Security review of a Caribbean professional services firm's systems
Cyber security consultancy

A cyber security review for an offshore corporate services firm

A professional services firm handling high-value client transactions asked for an honest assessment of its exposure after a near-miss invoice fraud attempt. We reviewed posture against the Cyber Essentials controls, prioritised remediation and trained the team.

Client

Offshore corporate and financial services firm (name withheld)

Sector

Financial and corporate services

Location

British Virgin Islands

Year

2025

The challenge

An attacker had gained visibility of an email thread and attempted to redirect a client payment by supplying amended bank details at exactly the right moment. The attempt was caught by an alert staff member rather than by any control.

The firm had antivirus and a firewall but no multi-factor authentication on email, no inventory of accounts and devices, inconsistent patching, and backups that had never been restored as a test.

What we did

  • We assessed the firm against the five Cyber Essentials controls — firewalls, secure configuration, access control, malware protection and patch management — and reported findings in plain English, ranked by risk reduction per unit of effort rather than by technical severity alone.
  • Multi-factor authentication was enabled first across email, remote access and finance systems, and mailbox forwarding-rule alerting was turned on to detect the tactic used in the attempted fraud.
  • Dormant and shared accounts were removed, administrative access was separated from day-to-day accounts, and a patching routine with defined timescales was put in place.
  • We ran short, scenario-based awareness training built around payment redirection and false urgency, and helped the firm adopt a verbal verification policy for any change to bank details.
  • Backups were reconfigured off-island and a restore was performed to prove recovery, followed by a one-page incident plan and a tabletop exercise.

Outcomes

  • Credential-theft exposure closed on every business-critical system through multi-factor authentication
  • The specific fraud technique used against the firm now detected automatically rather than by chance
  • A verified, tested off-island restore replacing an untested backup routine
  • A named incident plan rehearsed by the leadership team
  • Documented posture the firm can present during client and partner due diligence

Outcomes are described qualitatively. We publish performance figures only where a client has reviewed and approved the specific numbers; named references are available on request.