Success Story · Cybersecurity

360° Cybersecurity Strategy for a Financial Institution


  • Client: Nationwide financial institution with more than 200 branches, 2,500 employees and a growing digital operation that included online banking, a mobile app and its own payment gateway.

  • Challenge: The institution had suffered two intrusion attempts in the previous 12 months. Although neither compromised customer data, the subsequent investigations revealed serious deficiencies in its security posture:

    There was no SOC (Security Operations Center) or centralized monitoring of security events. The firewalls were outdated, with permissive rules accumulated over the years. No pentesting or periodic security audits were performed. Identity management was deficient: accounts of employees who no longer worked there were still active, and many users had excessive permissions. There was no documented or tested incident response plan. Cybersecurity training for employees was non-existent, exposing them to phishing and social engineering attacks.

    The financial regulator had issued a formal warning demanding substantial improvement within 6 months.

  • BePart Innova Solution: We designed and implemented a comprehensive cybersecurity strategy built on 5 pillars:

    1. Audit and pentesting: We carried out a complete audit of the infrastructure (network, servers, endpoints, web and mobile applications). We performed external and internal penetration tests, identifying 47 critical vulnerabilities and 123 of medium severity.

    2. SOC as a Service: We deployed a centralized SIEM (Security Information and Event Management) that collects logs from all of the organization's assets. We set up a 24/7 monitoring team with automatic alerts and escalation procedures.

    3. Hardening and network segmentation: We updated all firewalls, implemented Zero Trust network segmentation, deployed intrusion detection and prevention systems (IDS/IPS) and encrypted all internal communications.

    4. Identity management (IAM): We implemented an identity and access management system with mandatory multi-factor authentication (MFA), quarterly privilege reviews and automatic deactivation of inactive accounts.

    5. Training and drills: We launched a cybersecurity awareness program for all employees, including monthly phishing simulations and department-specific training. We established an incident response plan with quarterly drills.

  • Results:

    100% of critical vulnerabilities remediated within the first 8 weeks of the project.

    Real-time threat detection: The SOC detects and classifies incidents in less than 15 minutes on average, compared to the days or weeks it took before.

    94% reduction in phishing clicks: After 6 months of the awareness program, the click rate in phishing simulations dropped from 32% to 2%.

    Regulatory compliance: The institution successfully passed the financial regulator's audit within the established deadline.

    ISO 27001 certification: 9 months after implementation, the institution obtained ISO 27001 certification in information security.

  • TECHNOLOGIES

    SIEM / SOC 24/7


    Zero Trust / IAM / MFA


    IDS/IPS / Pentesting


    Ready to build
    with us? Contact us!