| Client Profile | Details |
|---|---|
| Industry | Financial Services — Wealth Management |
| Location | Folsom, California |
| Company Size | 15 Employees |
| Office | Single Office Location |
| Technology Environment | Microsoft 365, 22 Endpoints & Business Server Infrastructure |
| Primary Challenge | Repeated phishing attempts, unauthorized account access & security gaps |
| Engagement | Cybersecurity Remediation + Ongoing Managed Cybersecurity |
| Remediation Timeline | 6 Weeks |
A Folsom wealth management firm approached RJ PRO Tech Group after experiencing a series of increasingly concerning cybersecurity issues.
Employees had been receiving convincing emails that appeared to come from colleagues and known clients. The messages were difficult to distinguish from legitimate business communications, creating a significant risk for a company that regularly handles sensitive financial information and client records.
At least one employee email account had also been accessed by an unauthorized party. Leadership knew something was wrong, but they did not have the visibility needed to determine how extensive the problem was or whether the unauthorized access had completely stopped.
The firm already had several basic security measures in place. Antivirus software was installed on its computers, a firewall protected the network, and an IT contractor was available when technical problems occurred.
The problem was that these tools and services were primarily reactive.
There was no continuous security monitoring, no comprehensive visibility into account activity, and no reliable way to investigate suspicious events after they occurred. The leadership team was left with a critical unanswered question:
Was the attacker still inside the environment?
For a financial services company, that uncertainty creates more than a technical problem. The firm works with sensitive client financial information and has authority related to the movement of money. A successful compromise could therefore lead to financial losses, regulatory concerns, operational disruption and significant damage to client trust.
The firm also had an upcoming cyber insurance renewal, increasing the urgency to understand its security posture and address the weaknesses that could affect the renewal process.
Rather than immediately treating individual symptoms, RJ PRO Tech Group began with a broader assessment of the firm’s technology environment.
The goal was to identify the vulnerabilities that could allow an attacker to gain access, move through the environment, remain undetected or disrupt business operations.
The assessment uncovered several significant gaps.
Multi-factor authentication was enabled for email for approximately half of the staff, but it was not consistently enforced across remote access and administrator accounts.
This created an obvious weakness.
Even if one portion of the environment was protected by MFA, an attacker who obtained valid credentials for an account without MFA could potentially use those credentials as an entry point.
The solution required moving from partial MFA coverage to comprehensive protection across user, remote-access and administrative accounts.
The assessment also identified password reuse across multiple services.
Several employee credentials appeared in known public breach data, meaning attackers could potentially already possess legitimate usernames and passwords associated with the firm.
This demonstrated why relying on passwords alone was no longer sufficient.
A compromised password can become particularly dangerous when employees reuse the same credentials across multiple systems.
The company had an existing backup process, but there was a major difference between having backups and knowing that those backups could actually restore the business.
No restore testing had been performed since the backup system was installed.
In addition, the backup target was reachable from the primary network.
That meant a serious ransomware incident or other network-wide compromise could potentially put both production systems and backup resources at risk.
The remediation therefore focused not only on maintaining backups, but on making them isolated, protected and regularly tested.
Three machines were running software that was no longer receiving security updates.
One of these systems was being used for client reporting, making the issue particularly important from both a security and operational perspective.
Unsupported systems create unnecessary exposure because newly discovered vulnerabilities may no longer receive vendor patches.
These machines were therefore replaced or rebuilt as part of the remediation process.
The firm’s network architecture provided insufficient separation between different types of devices and users.
Guest Wi-Fi, employee devices and server resources were operating on the same network.
In a compromised environment, this type of flat architecture can make lateral movement easier.
If an attacker successfully compromises one endpoint, they may have significantly more opportunity to reach other systems.
RJ PRO Tech Group addressed this by segmenting the network and separating guest, employee and business-critical resources.
The assessment identified two accounts belonging to former employees that were still enabled.
This is a common but serious access-control problem.
Employee departures should trigger an immediate review and deactivation of accounts, credentials and access rights. Leaving inactive accounts enabled creates unnecessary opportunities for unauthorized access.
Those dormant accounts were disabled during the remediation process.
Perhaps the biggest visibility problem was the lack of centralized logging and continuous monitoring.
The firm did not have adequate records showing who was accessing accounts, from where, or when.
That made it difficult to reconstruct exactly what had happened during the earlier incidents.
More importantly, without continuous monitoring, suspicious activity could remain unnoticed until it became an obvious business problem.
RJ PRO Tech Group approached the remediation in phases, prioritizing the highest-risk vulnerabilities first.
This was important because the firm needed to continue serving clients while its security environment was being rebuilt.
The first priority was reducing the possibility of continued unauthorized access.
Password resets were performed across the firm’s accounts, while multi-factor authentication was expanded to cover users, remote access and administrative accounts.
Dormant accounts were disabled, and mailbox configurations were reviewed for suspicious forwarding rules and other indicators that could have been introduced during an email compromise.
The compromised account was also isolated and its available access history reviewed to better understand the incident.
These steps established a more secure baseline before additional security controls were introduced.
Traditional antivirus alone was not enough for the firm’s threat environment.
RJ PRO Tech Group deployed behavioral endpoint protection across the firm’s devices, adding a stronger layer of detection against suspicious activity.
Email security was also strengthened within Microsoft 365.
Filtering and impersonation protection were implemented to help identify suspicious messages, lookalike domains and attempts to impersonate internal employees or known contacts.
This was especially important because email-based social engineering had been one of the firm’s primary attack vectors.
The firm’s backup and disaster recovery strategy was redesigned.
Backups were configured with stronger protection and isolation from the production environment, while restore testing was introduced so the firm could verify that its data could actually be recovered when needed.
The company’s patching and server-management processes were also brought onto a managed schedule.
The three end-of-life machines were replaced or rebuilt, eliminating a known source of security exposure.
Network segmentation was implemented to separate guest Wi-Fi, employee devices and business-critical systems.
Firewall management and network monitoring were also brought under ongoing management.
Technology alone cannot eliminate cybersecurity risk.
An employee can still click a malicious link, disclose credentials or approve a fraudulent request even when a business has strong technical controls.
For that reason, security awareness training was introduced alongside simulated phishing exercises.
This gave the company a way to identify vulnerable behaviors and measure improvement rather than simply assuming employees understood the risks.
The firm also transitioned to ongoing managed cybersecurity, including continuous monitoring and 24/7 support.
That changed the security model from a primarily reactive approach to one where suspicious activity could be identified and escalated regardless of the time of day.
The six-week remediation significantly improved the firm’s overall security posture and, just as importantly, gave leadership greater visibility into its environment.
Key improvements included:
Security AreaBeforeAfterMulti-Factor AuthenticationOnly partially enabledExpanded across users, remote access and administrative accountsEmployee AccessFormer employee accounts remained activeDormant accounts disabledEndpoint SecurityTraditional antivirus protectionBehavioral endpoint protectionEmail SecurityVulnerable to impersonation and phishing attemptsEnhanced filtering and impersonation protectionBackupsExisting backups had not been restore-testedProtected backups with scheduled restore verificationUnsupported SystemsThree end-of-life machinesSystems replaced or rebuiltNetwork ArchitectureFlat networkSegmented network environmentSecurity MonitoringLimited visibility and no continuous monitoringOngoing managed security monitoringSecurity AwarenessNo structured phishing simulation programSecurity awareness training and simulated phishingIT ResponsePrimarily reactiveOngoing managed cybersecurity and 24/7 support
The most important improvement was not a single piece of software or one configuration change.
It was visibility.
Previously, the firm had limited ability to determine what was happening inside its environment. After remediation, security activity could be monitored continuously and suspicious events could be investigated more effectively.
That distinction matters.
A firewall can block certain types of traffic. Antivirus can detect certain malicious files. MFA can make stolen passwords less useful.
But none of those controls, by themselves, answer the question of what is happening across an entire business environment.
Continuous monitoring provides that missing layer of visibility.
The engagement also changed the firm’s approach to cybersecurity.
Before the remediation, security was largely reactive. Problems were addressed when they became visible, while basic tools operated in the background.
After the engagement, cybersecurity became an ongoing process.
Accounts were protected with stronger authentication. Endpoints had improved behavioral protection. Email defenses were strengthened. Backups were designed around recovery rather than simply storage. Network resources were segmented. Employee security awareness became part of the program. And monitoring was available around the clock.
This approach is particularly important for smaller financial services firms.
A company does not need hundreds of employees to become an attractive target. A small organization may still possess valuable financial information, credentials, client records and access to sensitive transactions.
The absence of a large internal IT or security department can also make continuous monitoring difficult to maintain without outside support.
This engagement highlighted several lessons that apply to many professional services and financial businesses.
Enabling MFA for some accounts is better than having none, but attackers only need one unprotected account to gain a foothold.
MFA should be applied consistently, particularly to administrative and remote-access accounts.
A backup that has never been restored is not a proven recovery strategy.
Regular restore testing provides evidence that the organization can actually recover when something goes wrong.
Modern attacks do not always depend on dropping an obvious malicious file onto a computer.
Attackers can use stolen credentials, legitimate tools and social engineering.
Security therefore needs multiple layers rather than reliance on traditional antivirus alone.
Without appropriate logging and monitoring, an organization may not know when suspicious activity occurs.
That makes both prevention and investigation harder.
Cybersecurity is not a one-time installation.
Threats change, employees change, systems change and vulnerabilities change.
The controls that protect a business today need to be monitored, maintained and reviewed over time.
The Folsom wealth management firm did not need another isolated security product.
It needed a coordinated security strategy that addressed access, endpoints, email, backups, infrastructure, employees and monitoring together.
RJ PRO Tech Group helped the firm close critical security gaps, strengthen its technology foundation and move from reactive IT support toward ongoing cybersecurity management.
For leadership, the biggest change was simple:
They no longer had to rely on assumptions about whether their environment was secure. They had a structured security program designed to identify problems, respond to threats and support the business continuously.
If your organization handles sensitive financial information but does not have clear visibility into who can access your systems, whether your backups actually work, or whether someone is watching for suspicious activity, the same types of gaps may already exist in your environment.
A security assessment can identify those weaknesses before an attacker does.
RJ PRO Tech Group provides managed IT and cybersecurity services for businesses throughout Folsom, El Dorado Hills, Sacramento and the surrounding Northern California region.
If you are concerned about your company’s cybersecurity posture, contact RJ PRO Tech Group for a security assessment and learn where your biggest risks may be.
Request a Free Consultation
El Dorado Hills Office: (916) 345-3451
Valley Springs Office: (209) 920-4077
Email: help@rj-pro.net