Engagements

Strengthened cybersecurity posture for entertainment benefits provider

Binary code and digital Lock

The challenge

A fraternal benefit society managing sensitive personal, financial, and health data for Canada’s entertainment guilds faced a critical need to assess its cybersecurity posture and identify regulatory compliance gaps. The organization engaged CRA’s cybersecurity professionals, under legal privilege, to conduct a comprehensive cybersecurity risk assessment of its IT infrastructure, applications, and business processes.

CRA approach

Our team executed a seven-phase assessment under legal privilege, beginning with a security hygiene analysis that leveraged CrowdStrike Falcon endpoint telemetry across the client’s server and workstation environment. This enabled us to identify end-of-life operating systems, unmanaged assets, and other security blind spots.

The assessment included a review of Microsoft 365 configurations, IT general controls, business process workflows, application security, database security, and network architecture. We performed both static and dynamic application security testing of the client’s custom Oracle APEX benefits administration platform and mapped key business processes to identify manual intervention points, data processing workflows, and critical personnel dependencies.

The review focused on member payment processing, insurance renewal calculations, and benefits eligibility determinations. We also evaluated database security configurations and network architecture and conducted a hands-on Microsoft 365 configuration workshop that provided live, expert-led remediation guidance and recommendations.

The impact

The engagement produced a privileged, defensible report that equipped the client’s board of directors and legal counsel with clear evidence of cybersecurity risk. Our findings enabled the organization to begin remediating 262 CISA Known Exploited Vulnerabilities immediately.

During the engagement, the client improved its Microsoft 365 secure configuration score from approximately 45% to more than 80% by implementing recommended changes. We also identified a potential SQL injection vulnerability and several code-level security weaknesses within the organization’s Oracle APEX benefits platform and provided a path to remediation.

In addition, we delivered a roadmap to address critical database security issues, including shared credential usage, the lack of separation between staging and production environments, and gaps in audit logging capabilities. The assessment provided prioritized recommendations aligned with regulatory expectations and a practical roadmap for strengthening the IT controls that protect members’ personal, financial, and health information.