// case study

Cloud to code: hardening a venture-backed AdTech company

A fast-moving AdTech company brought us in to find what their small team couldn’t see. We mapped the whole attack surface, contained a live breach, and closed hundreds of cloud and code exposures — then proved each one fixed.

Sector · AdTechEngagement · Security assessment + remediationSurface · AWS, GCP, endpoints, source code
900+
AWS findings surfaced
580+
GCP findings surfaced
1
live breach contained
100%
of the device fleet on EDR
// the client

A team moving faster than its security could keep up

A venture-backed AdTech company handling large volumes of data at speed. Engineering shipped fast; security had never had a dedicated owner. As enterprise customers and investors began asking harder questions, they needed to know — and fix — exactly where they were exposed, without slowing the product down.

// the challenge

No clear picture of their own risk

  • No unified view of cloud, code, or endpoint risk across two clouds (AWS and GCP).
  • Signs of a possible compromise that no one had confirmed or ruled out.
  • Secrets and access sprawl left behind by fast growth.
  • Enterprise and SOC 2-style scrutiny incoming — with no security team to answer it.
// what we did

Assess, prioritise, fix, verify

01
Assess

Mapped the full attack surface across cloud (AWS and GCP), source code, endpoints, and identity — no blind spots.

02
Prioritise

Cut the noise and ranked every issue by real-world exploitability and business impact, not raw scanner counts.

03
Fix

Worked alongside their engineers to remediate — hardening configurations, rotating exposed keys, and rolling EDR across the fleet.

04
Verify

Re-tested every fix to prove the issue was genuinely closed, not just marked done.

// what we found

Three that mattered most

was criticalEndpoint · identity
Session tokens stolen, MFA bypassed

A real, active compromise — detected, contained, and investigated before it could spread.

was criticalSource code · across repos
Live API keys exposed in source

Working credentials sitting in code. Found, rotated, and locked down with scanning wired into the pipeline.

was criticalCloud · AWS + GCP
900+ cloud misconfigurations

Public access, over-broad permissions, and missing baselines across two clouds — surfaced and hardened.

// the outcome

Mapped, hardened, and proven

  • 900+ AWS and 580+ GCP findings surfaced, triaged, and prioritised.
  • A live breach detected, contained, and investigated.
  • Exposed API keys rotated; the endpoint fleet moved 100% onto EDR.
  • A re-tested, verified security posture — every fix proven closed.
  • SSO federation and centralised Slack alerting designed for their stack (in progress).

They came in blind to their own risk. They left with a mapped, hardened, and continuously watched environment — and proof of every fix.

Client name withheld and specifics anonymised at their request. Every figure on this page is real.

Want the same clarity on your stack?

A short, no-obligation security review — you walk away knowing your top risks, whether or not you work with us.

Book a free security review