Case Studies
A mid-size medical practice lost more than $700,000 and exposed 12,000 patients' protected health information because their IT company built an environment that worked but was never secured. Open RDP. A departed employee's active account. No MFA. No monitoring. No cyber insurance. The attacker didn't need to be good. The door was open.
2026-08-14
A commercial mechanical contractor was never broken into and never had a dollar stolen from its accounts. A phished field-tech password, a domain anyone could forge, and an IT vendor who sold configuration as though it were a product turned the company's own email into a weapon against its customers, its suppliers, its bank, and its attorney. The abuse kept going after every password was changed. The controls that would have stopped it were almost all free. Nobody was there to say so.
2026-07
A 300-employee building supply distributor lost $1.4 million when a compromised warehouse laptop walked through an always-on tunnel to their MSP-hosted servers. One MSP hosted the servers. Another managed the laptops. The EDR caught the attack on Day 0. Nobody was watching. Three contracts, three denials, and a gap nobody owned.
2026-06-16
An 85-employee manufacturer lost $287,000, a $1.4 million annual client, and an insurance claim. The controls that would have caught it were a line item nobody signed.
2026-05-14