Financial Services IT & Cybersecurity — Maryland

Wire Fraud Won’t Wait.
Neither Should Your Security.

Community lenders, CDFIs, and financial nonprofits in the Baltimore metro are prime BEC targets — attackers know your wires are real and your staff is small. We specialize in protecting organizations exactly like yours.

GLBA Safeguards compliance · Bank Secrecy Act controls · CDFI Fund requirements · Maryland PIPA

Get a Free Security Assessment →

The Threats Are Real

Does This Sound Familiar?

These aren’t hypothetical threats. They’re what we see hitting Maryland financial organizations right now.

📧

Business Email Compromise

An attacker spoofs your CFO’s email and instructs your accounts payable team to wire $80,000 to a “new vendor account.” By the time anyone notices, the money is gone. BEC is the #1 financial fraud vector — and financial organizations are the most targeted industry.

Average BEC loss: $125,000+ per incident

🔓

Hacked Staff Accounts

A loan officer clicks a phishing link. Their credentials are harvested. Now an attacker has access to your loan origination system, borrower PII, and email for weeks before anyone notices. No MFA. No alerting. No way to know how much data walked out.

Mean time to detect account breach: 207 days

🛡️

Weak or Misconfigured Firewall

Your firewall was set up years ago and hasn’t been touched since. Default credentials. No IDS/IPS. Rules that were added “temporarily” and never removed. Attackers scan for exactly this — exposed management ports, outdated firmware, open RDP — and they find it fast.

GLBA requires documented network security controls

⚠️

GLBA Compliance Gaps

The FTC’s updated GLBA Safeguards Rule requires a written information security program, qualified individual oversight, annual penetration testing, and multi-factor authentication — by name. Many community lenders aren’t there yet. An exam finding or breach exposes you to FTC enforcement, litigation, and CDFI Fund scrutiny.

Updated GLBA Safeguards Rule: effective since June 2023

Why Lewis IT

We’ve Worked BEC Incidents. We Know What Breaks.

Most IT firms hand you a firewall and call it done. We’ve been brought in after the wire fraud happened — after the accounts were compromised, after the phishing email got clicked. We know how these attacks unfold because we’ve cleaned them up.

That experience shapes everything we build for financial clients. We don’t just check compliance boxes — we close the specific gaps that attackers exploit in organizations with thin IT staff and real wire transfer exposure.

“The question isn’t whether your organization will be targeted. CDFIs and community lenders are targeted constantly. The question is whether the attacker gets paid.”

— Don Lewis, CEO, Lewis IT LLC

Talk to Lewis IT About Your Exposure →

🔍

BEC Attack Surface Assessment

We map every BEC entry point: email authentication gaps, payment process weaknesses, staff awareness holes, and credential exposure on the dark web.

📋

GLBA Safeguards Gap Analysis

Full assessment against the updated FTC GLBA Safeguards Rule — written WISP, qualified individual designation, access controls, encryption, MFA, and annual pen test requirements.

🏦

Financial-Grade Incident Response

If you’ve already had an incident — or suspect one — we do forensic triage, wire recall coordination, breach documentation, and regulatory notification support under Maryland PIPA.

🛡️

Ongoing Managed Security (MDR)

24/7 endpoint detection, email security with anti-spoofing enforcement (DMARC/DKIM/SPF), firewall management, and privileged access controls. Built for lean IT teams.

Regulatory Coverage

We Know the Frameworks That Govern Your Work

Community lenders and CDFIs face a distinct set of compliance obligations. We’ve mapped them and built our security program around them.

🏛️

GLBA Safeguards Rule

The FTC’s updated rule requires a written information security program with 9 specific safeguards — including MFA, encryption, annual pen testing, and a designated Qualified Individual. Applies to any financial institution.

LEWIS IT DELIVERS: Written WISP · MFA rollout · Annual pen test · QI designation support
💰

Bank Secrecy Act Controls

BSA/AML compliance depends on the integrity of your transaction systems and the identities using them. Compromised credentials or tampered audit logs can create regulatory exposure during FinCEN examinations.

LEWIS IT DELIVERS: Audit log integrity · Access controls · Privileged account monitoring
🌱

CDFI Fund Requirements

CDFI Fund certification and award compliance increasingly includes data security expectations for organizations handling federal award dollars. A breach affecting borrower data can jeopardize program status and future awards.

LEWIS IT DELIVERS: Data protection program · Incident response plan · Borrower PII controls
⚖️

Maryland PIPA

Maryland’s Personal Information Protection Act requires notification of affected individuals within 45 days of a breach involving SSNs, financial account numbers, or other covered PII. Your incident response plan must be ready before the breach happens.

LEWIS IT DELIVERS: 45-day notification readiness · Breach documentation · AG notification support

What We Do

Security & IT Services Built for Financial Organizations

From the front-line protection your staff needs to the compliance documentation your regulators require.

Email Security & Anti-BEC Controls

DMARC, DKIM, and SPF enforcement stops domain spoofing cold. AI-powered email filtering catches the impersonation attacks that get past standard spam filters. Executive impersonation alerts and wire transfer verification workflows reduce human error.

Multi-Factor Authentication (MFA) Deployment

MFA is now required under GLBA. We deploy it across email, VPN, loan systems, and remote access — with phishing-resistant options (FIDO2) for high-value accounts. Staff onboarding included.

Firewall & Network Security

Firewall audit and hardening, network segmentation between staff and sensitive systems, IDS/IPS activation, and ongoing rule management. We eliminate the “set it and forget it” firewall that most community lenders are running.

Endpoint Detection & Response (EDR)

Next-gen EDR on every workstation and server — with 24/7 SOC monitoring. We catch the credential-harvesting malware, the reconnaissance tools, and the lateral movement that traditional antivirus misses entirely.

GLBA Written Information Security Program

We draft and maintain your WISP, risk assessment, vendor management inventory, and incident response plan — the full documentation package required under the updated GLBA Safeguards Rule. Living documents, not a one-time filing.

Security Awareness Training

Phishing simulation campaigns and monthly training modules focused on financial-sector attack scenarios — wire fraud verification, executive impersonation, fraudulent invoice schemes. Annual GLBA training requirement covered.

Breach Response & Incident Remediation

If you’re in an active incident — or think you might be — call us. Forensic triage, attacker eviction, wire recall coordination, regulatory notification prep under Maryland PIPA, and post-incident hardening. We’ve been here before.

Managed IT Support & Helpdesk

Day-to-day IT support for your staff — hardware, software, email, network. Flat-rate pricing, fast response. So your small team isn’t also your IT department.

Who We Serve

Maryland Financial Organizations We Work With

If you move money, hold borrower PII, or receive federal funding — you’re a target. We work with organizations across the financial services spectrum in the Baltimore metro.

🌱
CDFIs
Community Development Financial Institutions — loan funds, venture capital funds, credit unions
🏘️
Community Lenders
Small business loan programs, SBA-certified lenders, housing finance organizations
🏢
Financial Nonprofits
Economic development organizations, housing counseling agencies, asset-building nonprofits
💳
Fintech & Payment Firms
Payment processors, fintech startups, and firms handling sensitive financial transactions

The Threat Reality

Financial Services Is the Most Targeted Sector

$125K+
Average BEC incident loss for small financial organizations — FBI IC3 2023 Report
$2.9B
Total BEC losses reported to FBI in 2023 — up 9% year over year
207
Days average attacker dwell time before a financial breach is detected — IBM X-Force
June 2023
Updated GLBA Safeguards Rule effective date — MFA, pen testing, and WISP now required by law

Common Questions

What Financial Clients Ask Us First

We already had a BEC incident. Can you help after the fact?

Yes — and this is one of the situations we’re specifically built for. We handle forensic triage to determine the scope of compromise, coordinate with your bank on wire recall attempts, document the incident for Maryland PIPA notification requirements, and harden the environment so it doesn’t happen again.

Are CDFIs actually required to follow GLBA?

Yes. The FTC’s GLBA Safeguards Rule applies to any “financial institution” that is “significantly engaged” in financial activities — which includes CDFI loan funds, community development lenders, and similar organizations. Many CDFIs are surprised by this. If you’re holding non-public personal information about borrowers, you’re covered. The updated rule (effective June 2023) added specific technical requirements: MFA, encryption, annual pen testing, and a written security program with a named Qualified Individual.

We’re a small organization with only a few staff. Is this for us?

Especially. Lean teams with wire transfer authority are the most targeted — attackers know there are fewer approval layers. Our services are designed to give small financial organizations enterprise-grade controls without an enterprise IT budget or headcount. You get the protection, we handle the complexity.

What does a typical engagement look like?

We start with a free security assessment — a 90-minute call and lightweight technical review that maps your current exposure against GLBA requirements and your specific risk profile. We deliver a written findings report with prioritized recommendations. From there, you can engage us for any combination of project-based work (GLBA documentation, firewall hardening, MFA rollout) or ongoing managed services. No long-term commitment required upfront.

Do you work with organizations outside the Baltimore area?

Our primary service area is the Baltimore metro and broader Maryland, including Washington DC suburbs. We can support fully remote organizations anywhere in the US for consulting, compliance documentation, and managed security services. On-site work is limited to the greater Baltimore–DC corridor.

Free Security Assessment

Find Out Where You’re Exposed Before an Attacker Does

We’ll review your email security, network posture, GLBA compliance gaps, and BEC exposure — then give you a written report with prioritized next steps. No sales pressure. No obligation.

90-minute session · Written findings report · Free for Maryland financial organizations

Schedule Your Free Assessment →Call 240-784-1221

Already dealing with an active incident? Call directly — we pick up.