RESPONSE | EVENT PLANNING

RevUp overhauls cybersecurity after blocking email-spoofing attacker

Responding to an emerging threat

Cybersecurity is no longer optional. Small businesses are targeted in 43% of all attacks, yet only 1% have the expertise to respond effectively. The Pink Duck Company changes this, bringing enterprise-grade security to any business—no matter their size or budget.

“Knowing I can pick up the phone and speak to the same expert every time—someone with deep experience—gives me peace of mind.”

If you’ve attended an event in or around New York City in the past two decades, there’s a good chance RevUpConsults played a role.

Operating seamlessly behind the scenes, RevUp has partnered with iconic venues like the Manhattan Center and the Belvedere Estate to keep their schedules packed and events flawless. With a team of seasoned experts in business, marketing, and tourism, RevUp has built a reputation for excellence and reliability.

But even the most accomplished teams encounter areas for improvement, and RevUp saw an opportunity to strengthen its foundation in Information Technology.

Like many growing businesses, RevUp’s IT infrastructure had evolved organically over time. While it served them well for years, some elements, like their DNS records, had not received close scrutiny.

DNS (Domain Name System) acts as the internet's phonebook, translating easy-to-remember domain names (like www.revupconsults.com) into the numerical IP addresses computers use to connect with each other. These records are vital for operations but also publicly accessible, which means they can be inspected by attackers searching for vulnerabilities.

In RevUp’s case, their DNS records were missing a critical layer of protection: DMARC.

DMARC (Domain-based Message Authentication, Reporting, and Conformance) ensures that only authorized parties can send emails from a company’s domain. Without DMARC, an attacker can send fraudulent emails that appear to come from a trusted source—a vulnerability that was briefly exploited by a cybercriminal.

The attacker impersonated Mike Fiorentino, RevUp’s president and founder, sending fake invoices to a small number of clients. Thankfully, a vigilant customer noticed inconsistencies in the banking details and alerted the team immediately.

Taking swift action, Mike reached out to RevUp’s web hosting provider. While their initial referral to an overseas IT company led to basic measures like antivirus installation, the underlying issue remained unaddressed, and the attacks continued.

So Mike turned to The Pink Duck Company. The Cyber Incident Response Team (CIRT) quickly identified the missing DMARC record as the root cause. By adding it, they stopped the attacker in their tracks.

But they didn’t stop there. The Pink Duck team conducted a comprehensive assessment of RevUp’s systems and uncovered opportunities for improvement:

  • While RevUp had been paying for email security through their web host, the vulnerability had still gone unnoticed.
  • The company was incurring costs for unused hosting services.
  • The corporate website contained several vulnerabilities that, while not yet exploited, required immediate attention.

With Mike’s guidance, The Pink Duck Company upgraded RevUp’s IT infrastructure to a new level of resilience:

  • They rebuilt RevUp’s website on a more secure and reliable hosting platform.
  • The email system was seamlessly migrated to Google Workspace, providing enhanced security and productivity features.
  • Mike’s devices—phone, tablet, and laptop—were meticulously cleaned and reset to ensure no lingering threats remained.
  • Unused services were canceled, resulting in substantial cost savings.

The results were transformative. RevUp emerged with a simpler, robust IT infrastructure—all on a smaller budget.

Thanks to RevUp’s proactive leadership, the entire transformation was completed in just two weeks. Today, the company continues to thrive, supported by a modernized, secure foundation that matches their reputation for excellence.

The Pink Duck Company now remains a trusted partner in the background, ready to assist the next time an attacker strikes.