Customer success

6,800 security teams that stopped chasing alerts and started closing incidents

Banks, hospitals, grid operators, factories and software companies run Guardian Sentinel as the control plane for endpoint, network, cloud, identity and data. These are the numbers they report back to us — audited annually, reproduced from their own consoles, not from a survey.

Guardian customer base at a glance

6,800+ Organisations protected worldwide Including 43 of the Fortune 100
142 Countries with active Sentinel deployments 24 Guardian offices, follow-the-sun SOC
31.6M Endpoints, workloads and identities under management Peak sustained: 4.2T events per week
98% Gross revenue retention, trailing four quarters Net revenue retention 127%
4.8/5 Average customer satisfaction across 11,400 support cases Measured at case closure, not at survey time

Customer stories

Six programmes, six very different threat models

Every deployment below started with a specific, painful constraint — an audit deadline, a ransomware event, a merger, an OT network that had never been instrumented. Each story links to the full technical write-up.

Financial services 48,000 endpoints

Northwind Financial Group retired nine point products in one quarter

A tier-one European bank running separate agents for AV, EDR, DLP, device control, USB policy and vulnerability assessment. Agent conflicts were causing trading-desk latency spikes and the SOC was triaging 4,100 alerts a day across six consoles. Guardian Sentinel replaced all nine agents with one kernel-safe sensor and a single detection graph. Migration ran in five waves over 11 weeks with zero trading-hours disruption.

6 minMedian dwell time (was 9.4 days)
62%Lower SOC cost per endpoint
Healthcare 31 hospitals

Meridian Health Network contained a ransomware detonation in 94 seconds

A phishing payload reached a scheduling workstation at 02:14 on a Sunday. Sentinel's behavioural engine flagged the shadow-copy deletion sequence before the first file was encrypted, isolated the host, killed the process tree and rolled the machine back to its pre-execution state. No patient record was lost and no ward moved to paper. Meridian now runs Sentinel across 96,000 connected clinical devices, including infusion pumps and imaging systems that cannot host an agent.

94 secDetonation to full containment
0Patient records lost or exfiltrated
Manufacturing 22 plants

Halden Aerospace instrumented 22 OT plants without touching a PLC

Halden's production network had no security telemetry at all: the controls team refused any agent on the plant floor, and rightly so. Guardian deployed passive network sensors on SPAN ports at each site, fingerprinted 41,000 OT assets in nine days and built a behavioural baseline per production cell. The IT/OT boundary is now enforced by policy rather than by a spreadsheet, and every change to a controller programme is logged against a named engineer.

19 monthsZero unplanned security downtime
9 daysFull OT asset inventory
Retail & e-commerce 2,400 stores

Brightline Retail Group cut PCI DSS 4.0 evidence gathering from 11 weeks to 9 days

Brightline operates 2,400 stores across nine countries with a payment estate that spans in-store terminals, self-checkout lanes and an e-commerce platform. Sentinel's file-integrity monitoring, script-injection detection and continuous control evidence feed the QSA directly, so the annual assessment became a reporting exercise instead of a fire drill. Web-skimming attempts against the checkout path are now blocked at the browser boundary and reported per store.

9 daysPCI evidence cycle (was 11 weeks)
1,180Skimming attempts blocked in year one
Technology & SaaS 41,000 workloads

Vector Compute pushed cloud security left without slowing 900 deploys a day

Vector ships to production roughly 900 times a day across three hyperscalers and 214 Kubernetes clusters. Guardian's admission controller and IaC scanner run inside their existing pipeline, failing builds only on exploitable, reachable findings rather than on raw CVE counts. Runtime drift detection closes the loop: any container that deviates from its signed manifest is quarantined and the owning team is notified in their own Slack channel within seconds.

87%Fewer critical cloud misconfigurations
+0.4%Added CI pipeline duration
Energy & utilities 2.4M OT events/day

Caledonia Energy reached NIS2 readiness eight months ahead of the deadline

A regional transmission operator with 340 substations and a legacy SCADA estate that predates most of its security team. Guardian mapped every protocol conversation on the control network, established which flows were legitimate and turned the rest into high-fidelity detections. The reporting obligations under NIS2 — 24-hour early warning, 72-hour incident notification — are now produced automatically from the incident record rather than reconstructed by hand.

8 minMedian containment on OT alerts
340Substations with continuous monitoring

Trusted across every regulated industry

The organisations that cannot afford to be wrong

A representative slice of the Guardian customer base. Named with permission; hundreds more run Sentinel under mutual non-disclosure.

Northwind
Meridian
Halden
Brightline
Vector
Caledonia
Ardent
Kestrel
Solent
Pentridge
Orsova
Lattice

Aggregate outcomes

What changes in the first twelve months

Medians drawn from 412 enterprise deployments that completed a full year on Sentinel between July 2025 and June 2026. Baselines were captured during onboarding from the customer's own tooling, not estimated afterwards.

outcomes / 412 deployments / 12-month median
100% 75% 50% 25% 0 Time to detect −96% Time to respond −93% False positives −91% Analyst hours −77% Tools deployed −66% Baseline at onboarding After 12 months on Guardian Sentinel
Indexed to 100 at onboarding. Lower is better on every axis.

Why the numbers move

Detection stops being the bottleneck

Correlation happens on ingest, so a credential-theft chain that used to surface in a weekly hunt now raises a single scored incident while the attacker is still enumerating.

Analysts stop re-deriving context

The Sentinel AI Analyst attaches process ancestry, identity blast radius and prior sightings to every incident before a human opens it. Median first-touch time drops from 34 minutes to under four.

Board reporting becomes a query, not a project

Risk posture, control coverage and mean time to respond are computed continuously, so the quarterly pack is exported rather than assembled.

Methodology Baselines are taken from the customer's incumbent SIEM and ticketing system during the first 30 days. Deployments with fewer than 250 incidents in the baseline window are excluded. Full methodology is published in the 2026 Outcomes Report.

The numbers, unrounded

Median results across 412 enterprise deployments

Reported per customer at the twelve-month mark. Where a metric was not instrumented before Sentinel, that customer is excluded from the row rather than assigned a default.

Aggregate customer outcomes, July 2025 – June 2026 (n = 412)
Metric Median before Median after 12 months Change Reported by
Mean time to detect (MTTD) 4.1 days 3.8 minutes −99.9% 408 of 412
Mean time to respond (MTTR) 18.6 hours 77 minutes −93% 401 of 412
False-positive alert volume, weekly 7,340 661 −91% 388 of 412
Analyst hours per confirmed incident 6.4 h 1.5 h −77% 377 of 412
Security tools in production 29 10 −66% 412 of 412
Endpoint agents per managed device 4.2 1.0 −76% 412 of 412
Critical findings older than 30 days 1,910 62 −97% 369 of 412
Audit evidence preparation, per assessment 34 person-days 4 person-days −88% 294 of 412
Total cost of security operations, per endpoint / year $41.80 $16.10 −61% 352 of 412
Successful ransomware encryption events 0.7 per year 0 −100% 412 of 412

Scroll the table sideways to see every column.

Currency values are USD and exclude Guardian subscription fees; see Pricing for licence costs and the Total Economic Impact study for the full model.

In their words

What security leaders tell their peers

We did not buy Guardian to save money, we bought it because our SOC was drowning. The saving came anyway. Nine agents became one, six consoles became one, and for the first time my analysts finish a shift having actually closed things.

Elena Ridderström Group CISO, Northwind Financial Group

At 02:14 on a Sunday the platform made a containment decision that a human would have taken forty minutes to make. Ninety-four seconds later it was over. That single night paid for the contract several times over, and no clinician ever knew it happened.

Dr. Amara Okonkwo VP Information Security, Meridian Health Network

Our controls engineers vetoed every security product we had ever evaluated. Guardian was the first vendor that arrived willing to listen before it arrived willing to install. Passive first, agents only where they were safe — that is why it is running in all twenty-two plants.

Marcus Thaler Director of OT Security, Halden Aerospace

Time to value

The first ninety days, as our customers actually experience them

Every Guardian customer is assigned a named onboarding architect on day one. This is the plan they run, and the point at which each capability starts producing measurable results.

Days 1–5

Sensor rollout and baseline capture

Deploy to a 500-device pilot ring, connect identity providers and cloud accounts, and snapshot the incumbent tooling so improvement can be measured rather than claimed.

Days 6–21

Detection tuning against your environment

Behavioural models learn what normal looks like for your estate. Suppression rules are written with your analysts, not for them. Typical noise reduction at day 21 is between 70 and 85 percent.

Days 22–45

Response automation goes live

Containment playbooks move from recommend-only to automatic for the incident classes you approve. Most customers start with credential compromise and ransomware precursors.

Days 46–75

Full-estate rollout and legacy decommission

Remaining waves ship, and the first incumbent agents are removed. Contract overlap is usually one quarter; we help you plan the exit to avoid paying for both.

Day 90

Value review with your executive sponsor

A written comparison against the day-one baseline, presented by your customer success architect, plus a twelve-month roadmap agreed with your team.

Coverage and noise reduction over the first 90 days
100% 75% 50% 25% 0 Day 1 Day 21 Day 45 Day 75 Day 90 Estate coverage Alert noise vs. baseline

Coverage is measured as the share of managed assets reporting healthy telemetry. Noise is the weekly count of alerts closed without action, indexed to the pre-deployment baseline.

Beyond the licence

Programmes our customers actually use

Being a Guardian customer means access to the people who build the platform and to the peers who run it under the same pressure you do.

Customer Advisory Board

Forty-two security leaders across nine industries meet quarterly with Guardian product and research leadership. Roughly a third of every release is shaped in that room, and members see the eighteen-month roadmap under NDA before anyone else.

Ask about membership

Guardian Connect community

Nineteen thousand practitioners sharing detection logic, response playbooks and migration notes. Detection content contributed by the community is reviewed by Guardian Labs and, where it generalises, shipped to every tenant.

Join the community

Executive briefing centre

Bring your board, your auditors or your own customers to a half-day session with Guardian Labs researchers. Sessions run in London, Austin, Singapore and Frankfurt, and cover the adversaries actually targeting your sector.

Book a briefing

Certification and enablement

Guardian Certified Analyst and Guardian Certified Engineer tracks are included with Professional and Enterprise plans. Customers who certify at least two analysts resolve incidents 38 percent faster than those who do not.

See training paths

Retainer-backed incident response

Every Enterprise customer can attach pre-paid IR hours. If you never use them they convert to consulting or training credit at renewal, so the retainer is never wasted budget.

Explore IR retainers

Annual value review

Your customer success architect produces a written twelve-month review against the baseline captured at onboarding: coverage, MTTR, incidents prevented, tools retired and cost per protected asset.

See support plans

Do your own diligence

Talk to someone who is not paid by us

We will introduce you to a Guardian customer of comparable size, sector and regulatory exposure, and we will leave the call. Reference customers are volunteers, they are not compensated, and they are briefed to answer the hard questions — including what went wrong during their rollout.

  • Matched by profile. Same industry, comparable estate size and the same compliance regime wherever possible.
  • Unsupervised. No Guardian employee joins the call unless both sides ask for one.
  • Technical depth on request. We can arrange an architect-to-architect session rather than an executive conversation.
  • Usually within five business days of your request, subject to the reference customer's availability.

See what your own numbers would look like

Bring us your current MTTD, your alert volume and your tool inventory. In a 45-minute session we will model the delta against comparable Guardian deployments — and tell you plainly if the case is not there.