Skip to content
Aditya Puram, Gwalior, MP 474005 info@curioinfotech.com
+91 9202362121 Mon–Sat: 9:30 AM – 6:30 PM
Case Study

BFSI Firm — Cybersecurity Audit & Hardening

A two-month end-to-end cybersecurity audit and hardening program for a Gwalior-headquartered non-banking financial company with 8 branches across Madhya Pradesh — closing 47 vulnerabilities, rolling out enterprise MFA and achieving DPDP Act compliance ahead of the regulator's deadline.

Client 8-branch NBFC (anonymized)
Industry Finance & BFSI
Location Gwalior, Madhya Pradesh
Duration 2 months (audit) + ongoing AMC
Services Information SecurityServer ManagementIT Consultation
8
Branches standardized
2 mo
Audit duration
47
Risks remediated
DPDP
Compliance achieved

The Challenge

The NBFC had grown rapidly from a single Gwalior branch to eight branches across Madhya Pradesh, but its security posture had not kept pace. There had never been a formal security audit. Branch servers ran unpatched Windows installs from three or four years ago, several had Remote Desktop Protocol (RDP) directly exposed to the internet on port 3389, and the same local administrator password was reused across every branch. There was no multi-factor authentication on any system — not even the core loan-management application.

There was no documented incident response plan, no central logging, and no endpoint protection beyond a free consumer antivirus on each machine. When a branch laptop was stolen in early 2025, the IT team could not even produce a list of what data the device had accessed in the previous 90 days. Backup was a single external USB drive rotated weekly at each branch — with no off-site copy and no restore-test ever performed.

The driver was regulatory: India's Digital Personal Data Protection (DPDP) Act, 2023 had moved from voluntary to enforced, and the company's RBI-mandated internal audit had flagged "significant gaps in information security governance" as a material finding. Leadership needed a credible remediation plan inside one quarter — not a 200-page report that would sit on a shelf, but actual fixes on actual servers, with defensible evidence for the next compliance review.

"When the internal audit report landed on my desk, I realised we couldn't even tell a customer whose data we held, where it was, or who had accessed it. We needed someone who could actually fix this — not just write a report about it." — N____, Compliance Officer

Our Solution

Curio ran a structured two-month engagement combining an external + internal vulnerability assessment, an authenticated scan of every server and endpoint across all eight branches, and a targeted penetration test of the customer-facing loan-management portal and the head-office Wi-Fi. We used Nessus and OpenVAS for automated scanning and manual exploitation on the high-value findings — producing a prioritised risk register ranked by likelihood, impact and effort to remediate.

Remediation was sequenced by risk: critical exposures first (internet-facing RDP closed and moved behind a VPN, default credentials rotated, missing patches deployed through a managed patch pipeline), then architectural fixes (Microsoft Entra ID MFA enforced across all staff accounts, CrowdStrike endpoint protection rolled out to every endpoint, a Fortinet next-generation firewall standardised at each branch, and centralised SIEM logging shipped off each server to a tamper-evident store).

We then wrote the documentation the regulator actually wanted to see: a formal Information Security Policy, a written Incident Response Plan with named roles and 24-hour notification SLAs, a DPDP-mapped data inventory, and a quarterly patch-management cadence. The engagement closed with hands-on training for branch managers and the head-office team on phishing recognition, incident escalation and the new MFA workflow — so the controls actually stuck rather than becoming shelfware.

  1. Security Audit
    External + internal vulnerability scan of all 8 branches, authenticated patch-level audit, targeted penetration test of loan portal & head office Wi-Fi.
  2. Risk Prioritization
    Prioritised risk register ranked by likelihood × impact × effort — reviewed with leadership before any changes were made.
  3. Server Hardening
    Closed internet-facing RDP, rotated credentials, deployed managed patching, hardened OS baselines across all branch servers.
  4. MFA & Access Control
    Microsoft Entra ID MFA enforced org-wide, role-based access for the loan-management app, VPN replacing direct RDP, Fortinet NGFW at every branch.
  5. IR Plan & Training
    Documented Incident Response Plan, DPDP data inventory, SIEM logging and hands-on staff training on phishing and incident escalation.
Nessus OpenVAS Fortinet NGFW CrowdStrike Endpoint Microsoft Entra ID MFA Managed Patching SIEM Logging Site-to-Site VPN

Results & Impact

47
Vulnerabilities remediated
0
Critical exposures post-audit
8
Branches on standardised baseline
100%
Staff on MFA

By the end of the two-month engagement, every one of the 47 findings identified in the audit — including 9 critical and 14 high-severity items — had been remediated, verified by re-scan, and documented with before/after evidence. The follow-up internal audit conducted six weeks later reported zero critical findings and explicitly cited the remediation evidence pack Curio produced as the reason. DPDP Act readiness, which had been the original driver, was achieved with a documented data inventory, an incident-response plan and a named Data Protection point-of-contact.

Operationally, the change was visible. Internet-facing RDP was gone — replaced by a site-to-site VPN with Entra ID MFA — eliminating the single largest attack surface the firm had. CrowdStrike replaced the consumer antivirus across all endpoints, giving the IT team centralised visibility they had never had. The SIEM now feeds a single dashboard at head office, branch managers have a one-page incident escalation card on their desks, and the AMC engagement keeps the patch cycle and quarterly review cadence running so the firm does not drift back to where it started.

"For the first time, our internal audit came back clean. The Curio team didn't just hand us a report — they sat with our branch managers, explained every control, and left us with documentation we could actually defend. That's what DPDP compliance looks like in practice." — N____, Compliance Officer

Services Used

Next Case Study
D2C Brand — Performance Marketing →
How Curio scaled a Gwalior D2C wellness brand from 1.2x to 4.5x ROAS in 4 months — 12K+ orders, 3x revenue and page-1 rankings for 8 branded keywords.
Your Project Next

Want Results Like This?

Whether you're an NBFC, a fintech, a healthcare firm or any business that holds sensitive customer data — we audit, fix and document to a defensible standard. Book a no-obligation consultation with our Gwalior team.