar invoice from a long-standing vendor — on a domain one character off. The callback rule we had just written caught it before the wire left the trust account.
- Payment stopped
- $186k
- Mailboxes with MFA
- 100%
- Later attempts that reached a wire
- 0
Confidential client
Turning a declined cyber renewal into a bindable application
The broker came back with four fails: MFA coverage, backup isolation, EDR alerting, and no pentest in two years. We evidenced what was already true, closed the rest in six weeks, and the policy bound.
- Weeks to bindable evidence
- 6
- Application fails closed
- 4/4
- Exclusion applied
- None
Confidential client
Containing a clinic mailbox breach before notification became the story
A clinic manager clicked a Microsoft 365 notice. We revoked the session, hunted inbox rules, and gave counsel a fact pack the same day so the PHIPA conversation was about facts, not panic.
- Time to cut forwarding
- < 1 hr
- Days of undetected forwarding
- 11
- Staff on MFA after the week
- 70/70
Confidential client
Cleaning a retail tenant before Black Friday, not after it
Guest links, leftover contractor accounts and an IMAP leftover from a 2019 migration. We locked the tenant in three weeks so peak season was not the week identity failed.
- Stale accounts removed
- 47
- Weeks to lock-down
- 3
- Anonymous share links closed
- 120+
Confidential client
A municipal pentest that became a closed ticket list, not a PDF
Council had asked for a pentest. The last one sat unread. We scoped the systems residents actually use, ranked the paths, and retested the highs before the next council packet.
- High findings at retest
- 0 open
- Weeks from kickoff to retest
- 11
- Resident-facing outage
- None
Have a similar problem?
Tell us what you are dealing with. If we have solved it before, we will say so.
