← All case studies

The Key Was on the Laptop

Fictional company: Cornerstone Building Supply

A 300-employee building supply distributor lost $1.4 million when a compromised warehouse laptop walked through an always-on tunnel to their MSP-hosted servers. One MSP hosted the servers. Another managed the laptops. The EDR caught the attack on Day 0. Nobody was watching. Three contracts, three denials, and a gap nobody owned.

Cornerstone Building Supply distributes drywall, lumber, roofing, and insulation across the upper Midwest. Three hundred employees. Six warehouses. Family-owned for forty years. They serve general contractors and residential builders. Invoices go out by the truckload. Margins are thin. IT is one full-time manager, Derek, and a part-time helpdesk tech.

Cornerstone has two IT vendors. They hired them separately, years apart, for different problems. The two vendors have never spoken to each other.

Northline Technology Partners hosts the servers. Cornerstone's entire backend runs on four virtual machines at Northline's data center in Minneapolis. The domain controller handles every login. The accounting server runs Sage 100 for accounts payable, accounts receivable, and payroll, including employee Social Security numbers. The file server holds eight years of contracts, proposals, vendor pricing, and HR documents. The backup server runs nightly snapshots of the other three. All four servers live on one host, on one flat network. Northline manages the hardware, patches the operating systems, and runs the firewalls. They bill $6,000 a month.

Bridgepoint IT Solutions manages the workstations. Laptops, desktops, printers, new user setup, M365 admin, email, helpdesk. They sold Cornerstone an EDR (endpoint detection and response) agent on every workstation. It's installed. It's running. Alerts go to Bridgepoint's monitoring dashboard. They bill $3,200 a month.

Between the warehouses and the servers, Northline configured always-on encrypted tunnels, firewall to firewall. A laptop at the Fargo warehouse and the accounting server in Minneapolis sit on the same network. The tunnel doesn't ask who you are. It doesn't require a login. If your device is on the warehouse network, it can reach every server. The tunnel is just a road. Anyone on it reaches everything on it.

Bridgepoint has no access to Northline's environment. Northline has no visibility into the workstations Bridgepoint manages. The EDR covers the laptops. It does not cover the servers. Nobody asked for it on the servers. Nobody's contract says who should.

On a Tuesday, a warehouse supervisor at the Fargo location opened a personal email attachment on his work laptop during lunch. The attachment installed malware. Within minutes, the attacker had control of the device.

The EDR caught it. An alert fired in Bridgepoint's dashboard. It was categorized as medium severity. It joined 847 other unacknowledged alerts.

Bridgepoint's contract with Cornerstone covers "EDR deployment and management." Management means the software is installed and updated. It does not mean someone is watching the alerts. That's a different service tier. Cornerstone is on the Essentials plan. The managed detection and response tier costs more. Derek never bought it.

Two hours after the initial compromise, the attacker moved. The laptop was on the Fargo warehouse network. The warehouse network had an always-on tunnel to Northline's data center. There was nothing between the two networks. No separation. No segmentation. The attacker reached every server as if they were sitting in the data center.

Bridgepoint's EDR could not see what happened next. The servers are Northline's environment. Northline doesn't run EDR on the servers.

Four hours in, the attacker found what they needed. A service account called svc-sage-backup, created by Northline during a server migration two years earlier. It had domain admin privileges, the highest level of access in the network. It controlled every server, every user account, every permission. Northline created it to make the migration work and never reduced its access. The password hadn't changed since setup.

For the next six days, the attacker copied data out of the network. Customer records going back four years. Vendor pricing. Employee personal information, including Social Security numbers from the Sage 100 payroll database. Accounts receivable data. All of it moved through the same tunnel. No monitoring. No alerts on the server side.

The EDR on the Fargo laptop continued to fire. Twelve alerts over seven days, all related to suspicious outbound connections from the compromised machine. They sat in Bridgepoint's dashboard. Nobody looked.

On Day 7, a Monday at 2:00 AM, the attacker deployed ransomware across every server using the domain admin service account. Domain controller. Accounting server. File server. Backup server. All four encrypted. The backups lived on the same host, on the same flat network. Encrypted with everything else.

Derek arrived at 6:15 AM. Nothing worked. No logins. No accounting system. No shared drive. He called Northline first.

Northline confirmed the servers were encrypted. The underlying hardware was intact, but every server on it was locked. Their account manager told Derek they'd need to investigate, but the initial read was that nothing on the hardware layer was compromised. Whatever did this came from inside the customer environment, not from a failure on Northline's side.

Derek pulled up the master service agreement. Section 7.3: "Provider manages hardware, physical facility, and operating system patching. Customer is responsible for application security, endpoint management, access controls, and network architecture within Customer's environment." Derek's lawyer later confirmed: with that language, Northline likely owes nothing. The MSA doesn't cap their liability at some reduced amount. It excludes it. The attack came through a laptop Northline doesn't manage, across a network architecture Cornerstone is responsible for, using an access control gap the contract puts on the customer. Northline did what the contract says. The contract says what Northline wrote.

He called Bridgepoint next. Their helpdesk lead pulled up the dashboard and showed Derek the twelve alerts on the Fargo laptop, all dated back to Day 0. "We saw the alerts. We don't have access to Northline's environment. We didn't know it had spread."

Derek asked why nobody called him.

"Our contract is endpoint management. The alerts were on the endpoint. We don't have a process for escalating to another vendor's environment."

Bridgepoint's contract: "Provider will deploy, configure, and maintain endpoint detection and response software on Customer-designated devices." No mention of alert triage. No incident response obligation. No requirement to contact other vendors. Same story as Northline. The contract language puts security responsibilities on the customer. Bridgepoint's lawyer would make the same argument: the breach didn't result from anything Bridgepoint failed to do under the contract.

The EDR worked. It detected the compromise on Day 0. The alerts were accurate. Nobody was paid to watch them.

Derek's third call was to the insurance company. Cornerstone carried a cyber policy through Granite Shield Cyber, placed by their broker at Midland Insurance. $2 million aggregate. $50,000 retention. $2,800 a year.

The insurer assigned breach counsel from their approved panel, a law firm that specializes in cyber incidents. Breach counsel retained a forensic investigation firm. Within 48 hours, the forensic team was imaging Cornerstone's systems, pulling server logs, firewall configurations, and EDR data. Their job was to document the attack chain and the state of Cornerstone's environment at the time of the breach. The forensic report goes to the insurer's claims team. It is thorough, and it is not on the policyholder's side.

The forensic report documented the remote access VPN configuration: username and password, no MFA (multi-factor authentication). It documented the network architecture: one flat network from warehouse to server, no separation, no segmentation. It documented the EDR deployment: agents on workstations, no monitoring contract, 847 unacknowledged alerts at the time of the breach. The insurer's claims team compared the forensic findings to the application Cornerstone signed eight months earlier.

On Day 31, the denial letter arrived. The insurer cited three questions from the application.

Q14: "Does the organization require multi-factor authentication for all remote access to network resources?" Cornerstone answered yes. Reality: Cornerstone also has a remote access VPN for employees working from home or traveling. Derek, the helpdesk tech, two sales reps. Username and password. No MFA. Derek checked yes on the application because the company uses M365 with MFA for email, and he thought that covered it. The insurer's question is about remote access to network resources. The VPN is remote access. It has no second factor. The attack didn't come through the VPN. It came through the site-to-site tunnel, which is a different problem entirely. The insurer doesn't care. The question asked whether MFA is on all remote access. It isn't. Denied.

Q22: "Does the organization segment its network to separate critical systems from end-user devices?" Cornerstone answered yes. Reality: everything is flat through the tunnel. Derek checked yes because the servers are "in a different building." Physical separation is not network segmentation.

Q31: "Does the organization monitor endpoint detection alerts and maintain an incident response process?" Cornerstone answered yes. Reality: EDR is installed. Alerts go to a dashboard nobody opens. There is no incident response plan. There is no escalation process.

Material misrepresentation on all three questions. Coverage denied. Not reduced. Denied.

The attack came through the site-to-site tunnel. The insurance denial came because of the remote access VPN. The two had nothing to do with each other. In the most well-known cyber insurance denial, Travelers v. International Control Services, the attacker came in through the exact gap the policyholder misrepresented. The insurer didn't need that. They don't need a causal connection between the misrepresentation and the breach. They need a material misrepresentation on the application. Derek didn't set out to mislead anyone. He answered questions he didn't fully understand, about controls he thought he had. The result is the same.

The broker wasn't liable. The attestation is the policyholder's responsibility. Midland never walked Derek through what the questions meant. Midland isn't required to.

What Cornerstone lost

Fourteen days of manual operations. Six warehouses tracked inventory on paper. Invoices stopped going out. Deliveries continued but couldn't be confirmed or billed. Two general contractors with delivery SLAs assessed penalty fees. One of them, a $1.2 million annual account, moved to a competitor during the outage. They didn't come back.

Total cost: approximately $1.7 million. Recovery, lost revenue, SLA penalties, customer loss, and breach notification costs for employee personal information.

Neither vendor is likely liable under their contracts. Insurance payout: zero.

Cornerstone is holding all of it.

People

The warehouse supervisor opened a personal email attachment on a work laptop. There was no acceptable use policy. No security awareness training. No guidance on what to do and what not to do with personal email on company hardware. The supervisor had never been trained. Nobody told him the laptop in his hands was a door to the accounting system.

Derek is the entire security program. He manages user accounts, handles helpdesk escalations, and makes purchasing decisions about tools he wasn't trained to evaluate. He chose Bridgepoint's Essentials plan over the monitoring tier because nobody explained what the gap between "deploy" and "monitor" looks like at 2:00 AM on a Monday. He answered the insurance application based on what he thought the questions meant, not what the insurer's forensic team would later measure.

Derek hired Northline and Bridgepoint years apart, for different problems. He never put the two contracts on the same table. He never asked what falls in the gap between them. Nobody compared the insurance policy's stipulations to the actual controls across both vendor scopes. The gap between the two contracts is the thing that broke, and that gap is in nobody's contract.

Process

Bridgepoint managed the endpoints. Northline managed the servers. Neither had visibility into the other's environment. No shared asset inventory existed. The servers had no EDR because that wasn't in Northline's contract, and Bridgepoint's scope stopped at the endpoint. The attacker crossed from a managed environment into an unmanaged one, and no one on either side could see it happen.

EDR was deployed on every workstation. Alerts fired accurately. But Cornerstone's contract with Bridgepoint covered deployment, not response. The alerts went to a dashboard that Bridgepoint staffed during business hours on the standard plan. The monitoring tier, the one with triage and escalation commitments, cost more. There was no incident response plan. There was no escalation process between the two vendors. There was no shared runbook. If Bridgepoint saw something moving toward Northline's servers, there was no number to call and no one expecting the call.

Backups ran nightly. Nobody tested restores. The backup server sat on the same network as everything else. The backups existed to recover from hardware failure, not from an attacker with domain admin credentials and a clear path to the backup server.

Technology

The site-to-site tunnel gave every device on the warehouse network access to every server with no segmentation. The tunnel is a network link, not a remote access connection, so MFA doesn't apply to it. But the flat architecture meant a compromised laptop was a compromised server network. No network boundaries. No firewall rules between segments because there were no segments. A laptop at the most remote warehouse could reach the domain controller, the backup server, and every share on the file server. The architecture made lateral movement invisible because there was no boundary to cross.

The remote access VPN that Derek and a few others used for off-site work had no MFA. Username and password only. That VPN wasn't part of the attack, but it voided the insurance.

The svc-sage-backup service account had domain admin privileges because that's what made the migration work two years ago. Service accounts don't get MFA. They get scoped permissions and regular credential rotation. This one got neither. The password hadn't changed since setup. When the attacker found it, they had the keys to every server on the network.

The backup server sat on the same host, on the same flat network, reachable from any device. No immutable storage. No offsite copy. No air gap. The attacker encrypted it along with everything else.

What would have stopped it

A scoped service account. The svc-sage-backup account needed access to Sage 100 and backup jobs. It did not need domain admin. Removing domain admin from that account and granting only the specific permissions required would have contained the attacker to the initial compromised laptop. No domain admin means no ability to deploy ransomware across every server. Northline's admin could have done this in two hours. It was never on anyone's task list.

Network segmentation. Servers on one network segment. Warehouse endpoints on a separate segment. Firewall rules between them. Allow laptops to reach the accounting server and the file server on specific ports. Block direct access to the domain controller and backup server from the endpoint network. The attacker's path from the Fargo laptop to the domain controller would have hit a firewall rule instead of open air. Northline's network team could have configured this. The contract never included it, and Derek never asked because he didn't know the network was flat.

EDR on the servers. The same agent running on every workstation, deployed to every server. If EDR had been on the domain controller, the attacker's activity and the use of svc-sage-backup would have generated alerts in the same dashboard Bridgepoint already had. The gap in visibility existed because the servers were in a different vendor's scope and nobody added EDR to the server contract.

Monitored EDR with a response commitment. An alert fires, a person triages it within 30 minutes, and escalation happens within an hour. The EDR caught the compromise on Day 0. Twelve alerts over seven days. With a monitoring contract that includes triage and response, the first alert triggers a call to Derek, an investigation, and containment. The attacker's six-day window collapses to hours. The monitoring tier Bridgepoint offered would have cost roughly $1,500 to $3,000 a month. Cornerstone was paying $3,200 for deployment without response. The difference between what they bought and what they needed was a line item.

MFA on the remote access VPN. The attack came through the site-to-site tunnel, not the remote access VPN. But the insurance denial came because the remote access VPN had no MFA. Username and password only. Adding a second factor to the VPN would not have stopped this specific attack. It would have kept the insurance policy valid. That's $1.7 million in coverage Cornerstone lost because a VPN that four people use didn't have a second factor enabled. MFA on remote access is table stakes for cyber insurance. The control and the coverage are separate problems. Cornerstone failed both.

Immutable offsite backups. Backup target on a separate network, with separate credentials, with immutability enabled. Not on the same host. Not reachable from the production network. When the attacker encrypted the backup server, the offsite copy would have been untouched. Recovery from a verified offsite backup takes hours, not fourteen days of paper operations.

A joint incident response plan. One document. Both vendors named. One escalation phone number. A shared runbook that says: if Bridgepoint sees suspicious activity moving from a workstation toward Northline's servers, Bridgepoint calls Northline directly. If Northline sees unusual logins on the domain controller, Northline calls Bridgepoint. Right now, neither vendor knows the other exists in any operational sense. Derek is the only bridge between them, and Derek doesn't monitor alerts at 2:00 AM.

What to do tomorrow

Pull both vendor contracts and read the shared responsibility language. What does each vendor say they manage? What do they say you manage? Put the two documents side by side. Look for the thing neither contract covers. Network segmentation. Alert escalation. Service account reviews. Server-side EDR. If it's not in either contract, it's your risk, and you're paying for it whether you buy the control or absorb the loss.

Pull your cyber insurance application and read every question you answered yes to. For each one, verify you actually have the control in place today. Not that you think you do. That you can prove it. MFA on remote access means a second factor on every VPN, RDP, and remote connection your people use, not just email. Segmentation means network boundaries with enforced rules, not servers in a different building. Monitoring means a person looks at the alerts and acts on them, not that the software is installed. If any answer doesn't hold up, call your broker before renewal. Not after the claim.

Put your vendors on the same call. Introduce them. Ask one question: "If a compromised laptop on our network starts reaching the servers, what happens?" If either answer includes "that's not in our scope" or "you'd need to call the other vendor," you don't have an incident response plan. You have two contracts and a gap in the middle. That gap is where the $1.7 million lives.

Discussion questions

  • Do you have more than one IT vendor managing different parts of your infrastructure? Have those vendors ever been on the same call? Is there a document that defines what happens when an incident crosses from one vendor's scope into the other's?
  • Look at your site-to-site VPN or tunnel configuration. Is it firewall-to-firewall, always on? Does every device on the local network automatically have access to the remote network? If a laptop at your most remote office were compromised right now, what servers could the attacker reach without any additional login?
  • Pull up your EDR dashboard. How many unacknowledged alerts are there right now? Who is responsible for triaging them? Is that person checking today, or is that responsibility in a service tier you didn't buy?
  • Find the service accounts in your Active Directory. How many have domain admin or equivalent privileges? When was the last time someone reviewed whether they still need that level of access? Who owns that review?
  • Read your cyber insurance application. Did the person who filled it out understand what "network segmentation" and "multi-factor authentication for remote access" mean in technical terms? Would your environment survive an audit against those answers today?

Frequently asked

What is the The Key Was on the Laptop case study about?

A 300-employee building supply distributor lost $1.4 million when a compromised warehouse laptop walked through an always-on tunnel to their MSP-hosted servers. One MSP hosted the servers. Another managed the laptops. The EDR caught the attack on Day 0. Nobody was watching. Three contracts, three denials, and a gap nobody owned.

Is Cornerstone Building Supply a real company?

No. Cornerstone Building Supply is a fictional company used to illustrate a real attack pattern. The tactics, techniques, and procedures are real and documented; the company, the people, and the specific details are invented.

What would have prevented this?

The case study breaks down what was missing — across people, process, and technology — and the specific compensating controls that would have stopped the attack, including one action to take this week.

Subscribe for new case studies