Cybersecurity

We Broke Into a New Jersey Manufacturer in 40 Minutes. Here's What We Found.

An authorized CATSCAN® engagement at a New Jersey manufacturer showed how ordinary physical, human, and technical gaps can combine into a meaningful attack path.

By Tom Brennan

Featured image for We Broke Into a New Jersey Manufacturer in 40 Minutes. Here's What We Found.

The first sign of a serious security problem is not always a ransomware note, a locked account, or a flashing alert on a security dashboard.

Sometimes, it is a door that opens for someone who looks like they belong.

In a controlled, authorized CATSCAN® engagement for a New Jersey manufacturer, our team demonstrated how quickly an attacker could move from the outside of a facility toward meaningful access. The result was not a movie-style zero-day exploit or an elaborate criminal operation.

It was a collection of ordinary gaps working together:

  • A badge that was not questioned.
  • A vendor email that looked legitimate.
  • An unlocked network closet.
  • A shared password.
  • An unpatched server.
  • A helpful employee holding a door.

For a 50–350 person manufacturer, municipality, public agency, or growing company, these small openings can connect into one large attack path.

What CATSCAN® Tests That Automated Scanners Do Not

CATSCAN® stands for Comprehensive Assessment of Threats, Systems, Controls, And Networks.

Unlike an automated vulnerability scanner, CATSCAN® simulates a real adversary. It combines cyber exploitation with physical infiltration, social engineering, and intelligence-driven targeting.

Think of a vulnerability scanner as inspecting a castle from outside the walls. It may identify an unlocked window or a weak section of the perimeter.

CATSCAN® asks a more practical question:

Could a determined attacker use that window, persuade someone to open a gate, reach the server room, and move through the castle without being stopped?

The framework mirrors tactics used by sophisticated threat actors, including nation-state and advanced persistent threat groups. Every engagement is individually scoped, authorized, and governed by rules of engagement.

The published CATSCAN® figures help explain why this matters:

  • 84% of organizations suffered a cyberattack in the last 12 months.
  • 98% use vulnerability scanners, but only 34% find them effective.
  • Only 26% conduct penetration tests more than once a year.

Scanning remains useful. It is one layer of defense. But a clean scan is not the same as a demonstrated ability to resist a real attack.

Executive cybersecurity consultation with risk metrics and a protective shield

The Seven Phases of a CATSCAN® Engagement

A CATSCAN® engagement is like a carefully controlled heist walkthrough. The purpose is not to damage property or disrupt operations. The purpose is to understand the path an attacker could take and give leadership a prioritized way to close it.

Phase I: Information Gathering and Vulnerability Detection

The team begins with reconnaissance.

This includes open-source intelligence, or OSINT, along with information about people, facilities, technologies, foot traffic, and public-facing systems. The team reviews physical and logical controls, terrain features, access points, and possible infiltration or exfiltration points.

In plain language, this means learning how the organization works before attempting to test it.

For a manufacturer, that could include understanding delivery schedules, contractor access, public employee information, exposed systems, building entrances, and where technology and production environments connect.

Phase II: Information Analysis, Planning, and Weaponization

Next, the team analyzes what it learned and plans the engagement around the organization’s actual weaknesses.

Depending on the approved scope, preparation may include custom payloads, hardware trojans, disguises, and falsified personas or companies. These are not generic tools selected from a checklist. They are controlled elements designed to test a specific attack path.

This is similar to preparing the right key for a particular lock rather than carrying a bucket of random keys.

Phase III: Attack and Penetration

The team then tests the planned paths.

This may include cloned badges, face-to-face social engineering, cyber exploits, or the controlled placement of hardware trojans. The goal is to determine which access points provide the greatest advantage to an attacker.

The point is not simply to prove that one control can be bypassed. It is to see whether bypassing one control creates a chain reaction across the facility, network, or workforce.

Phase IV: Privilege Escalation and Exploitation

Once access is obtained, the team tests how far that access can go.

In the digital environment, this may involve servers, applications, networks, and identity systems. In the physical environment, the team may evaluate gates, fences, locks, radar, and motion detection systems.

People are also part of the attack surface. Under the approved rules of engagement, staff may be tested through email, phone calls, fax, text messages, or face-to-face interactions.

A shared password or excessive user privilege can turn limited access into broad access, much like finding that a visitor’s badge also opens the executive suite.

Phase V: Installation

This phase evaluates whether an attacker could establish a persistent foothold.

Testing may include privilege escalation on compromised servers, controlled file payloads, physical key impressions, or lockpicking within the approved scope.

The question is whether the organization would notice the foothold, how long it might remain, and whether existing controls would remove it.

Phase VI: Command and Control

An attacker who gets in wants to stay in.

CATSCAN® tests whether stable remote access could be maintained and whether people could be manipulated into bypassing physical barriers again.

This is where many organizations discover the difference between blocking one event and detecting an ongoing operation. A single locked door may not matter if an attacker can repeatedly persuade someone to open it.

Phase VII: Actions on Objective

The final phase measures what could be achieved.

The team may test lateral movement across systems and facilities, collect video, audio, and photographic evidence, and exfiltrate data or physical assets where specifically authorized.

The objective is defined before testing begins. Findings are documented so leaders can understand what happened, which controls failed, and what should be addressed first.

A seven-stage adversarial cybersecurity assessment represented through connected facility, identity, network, and evidence checkpoints

One Break-In Can Expose Eight Layers of Protection

The seven CATSCAN® phases often move across what we describe as eight layers of protection:

  1. Governance and strategy, Who owns cyber risk, and how are decisions prioritized?
  2. Identity and access: Are badges, passwords, accounts, and privileges controlled?
  3. People and social engineering: Can employees recognize and challenge unusual requests?
  4. Endpoints and servers: Are devices patched, monitored, and properly configured?
  5. Network, cloud, and Microsoft 365, Can an attacker move between connected environments?
  6. Applications and data: Are critical systems and sensitive information protected?
  7. Physical facilities: Can someone enter the building, wiring closets, or restricted areas?
  8. Detection, response, and recovery: Would the organization see the attack and know what to do next?

A vulnerability assessment may identify an unpatched server. A red team exercise can show how that server connects to a shared account, an unlocked closet, and a production system.

That context matters to a chief executive officer, chief financial officer, general counsel, or board because the business consequence is rarely “one technical finding.” The consequence may be production downtime, delayed shipments, customer concerns, contract pressure, legal exposure, or damage to EBITDA.

Cybersecurity is not only about protecting technology. It is about protecting the strategic goals that technology supports.

Why It Matters

Point-in-time testing is valuable, but exposure does not remain frozen after the report is delivered.

An attacker may re-check the same things first:

  • Has a previously exposed account been disabled?
  • Is the unpatched server still vulnerable?
  • Did a vendor’s access change?
  • Is the network closet still unlocked?
  • Can a new employee be persuaded to hold the door?
  • Did a Microsoft 365 configuration drift?
  • Are alerts being reviewed outside business hours?

This is why penetration testing should be connected to continuous monitoring, risk management, and executive oversight.

A clean vulnerability scan can create false comfort. So can a passed checklist, an insurance questionnaire, or a completed compliance assessment. These tools may document that a control exists at a specific point in time. They do not necessarily demonstrate that the control works under pressure.

Customer contracts and supplier requirements may also ask for evidence of penetration testing, threat detection and response, access control, incident readiness, or third-party risk management. Insurance questionnaires may ask similar questions.

The right response is not to chase paperwork. It is to understand what has actually been tested, what remains uncertain, and which investments best protect revenue and strategic goals.

For breach developments and related legal obligations, organizations can also use the Breach Intelligence Hub as a plain-English resource for daily breach updates.

How We Deliver It

CATSCAN® is the centerpiece of this work. The CATSCAN® scoping page helps define whether your organization needs external or internal network penetration testing, web application testing, Microsoft 365 and Azure assessment, social engineering, wireless testing, or hardware and device testing.

CATSCAN® can also be coordinated with the broader Proactive Risk service model:

  • CyberAdvisor℠ provides vCISO-level strategy, governance, risk reporting, and executive guidance.
  • MeasureRISK℠ connects findings to compliance, evidence, policy, and risk management priorities.
  • ManageIT℠ supports managed security services, 24/7 monitoring, threat detection and response, endpoint operations, and log visibility.
  • RISKWatch℠ addresses vendor and third-party risk that can create another path into the organization.
  • FraudShield™ helps measure and improve exposure to phishing and social engineering.
  • CyberTrain℠ tests incident response, communications, and executive decision-making through facilitated exercises.
  • GOVERNAI℠ helps organizations govern emerging AI use, access, and data-handling risk.
  • The CIS Controls crosswalk helps translate technical findings into prioritized safeguards and accountable business actions.

For organizations evaluating Microsoft 365 security and identity threat detection and response, it can also be useful to compare industry approaches from providers such as Blackpoint Cyber, Todyl, and Petra Security. The important question is not which tool has the longest feature list. It is whether identity, email, endpoint, cloud, network, and human activity are connected into a defensible operating model.

For a plain-English introduction to red team and blue team roles, start with the Rainbow Hacker reference card. Red teams test the castle. Blue teams defend it. Purple teams help both sides learn from the same exercise.

Cybersecurity operations workstation showing technical analysis and monitored systems

Scope Your Engagement

The “40 minutes” was not the takeaway. The takeaway was how ordinary gaps can combine into a meaningful attack path.

A badge, email, password, server, door, or helpful employee may each appear manageable in isolation. Together, they can affect operations, customer trust, legal obligations, and EBITDA.

Proactive Risk can help your leadership team determine what should be tested first, what rules of engagement are appropriate, and how findings should connect to your broader security program.

Scope Your Engagement or Talk to a Consultant for a no-obligation conversation and Executive Risk Review. A preliminary discussion is not an audit, certification, compliance determination, or guarantee of prevention. Any follow-on assessment or managed service is separately scoped.

Summary: Test the Path, Not Just the Tool

Automated vulnerability scanning has a place in a mature security program. It can help identify weaknesses at scale.

But real attackers do not operate one tool at a time.

They combine public information, physical access, social engineering, stolen credentials, unpatched systems, identity abuse, and lateral movement. CATSCAN® is designed to test those connections through a controlled, intelligence-led adversarial operation.

For New Jersey manufacturers, municipalities, public agencies, and mid-sized businesses, the practical question is simple:

If an attacker started outside your building today, how far could they go before someone or something stopped them?

Answering that question honestly is one step toward securing the future of your strategic goals.

CATSCAN® is a registered trademark of Proactive Risk, Inc. (USPTO).


PROACTIVE RISK
Intelligence-Led Cybersecurity & Risk Management
ANTICIPATE. DEFEND. PREVAIL.

36 First Avenue, Suite 203, Denville, NJ 07834
973-298-1160
https://proactiverisk.com

Back to the Proactive Risk blog · Talk with Proactive Risk