// field log — construction
Targeted and untouched: stopping a phishing campaign cold.
A Southern California construction company was hit by a sophisticated phishing campaign — emails impersonating real subcontractors, referencing real project details, carrying credential-harvesting links.
// the situation
This wasn't spray-and-pray. The attackers had done their homework, and the same campaign compromised one of the company's own customers — an organization without equivalent controls.
// what we did
The defenses were already in place, because we'd built them in layers: advanced email security filtering spoofed senders and malicious links, AI-driven endpoint detection blocking harvesting attempts, mandatory MFA across Microsoft 365, conditional access with anomaly detection, and 24/7 monitoring. Every layer covers the gaps in the one before it.
// results
> Zero financial loss. Zero compromised records. Zero unauthorized access.
> Threat contained in minutes.
> Their unprotected customer: data exfiltration and weeks of remediation.
> Two more organizations engaged us for security assessments after the incident.