An asset manager averts a €22K wire fraud — and builds a security programme that blocked every attack for 10 months
After a CFO email compromise nearly resulted in a fraudulent wire transfer, we were called in. We delivered an emergency security overhaul in 4 weeks and a 3-month hardening programme.
The Challenge
The CFO's email account was compromised through a targeted phishing attack. An attacker posed as a supplier and almost succeeded in diverting €22,000 to a fraudulent IBAN — discovered by chance 10 minutes before bank processing. The firm managed €140M in client assets with zero security controls: no MFA, no monitoring, shared admin passwords, and no security awareness training.
- CFO email compromised — BEC (Business Email Compromise) attack
- €22,000 near-miss wire transfer to fraudulent IBAN
- No MFA across any account — 22 users fully exposed
- Shared administrator passwords across all systems
- No email authentication: SPF not enforced, no DKIM or DMARC
- No SIEM, no monitoring, no incident response plan
- Staff phishing click rate: 38% in initial simulation — nearly double the industry average
Our Solution
Emergency Response (Day 1–3)
Revoked all active sessions, reset all credentials, enabled MFA for every account, and isolated the compromised mailbox for forensic analysis. Contacted the bank to confirm no further transactions had been processed.
Email Authentication
Implemented strict SPF, DKIM signing, and a DMARC policy progressed from monitoring to enforcement within 2 weeks — preventing any further spoofing of the company domain.
Endpoint & Identity Protection
Deployed Microsoft Defender for Business across all devices, implemented Conditional Access policies (MFA required, geo-blocking non-EU countries, compliant device enforcement), and set up Privileged Identity Management (PIM) for admin accounts.
SIEM & Threat Detection
Deployed Microsoft Sentinel with custom detection rules for BEC patterns, impossible travel, and mass email forwarding. Configured automated incident response playbooks and integrated PagerDuty alerting.
Security Awareness Programme
Delivered a 2-day security awareness training for all 22 staff. Implemented monthly phishing simulations with targeted coaching for users who fail — reducing the click rate from 38% to 6% over 3 months.
Results
Tech Stack
Next Case Study
Power Platform & Business Intelligence
Industrial Distribution