Wire Fraud Won’t Wait.
Neither Should Your Security.
Community lenders, CDFIs, and financial nonprofits in the Baltimore metro are prime BEC targets — attackers know your wires are real and your staff is small. We specialize in protecting organizations exactly like yours.
GLBA Safeguards compliance · Bank Secrecy Act controls · CDFI Fund requirements · Maryland PIPA
Does This Sound Familiar?
These aren’t hypothetical threats. They’re what we see hitting Maryland financial organizations right now.
📧 Business Email CompromiseAn attacker spoofs your CFO’s email and instructs your accounts payable team to wire $80,000 to a “new vendor account.” By the time anyone notices, the money is gone. BEC is the #1 financial fraud vector — and financial organizations are the most targeted industry. Average BEC loss: $125,000+ per incident | 🔓 Hacked Staff AccountsA loan officer clicks a phishing link. Their credentials are harvested. Now an attacker has access to your loan origination system, borrower PII, and email for weeks before anyone notices. No MFA. No alerting. No way to know how much data walked out. Mean time to detect account breach: 207 days |
🛡️ Weak or Misconfigured FirewallYour firewall was set up years ago and hasn’t been touched since. Default credentials. No IDS/IPS. Rules that were added “temporarily” and never removed. Attackers scan for exactly this — exposed management ports, outdated firmware, open RDP — and they find it fast. GLBA requires documented network security controls | ⚠️ GLBA Compliance GapsThe FTC’s updated GLBA Safeguards Rule requires a written information security program, qualified individual oversight, annual penetration testing, and multi-factor authentication — by name. Many community lenders aren’t there yet. An exam finding or breach exposes you to FTC enforcement, litigation, and CDFI Fund scrutiny. Updated GLBA Safeguards Rule: effective since June 2023 |
Why Lewis IT We’ve Worked BEC Incidents. We Know What Breaks.Most IT firms hand you a firewall and call it done. We’ve been brought in after the wire fraud happened — after the accounts were compromised, after the phishing email got clicked. We know how these attacks unfold because we’ve cleaned them up. That experience shapes everything we build for financial clients. We don’t just check compliance boxes — we close the specific gaps that attackers exploit in organizations with thin IT staff and real wire transfer exposure. “The question isn’t whether your organization will be targeted. CDFIs and community lenders are targeted constantly. The question is whether the attacker gets paid.” — Don Lewis, CEO, Lewis IT LLC |
|
We Know the Frameworks That Govern Your Work
Community lenders and CDFIs face a distinct set of compliance obligations. We’ve mapped them and built our security program around them.
🏛️ GLBA Safeguards RuleThe FTC’s updated rule requires a written information security program with 9 specific safeguards — including MFA, encryption, annual pen testing, and a designated Qualified Individual. Applies to any financial institution. LEWIS IT DELIVERS: Written WISP · MFA rollout · Annual pen test · QI designation support | 💰 Bank Secrecy Act ControlsBSA/AML compliance depends on the integrity of your transaction systems and the identities using them. Compromised credentials or tampered audit logs can create regulatory exposure during FinCEN examinations. LEWIS IT DELIVERS: Audit log integrity · Access controls · Privileged account monitoring | 🌱 CDFI Fund RequirementsCDFI Fund certification and award compliance increasingly includes data security expectations for organizations handling federal award dollars. A breach affecting borrower data can jeopardize program status and future awards. LEWIS IT DELIVERS: Data protection program · Incident response plan · Borrower PII controls | ⚖️ Maryland PIPAMaryland’s Personal Information Protection Act requires notification of affected individuals within 45 days of a breach involving SSNs, financial account numbers, or other covered PII. Your incident response plan must be ready before the breach happens. LEWIS IT DELIVERS: 45-day notification readiness · Breach documentation · AG notification support |
Security & IT Services Built for Financial Organizations
From the front-line protection your staff needs to the compliance documentation your regulators require.
Email Security & Anti-BEC ControlsDMARC, DKIM, and SPF enforcement stops domain spoofing cold. AI-powered email filtering catches the impersonation attacks that get past standard spam filters. Executive impersonation alerts and wire transfer verification workflows reduce human error. | Multi-Factor Authentication (MFA) DeploymentMFA is now required under GLBA. We deploy it across email, VPN, loan systems, and remote access — with phishing-resistant options (FIDO2) for high-value accounts. Staff onboarding included. |
Firewall & Network SecurityFirewall audit and hardening, network segmentation between staff and sensitive systems, IDS/IPS activation, and ongoing rule management. We eliminate the “set it and forget it” firewall that most community lenders are running. | Endpoint Detection & Response (EDR)Next-gen EDR on every workstation and server — with 24/7 SOC monitoring. We catch the credential-harvesting malware, the reconnaissance tools, and the lateral movement that traditional antivirus misses entirely. |
GLBA Written Information Security ProgramWe draft and maintain your WISP, risk assessment, vendor management inventory, and incident response plan — the full documentation package required under the updated GLBA Safeguards Rule. Living documents, not a one-time filing. | Security Awareness TrainingPhishing simulation campaigns and monthly training modules focused on financial-sector attack scenarios — wire fraud verification, executive impersonation, fraudulent invoice schemes. Annual GLBA training requirement covered. |
Breach Response & Incident RemediationIf you’re in an active incident — or think you might be — call us. Forensic triage, attacker eviction, wire recall coordination, regulatory notification prep under Maryland PIPA, and post-incident hardening. We’ve been here before. | Managed IT Support & HelpdeskDay-to-day IT support for your staff — hardware, software, email, network. Flat-rate pricing, fast response. So your small team isn’t also your IT department. |
Maryland Financial Organizations We Work With
If you move money, hold borrower PII, or receive federal funding — you’re a target. We work with organizations across the financial services spectrum in the Baltimore metro.
🌱 CDFIs Community Development Financial Institutions — loan funds, venture capital funds, credit unions | 🏘️ Community Lenders Small business loan programs, SBA-certified lenders, housing finance organizations | 🏢 Financial Nonprofits Economic development organizations, housing counseling agencies, asset-building nonprofits | 💳 Fintech & Payment Firms Payment processors, fintech startups, and firms handling sensitive financial transactions |
Financial Services Is the Most Targeted Sector
$125K+ Average BEC incident loss for small financial organizations — FBI IC3 2023 Report | $2.9B Total BEC losses reported to FBI in 2023 — up 9% year over year | 207 Days average attacker dwell time before a financial breach is detected — IBM X-Force | June 2023 Updated GLBA Safeguards Rule effective date — MFA, pen testing, and WISP now required by law |
What Financial Clients Ask Us First
We already had a BEC incident. Can you help after the fact?
Yes — and this is one of the situations we’re specifically built for. We handle forensic triage to determine the scope of compromise, coordinate with your bank on wire recall attempts, document the incident for Maryland PIPA notification requirements, and harden the environment so it doesn’t happen again.
Are CDFIs actually required to follow GLBA?
Yes. The FTC’s GLBA Safeguards Rule applies to any “financial institution” that is “significantly engaged” in financial activities — which includes CDFI loan funds, community development lenders, and similar organizations. Many CDFIs are surprised by this. If you’re holding non-public personal information about borrowers, you’re covered. The updated rule (effective June 2023) added specific technical requirements: MFA, encryption, annual pen testing, and a written security program with a named Qualified Individual.
We’re a small organization with only a few staff. Is this for us?
Especially. Lean teams with wire transfer authority are the most targeted — attackers know there are fewer approval layers. Our services are designed to give small financial organizations enterprise-grade controls without an enterprise IT budget or headcount. You get the protection, we handle the complexity.
What does a typical engagement look like?
We start with a free security assessment — a 90-minute call and lightweight technical review that maps your current exposure against GLBA requirements and your specific risk profile. We deliver a written findings report with prioritized recommendations. From there, you can engage us for any combination of project-based work (GLBA documentation, firewall hardening, MFA rollout) or ongoing managed services. No long-term commitment required upfront.
Do you work with organizations outside the Baltimore area?
Our primary service area is the Baltimore metro and broader Maryland, including Washington DC suburbs. We can support fully remote organizations anywhere in the US for consulting, compliance documentation, and managed security services. On-site work is limited to the greater Baltimore–DC corridor.
Find Out Where You’re Exposed Before an Attacker Does
We’ll review your email security, network posture, GLBA compliance gaps, and BEC exposure — then give you a written report with prioritized next steps. No sales pressure. No obligation.
90-minute session · Written findings report · Free for Maryland financial organizations
| Schedule Your Free Assessment → | Call 240-784-1221 |
Already dealing with an active incident? Call directly — we pick up.
