Skip to content
StrikeCyberStrikeCyber
Financial Services

Red Team Assessment for a Financial Services Firm

A financial services firm needed to know whether a real attacker could reach its payment systems and whether its team would detect them.

Financial Services sector
Industry
Financial Services
Services
Red Teaming
Engagement
Objective-based red team assessment
Region
National

The Challenge

The client is a financial services firm that handles customer funds and processes high-value payments daily. It had invested steadily in security tooling and passed its regular compliance checks, but leadership wanted to answer a harder question. If a determined, financially motivated attacker targeted the firm today, could they reach the payment systems, and would the security team notice in time to stop them?

The firm operates under APRA CPS 234, which sets clear expectations for testing security controls in a way that reflects genuine threats. A checklist audit could not answer the leadership question. What was needed was an objective-based red team that behaved like a real adversary, starting from the outside with no special access, and worked toward a defined goal while the internal team responded as they would to any live incident.

Our Approach

StrikeCyber scoped a covert, objective-based red team with a clear goal agreed with a small group of stakeholders. The engagement emulated a realistic threat actor and followed techniques mapped to the MITRE ATT&CK framework, with strict rules of engagement to protect production payment operations.

  • Reconnaissance and open-source intelligence to profile the organisation, its people and its external footprint, using an AI-augmented platform to accelerate discovery.
  • Initial access through a targeted phishing campaign paired with an adversary-in-the-middle technique to defeat single-factor and phishable authentication.
  • Post-exploitation, lateral movement and privilege escalation toward the payment environment, testing segmentation, monitoring and the response team throughout.

Expert operators drove the engagement by hand, making the decisions a real attacker would make. The blue team was not told the test was running, so the firm gained an honest measure of its detection and response. This is the value of a true red teaming engagement over a checklist.

What We Found

  • Successful initial access. A tailored phishing email led a user to an adversary-in-the-middle page that captured the session and bypassed multi-factor authentication, giving a foothold in the corporate environment.
  • Effective lateral movement. From that foothold, operators harvested credentials and moved between systems, escalating privileges by exploiting over-permissive access and weak internal segmentation.
  • A clear path toward payment systems. The team reached the network zone adjacent to the payment environment, demonstrating a realistic route toward the firm's most critical assets before the objective boundary was reached.
  • Detection and response gaps. Several key stages generated telemetry that was collected but not alerted on, so the activity went unnoticed for far longer than it should have.

The Outcome

StrikeCyber delivered a full attack narrative mapped to MITRE ATT&CK and to the firm's CPS 234 obligations, showing each step from the phishing email to the payment-adjacent zone alongside where detection should have triggered. The firm rolled out phishing-resistant multi-factor authentication, tightened internal segmentation around the payment environment, and reduced the over-permissive access that had enabled lateral movement.

Just as importantly, the security team used the missed detections to build and tune new alerting for the specific techniques that had gone unnoticed, then rehearsed its response. A follow-up purple team exercise confirmed the firm could now detect and disrupt the same attack path early. Leadership gained a clear, evidence-based answer to its original question and documented assurance to support its regulatory position.

Why It Matters

Compliance checks confirm controls exist. A financial services red team confirms whether they actually stop a determined attacker and whether your team sees the attack coming. For a firm that moves customer funds, the difference is decisive, because the flaws that lead to real loss are the chained, human-driven ones a scan will never surface. To find out whether an attacker could reach your critical systems, get in touch.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation