The Challenge
The client is a logistics operator whose warehouse, fleet and customer systems run continuously. Downtime does not degrade the business gracefully; it stops trucks moving and shipments arriving, and the cost accrues by the hour. Leadership had accepted the premise that a phishing email would eventually succeed against someone, and wanted to know what happened next.
That is a different question from whether the perimeter holds. It asks how much damage one compromised laptop can cause, how fast the security team notices, and whether the organization can keep operating while responding. A traditional penetration test starting from the outside would have spent much of its budget on the part they had already conceded.
Our Approach
StrikeCyber ran an assumed breach exercise, starting from a standard corporate laptop with the access of an ordinary employee. The scenario deliberately skipped initial access and began where a real intrusion becomes dangerous.
- Reconnaissance from the endpoint: what an ordinary user account can see and reach across the network, file shares and internal applications.
- Credential harvesting and lateral movement, escalating privilege toward the systems that control warehouse and dispatch operations.
- A parallel response evaluation, measuring what the security team detected, when, and what actions they took.
Unlike a covert red team, the client's incident response team knew an exercise was running within a defined window, which let StrikeCyber evaluate the response process itself rather than only its detection rate. Both are useful; this client needed the second.
What We Found
- Excessive reach from a standard account. An ordinary user could enumerate the full directory, reach file shares containing operational documentation, and access internal applications with no business relationship to their role.
- Credentials in reachable locations. Service account passwords sat in scripts and documentation on shares readable by any authenticated user, providing an immediate escalation path.
- Flat internal segmentation. Once operators held a service account, nothing meaningful separated the corporate network from the systems supporting warehouse operations.
- A response process that worked slowly. The team detected the activity, but escalation depended on one individual, and the runbook did not cover how to isolate a system without stopping dispatch.
The Outcome
The operator restricted directory enumeration and reviewed share permissions, removing the credentials found in scripts and moving them into a managed secret store. Segmentation was introduced between the corporate network and operational systems, which was the single change that most reduced blast radius.
The response improvements mattered as much. The runbook was rewritten to define isolation procedures that account for operational continuity, escalation was widened beyond one person, and the team rehearsed the scenario twice more. Measured against the original exercise, containment time fell from days to hours.
Why It Matters
Assume the phishing email works, because eventually one does. What determines whether that becomes an incident or a catastrophe is how far the attacker can reach afterward and how quickly you can contain them. For an operator whose business stops when systems stop, rehearsing that under controlled conditions is considerably cheaper than discovering it live. To run an assumed breach exercise, get in touch.
