Skip to content
Back to case studies

Government-linked corporation

Four layers of security. One intrusion none of them saw.

Sector

Government-linked corporation, public sector

Services

Managed SOC, proactive threat hunting, incident response

What we found

An intrusion four layers deep

A national organisation holding workforce data for an entire country had four layers of security in place. None of them had flagged anything.

Our threat hunting found an intrusion already inside the environment. The attacker was operating with valid administrative credentials, which is why nothing had triggered. They had accessed sensitive files and had begun deleting their own login traces to remove the evidence of how they got in.

The evidence

What the account was doing

STATUS

Contained before any data left the environment.

LAYERS BYPASSED

Four, none of which raised an alert.

No alertNo alertNo alertNo alert

ADMIN CREDENTIALS

Valid, and in active use by the attacker.

FILE ACCESS

Sensitive files confirmed accessed.

LOG DELETION

Halted while in progress.

What we did

Containment and remediation

We contained the threat, produced a full incident report tracing the activity, and advised on remediation.

The client's position before the engagement was not unusual. They had invested in controls and had no reason to believe anything was wrong. What they did not have was anyone continuously examining what those controls were failing to catch, and an attacker using legitimate credentials will not trigger a control designed to detect illegitimate ones.

Bring enterprise-grade defence to your organisation.

Our team is here to answer your questions and show how a fully managed SOC keeps your organisation protected around the clock, from continuous monitoring to threat hunting and machine-speed response.