Home
Resources
Case Studies
Professional Liability Insurer Case Study

Client Success Story

Professional Liability Insurer Case Study

How rapid containment and layered security operations stopped a live malware threat before it became a business disruption.

Recently, a malicious file began working its way through a workstation at the client location. Within minutes, Net Friends' security operations team spotted the activity, isolated the affected endpoint, and shut the incident down. What could have been a costly disruption for a regulated insurance carrier instead became a non-event, thanks to NetSafe® MDR.

Challenges

  • A live malware infection actively spreading on an endpoint
  • A regulated insurance carrier holding sensitive policyholder and client data
  • An attacker attempting to gain remote control through a rogue deployment tool

Benefits

  • Threat detected and contained the same business day
  • No disruption to daily operations or client service
  • Documented proof that the security program holds up under pressure
  • Threat detected. NetSafe MDR flagged malicious activity on an endpoint. The detection was tied to a malware strain associated with credential theft and unauthorized remote access.
  • Endpoint isolated. The SOC isolated the endpoint immediately, cutting it off from the rest of the network while the investigation continued.  
  • Investigation completed. The team traced the attack chain to an attempted rogue deployment of a remote access tool. There were multiple alerts tied to the same incident that were the SOC reviewed and resolved that same day.
  • Trust restored. Once the endpoint was confirmed clean, it was safely returned to service, and the incident was formally closed.

How Net Friends Helped

The professional liability insurer did not have to lift a finger during the incident itself.

The SOC team behind Net Friends’ NetSafe MDR’s SOCMDR caught the threat before it had a chance to move laterally or reach other systems. The attempted remote access is worth noting on its own. Attackers commonly try to slip in legitimate remote access tools to maintain a foothold and catching that attempt early meant the door never actually opened.

Because the client already had a live MDR contract in place, there was no ramp up required. The tools were already watching, the playbook was already written, and the team simply executed it.

A Program Built for This Moment

This was the payoff from steady, ongoing security work. Over that same one-to-three-month period, the team also reviewed and released quarantined emails through a regular process, and adjusted spam and message action policies as new patterns showed up. A monthly penetration test keeps the systems honest, and regular security awareness training with phishing simulations keeps the firm's people just as sharp as its technology.

For a firm that provides professional liability insurance, that everyday discipline matters just as much as the big wins. It is the difference between a security program that only shows up for emergencies and one that quietly lowers risk day after day. A steady layered approach regularly delivers.

Earning Trust Every Single Day

"We didn't even know there was a fire until Net Friends had already put it out. Their team caught the threat, isolated it, and had everything back to normal the same day. As an insurer, we ask our own clients to trust us when it matters most. It's reassuring to have a security partner who earns that same trust every single day."

IT Director, Professional Liability Insurer
(name withheld for security purposes)

No items found.
No items found.
No items found.
No items found.
Read More Case Studies

Sometimes, it's nice to see a [net] friendly face!

Book a meeting, or just send a message and someone from our team of friendly IT experts will get right back to you!