Introduction 1 / 8
Case study · 5–7 minutes

Mark's Thursday

A three-person advisory practice. One afternoon. One email. A client's $250,000 house closing.

This walkthrough shows how an attack gets past antivirus and a firewall, why your custodian's security does not cover it, and what kind of monitoring would have caught it in time.

You will be asked to predict what happens at a few points. The wrong answers are the ones most advisors pick, which is exactly what makes them worth walking through.

No technical background needed. Any term appears like this — — and you can tap it for a plain-English definition at any time.

Scene 1 · Thursday, 3:50 p.m.

An agreement that needed signing

Mark advises about sixty households. Summit Custody holds his clients' assets, and paperwork from them is routine. This arrives shortly before the end of the day.

Tap the parts of this email that should raise a question. 0 of 4 found.

Scene 2 · 3:51 p.m.

What the document actually did

While the agreement displayed, the file also exploited a flaw in the document viewer software itself — a flaw the company that makes it does not know exists.

That is a . The vendor has had zero days to fix it. There is no update to install, because nobody has written one. And no antivirus has a description of it, because nobody has seen it before.

Does the practice's antivirus catch this?
Pick what you think happens. There is no penalty for guessing.
Scene 3 · 3:52 p.m.

The call home

A minute later the program that the document started opens a connection out to a server the attacker controls, and waits for instructions.

It uses on the standard web port — the same protocol as every website the practice visits all day.

Does the firewall block that connection?
The practice has a business-grade firewall, properly installed.
Scene 4 · That evening

"But our custodian handles security"

Mark left at 6. His email and the Summit Custody portal are still open and still signed in, the way they are most evenings.

The attacker's program reads his inbox and finds a thread with Mrs. Chen: she is wiring $250,000 next Wednesday for a house closing.

Two things then happen. A hidden is created so that Mrs. Chen's replies bypass Mark's inbox entirely. Then, from Mark's real email account, she is sent updated wire instructions.

Summit Custody has serious security. Is Mrs. Chen's money safe?
This is the most common assumption, and the most expensive one.
Scene 5 · The same night, twice

What each setup sees

Identical attack. Identical practice. The only difference is whether anything is watching behavior.

Antivirus + firewall only
With behavior monitoring

Tap any alert on the right to see why that moment was abnormal.

Scene 6

Three things to take away

1
Zero-day attacks have no signature.Tools that work by recognizing known threats cannot see something never seen before. That is a structural limit, not a product defect.
2
Firewalls check where traffic goes, not what is happening on your computer.The malicious connection looked exactly like ordinary browsing, because the attacker made it look that way.
3
Your custodian's security ends where your laptop begins.Summit Custody was never breached. Everything happened on Mark's machine, through Mark's real accounts.

Antivirus and firewalls are still necessary. They are just no longer sufficient. They stop a large volume of routine, known attacks every day, and removing them would be a serious mistake. The gap is specifically attacks built to be new.

The practical question is not which product to buy. It is whether anything in your practice would notice a computer or an account behaving unlike itself — and whether anyone would see it the same night, rather than after a client's closing fails.

Scene 7

Practice risk score

Three quick questions, then a six-question review of your practice.

Question 1
Why did the antivirus not alert on the document?
Question 2
Why did Mrs. Chen have no reason to doubt the wire instructions?
Question 3
What made the attack detectable on the monitored side?

Six questions about your practice

Nothing is recorded or sent anywhere — this runs entirely in your browser.

Practice risk gauge
Lower riskModerateHigher risk
See how EDR protects advisory practices →

Mark's Thursday is an illustrative composite, not a report of a specific incident. Summit Custody and Brightpath Advisors are fictional. Amounts and times are used to show how an attack unfolds and are not statistics. Nothing here is legal, compliance, or investment advice; consult your compliance counsel about your obligations.