BFSI Firm — Cybersecurity Audit & Hardening
A two-month end-to-end cybersecurity audit and hardening program for a Gwalior-headquartered non-banking financial company with 8 branches across Madhya Pradesh — closing 47 vulnerabilities, rolling out enterprise MFA and achieving DPDP Act compliance ahead of the regulator's deadline.
The Challenge
The NBFC had grown rapidly from a single Gwalior branch to eight branches across Madhya Pradesh, but its security posture had not kept pace. There had never been a formal security audit. Branch servers ran unpatched Windows installs from three or four years ago, several had Remote Desktop Protocol (RDP) directly exposed to the internet on port 3389, and the same local administrator password was reused across every branch. There was no multi-factor authentication on any system — not even the core loan-management application.
There was no documented incident response plan, no central logging, and no endpoint protection beyond a free consumer antivirus on each machine. When a branch laptop was stolen in early 2025, the IT team could not even produce a list of what data the device had accessed in the previous 90 days. Backup was a single external USB drive rotated weekly at each branch — with no off-site copy and no restore-test ever performed.
The driver was regulatory: India's Digital Personal Data Protection (DPDP) Act, 2023 had moved from voluntary to enforced, and the company's RBI-mandated internal audit had flagged "significant gaps in information security governance" as a material finding. Leadership needed a credible remediation plan inside one quarter — not a 200-page report that would sit on a shelf, but actual fixes on actual servers, with defensible evidence for the next compliance review.
"When the internal audit report landed on my desk, I realised we couldn't even tell a customer whose data we held, where it was, or who had accessed it. We needed someone who could actually fix this — not just write a report about it." — N____, Compliance Officer
Our Solution
Curio ran a structured two-month engagement combining an external + internal vulnerability assessment, an authenticated scan of every server and endpoint across all eight branches, and a targeted penetration test of the customer-facing loan-management portal and the head-office Wi-Fi. We used Nessus and OpenVAS for automated scanning and manual exploitation on the high-value findings — producing a prioritised risk register ranked by likelihood, impact and effort to remediate.
Remediation was sequenced by risk: critical exposures first (internet-facing RDP closed and moved behind a VPN, default credentials rotated, missing patches deployed through a managed patch pipeline), then architectural fixes (Microsoft Entra ID MFA enforced across all staff accounts, CrowdStrike endpoint protection rolled out to every endpoint, a Fortinet next-generation firewall standardised at each branch, and centralised SIEM logging shipped off each server to a tamper-evident store).
We then wrote the documentation the regulator actually wanted to see: a formal Information Security Policy, a written Incident Response Plan with named roles and 24-hour notification SLAs, a DPDP-mapped data inventory, and a quarterly patch-management cadence. The engagement closed with hands-on training for branch managers and the head-office team on phishing recognition, incident escalation and the new MFA workflow — so the controls actually stuck rather than becoming shelfware.
-
Security AuditExternal + internal vulnerability scan of all 8 branches, authenticated patch-level audit, targeted penetration test of loan portal & head office Wi-Fi.
-
Risk PrioritizationPrioritised risk register ranked by likelihood × impact × effort — reviewed with leadership before any changes were made.
-
Server HardeningClosed internet-facing RDP, rotated credentials, deployed managed patching, hardened OS baselines across all branch servers.
-
MFA & Access ControlMicrosoft Entra ID MFA enforced org-wide, role-based access for the loan-management app, VPN replacing direct RDP, Fortinet NGFW at every branch.
-
IR Plan & TrainingDocumented Incident Response Plan, DPDP data inventory, SIEM logging and hands-on staff training on phishing and incident escalation.
Results & Impact
By the end of the two-month engagement, every one of the 47 findings identified in the audit — including 9 critical and 14 high-severity items — had been remediated, verified by re-scan, and documented with before/after evidence. The follow-up internal audit conducted six weeks later reported zero critical findings and explicitly cited the remediation evidence pack Curio produced as the reason. DPDP Act readiness, which had been the original driver, was achieved with a documented data inventory, an incident-response plan and a named Data Protection point-of-contact.
Operationally, the change was visible. Internet-facing RDP was gone — replaced by a site-to-site VPN with Entra ID MFA — eliminating the single largest attack surface the firm had. CrowdStrike replaced the consumer antivirus across all endpoints, giving the IT team centralised visibility they had never had. The SIEM now feeds a single dashboard at head office, branch managers have a one-page incident escalation card on their desks, and the AMC engagement keeps the patch cycle and quarterly review cadence running so the firm does not drift back to where it started.
"For the first time, our internal audit came back clean. The Curio team didn't just hand us a report — they sat with our branch managers, explained every control, and left us with documentation we could actually defend. That's what DPDP compliance looks like in practice." — N____, Compliance Officer
Services Used
Information Security
Vulnerability scan, penetration test, MFA rollout, CrowdStrike endpoint protection and a documented Incident Response Plan.
Explore serviceServer Management
Managed patching, OS hardening, SIEM logging and ongoing AMC across all eight branch servers.
Explore serviceIT Consultation
Risk-prioritised remediation roadmap, DPDP data inventory and compliance documentation for the regulator.
Explore service