Engagements

Case Studies.

All client engagements below are presented anonymously, in keeping with the trust that underpins every advisory relationship we hold.

Custodia One is a trust business. The confidence clients place in us when they share a breach, an incident, or a vulnerability is not ours to trade for a testimonial. We identify clients only by sector, scale, and geography, sufficient to demonstrate relevance without compromising the relationship that made the engagement possible.

Corporate

A Fortune 500 Financial Institution

Global · 14 Countries

The Situation

Following an attempted spear-phishing attack targeting three members of the C-suite, the institution's risk committee concluded that technical controls alone were insufficient. The individuals targeted had been profiled using publicly available information over a period of several months before the first contact was made. The attack was sophisticated, personalised, and very nearly succeeded.

Our Approach

Custodia One conducted a targeted human risk assessment of the senior leadership team, mapping each individual's digital exposure across professional and personal channels. A structured briefing programme was designed and delivered directly to the C-suite, followed by a broader awareness programme for senior managers across four regions.

The Outcome

The engagement resulted in a revised personal digital hygiene policy for C-suite and board-level personnel, adopted across the group's global operations. The institution subsequently retained Custodia One for an ongoing advisory relationship.

Leadership & Boards

The Board of a World-Leading Consumer Technology Company

North America · Europe

The Situation

Following a high-profile breach at a peer institution, the board requested a dedicated briefing on their own exposure as individuals, not as a company. Several board members held simultaneous advisory positions at other organisations, significantly expanding their personal attack surface beyond what any corporate security policy could address.

Our Approach

Custodia One profiled each board member's public digital footprint and identified specific vectors of exposure including personal social media presence, open-source intelligence trails, and third-party data broker records. A private briefing was delivered to the full board, with individual advisory sessions for the most exposed members.

The Outcome

Multiple board members voluntarily reduced their public digital footprint following the engagement. The company adopted a board-level personal security protocol as a standing governance item, the first of its kind within the group's history.

Corporate

A Reputed International Luxury Hotel Group

Middle East · Europe · Asia

The Situation

A series of social engineering incidents targeting senior hotel staff, including front office managers and finance teams, exposed a pattern of credential theft and identity fraud. Perpetrators had systematically exploited staff helpfulness and service culture to extract access to guest data and financial systems. The reputational risk to the group was significant.

Our Approach

Custodia One delivered a targeted awareness programme for hospitality professionals across multiple properties, focusing on the specific social engineering tactics used against service-sector staff. The training was adapted to reflect the cultural and operational context of each property and delivered in coordination with the group's regional security leads.

The Outcome

The hotel group adopted a revised guest data protection protocol and incorporated Custodia One's human risk framework into its annual staff induction programme across all properties.

Schools & Colleges

An International School Network

Three Countries · Multiple Campuses

The Situation

A safeguarding incident involving online grooming of a student, facilitated through a gaming platform, prompted the school network's leadership to commission a comprehensive review of their digital safeguarding posture. The incident had gone undetected for several months, highlighting critical gaps in staff awareness, parental guidance, and institutional response protocols.

Our Approach

Custodia One delivered a multi-strand programme: staff training on identifying and reporting digital safeguarding concerns; student-facing sessions tailored by age group; and a parent briefing addressing platform risks, monitoring approaches, and how to open conversations about digital safety at home. All materials were developed in consultation with the schools' safeguarding leads.

The Outcome

The network adopted Custodia One's recommended safeguarding framework across all campuses. Staff reported a marked increase in confidence in identifying and escalating digital risk concerns. The programme has since been repeated annually.

Community

A State-Level Women's Safety Initiative

India · Multiple Cities

The Situation

Women across urban and semi-urban communities faced a growing range of digital threats including online harassment, financial fraud, and identity exploitation. Awareness was low, reporting pathways were unclear, and existing helpline infrastructure needed stronger community reach to be effective.

Our Approach

Custodia One partnered with a state police-run women's helpline to design and deliver a structured community outreach programme. Workshops were conducted across communities, communication materials were developed to simplify complex digital safety concepts, and the helpline's reporting and response processes were clearly mapped and communicated to participants.

The Outcome

The programme reached communities at scale across multiple cities. Awareness of digital threats and knowledge of formal reporting pathways increased measurably among participants. The communication materials and workshop framework were retained by the helpline for ongoing outreach.

Certain Engagements Remain Entirely Confidential.

Our work with law enforcement agencies, government ministries, intelligence functions, and forensic investigation teams is not represented here, not even in anonymised form.

The sensitivity of those engagements, the nature of the information involved, and the trust placed in us by those institutions demand absolute discretion. In those verticals, our track record speaks only in private, and that is precisely how it should be.