Case Study · Mortgage & Financial Services

How Walden Mortgage Group protects thousands of customers' records with two people. And the security is the easy part.

A two-person IT department. 300 to 350 endpoints. Mortgage PII and HR records under the FTC Safeguards Rule. One console holding all of it, and a support load Brandon Buffin counts on one hand.

PK Protect PK Endpoint Manager Transparent encryption FTC Safeguards HR + Mortgage
The setup

Most companies carrying this much regulated data don't run it with two people. Walden does.

Every mortgage Walden writes holds someone's Social Security number and financial life. Add the HR records across the Ball Homes companies, and two people are accountable for all of it, under the FTC Safeguards Rule and a cyber-insurance carrier that now asks, in writing, whether the data is encrypted.

2-person
The entire IT department. No CISO, no committee to share the risk
300–350
Endpoints protected, covering mortgage and HR data
2 streams
Regulated data in use: mortgage customer PII and HR records across the Ball Homes companies
One hand
The support tickets Brandon can count since deployment

If it adds tickets to my daily life, it's not gonna go well, either for the users or for me. Even if it's the best security out there.

Brandon BuffinIT Director, Ball Homes

That's the bar a lean team sets. A control people fight isn't a control. Whatever came next had to be easy, or it wasn't a real solution at all.

How it works

The default is protected. Nobody has to decide to be safe.

Sensitive files get encrypted automatically, the moment they land, without anyone choosing to. PK Protect Endpoint Manager does exactly that. The people generating the data mostly don't know protection is running at all. That's the point.

Encrypt-on-drop flow A user saves a file. The PK Protect PEM agent intercepts the file I/O, pulls policy and keys from the PEM console, and writes the file encrypted at rest. Authorized users open it again with a transparent decrypt and no two-factor step. THE DEFAULT IS PROTECTED · ENCRYPT-ON-DROP PEM CONSOLE · policy · keys identity · role / centrally logged POLICY KEY USER SAVES A FILE user just works report.xlsx FILE I/O PK PK PROTECT PEM agent intercepts runs on every endpoint WRITE ENCRYPTED AT REST the default is protected report.xlsx.pem AUTHORIZED OPEN · TRANSPARENT DECRYPT · NO 2FA STEP
Scroll to see the full diagram →
The safe state is the default state. Everything else follows from that one design choice.

Easy to run

Brandon runs all of it from one central console. That's where he sets policy, and it's where he proves compliance, which is the part auditors actually care about. Coming off a prior tool being sunset, PKWARE stood PK Protect up fast, with no gap in protection during the switch.

Built around the workflow

When the mortgage team hit a real workflow snag, a PKWARE engineer built a custom, self-purging decrypt workflow with Brandon so no plaintext ever lingers. The full build, and the architecture behind it, is in the case study.

The outcomes

Invisible, provable, and cheaper to insure.

01

Compliance that happens on its own

Because protection is automatic, everyone touching that regulated data is compliant without lifting a finger. Adoption isn't a project. It's the default.

02

Enterprise-grade without the headcount

A lean team can't carry a tool that needs babysitting. Walden gets the protection standard without the people standard to run it.

03

Cyber insurance that costs less

Insurers now ask, in writing, whether you encrypt data at rest. Walden can answer yes on the mortgage side, and the rates are coming down.

For your evaluation

If you carry enterprise data risk with an SMB-sized team, Walden's deployment answers what you're actually asking.

Q.01
We're a small team. Can we actually run this?

Walden does, with two people and a support load Brandon counts on one hand. If it created real work, it would have shown up fast in a shop that lean. It didn't.

Q.02
Will our people use it, or fight it?

They don't fight it because there's nothing to fight. Encryption is automatic, most employees don't know it's running, and the decrypt step their old tool forced on people is gone.

Q.03
Will it hold up with auditors and cyber insurers?

Brandon proves compliance from one console, across mortgage and HR data, and can now truthfully tell insurers he encrypts data at rest, which is helping bring rates down.

Frequently asked

Enterprise-grade data protection for small teams.

Yes. Walden Mortgage Group runs PK Protect across 300 to 350 endpoints with a two-person IT department and a minimal support load. The platform fits a lean team because it's simple by design, not stripped down. Encryption is automatic and administered from one console, so protection doesn't scale with headcount.

PEM is PKWARE's encryption control plane. It manages policy, identity-bound keys, and audit from one console. Sensitive files are encrypted automatically the moment they land, and authorized users open them with no separate decryption step. At Walden, that's how a two-person team protects mortgage and HR data without asking employees to make encryption decisions.

The FTC Safeguards Rule requires financial institutions to protect customer information, including encrypting sensitive data. PK Protect encrypts regulated mortgage PII at rest automatically and lets an administrator prove, from one console, exactly what's encrypted and how. For Walden, that turns an audit question into a default answer.

Cyber insurers increasingly ask, in writing, whether an organization encrypts sensitive data at rest. Being able to answer yes removes a common reason to deny coverage or raise rates. In Walden's deployment, encrypting mortgage data at rest is helping bring cyber-insurance rates down.

Transparent encryption means files are encrypted and decrypted automatically based on policy, so authorized users just work. There's no password-per-file, no two-factor decrypt step, no keys for employees to manage. When the safe path is also the easy path, adoption becomes the default instead of something IT has to enforce.

Yes. Walden protects two regulated data streams, mortgage customer PII and HR records across the Ball Homes companies, from a single PK Protect console. One control plane, one set of policy and audit practices, provable across both streams.

Get the full case study.

Thirteen pages on how a two-person team protects regulated mortgage and HR data without an enterprise budget, including the custom self-purging decrypt workflow and the architecture this page didn't give away.

Featured customer Walden Mortgage Group, the mortgage arm of Ball Homes · Kentucky & Tennessee
Source interview Brandon Buffin, IT Director, Ball Homes · July 2026
Audience IT, security & compliance leaders running lean
Trusted by leading organizations for over 40 years

21 of the 25 largest U.S. commercial banks. 30% of the Fortune 100.