Industry:

Financial Services (Federal Credit Union)

Number of Employees:

201-500

Products

  • Security Control Validation (SCV)
  • Attack Path Validation (APV)

About:

A US-based federally chartered credit union serving a specialized member community. It operates under financial-services regulatory frameworks, including NCUA oversight, FFIEC IT examination guidelines, and NIST CSF, running a lean security team in a highly locked-down environment built around least-privilege access.

How a Federal Credit Union Validates Its Security Stack Against Real-World Threats with Picus

Challenges and Results:

Security controls assumed effective, tested once a year
Weekly validation across endpoint, network, email, and web layers
A prior simulation tool left web-filtering coverage unverified
Switched to Picus to close the gap and test user-context threats
Threat exposure scores inflated where controls had no API visibility
Identified exactly which controls needed manual validation workflows
No structured way to demonstrate posture trends to leadership
Executive reporting cadence with period-over-period comparison
Firewall signatures updated reactively, without validation evidence
Simulation results drive a direct find-to-fix loop into IPS/IDS
Detection coverage hard to confirm across separate tools
Bidirectional threat-hunting workflow correlating EDR alerts to simulations

Executive Summary

A US-based federal credit union operates under strict financial services oversight, where proving security control effectiveness is a regular part of audit and examination readiness. Its small security team needed to move beyond assuming its tools worked and continuously validate them against real-world attack techniques. The team deployed Picus Security Control Validation (SCV) and Attack Path Validation (APV) to test endpoint, network, email, and web defenses on a weekly cadence. Continuous validation turned the security stack into something the team could measure and prove: endpoint detection consistently scored above 90, IPS/IDS coverage improved year over year, and every simulation result fed directly into firewall updates and executive reporting.

The Challenge: Proving the Stack Works, Not Just Assuming It

The team operates one of the most locked-down environments in financial services, where even opening a command prompt requires elevated privileges. That tight posture made continuous validation essential. With controls layered across endpoint, network, email, and web, the team needed proof that each one would actually stop a real attack, not just an assumption that it would. A previous simulation tool had left key questions unanswered, particularly around DNS-layer web filtering, where user-context threats were difficult to validate reliably. The team also faced a measurement problem: where controls had no direct API visibility into the validation platform, their prevention actions went uncredited, which inflated exposure scores and made it harder to see true coverage. The team needed a clearer, more consistent picture before it could act with confidence.

The Solution: Continuous Validation Across Every Layer

Rather than adding another control to the stack, the team used Picus to validate and strengthen what they already ran. Weekly simulations test the endpoint detection platform, the SIEM, the email gateway, and DNS-based web filtering, with every result mapped to MITRE ATT&CK for structured review. Security Control Validation runs scheduled simulations across endpoint, network infiltration, email gateway, and URL filtering. The endpoint module confirms that malicious executables, DLLs, and PE files are blocked, while network simulations validate SIEM detection coverage. Attack Path Validation tests domain credential attacks and ransomware emulation paths on a monthly cadence, running on a dedicated agent to keep simulation traffic clean and isolated from production alerting. Where a control had no direct integration, the team used the simulation findings to build manual validation workflows, so coverage gaps were understood and accounted for rather than hidden inside an inflated score. 

The Results: Measured, Proven, and Reported

Continuous validation gave the team evidence where they previously had assumptions. Endpoint detection now scores consistently above 90 on weekly runs. IPS/IDS coverage improved year over year. When URL filtering simulations needed tuning, a configuration fix restored accurate block confirmations from the firewall. The biggest shift is operational. Simulation results now drive a direct loop: findings push updated signatures into the IPS/IDS, and period-over-period comparisons give leadership a clear view of security posture trends. For a team that operates under regular audit and examination cycles, that evidence also shortens the path to demonstrating control effectiveness when regulators ask. The team has even extended the platform into proactive threat hunting, correlating detection alerts back to specific simulations to confirm exactly which technique an alert maps to.

Why the Team Chose Picus

The credit union chose Picus to close a validation gap that its previous tool could not, and stayed for the continuous, automated cadence that fits a lean team under constant audit pressure. Full-platform licensing from onboarding gave the team room to grow into attack path validation and, increasingly, AI-driven threat simulation.

The Takeaway

Blocking an attack is not enough. Security teams have to prove their controls work, consistently and on a schedule, not assume it between annual tests. For a lean team in a heavily regulated environment, continuous validation is what turns a security stack from a set of assumptions into a body of evidence. The result is faster remediation, clearer reporting to leadership, and the confidence to show, not just claim, that the defenses hold.

What Our Customers Say

RESOURCES

Discover Our Latest News and Content