Client Case Study

From Breach Forensics to a Company-Wide Identity Plan

Pharmaceutical packaging and distributionCanada, United States, EU and India
Client
Pharmaceutical services firm (name withheld)
Industry
Pharmaceutical packaging and distribution
Location
Canada, United States, EU and India
Services
Email compromise forensics, Microsoft Entra ID identity management, Microsoft Intune device management, Conditional Access and MFA

The Challenge

This client is a pharmaceutical services company — drug sourcing, packaging, GMP storage and distribution across Canada, the United States, the EU and India. In November 2018 one of its mailboxes was taken over, and the company needed to know exactly what had happened, how far it reached, and how to shut the door.

Eight years later the question had changed shape. The company had grown to roughly 40 to 50 employees across its international operations, mostly on Windows laptops, with accounts and devices managed loosely at each location. They came back asking for something structural: one identity per person, every device enrolled and manageable, rolled out in stages rather than as a big bang.

What We Did

  • Reconstructed the 2018 intrusion from the mail system’s own records rather than from assumption: attacker activity began at 10:10:03 a.m. on 15 November 2018, ended at 10:49:42 a.m. the same morning, and sent 2,706 emails from the compromised account inside that window.
  • Gave the client a defensible written account of the incident, which set the real scope for cleanup and for telling their contacts what had happened — facts, not guesses.
  • Returned in July 2026 to scope the environment properly before proposing anything: headcount, device mix, how accounts were being managed at each site, and what would break if it all changed at once.
  • Designed against the client’s stated scope — Microsoft 365 Business Premium, Microsoft Entra ID for centralized identity, Microsoft Intune for Windows laptop management, Entra Join for company devices, and security policy including multi-factor authentication, device compliance, Conditional Access and BitLocker.
  • Advised on licensing and deployment approach, enrolment of both existing and new devices, and a migration path to centralized management with minimal disruption to users.
  • Delivered a written statement of work within days of the request, and followed up on it directly rather than leaving it to chase itself.

“Our objective is to implement a centralized login and device management solution that can support all employees as we roll it out.”

— IT systems lead, pharmaceutical services client

The Result

The 2018 work produced a minute-by-minute forensic account from primary evidence. The relationship it earned is the point: eight years later, the company that handled the breach is the one asked to redesign identity across four countries. The 2026 engagement is at statement-of-work stage — a staged rollout of centralized identity and managed devices for the full 40 to 50 person workforce, which is the structural answer to what happened in 2018. A compromised password matters far less when sign-in is centrally controlled and a suspect device can be isolated remotely.

Facing something similar in your business?

We handle engagements like this every week for businesses across the GTA — from email security audits to full Microsoft 365 management.

We value your privacy

This website uses cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Read our Cookie Policy and Privacy Policy.