Learning & Information
Hacks
Building Resilience Beyond the Incident
Aug 17, 2026 | 6 min read
Many teams focus heavily on advanced technical defenses, expensive tools, or expanding their security staff. While those elements have their place, our data from the first half of 2026 shows most breaches stem from basic issues like unreviewed access permissions, weak account lifecycle management, or relying too heavily on a single person. We review an insider threat case study to observe these risks and highlight how to minimize them.
When an organization faces a security breach, the immediate instinct is to fix the specific hole and get back to business as usual. But just resetting to that status quo leaves you vulnerable. The momentum of an active incident is actually the best time to shift from reactive firefighting to a proactive, risk-focused security setup.
Many teams focus heavily on advanced technical defenses, expensive tools, or expanding their security staff. While those elements have their place, our data from the first half of 2026 shows a rise in incidents driven by much simpler operational gaps. Most breaches stem from basic issues like unreviewed access permissions, weak account lifecycle management, or relying too heavily on a single person. True resilience means prioritizing the everyday checks and balances that actually hold up under real-world pressure.
Building a meaningful defense
Building a security program is a lot like putting an extension on a house. You can spend months searching the internet for different contractors, hoping they are qualified and fairly priced. Or, you can work with a known and trusted project manager who is deeply embedded in the trade, has plenty of references, and already knows the best people for the job.
We act as that project manager for your security. Instead of letting you guess or waste your budget on generic tools, we guide you toward defenses that stop real-world threats. Because we handle so many live incidents, we see exactly how attackers are breaking in right now.
No single company can solve every security problem. When you need a specific solution, we tap into our network of the best security providers in Web3. We bring them in, handle the logistics, and ensure your system is built properly so you can focus on running your business.
The following case study shows how this works in practice, helping a client contain an internal exploit and rebuild their operational defenses.
Case Study: The Insider Threat
During the first half of the year, we supported several clients facing an incredibly challenging scenario: what to do when funds are stolen by a trusted employee?
In one instance, a client lost millions after an employee abused their legitimate access to company funds for personal gain. This is one of the toughest situations a team can face because the suspect already has the necessary keys and permissions, which makes traditional perimeter defenses ineffective.
When the client reached out, our incident response team stepped in to help handle both the immediate cleanup and the wider fallout:
- REVOKING ACCESS: We worked closely with the team to quickly cut off the suspect's access across all company systems. We triaged their environment to ensure no backdoors were left open and enforced a company-wide password reset.
- PRESERVING EVIDENCE: We advised the client on how to preserve system logs without disrupting daily operations. They provided several months of detailed on-chain and off-chain transaction logs related to the suspect's activity.
- DATA REVIEW: Our team conducted an independent analysis of these logs to establish the exact scale of the theft and create an accurate, forensic record of the losses.
- INCIDENT REPORTING: Recovering the stolen assets was a priority, particularly for the client's insurance claim. We provided the detailed, verified reporting needed to substantiate the claim, while also helping the team submit clear evidence and on-chain indicators to law enforcement.
- RECRUITMENT PROCESSES: This incident highlighted the need for more robust internal checks. We used our network and experience to help the client review their hiring practices and support them as they recruited for new positions.
Because the client acted quickly to contact law enforcement and our team, the incident was contained, and a portion of the stolen funds was successfully returned. The logs preserved by the client were essential for building both the criminal case and the insurance claim.
How can you minimize the risk?
Defending against an insider threat requires moving past standard technical boundaries. When someone is already inside your perimeter, traditional walls do not work. Instead, minimizing this risk requires a practical "trust and verify" approach built on simple checks and balances.
1. MANAGERIAL CONTROLS
Security is not just about software; it relies heavily on team culture and basic management.
- HUMAN MANAGEMENT: Effective management is not about micromanaging or being overly harsh, which can actually alienate staff and drive internal risks. It is about managers truly knowing their people. In hindsight, subtle shifts in behavior, personal pressures, or disengagement are often visible. Connected managers notice when someone is acting out of character and can step in to support them before a problem escalates.
- HIRING PRACTICES: Technical talent is easy to measure, but integrity is just as vital for roles handling critical infrastructure or company treasuries. Background checks and continuous vetting should be a standard part of the onboarding process for high-access positions.
- ESTABLISHED RELATIONSHIPS: When a crisis hits, you do not want to waste hours vetting security firms, negotiating commercial terms, or waiting for legal teams to sign non-disclosure agreements. Having an established relationship with a security partner beforehand means you can skip the paperwork and get experts straight into your war room when minutes matter.
2. TECHNICAL CONTROLS
On the technical side, stopping internal abuse is mostly about visibility. You just need simple, reliable ways to see exactly what is happening inside your network so you aren't flying blind.
- BASELINE LOGGING AND ANOMALY DETECTION: You need clear visibility into what is happening across your systems. Simple, automated logging rules can flag unusual activity, like a team member accessing core files or treasuries outside of normal working hours, or downloading unusual amounts of data.
- MANAGING ENDPOINTS: Allowing employees to use personal devices for critical work creates a massive blind spot. If an employee accesses core systems from a personal laptop with no basic security baselines, you are operating in the dark. Moving high-risk functions to company-owned devices secured with Mobile Device Management (MDM) and Endpoint Detection and Response (EDR) gives you a clear baseline. If unusual activity or an unapproved transaction occurs, the system automatically alerts your team and can isolate the device instantly.
Operational readiness
True operational resilience must be built as muscle memory within your internal team.
We know our clients are building fast and pushing boundaries, and security needs to keep pace. We encourage internal teams to challenge existing access controls, question assumptions, and even slow down a deployment if it means doing it properly. Spotting and calling out long-standing gaps is the first major step toward staying secure.
We build defenses with our clients, not for them. By working closely alongside our consultants and partners throughout the readiness journey, your internal team does not just inherit a compliance report. They learn the practical skills to run drills, protect themselves, and continuously improve their own security setup. The strongest teams aren't the ones with flawless systems, they are the ones willing to constantly test, question, and upgrade them.