Every client here is anonymized — industry and region only, no names, no logos. We don't share client details without explicit written consent. What we can share is the work: the situation, the outcome, and what the first month actually looked like.
Finance / New York Metro
Situation
Client A came in through a referral from a colleague who had just gone through onboarding. The intake process surfaced what we see more often than anyone wants to admit: 312 reused or near-identical passwords across personal and work accounts, two accounts already flagged in the HIBP breach database, and no 2FA on any financial platform. The client knew it was a problem — had known for years — but hadn't had the bandwidth to fix it systematically. One afternoon of credential hygiene turned into a three-year backlog.
The threat profile here was straightforward but acute. A hedge fund analyst with institutional email addresses, broker logins, and crypto positions sitting behind recycled passwords is a high-value target. One breach notification away from a bad quarter.
30-Day Outcome
"I stopped thinking about passwords. That alone was worth it."
— Client A, Finance, New York Metro
Healthcare / New York Metro
Situation
Client B is a two-physician household with three children — ages 8, 12, and 16. Between them: seven active devices, a smart home system installed during COVID and never reconfigured, a shared family iCloud account the 8-year-old also used, and no backup strategy for any of it. The parents had separate password managers that didn't talk to each other, and the kids had unsupervised access to the family Wi-Fi with no traffic visibility.
The smart home was the exposure nobody had thought about: factory default credentials still active on the router, the thermostat, and two cameras. The 12-year-old's iPad was on the same network segment as the parents' work laptops, which meant any app installed on that iPad had the same network-level access as the adults. In a home with HIPAA-adjacent professional obligations, that's a real problem.
30-Day Outcome
"My 12-year-old's iPad was the back door to our whole house. Not anymore."
— Client B, Healthcare, New York Metro
Real Estate / New York, New Jersey, Connecticut
Situation
Client C runs the operating entity for a significant real estate portfolio — north of $40M in crypto spread across four self-custody wallets, three active LLCs with overlapping admin credentials, and a spouse who, in the event of incapacitation, would have no documented path to access anything. No succession plan. No digital estate document. A family attorney who had been raising this for two years with no resolution.
The LLC situation was the immediate fire: three companies, each with admin accounts shared informally among the principal, a business partner, and an assistant. No separation. No rotation cadence. One disgruntled departure or phishing hit away from a hostile actor holding administrative access to all three entities simultaneously. The crypto wallets were isolated, but with no multi-sig structure and no documented recovery path, they were a single point of failure for a material portion of the estate.
30-Day Outcome
"My estate attorney called Sentinel the missing piece. We'd been talking about it for two years."
— Client C, Real Estate, Tri-State