Legacy perimeter security couldn’t keep pace
A wealth management firm faced sophisticated phishing attacks targeting high-net-worth client accounts, struggled with remote workforce security in the shift to hybrid work, and needed SOC 2 Type II certification to satisfy institutional clients. Legacy VPN and perimeter security were no longer sufficient against modern threats.
The firm’s client base made it a specifically attractive target: wire-transfer fraud and advisor-impersonation attacks aimed at wealth management clients tend to be more targeted and better-researched than commodity phishing, because the payoff for a successful attack is larger. A legacy perimeter model that trusted anything already inside the VPN gave an attacker who compromised one remote employee’s credentials a wide-open path to systems well beyond what that employee’s role actually required — the exact opposite of the access model a firm handling $12B in client assets needs.
A converged Zero Trust and governance program
VERITY
CORE
SENTRY: Deployed a comprehensive Zero Trust architecture with SASE/ZTNA — replacing always-on VPN tunnels with per-session, per-application access decisions — layered in EDR/XDR and MDR with a 24/7 SOC, and hardened email security with AI-assisted anti-phishing detection tuned to the spear-phishing and business-email-compromise patterns that target wealth management clients directly: wire-transfer-request impersonation, advisor-impersonation lookalike domains, and account-takeover attempts aimed at high-net-worth client portals rather than generic mass-market phishing.
VERITY: vCISO-led SOC 2 Type II preparation, paired with an AI governance framework built specifically for the risks a wealth manager takes on when advisors and staff start using generative AI tools day to day. That framework covers ground a generic AI-governance checklist doesn’t: data controls preventing client PII and account details from being pasted into consumer-facing LLM tools whose data-handling and retention terms were never vetted for a regulated environment, since a client’s account number or SSN typed into a public chatbot to draft an email can leave the firm’s control the moment it’s submitted; model and data-access controls defining which roles can query which internal data sources through any AI tool, so a broadly deployed AI assistant doesn’t become a shortcut around access restrictions already built into the firm’s core systems; and a recordkeeping policy addressing where SEC Rule 17a-4 and FINRA Rule 4511 books-and-records obligations extend to AI-assisted client communications — if an advisor uses an AI tool to draft or summarize something that becomes part of a client communication, that output has to be captured and retained the same way the firm already retains email and chat, not treated as disposable scratch work. Security awareness training extended into this ground specifically, training staff on what does and doesn’t belong in a prompt.
CORE: Microsoft 365 E5 optimization to fully license and activate the security and compliance capabilities already included in the tier, conditional access policy design tying authentication requirements to device compliance, location, and risk signal rather than a static allow-list, and cloud security posture management providing continuous configuration-drift detection across the Microsoft 365 tenant underpinning the firm’s SOC 2 Type II control evidence.
What changed
Achieved SOC 2 Type II certification on the first audit, eliminated successful phishing attempts against client-facing accounts (99.4% detection rate), reduced overall security incidents by 85%, and enabled secure remote work for 100% of staff.
Zero Trust implementation retired the attack surface tied to legacy VPN vulnerabilities, replacing implicit network trust with continuous identity verification.
The 99.4% phishing detection rate, 85% incident reduction, zero-findings SOC 2 audit, and 100% secured remote workforce figures above are aggregated from anonymized outcome data across multiple real Armorstack Zero Trust engagements with wealth and investment management firms. They are not drawn from, or attributed to, any single client, and no spokesperson quote is attached to them.
Ready for results like these?
Generative AI is already in your advisors’ workflow whether there’s a governance framework around it or not — and for a wealth manager, the exposure isn’t hypothetical: client PII in a prompt, an AI-drafted communication with no retention trail, a model with broader data access than any single advisor should have. Apply for the free 30-day AI Risk Assessment or talk to us about closing that gap before a regulator or a client finds it first.
← Back to all case studies