
Quality Credit Services, an Ontario financial services firm, needed tightly controlled access to its line-of-business and reporting applications, restricted to within the province, with two-factor authentication, modern email and round-the-clock security monitoring.
We built a Remote Desktop Services environment for centralized delivery, applied geographic restriction and 2FA, migrated to Microsoft 365, hosted the firm's custom reporting application, built Power BI dashboards, deployed MaaS360 for mobile devices, and put a 24/7 SOC behind all of it.
The firm's requirement was easy to state and harder to build: staff had to reach the applications the business runs on, from where they work, and nobody else had to be able to reach them at all. Access needed restricting to within the province. Every session needed a second factor. Email had to be modern. Something had to be watching for threats at three in the morning as attentively as at three in the afternoon.
Requirements phrased that way usually get answered with a list of products. The more useful question is where the data is allowed to be. If applications run on individual workstations and laptops, the data is on those devices, and every control after that point is an attempt to protect copies you no longer fully govern. If applications run centrally and only pixels reach the endpoint, the endpoint stops being a place where data lives, and controls have one boundary to defend instead of many. That distinction shaped the whole design.
Each control answers a different question. Stacked, they define who may connect, from where, with what, and who is watching.
Remote Desktop Services gives you one place where applications execute and one place where sessions arrive, which is what makes every other control tractable. Geographic restriction means something because there is a defined point at which connections are accepted or refused. Two-factor authentication protects a single front door rather than a row of side entrances. Monitoring has a coherent picture to look at, because the interesting activity happens in one environment instead of being distributed across every laptop the firm owns.
Hosting the firm's custom reporting application on that same managed infrastructure follows identical logic. Bespoke internal software has a habit of ending up on whatever machine the person who commissioned it had spare, where it is backed up by accident, patched by nobody, and discovered to be business-critical at the worst possible moment. Power BI was then built on data the firm already held. Reporting projects fail when they start by asking what dashboard people want; they work when they start by establishing which decisions are currently being made without evidence.
We have deliberately kept this description at the level of architecture. For a firm in financial services, the specifics of how controls are configured are part of what protects it, and are not ours to publish.
If you handle other people's money or their financial data, the first architectural question is not which security products to buy. It is whether your data sits in one place you control or many places you hope are configured correctly. Centralized application delivery answers that in a way endpoint tooling cannot, because it changes where the data is rather than adding protection around where it already went.
The second question is what happens outside business hours. A security stack without continuous monitoring is a set of alarms nobody is in the building to hear. Whether that monitoring comes from your own team or a provider matters far less than whether the person receiving the alert has the authority and tooling to act immediately. The third is your own software: almost every established firm has an internally built application that quietly became essential. Treat it as infrastructure — hosted, monitored, backed up, patched — before circumstance forces you to.
More on this: financial and insurance services; managed SOC, EDR and MDR.
We are SOC 2 Type 2 attested and resolve 95% of tickets the same day. If you need application access that is genuinely restricted and genuinely watched, we will tell you what that takes before you commit to it.