NVR, Inc. is a Fortune 500 homebuilder operating across 16 states and Washington, D.C., with over 540,000 homes built and more than 600,000 homeowners served. The company runs a vertically integrated model spanning homebuilding (Ryan Homes, NVHomes, Heartland Homes), mortgage banking, settlement services, and structural component manufacturing across 10 states. That's a sprawling attack surface: customer PII flowing through mortgage and settlement pipelines, manufacturing OT in building products facilities, and the usual corporate sprawl across 37 metro areas.
The threat model here isn't theoretical. NVR Mortgage processes financial data exclusively for NVR homebuyers - so every transaction tightly couples personal identity data with lending records. NVR Settlement Services handles title and closing workflows, another dense node of sensitive information. Meanwhile, building products manufacturing introduces operational technology concerns that traditional enterprise security teams don't always prioritize. A breach in any one of these segments compounds quickly across the others.
Security work at this scale means defending a mid-large enterprise where the business spans consumer-facing web properties, regulated financial services, and industrial operations simultaneously. The company's significant referral-driven sales model suggests customer trust is core to the business - making data protection a direct revenue concern, not just a compliance checkbox. Teams operating here are likely dealing with PCI-DSS, GLBA, and state-level privacy regulations layered across distinct business units with different risk profiles.






