Financial Services
Regional bank, $8B in assets, 120+ branches, 3,500 employees
0
records exfiltrated from production banking systems
6-week engagement
spanning phishing, physical access, and network exploitation vectors
Regulatory compliance achieved
satisfied the OCC's mandate for adversarial testing
The Challenge
A regional bank with $8 billion in assets, over 120 branch locations, and 3,500 employees was mandated by federal regulators to conduct an adversarial red team engagement. Following heightened scrutiny from the Office of the Comptroller of the Currency (OCC), the bank needed to demonstrate that its security controls could withstand a realistic, persistent threat actor operating across multiple attack vectors over an extended period. Previous penetration tests had validated individual systems, but regulators wanted evidence that the institution could detect, respond to, and contain a sophisticated adversary moving through the full attack chain.
The bank's security infrastructure included a centralized Security Operations Center (SOC) staffed by 18 analysts, a next-generation firewall perimeter, endpoint detection and response (EDR) across all workstations, data loss prevention (DLP) controls on outbound traffic, and network segmentation isolating production banking systems from corporate IT. Despite these investments, leadership recognized that untested defenses were unproven defenses.
The Approach
For this engagement I brought together a five-person red team, operating under a strict rules of engagement document agreed with both the bank's CISO and its compliance team. The goal was to simulate a financially motivated threat actor with advanced capabilities and persistent intent, across three attack vectors: social engineering and phishing, physical access attempts against branch locations, and remote network exploitation.
Phase 1: Reconnaissance and Initial Access
I began with open-source intelligence gathering, mapping the bank's digital footprint across public records, job postings, social media, and exposed infrastructure. This phase revealed details about internal tooling, vendor relationships, and employee roles. Using this intelligence, the team crafted targeted spear-phishing campaigns against employees across four branch offices.
A carefully constructed phishing email impersonating the bank's internal IT department prompted a branch operations manager to enter credentials on a cloned SSO portal, providing initial access to the corporate network through a compromised VPN account. The email contained no malware: it relied entirely on social engineering and the employee's trust in the internal IT communication channel.
Phase 2: Establishing Persistence and Lateral Movement
After gaining initial access, I established persistence with a lightweight command-and-control agent disguised as a legitimate system process, then enumerated Active Directory, identified service accounts with elevated privileges, and moved laterally into the corporate network. Over the following three weeks, the team pivoted through multiple network segments, compromised additional accounts through credential harvesting, and mapped the bank's internal topology.
Simultaneously, the physical access side of the engagement ran reconnaissance at two branch locations. By tailgating employees through badge-controlled doors and posing as vendor technicians, the team gained access to restricted areas including server rooms and ATM maintenance closets, testing the bank's visitor management procedures and physical security controls.
Phase 3: Objective Fulfillment and Detection Validation
The primary objective was to reach production banking systems and attempt data exfiltration. Despite significant lateral movement within the corporate network, the segmentation boundary into the production banking environment held: the bank's micro-segmentation controls, combined with DLP inspection on all east-west and north-south traffic, prevented any access to sensitive systems.
Importantly, the SOC detected several of these activities during the engagement. The phishing campaign was flagged within 48 hours, lateral movement using compromised service accounts triggered automated alerts, and physical security caught anomalies through badge access logs. The bank's incident response team successfully contained the lateral movement on two occasions, forcing a return to alternative access methods.
Key Findings
- Phishing susceptibility: Three employees across two branches interacted with phishing lures, highlighting the need for enhanced security awareness training with realistic simulations.
- Credential management gaps: Service accounts with elevated privileges were not rotating credentials frequently enough, and some had access to more network segments than operationally necessary.
- Physical access controls: Visitor management policies were not consistently enforced at branch locations, allowing tailgating attacks to succeed during peak hours.
- Network segmentation strength: The production banking environment was effectively isolated. The inability to cross the segmentation boundary validated this critical control.
- SOC detection capability: The SOC demonstrated strong detection across most attack phases, with an average mean time to detection (MTTD) of 36 hours for non-obvious indicators.
- Incident response execution: The IR team executed containment playbooks effectively, though communication between SOC analysts and IR responders could be streamlined.
Outcome
The engagement concluded with zero records exfiltrated from production banking systems. The bank's network segmentation, DLP controls, and SOC monitoring successfully prevented the red team from reaching its primary objective, satisfying the regulatory mandate and demonstrating the bank's capability to withstand a persistent adversary.
I delivered an 85-page report detailing every phase of the engagement, including specific recommendations for the eight improvement areas identified. The bank's CISO presented the results to the board of directors and regulatory examiners, who commended the institution's proactive approach to adversarial testing. The bank has since brought me back for annual red team exercises to maintain compliance and continuously validate its defensive posture.
Kishin gave us the adversarial perspective we needed. The engagement was professional and thorough, and the findings directly strengthened our security program. We passed our regulatory examination with confidence.
Following the engagement, the bank implemented mandatory quarterly phishing simulations, accelerated service account credential rotation, upgraded visitor management technology at all branch locations, and a revised SOC escalation playbook. These improvements were completed within 90 days of the report delivery, and a follow-up assessment confirmed the remediation of all eight identified gaps.