Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump-Xi Summit Underscores China’s Rare-Earth Trade Leverage

    September 23, 2026

    Liberal operative was offered $1,000 to get media to cover ‘grubby rumour’ minister was having affair, Icac hears | Independent Commission Against Corruption

    September 23, 2026

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump-Xi Summit Underscores China’s Rare-Earth Trade Leverage
    • Liberal operative was offered $1,000 to get media to cover ‘grubby rumour’ minister was having affair, Icac hears | Independent Commission Against Corruption
    • Discord’s age verification era is upon us, despite community backlash
    • Only 13% of OT Network Segments Are Fully Isolated: Analysis
    • Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says
    • Reptiles, gold and money: How Australia is cracking down on wildlife trafficking
    • Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott
    • Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    How a global investment firm reduced security surprises

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 6, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty.

    Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter?

    For a global investment firm operating across 18 locations, that question became increasingly important. A small security engineering team was responsible for securing a growing environment while balancing infrastructure projects, identity management, user support, and the countless responsibilities that come with protecting a modern enterprise.

    The team wasn’t struggling to generate findings. They were struggling to understand which findings represented real risk, whether remediation efforts were working, and how to ensure leadership would never be surprised by an exposure that should have been discovered earlier.

    That journey led them from point-in-time testing to continuous validation.

    Outcomes at a glance

    • Reduced impacts from 251 to 0 in a same-scope internal penetration test (pentest)
    • Reduced compromised credentials from 52 to 0
    • Reduced compromised hosts from 67 to 0
    • Reduced cracked Active Directory passwords from 40 to 0
    • Expanded continuous validation across 18 locations using a phased rollout strategy
    • Enabled a lean security team to continuously validate risk without significant operational overhead

    Impact

    The team wasn’t expecting perfection. Every environment contains weaknesses, and no experienced security practitioner assumes an internal pentest will come back clean.

    What surprised them was how effectively those weaknesses could be chained together once an attacker gained a foothold.

    One of the firm’s early internal pentests identified 85 weaknesses. By itself, the number wouldn’t have stood out to most security teams. The real concern wasn’t the weaknesses themselves. It was what those weaknesses enabled.

    NodeZero® showed that those weaknesses could produce 251 impacts, including domain compromise, sensitive data exposure, ransomware exposure, host compromise, domain user compromise, and compromised credentials. 

    That distinction matters because attackers don’t exploit weaknesses in isolation. They chain weaknesses, misconfigurations, and credentials together to achieve an objective. A low-priority finding on its own may appear manageable, but when combined with other weaknesses, it can become part of a pathway to something much more serious.

    Figure 1. An early internal pentest identified 85 weaknesses that led to 251 impacts, including domain compromise, ransomware exposure, sensitive data exposure, and host compromise.

    As the organization’s senior security engineer explained: “That impact section in NodeZero is just pure evidence of what can happen in a real life scenario.”

    The shift from theoretical risk to demonstrated impact changed how the team approached remediation, shifting the conversation from identifying weaknesses to understanding their potential business impact.

    Background

    Like many organizations, this organization was already investing in security testing. The challenge wasn’t finding another tool. It was finding an approach that could scale across the business without creating additional work for a small security team already balancing infrastructure projects, identity management, user support, and countless other responsibilities.

    As the senior security engineer described: “NodeZero is, let’s say, 5% of my work. I’m dealing with a million different things, a million different projects, a million different responsibilities.”

    That reality made operational simplicity more than a convenience. It became a requirement.

    The team had experience with security testing platforms that required significant infrastructure and ongoing maintenance to keep running effectively. For a small team juggling competing priorities, that overhead mattered. NodeZero offered a different model. The platform was simple to deploy, easy to operate, and allowed the team to begin testing immediately without dedicating resources to managing complex hardware infrastructure.

    That ease of deployment became particularly important because the team wasn’t interested in running a proof of concept. They wanted to build a sustainable program that could scale with the business.

    Click here to continue reading about the obstacles the organization faced and how they mitigated them.

    The need to validate outcomes

    The objective was never to eliminate every weakness. It was to eliminate uncertainty around the risks that mattered most.

    That’s the difference between measuring activity and validating outcomes.

    Learn more about Horizon3.ai and NodeZero.

    firm global Investment reduced Security surprises
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    UK to fight Russian disinformation and push new global AI standards, Burnham says

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    Rogue external MFA providers can steal passwords during logins

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump-Xi Summit Underscores China’s Rare-Earth Trade Leverage

    September 23, 2026

    Liberal operative was offered $1,000 to get media to cover ‘grubby rumour’ minister was having affair, Icac hears | Independent Commission Against Corruption

    September 23, 2026

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump-Xi Summit Underscores China’s Rare-Earth Trade Leverage

    September 23, 2026

    Liberal operative was offered $1,000 to get media to cover ‘grubby rumour’ minister was having affair, Icac hears | Independent Commission Against Corruption

    September 23, 2026

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.