Case Studies

Real engagements. Real results.

A selection of anonymized engagements from our portfolio. Client identities are protected per our standard confidentiality agreements.

All case studies are anonymized. Client names, specific technologies, and identifying details have been modified or omitted per confidentiality agreements.

01
Financial ServicesPenetration Testing

External Network Pentest Uncovers Critical Authentication Bypass

Challenge

A regional financial institution had passed its annual compliance audit but had never undergone an adversarial penetration test. Leadership suspected their perimeter was stronger than it was.

Approach

We conducted a black-box external network penetration test over 10 days, simulating an unauthenticated attacker with no prior knowledge of the environment. Testing covered all externally reachable IP ranges, web applications, and authentication endpoints.

Key Findings
  • Critical

    Authentication bypass on legacy VPN endpoint allowing unauthenticated access to internal network segment

  • High

    Exposed admin panel with default credentials on network management appliance

  • High

    Outdated SSL/TLS configuration enabling downgrade attacks on customer-facing portal

  • Medium

    Subdomain takeover vulnerability on decommissioned marketing subdomain

Outcome

All critical and high findings were remediated within 30 days. The client implemented a quarterly penetration testing cadence and engaged REI Security for ongoing vulnerability management.

4
Critical/High Findings
10
Day Engagement
30
Days to Full Remediation
02
HealthcareSecurity Architecture Review

Network Segmentation Overhaul Reduces Lateral Movement Risk

Challenge

A multi-site healthcare provider was operating a flat network architecture across three facilities. A ransomware incident at a peer organization prompted leadership to assess their own exposure to lateral movement attacks.

Approach

We performed a comprehensive network architecture review and threat modeling exercise, mapping all east-west traffic flows, identifying implicit trust relationships, and modeling attacker lateral movement paths from each network zone.

Key Findings
  • Critical

    Clinical workstations and administrative systems on the same broadcast domain with no segmentation

  • High

    Medical device network reachable from guest Wi-Fi with no firewall enforcement

  • High

    Backup systems accessible from all network zones without authentication requirements

  • Medium

    Overly permissive firewall rules inherited from legacy infrastructure migration

Outcome

REI Security designed and oversaw implementation of a segmented network architecture with dedicated zones for clinical, administrative, IoT/medical devices, and guest traffic. Lateral movement paths were reduced by over 80%.

3
Facilities Assessed
80%+
Lateral Movement Reduction
6
Week Implementation
03
TechnologyWeb Application Testing

API Security Assessment Exposes Broken Object-Level Authorization

Challenge

A SaaS company preparing for a Series B funding round needed a third-party security assessment of their core API to satisfy investor due diligence requirements. Their internal team had conducted code reviews but no external adversarial testing.

Approach

We performed a grey-box web application and API penetration test over 14 days, focusing on OWASP API Top 10 vulnerabilities, authentication flows, authorization logic, and data exposure risks across all API endpoints.

Key Findings
  • Critical

    Broken object-level authorization allowing any authenticated user to access other users' data by manipulating resource IDs

  • High

    Mass assignment vulnerability enabling privilege escalation to admin role via user update endpoint

  • High

    Sensitive PII returned in API responses for endpoints that did not require it

  • Medium

    Lack of rate limiting on authentication endpoints enabling credential stuffing attacks

Outcome

All critical and high findings were remediated prior to the funding close. The client received a clean re-test attestation letter used in investor due diligence. REI Security was retained for pre-release security reviews on all future product updates.

14
Day Assessment
4
Critical/High Findings
100%
Findings Remediated Pre-Close
04
Professional ServicesSocial Engineering

Phishing Simulation Reveals 34% Click Rate Across Executive Team

Challenge

A mid-size law firm suspected their staff were vulnerable to phishing attacks after a client reported receiving a suspicious email appearing to originate from the firm. Leadership wanted to quantify their human attack surface.

Approach

We designed and executed a multi-wave phishing simulation campaign targeting all 120 staff members, including partners and executive assistants. Campaigns were tailored to mimic realistic pretexts including IT helpdesk requests, DocuSign notifications, and client portal alerts.

Key Findings
  • High

    34% of executive team clicked phishing links; 18% submitted credentials on simulated capture pages

  • High

    No MFA enforced on email accounts, meaning credential capture would result in full account compromise

  • Medium

    Staff click rates highest on DocuSign and IT helpdesk pretexts — no security awareness training in prior 18 months

  • Medium

    No email filtering rules blocking lookalike domains registered within 30 days

Outcome

REI Security delivered a tailored security awareness training program and assisted with MFA rollout across all 120 accounts. A follow-up simulation 90 days later showed click rates reduced to under 6%.

120
Staff Targeted
34%→6%
Click Rate Reduction
90
Days to Improvement
Get Started

See what we'd find in your environment.

Every organization has exposure. The question is whether you find it first. Schedule a free assessment and know your risk before an attacker does.

Free, no-obligation security assessment. We'll identify your top exposure points within 48 hours.

Get a Free Assessment