How Walden Mortgage Group protects thousands of customers' records with two people. And the security is the easy part.
A two-person IT department. 300 to 350 endpoints. Mortgage PII and HR records under the FTC Safeguards Rule. One console holding all of it, and a support load Brandon Buffin counts on one hand.
Most companies carrying this much regulated data don't run it with two people. Walden does.
Every mortgage Walden writes holds someone's Social Security number and financial life. Add the HR records across the Ball Homes companies, and two people are accountable for all of it, under the FTC Safeguards Rule and a cyber-insurance carrier that now asks, in writing, whether the data is encrypted.
If it adds tickets to my daily life, it's not gonna go well, either for the users or for me. Even if it's the best security out there.
That's the bar a lean team sets. A control people fight isn't a control. Whatever came next had to be easy, or it wasn't a real solution at all.
The default is protected. Nobody has to decide to be safe.
Sensitive files get encrypted automatically, the moment they land, without anyone choosing to. PK Protect Endpoint Manager does exactly that. The people generating the data mostly don't know protection is running at all. That's the point.
Easy to run
Brandon runs all of it from one central console. That's where he sets policy, and it's where he proves compliance, which is the part auditors actually care about. Coming off a prior tool being sunset, PKWARE stood PK Protect up fast, with no gap in protection during the switch.
Built around the workflow
When the mortgage team hit a real workflow snag, a PKWARE engineer built a custom, self-purging decrypt workflow with Brandon so no plaintext ever lingers. The full build, and the architecture behind it, is in the case study.
Invisible, provable, and cheaper to insure.
Compliance that happens on its own
Because protection is automatic, everyone touching that regulated data is compliant without lifting a finger. Adoption isn't a project. It's the default.
Enterprise-grade without the headcount
A lean team can't carry a tool that needs babysitting. Walden gets the protection standard without the people standard to run it.
Cyber insurance that costs less
Insurers now ask, in writing, whether you encrypt data at rest. Walden can answer yes on the mortgage side, and the rates are coming down.
If you carry enterprise data risk with an SMB-sized team, Walden's deployment answers what you're actually asking.
Walden does, with two people and a support load Brandon counts on one hand. If it created real work, it would have shown up fast in a shop that lean. It didn't.
They don't fight it because there's nothing to fight. Encryption is automatic, most employees don't know it's running, and the decrypt step their old tool forced on people is gone.
Brandon proves compliance from one console, across mortgage and HR data, and can now truthfully tell insurers he encrypts data at rest, which is helping bring rates down.
Enterprise-grade data protection for small teams.
Yes. Walden Mortgage Group runs PK Protect across 300 to 350 endpoints with a two-person IT department and a minimal support load. The platform fits a lean team because it's simple by design, not stripped down. Encryption is automatic and administered from one console, so protection doesn't scale with headcount.
PEM is PKWARE's encryption control plane. It manages policy, identity-bound keys, and audit from one console. Sensitive files are encrypted automatically the moment they land, and authorized users open them with no separate decryption step. At Walden, that's how a two-person team protects mortgage and HR data without asking employees to make encryption decisions.
The FTC Safeguards Rule requires financial institutions to protect customer information, including encrypting sensitive data. PK Protect encrypts regulated mortgage PII at rest automatically and lets an administrator prove, from one console, exactly what's encrypted and how. For Walden, that turns an audit question into a default answer.
Cyber insurers increasingly ask, in writing, whether an organization encrypts sensitive data at rest. Being able to answer yes removes a common reason to deny coverage or raise rates. In Walden's deployment, encrypting mortgage data at rest is helping bring cyber-insurance rates down.
Transparent encryption means files are encrypted and decrypted automatically based on policy, so authorized users just work. There's no password-per-file, no two-factor decrypt step, no keys for employees to manage. When the safe path is also the easy path, adoption becomes the default instead of something IT has to enforce.
Yes. Walden protects two regulated data streams, mortgage customer PII and HR records across the Ball Homes companies, from a single PK Protect console. One control plane, one set of policy and audit practices, provable across both streams.
Get the full case study.
Thirteen pages on how a two-person team protects regulated mortgage and HR data without an enterprise budget, including the custom self-purging decrypt workflow and the architecture this page didn't give away.
21 of the 25 largest U.S. commercial banks. 30% of the Fortune 100.