TrollEye Security

GBC Overall Case Study

Explore the Engagement
Customer Success · Red Teaming

How General Bank of Canada Validated Years of Security Investment Against Real-World Attacks

General Bank of Canada and its sister companies had spent years strengthening their cybersecurity posture. TrollEye conducted a multi-faceted Red Team assessment to determine whether technical, human, physical, and response controls could withstand a sophisticated threat actor.

Banking & Financial Services 51–200 Employees Alberta, Canada
Coordinated Adversarial Validation Multi-Vector Technical, human, physical, and response controls tested together.

The assessment used attack paths ranging from dark-web intelligence and phishing to external testing and physical breach attempts.

Primary Outcome Existing security investments were validated and practical improvement priorities were established.
The Problem

Years of improvement still left one unanswered question.

Cyberattacks and breaches were creating growing financial and operational disruption across the financial sector. At the same time, cybersecurity regulations and expectations were becoming increasingly stringent.

General Bank of Canada and its sister organizations had already spent several years improving security. Technical controls had matured, awareness programs had expanded, and cybersecurity risk had become a prominent part of the organizations’ risk registers. As GBC explained, “We had undertaken significant efforts over several years to strengthen our security posture, and it was time to test the effectiveness of these measures.”

Leadership no longer needed confirmation that controls existed. It needed independent evidence that those controls would work together against a sophisticated attacker.

The Validation Gap Could the organization prevent, detect, and respond to an attacker combining human, technical, physical, and intelligence-based attack methods?
Risk 01

Individual controls did not reflect real-world attacks

Vulnerability scans and isolated assessments could identify individual weaknesses, but they could not evaluate how the entire security ecosystem would perform during a coordinated attack.

Risk 02

Sophisticated attacks cross multiple boundaries

A realistic threat actor could combine exposed intelligence, phishing, external access, physical intrusion, compromised credentials, and internal movement.

Risk 03

Detection and response also needed validation

Preventive controls were only part of the security posture. Leadership also needed to know whether suspicious activity would be detected, contained, escalated, and remediated.

What GBC Needed

Practical testing instead of theoretical confidence.

Leadership formed a joint committee across General Bank of Canada, First Canadian Insurance Corporation, and Millennium Insurance Corporation to determine the next step. GBC recognized that “theoretical security measures require practical testing against sophisticated attack scenarios to validate their effectiveness.” The committee determined that a specialist third party should conduct a comprehensive Red Team exercise and provide an independent, evidence-based view of how the entire security ecosystem performed under realistic attack conditions.

The Solution

TrollEye tested the organization the way a real adversary would.

TrollEye designed a comprehensive Red Team exercise that evaluated the security ecosystem rather than testing individual controls in isolation.

Intelligence gathering informed the attack strategy, and multiple vectors were combined to determine how an attacker could move from publicly available information to human manipulation, external access, physical intrusion, and the internal environment.

The objective was to provide a realistic assessment of how GBC’s controls performed together under coordinated pressure.

The Coordinated Assessment

Six attack vectors created one connected view of the security program.

Each activity supported the wider engagement instead of producing a series of disconnected reports.

01

Reconnaissance

TrollEye researched the organizations, facilities, personnel, vendors, and potential routes an attacker could use.

02

Dark-Web Analysis

Exposed information and intelligence were reviewed for data that could strengthen a realistic attack.

03

Phishing Campaigns

Targeted scenarios and lookalike infrastructure tested employee awareness and resistance to credential-based attacks.

04

External Testing

Internet-facing systems were assessed for routes into the environment and opportunities to chain weaknesses together.

05

Physical Intrusion

The Red Team attempted to bypass facility controls and reach the internal network using realistic social-engineering pretexts.

06

Internal Assessment

Internal access, rogue-device detection, lateral movement, and the response to simulated compromise were evaluated.

The Difference

The assessment tested attack chains, not just individual weaknesses.

Many alternatives focused on isolated controls or relied heavily on automated scanning. TrollEye combined human expertise with technical, physical, and organizational testing to determine how weaknesses could be chained together and whether the organization could detect and respond to the resulting activity.

Success Criteria

GBC established six objectives to define a successful assessment.

The Red Team engagement was designed around specific measures established by GBC. Together, they evaluated whether the organization could prevent, detect, and respond to realistic attack simulations across its people, facilities, and technical environment.

01

Prevent Unauthorized Physical Access

Determine whether physical security controls and employee procedures could prevent unauthorized entry into GBC facilities.

02

Detect External Penetration Attempts

Assess whether technical controls could detect and prevent attempts to compromise internet-facing systems and gain external access.

03

Evaluate Employee Phishing Awareness

Test how employees responded to targeted phishing campaigns and whether they recognized suspicious requests and credential threats.

04

Detect Rogue Devices on the Network

Determine whether GBC could identify an unauthorized device connected directly to its internal network.

05

Assess Exposure to Lateral Movement

Evaluate whether an attacker with initial access could move through the network, expand privileges, and reach additional systems.

06

Validate Incident Response Capabilities

Test whether teams could detect, contain, escalate, and remediate a developing security incident under realistic conditions.

How Success Was Measured

Findings and response performance provided the evidence.

GBC evaluated the engagement through a classification system of critical, high, medium, and low findings together with the ability of its teams and controls to detect and respond to each simulated attack.

Customer Impact

GBC gained a clearer view of how its defenses performed together.

The engagement gave GBC more than a collection of findings. It showed how people, technology, physical controls, and response processes behaved when placed under one coordinated, adversary-led assessment.

Primary Result

A connected assessment replaced isolated assumptions.

By combining reconnaissance, dark-web intelligence, phishing, external testing, physical intrusion attempts, and internal testing, GBC could evaluate whether weaknesses could be chained together and whether existing controls could interrupt a realistic attack.

01

Realistic Control Validation

GBC received evidence of how its controls performed when exposed to coordinated pressure rather than being reviewed individually.

02

Attack-Path Visibility

The organization could see how information, human behavior, technical access, and physical access might contribute to a wider attack chain.

03

Greater Security Confidence

The exercise helped GBC distinguish between controls that appeared effective on paper and those that held up during realistic testing.

Customer Value

The result was evidence leadership could use.

GBC gained a practical understanding of where its security program was resilient, where attack paths could emerge, and where future improvements would have the greatest value. The engagement turned testing into a broader assessment of organizational readiness rather than a conventional vulnerability report.

Test More Than Individual Controls

Find out how your security program performs when everything is connected.

TrollEye combines human-led testing, technical validation, and realistic attack scenarios to reveal how weaknesses, controls, people, and response processes interact across your organization. See what holds up, what breaks down, and what deserves attention next.

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated