Case Study · Security & Identity

EDR and Safetica DLP for a Fintech Startup

How TexArxs combined EDR with Safetica DLP to protect a fintech startup's Mac and Windows devices and sensitive customer data, without adding complexity.

  • 2 layers EDR for threats, DLP for data
  • 80 / 20 macOS and Windows, one security setup
  • 7 Data channels covered by DLP policies
  • 5 phases Assess, pilot, configure, deploy, optimise

Before and After

What changed Before After
Endpoint Visibility Limited across Mac and Windows One central view of the fleet
Threat Detection Limited detection and response EDR detection and investigation
Data Leaving the Company Hard-to-monitor channels Monitored and controlled by policy
Security Monitoring Few internal resources Alerts reviewed and policies tuned

Challenge

A growing fintech startup in digital lending was handling sensitive customer, financial and business information with a lean IT team. About 20 people worked across a mixed fleet, roughly 80% macOS and 20% Windows, many of them remotely, using Google Workspace and other cloud apps from company-managed devices.

The company needed stronger security without adding unnecessary complexity or slowing devices down. The main gaps were:

  • Limited visibility of endpoint security across Mac and Windows devices.
  • Threat detection and response that needed to be stronger.
  • Data movement risk: sensitive information could leave through email, webmail, cloud apps and USB drives.
  • Few internal resources for continuous security monitoring.
  • Compliance and data protection expectations that come with working in fintech.

Our Approach: Two Layers That Answer Two Questions

We designed a layered approach that combines endpoint detection and response (EDR) with Safetica data loss prevention (DLP). Each layer answers a different question:

EDR: Is something malicious happening on this device?

DLP: Is sensitive information being accessed, moved or shared in a way it should not be?

How We Delivered It

  1. Assess. We reviewed devices and operating systems, existing device management tools, apps, user groups, data flows, current security controls and every channel where data could leave.
  2. Pilot. We ran a controlled pilot on selected Mac and Windows devices, checking agent stability, device performance, app compatibility, EDR detection, DLP policies, false positives, security permissions and the user experience.
  3. Configure. We built policies around how the company actually works. DLP policies started in monitor and alert mode, so we could understand normal business activity before tightening controls.
  4. Deploy. After the pilot, we rolled out the EDR and Safetica agents and policies to the rest of the fleet in stages.
  5. Optimise. We reviewed EDR alerts and DLP events, tuned policies, reduced false positives, added the right exceptions and kept an eye on device health.

Data Loss Prevention with Safetica

Rather than blanket restrictions, each policy considers five things together: the type of data, the user, the device, the destination and the action. That lets the company tighten control over sensitive data while keeping everyday work moving.

The policies cover seven channels:

  • Email and webmail
  • Cloud storage
  • Web apps
  • USB drives and other removable media
  • Desktop apps
  • File transfers
  • User activity involving protected information

They focus on the information that matters in fintech: customer and KYC information, financial data, internal and confidential business documents, employee information, and regulatory and compliance records.

Depending on the situation, a policy can monitor, alert, warn or block, so controls can be strengthened step by step.

Endpoint Detection and Response

EDR gives the IT team one central place to see and act on threats across Mac and Windows devices, including:

  • Detection of malware, ransomware and other suspicious behaviour
  • Device activity data for investigating alerts
  • Security alerts and response actions
  • Central management of security policies

We fitted the deployment into the company’s existing device management processes, to keep the extra admin work small.

Built for Both macOS and Windows

The same security approach had to work on both platforms.

  • On Mac devices, we planned for Apple silicon and Intel processors, macOS security architecture, system extensions, privacy permissions, agent deployment, performance and remote users.
  • On Windows devices, we deployed the security agents, configured security and threat protection policies, set up EDR data collection and Safetica DLP controls, and assigned policies by user and device.

How the Layers Fit Together

  1. Device management keeps every company device enrolled and configured.
  2. EDR detects and responds to threats on each device.
  3. Safetica DLP controls how sensitive data moves through Google Workspace, the web, email and removable media.
  4. Identity and access controls decide who can reach what.
  5. IT and security monitoring reviews alerts and events from all of the above.

Outcome

  • Better visibility of security events and device activity across the Mac and Windows fleet.
  • Stronger threat protection, with detection and investigation that go beyond traditional antivirus.
  • Better data protection, with visibility and control over sensitive information moving through devices, web apps, email, cloud services and removable media.
  • Fewer blind spots: data transfer channels that were hard to watch are now covered by policy.
  • Documented security controls that support the company’s wider security and compliance work.
  • A foundation that scales as new people, devices and apps are added.

Our Role

TexArxs supported the company through the whole implementation: endpoint security assessment, EDR evaluation and rollout, Safetica DLP policy design and rollout on macOS and Windows, the pilot, policy tuning, and ongoing endpoint security support.

The result is a practical security setup that pairs EDR threat protection with Safetica data protection, designed for a growing fintech startup while keeping the impact on device performance and day-to-day work low.

Facing something similar? Let’s talk.

Talk to TexArxs

Our work

All Case Studies