
Fraud Investigations
Investigate diverted funds or goods, false documents, procurement and expense fraud, supplier collusion and online scams. We gather evidence to clarify the facts and inform decisions.
Explore the serviceStrengthen detection. Review who can access.
Assess logs, defensive rules, identities and privileges to identify coverage gaps and organise improvements with the technical team.
Scope and deliverables defined for your business.
BARUCH / ANALYSIS AND EXECUTIONDefensive assessment
01 / When it makes sense
Low-value alerts, detection gaps or excessive permissions make exposure harder to control and suspicious behaviour harder to address.
Information Security, SOC, IT and identity and access teams responsible for the environments.
In practice
Hypothetical examples of situations where this solution can help your organisation.
An account can still change registrations, commissions or payments after a staffing change. IT and process owners need to review permissions and decide who approves and removes each type of access.
The team needs to review logs and rules to understand what it can detect and where gaps remain.
Teams want to review configurations and procedures to better address suspicious behaviour in their systems.
02 / From analysis to decisions
03 / Your deliverables
Choose an option to see an example deliverable.
Swipe the options to see more deliverables →
Logging and detection coverage, operational gaps and recommendations for response procedures.
Illustrative structure. No client data or results.
The example system records role changes.
Fictional source EX-01Review of exceptional privileges is not defined.
Coverage to validateDefine an owner and procedure for assessing the exception.
Referral criterionThe assessment connects logging, detection and response; having a log does not mean the control is complete.
Content and depth are defined according to your project scope.
Findings concerning accounts, roles, privileges and access provisioning and removal workflows.
Illustrative structure. No client data or results.
| Focus | Illustrative example | Interpretation / next step |
|---|---|---|
| Functional account A | Administrative privilege without a current justification in the example. | Reassess need and approval |
| Inactive account B | Access remains linked to a role that has ended. | Confirm and review revocation |
| Third-party role C | A permission review date has not been set. | Assign a review owner |
Accounts, privileges and justifications are linked to guide provisioning, review and revocation with responsible teams.
Content and depth are defined according to your project scope.
Prioritised improvements, suggested owners and criteria for reviewing controls.
Illustrative structure. No client data or results.
Validate the inventory and need for permissions.
Access owners involvedSubmit changes through the company's approval workflow.
No automatic revocationRecord approval and the criteria for the next review.
Verifiable controlThe plan connects each action to an owner while keeping the organisation in control of access changes.
Content and depth are defined according to your project scope.
Which decision should this deliverable support?
Tell us what you need04 / The work
Explore the stages of the work. The scope starts with your context, available information and the decision your business needs to make.
We review log sources, defensive configurations, identities, roles and privileges included in scope.
We validate detection and procedures through controlled scenarios and examine authentication, access provisioning and removal.
We prioritise configuration, detection and permission recommendations with suggested owners and review criteria.
05 / A tailored scope
Combine the capabilities your challenge requires.
We review log sources, defensive configurations, detection rules and response procedures, assessing their coverage through controlled scenarios alongside the teams responsible for the environment.
Deliverable: A defensive coverage assessment, configuration and detection recommendations, and prioritized response procedures to address operational gaps identified in the organization's existing security practices.
We map identities, roles and privileges, reviewing authentication and access provisioning and removal processes against responsibilities, segregation of duties and the criticality of assets.
Deliverable: An inventory of access risks and an improvement plan with priorities, suggested owners and review criteria to support consistent management of permissions across the organization.
Contact Baruch
Chat on WhatsApp or prepare your enquiry using the form below.
Let's talk
Add your details and a short description to prepare your enquiry by email or WhatsApp.