Icon chevron up
Here's a dismissible notice for cookies notices etc.
Dismiss
A financial services office where staff reach line-of-business applications through controlled access

Secure application delivery for Quality Credit Services

Quality Credit Services, an Ontario financial services firm, needed tightly controlled access to its line-of-business and reporting applications, restricted to within the province, with two-factor authentication, modern email and round-the-clock security monitoring.

We built a Remote Desktop Services environment for centralized delivery, applied geographic restriction and 2FA, migrated to Microsoft 365, hosted the firm's custom reporting application, built Power BI dashboards, deployed MaaS360 for mobile devices, and put a 24/7 SOC behind all of it.

The situation

The firm's requirement was easy to state and harder to build: staff had to reach the applications the business runs on, from where they work, and nobody else had to be able to reach them at all. Access needed restricting to within the province. Every session needed a second factor. Email had to be modern. Something had to be watching for threats at three in the morning as attentively as at three in the afternoon.

Requirements phrased that way usually get answered with a list of products. The more useful question is where the data is allowed to be. If applications run on individual workstations and laptops, the data is on those devices, and every control after that point is an attempt to protect copies you no longer fully govern. If applications run centrally and only pixels reach the endpoint, the endpoint stops being a place where data lives, and controls have one boundary to defend instead of many. That distinction shaped the whole design.

What we built, and what each piece is for

Each control answers a different question. Stacked, they define who may connect, from where, with what, and who is watching.

Remote Desktop Services
→ Applications execute centrally; endpoints receive a session, not data
Geographic restriction
→ Connections accepted only from within the province
Two-factor authentication
→ A stolen password alone is not enough to sign in
Microsoft 365
→ Mail and identity on a current, centrally governed platform
Hosted custom reporting application
→ The firm's own software runs on managed infrastructure, not under a desk
Power BI reporting and dashboards
→ Existing data presented so it can be read and acted on
MaaS360 mobile device management
→ Phones and tablets enrolled, governed and separable from their holder
24/7 SOC monitoring
→ Someone is watching, and responding, at every hour

Why centralized delivery came first

Remote Desktop Services gives you one place where applications execute and one place where sessions arrive, which is what makes every other control tractable. Geographic restriction means something because there is a defined point at which connections are accepted or refused. Two-factor authentication protects a single front door rather than a row of side entrances. Monitoring has a coherent picture to look at, because the interesting activity happens in one environment instead of being distributed across every laptop the firm owns.

Hosting the firm's custom reporting application on that same managed infrastructure follows identical logic. Bespoke internal software has a habit of ending up on whatever machine the person who commissioned it had spare, where it is backed up by accident, patched by nobody, and discovered to be business-critical at the worst possible moment. Power BI was then built on data the firm already held. Reporting projects fail when they start by asking what dashboard people want; they work when they start by establishing which decisions are currently being made without evidence.

We have deliberately kept this description at the level of architecture. For a firm in financial services, the specifics of how controls are configured are part of what protects it, and are not ours to publish.

The outcome

What this means for a similar business

If you handle other people's money or their financial data, the first architectural question is not which security products to buy. It is whether your data sits in one place you control or many places you hope are configured correctly. Centralized application delivery answers that in a way endpoint tooling cannot, because it changes where the data is rather than adding protection around where it already went.

The second question is what happens outside business hours. A security stack without continuous monitoring is a set of alarms nobody is in the building to hear. Whether that monitoring comes from your own team or a provider matters far less than whether the person receiving the alert has the authority and tooling to act immediately. The third is your own software: almost every established firm has an internally built application that quietly became essential. Treat it as infrastructure — hosted, monitored, backed up, patched — before circumstance forces you to.

More on this: financial and insurance services; managed SOC, EDR and MDR.

Controlled access, monitored around the clock

We are SOC 2 Type 2 attested and resolve 95% of tickets the same day. If you need application access that is genuinely restricted and genuinely watched, we will tell you what that takes before you commit to it.

Close search

Search