Project Description
How MFA Strengthened Security and Cut Costs for a Melbourne Asset Management Firm

Our client is a well-established Asset Management Company based in Melbourne, operating since the early 2000’s. With a team of approximately 40 employees spread across multiple locations—including international offices—they specialise in managing property-specific investments and pooled funds tailored to varying investor risk profiles.
Their clientele includes high-net-worth individuals and corporate entities, and the firm handles substantial financial transactions daily. Given the nature of their work, the company is a prime target for cyber threats, particularly those aimed at misdirecting funds or accessing sensitive personal identifiable information (PII).
Having already experienced several unsuccessful cyber attacks, the company was acutely aware of the risks and committed to strengthening its security posture before a breach could occur.
A two-fold security problem

The firm’s primary vulnerabilities were twofold:
- Invoice fraud, where attackers attempt to redirect large financial transfers.
- Identity theft, through unauthorized access to investor data stored in SharePoint.
While the company had already implemented Multi-Factor Authentication (MFA) across its Microsoft 365 environment—including Exchange Online, SharePoint, and VPN access—there remained a critical concern: MFA alone could be bypassed if a phishing attack tricked users into entering their credentials and MFA codes into a malicious form.
This potential loophole posed a serious threat to the integrity of their systems and the confidentiality of their client data. The company needed a solution that would go beyond MFA and provide layered, context-aware protection.
- Enhanced Security Posture:
The combination of MFA and Conditional Access has created a multi-layered defence system that protects against phishing, credential theft, and unauthorised access. - Reduced Cyber Insurance Premiums:
The implementation of advanced security measures led to a lower risk profile, which in turn reduced the company’s cyber insurance costs—a direct financial benefit. - Improved Compliance and Peace of Mind:
The firm now meets higher standards for data protection and regulatory compliance, giving stakeholders confidence in the company’s ability to safeguard sensitive information. - Operational Continuity:
The security enhancements were implemented with zero disruption to daily operations, ensuring seamless access for authorized users while keeping threats at bay.
The Approach
Proactive Technology Partners stepped in to assess the risk profile of the client’s Microsoft 365 tenancy and identify ways to enhance security beyond standard MFA enforcement.
After a thorough evaluation, we determined that Conditional Access policies would provide the most effective way to reduce the risk of unauthorized access. Conditional Access allows organisations to define specific conditions under which users can access Microsoft 365 resources—adding a powerful layer of control on top of MFA.
The Solution
We implemented two key Conditional Access policies designed to complement and strengthen the existing MFA setup:
- Policy 1: Device-Based Access Control
Access to Microsoft 365 is now restricted to devices that are registered with Azure Active Directory (Azure AD). If a device is not registered, it can only access Microsoft 365 while physically located within the client’s office network. - Policy 2: VPN Enforcement for External Access
For users who need to access Microsoft 365 from outside the office using non-registered devices, a secure VPN connection is required. This ensures that remote access is only granted through trusted, encrypted channels.
These policies significantly reduce the risk of credential theft and unauthorized access—even in scenarios where MFA credentials might be compromised.
What’s Next?
With MFA and Conditional Access now forming the backbone of their security strategy, the company is exploring additional measures such as privileged access management, security awareness training, and automated threat detection to further harden their environment.
This case demonstrates that investing in security is not just about protection—it’s about enabling business continuity, reducing financial risk, and building trust. For this asset management firm, the decision to go beyond MFA has paid off in both peace of mind and bottom-line savings.


