
A cyber security review for an offshore corporate services firm
A professional services firm handling high-value client transactions asked for an honest assessment of its exposure after a near-miss invoice fraud attempt. We reviewed posture against the Cyber Essentials controls, prioritised remediation and trained the team.
Offshore corporate and financial services firm (name withheld)
Financial and corporate services
British Virgin Islands
2025
The challenge
An attacker had gained visibility of an email thread and attempted to redirect a client payment by supplying amended bank details at exactly the right moment. The attempt was caught by an alert staff member rather than by any control.
The firm had antivirus and a firewall but no multi-factor authentication on email, no inventory of accounts and devices, inconsistent patching, and backups that had never been restored as a test.
What we did
- We assessed the firm against the five Cyber Essentials controls — firewalls, secure configuration, access control, malware protection and patch management — and reported findings in plain English, ranked by risk reduction per unit of effort rather than by technical severity alone.
- Multi-factor authentication was enabled first across email, remote access and finance systems, and mailbox forwarding-rule alerting was turned on to detect the tactic used in the attempted fraud.
- Dormant and shared accounts were removed, administrative access was separated from day-to-day accounts, and a patching routine with defined timescales was put in place.
- We ran short, scenario-based awareness training built around payment redirection and false urgency, and helped the firm adopt a verbal verification policy for any change to bank details.
- Backups were reconfigured off-island and a restore was performed to prove recovery, followed by a one-page incident plan and a tabletop exercise.
Outcomes
- Credential-theft exposure closed on every business-critical system through multi-factor authentication
- The specific fraud technique used against the firm now detected automatically rather than by chance
- A verified, tested off-island restore replacing an untested backup routine
- A named incident plan rehearsed by the leadership team
- Documented posture the firm can present during client and partner due diligence
Outcomes are described qualitatively. We publish performance figures only where a client has reviewed and approved the specific numbers; named references are available on request.
Other case studies.
Rebuilding a boutique hotel's website for direct bookings
A BVI hotel group whose ageing website was slow on mobile, invisible to AI assistants and pushing guests towards commission-heavy third-party channels. We rebuilt it as a fast, mobile-first, structured site and now maintain it under a monthly care plan.
Getting a marine charter operator into AI answers as well as Google
A charter business whose overseas customers increasingly begin their research by asking an AI assistant rather than searching. We built a combined SEO and generative engine optimisation programme so the operator is both ranked and quoted.