How a mid‑sized Canadian investment firm used Axiam’s Bastion Host with liveness‑verified Facial Sign‑In to block an intrusion, produce court‑ready identity evidence, and enable prosecution—without paying ransom.
FTBC Capital — a Canadian investment management firm overseeing $1B AUA. Targets of repeat ransomware attempts by the ShadowCrypt group.
Malicious link clicked; credential harvesting fails—no passwords exist.
SSH/RDP scans hit bastion; biometric gate stops sessions pre‑auth.
Liveness challenge records attacker’s face at insider device.
Audit video + device/geo metadata shared with RCMP cybercrime.
Liveness check captures attacker face; tamper‑evident video hash archived.
Device fingerprint + IP/geo context correlated with existing case files.
Time‑stamped session logs + chain‑of‑custody package for prosecutors.
Figures are representative; update with your verified metrics.
“With Axiam’s Bastion + Facial Sign‑In, there were no credentials to steal and no public IPs to probe. The audit video made the difference—turning an anonymous incident into a prosecutable case.”
Retire passwords and weak MFA. Gate every privileged session with a verified face.