The Challenge
The client is a financial services firm that handles customer funds and processes high-value payments daily. It had invested steadily in security tooling and passed its regular compliance checks, but leadership wanted to answer a harder question. If a determined, financially motivated attacker targeted the firm today, could they reach the payment systems, and would the security team notice in time to stop them?
The firm operates under APRA CPS 234, which sets clear expectations for testing security controls in a way that reflects genuine threats. A checklist audit could not answer the leadership question. What was needed was an objective-based red team that behaved like a real adversary, starting from the outside with no special access, and worked toward a defined goal while the internal team responded as they would to any live incident.
Our Approach
StrikeCyber scoped a covert, objective-based red team with a clear goal agreed with a small group of stakeholders. The engagement emulated a realistic threat actor and followed techniques mapped to the MITRE ATT&CK framework, with strict rules of engagement to protect production payment operations.
- Reconnaissance and open-source intelligence to profile the organisation, its people and its external footprint, using an AI-augmented platform to accelerate discovery.
- Initial access through a targeted phishing campaign paired with an adversary-in-the-middle technique to defeat single-factor and phishable authentication.
- Post-exploitation, lateral movement and privilege escalation toward the payment environment, testing segmentation, monitoring and the response team throughout.
Expert operators drove the engagement by hand, making the decisions a real attacker would make. The blue team was not told the test was running, so the firm gained an honest measure of its detection and response. This is the value of a true red teaming engagement over a checklist.
What We Found
- Successful initial access. A tailored phishing email led a user to an adversary-in-the-middle page that captured the session and bypassed multi-factor authentication, giving a foothold in the corporate environment.
- Effective lateral movement. From that foothold, operators harvested credentials and moved between systems, escalating privileges by exploiting over-permissive access and weak internal segmentation.
- A clear path toward payment systems. The team reached the network zone adjacent to the payment environment, demonstrating a realistic route toward the firm's most critical assets before the objective boundary was reached.
- Detection and response gaps. Several key stages generated telemetry that was collected but not alerted on, so the activity went unnoticed for far longer than it should have.
The Outcome
StrikeCyber delivered a full attack narrative mapped to MITRE ATT&CK and to the firm's CPS 234 obligations, showing each step from the phishing email to the payment-adjacent zone alongside where detection should have triggered. The firm rolled out phishing-resistant multi-factor authentication, tightened internal segmentation around the payment environment, and reduced the over-permissive access that had enabled lateral movement.
Just as importantly, the security team used the missed detections to build and tune new alerting for the specific techniques that had gone unnoticed, then rehearsed its response. A follow-up purple team exercise confirmed the firm could now detect and disrupt the same attack path early. Leadership gained a clear, evidence-based answer to its original question and documented assurance to support its regulatory position.
Why It Matters
Compliance checks confirm controls exist. A financial services red team confirms whether they actually stop a determined attacker and whether your team sees the attack coming. For a firm that moves customer funds, the difference is decisive, because the flaws that lead to real loss are the chained, human-driven ones a scan will never surface. To find out whether an attacker could reach your critical systems, get in touch.
