Real engagements. Real results.
A selection of anonymized engagements from our portfolio. Client identities are protected per our standard confidentiality agreements.
All case studies are anonymized. Client names, specific technologies, and identifying details have been modified or omitted per confidentiality agreements.
External Network Pentest Uncovers Critical Authentication Bypass
A regional financial institution had passed its annual compliance audit but had never undergone an adversarial penetration test. Leadership suspected their perimeter was stronger than it was.
We conducted a black-box external network penetration test over 10 days, simulating an unauthenticated attacker with no prior knowledge of the environment. Testing covered all externally reachable IP ranges, web applications, and authentication endpoints.
- Critical
Authentication bypass on legacy VPN endpoint allowing unauthenticated access to internal network segment
- High
Exposed admin panel with default credentials on network management appliance
- High
Outdated SSL/TLS configuration enabling downgrade attacks on customer-facing portal
- Medium
Subdomain takeover vulnerability on decommissioned marketing subdomain
All critical and high findings were remediated within 30 days. The client implemented a quarterly penetration testing cadence and engaged REI Security for ongoing vulnerability management.
Network Segmentation Overhaul Reduces Lateral Movement Risk
A multi-site healthcare provider was operating a flat network architecture across three facilities. A ransomware incident at a peer organization prompted leadership to assess their own exposure to lateral movement attacks.
We performed a comprehensive network architecture review and threat modeling exercise, mapping all east-west traffic flows, identifying implicit trust relationships, and modeling attacker lateral movement paths from each network zone.
- Critical
Clinical workstations and administrative systems on the same broadcast domain with no segmentation
- High
Medical device network reachable from guest Wi-Fi with no firewall enforcement
- High
Backup systems accessible from all network zones without authentication requirements
- Medium
Overly permissive firewall rules inherited from legacy infrastructure migration
REI Security designed and oversaw implementation of a segmented network architecture with dedicated zones for clinical, administrative, IoT/medical devices, and guest traffic. Lateral movement paths were reduced by over 80%.
API Security Assessment Exposes Broken Object-Level Authorization
A SaaS company preparing for a Series B funding round needed a third-party security assessment of their core API to satisfy investor due diligence requirements. Their internal team had conducted code reviews but no external adversarial testing.
We performed a grey-box web application and API penetration test over 14 days, focusing on OWASP API Top 10 vulnerabilities, authentication flows, authorization logic, and data exposure risks across all API endpoints.
- Critical
Broken object-level authorization allowing any authenticated user to access other users' data by manipulating resource IDs
- High
Mass assignment vulnerability enabling privilege escalation to admin role via user update endpoint
- High
Sensitive PII returned in API responses for endpoints that did not require it
- Medium
Lack of rate limiting on authentication endpoints enabling credential stuffing attacks
All critical and high findings were remediated prior to the funding close. The client received a clean re-test attestation letter used in investor due diligence. REI Security was retained for pre-release security reviews on all future product updates.
Phishing Simulation Reveals 34% Click Rate Across Executive Team
A mid-size law firm suspected their staff were vulnerable to phishing attacks after a client reported receiving a suspicious email appearing to originate from the firm. Leadership wanted to quantify their human attack surface.
We designed and executed a multi-wave phishing simulation campaign targeting all 120 staff members, including partners and executive assistants. Campaigns were tailored to mimic realistic pretexts including IT helpdesk requests, DocuSign notifications, and client portal alerts.
- High
34% of executive team clicked phishing links; 18% submitted credentials on simulated capture pages
- High
No MFA enforced on email accounts, meaning credential capture would result in full account compromise
- Medium
Staff click rates highest on DocuSign and IT helpdesk pretexts — no security awareness training in prior 18 months
- Medium
No email filtering rules blocking lookalike domains registered within 30 days
REI Security delivered a tailored security awareness training program and assisted with MFA rollout across all 120 accounts. A follow-up simulation 90 days later showed click rates reduced to under 6%.
See what we'd find in your environment.
Every organization has exposure. The question is whether you find it first. Schedule a free assessment and know your risk before an attacker does.
Free, no-obligation security assessment. We'll identify your top exposure points within 48 hours.
Get a Free Assessment