Customer outcomes

What actually changed after Guardian Sentinel went live

Nine deployments, measured before and after, with the numbers verified by the customer's own security operations team. No composite organisations, no illustrative scenarios — every metric on this page came out of a production environment.

93% Median reduction in mean time to contain Across the nine deployments below
8.4× More incidents closed per analyst per shift Twelve months after go-live
71% Fewer alerts reaching a human After autonomous triage was enabled
4.1× ROI Average return within 24 months Tool consolidation plus avoided loss

Featured story

Northbank Financial Group cut containment from 6 hours to 4 minutes

Financial services 74,000 endpoints 19 countries Sentinel Enterprise

The challenge

Northbank ran four separate detection products across retail banking, capital markets and a recently acquired payments business. Correlation happened in a SIEM that ingested 11 TB a day, and the tier-one queue averaged 2,900 alerts per shift. Two consecutive regulatory examinations flagged the same finding: the bank could not evidence how quickly it detected and contained intrusions in its card processing environment.

What Guardian did

Sentinel was deployed agent-first across endpoints and cloud workloads, running in parallel with the incumbent stack for 60 days so detections could be compared side by side on identical traffic. Identity telemetry from the bank's two directory tenants was connected in week three, which immediately surfaced 41 service accounts with unconstrained delegation. Autonomous containment was enabled in stages — first for commodity malware, then for credential theft, then for the card environment once the change advisory board had six weeks of evidence.

The result

  • Mean time to contain fell from 6 hours 12 minutes to 4 minutes for the intrusion classes covered by autonomous response.
  • Three detection products retired, removing 2.4 million dollars of annual licence and support cost.
  • SIEM ingest dropped 62% once raw endpoint telemetry stayed in Sentinel and only enriched incidents were forwarded.
  • Both open examination findings closed at the next review, with containment evidence generated automatically per incident.
northbank / before-after.metrics

Before Guardian vs. 12 months after

38 min 40 s Time to detect 372 min 4 min Time to contain 2,900 190 Daily alerts Before After Guardian

We ran both stacks on the same traffic for two months because I did not believe the numbers. Sentinel caught two credential-theft chains our incumbent never raised, and it contained them before the on-call analyst had opened the ticket.

Elena Moreau
Group CISO, Northbank Financial Group

All stories

Nine deployments, nine different starting points

Filter by industry to find the environment closest to yours. Each story includes the original problem, the deployment shape and the metrics twelve months on.

Healthcare 38 hospitals

Meridian Health Network

Challenge. 24,000 connected clinical devices that could not take an agent, a flat network between imaging and administration, and a ransomware attempt that reached the radiology VLAN before anyone noticed.

Approach. Passive device fingerprinting plus network enforcement isolated unmanaged medical equipment without touching device firmware. Response playbooks were written with clinical engineering so containment never interrupts an active procedure.

0Cancelled procedures since go-live
11 minMean time to contain
Manufacturing 14 plants

Kestrel Aerospace Components

Challenge. A tier-one supplier under contractual obligation to prove segmentation between engineering IP and the shop floor, running twenty-year-old programmable logic controllers that fail on aggressive scanning.

Approach. Read-only OT protocol inspection on Purdue levels 2 and 3, IP exfiltration monitoring on the engineering estate, and change-window-aware response that queues actions until the line stops.

100%Line uptime maintained
6,340OT assets discovered, 1,900 unknown
Energy & utilities 2.1M customers

Lumen Grid Utilities

Challenge. A regional transmission operator facing sustained reconnaissance from a state-linked group, with substation networks reachable through a vendor remote-access path nobody had inventoried.

Approach. Third-party access was collapsed into a brokered, recorded path with per-session approval. Guardian MDR took 24/7 monitoring of substation telemetry, with escalation directly to the control room supervisor.

3 minMDR escalation SLA met at p99
118Unmanaged vendor paths eliminated
Retail & e-commerce 1,240 stores

Vantage Retail Group

Challenge. Card-skimming scripts kept reappearing on the checkout journey through a tag manager, and seasonal credential-stuffing traffic regularly overwhelmed the fraud team during peak trading.

Approach. Client-side script integrity monitoring with automatic rollback, identity analytics tuned for shared store terminals, and a frozen change policy enforced automatically from mid-November.

19 sMedian script rollback time
-84%Account takeover attempts succeeding
Government Public sector

National Transit Authority

Challenge. Eleven agency subdivisions with separate security teams, no shared incident view, and a statutory 24-hour breach notification requirement that nobody could reliably meet.

Approach. Multi-tenant deployment with per-agency data boundaries and a federated incident view for the national coordination centre. Notification packets are generated from incident evidence within minutes of triage.

52 minMedian time to notification-ready packet
11Agencies on one console, data still segregated
Technology & SaaS Multi-cloud

Orbital Systems

Challenge. Four hundred engineers shipping to production 90 times a day across three cloud providers, with security review consistently identified as the slowest gate in the delivery pipeline.

Approach. Runtime detection on every workload, infrastructure-as-code scanning wired into pull requests, and risk-scored findings that only block a merge when an exploitable path to production data exists.

-97%Security review time per release
4.2 sMedian container drift detection
Education 61,000 students

Halden University

Challenge. An intentionally open research network, 30,000 unmanaged personal devices each September, and a grant-funded research group holding data subject to export control.

Approach. Tiered policy separating the open campus network from a hardened research enclave, with data classification driving egress controls rather than blanket blocking that would break legitimate research.

-91%Compromised student accounts per term
2.5 FTESecurity team, unchanged after growth
Financial services Insurance

Ardent Mutual Insurance

Challenge. A claims platform holding 14 million medical records, a broker network of 3,000 independent agencies with variable security hygiene, and a cyber-insurance renewal that had doubled in price.

Approach. Data protection first: classification of the claims estate, then egress controls and third-party access scoring for the broker portal, with evidence packaged for the underwriter.

-34%Cyber-insurance premium at renewal
14.2MRecords classified in 9 days
Logistics 42 countries

Corvus Logistics

Challenge. A freight operator recovering from a wiper incident that took warehouse management offline for nine days, with no reliable record of how the adversary had entered or how far they had moved.

Approach. Guardian incident response led recovery and rebuild, then the platform was deployed with immutable telemetry retention so the next investigation starts with evidence rather than guesswork.

9 days → 4 hProjected recovery time objective
365 dImmutable telemetry retention

Side by side

Outcomes by industry, twelve months after go-live

Same measurement window, same definitions. Mean time to contain is measured from first malicious observable to verified containment, not from ticket creation.

Verified customer metrics, measured 12 months after production go-live.
Organisation Industry Scale MTTC before MTTC after Alert reduction Tools retired
Northbank Financial Group Banking 74,000 endpoints 6 h 12 m 4 m 93% 3
Meridian Health Network Healthcare 38 hospitals 4 h 40 m 11 m 78% 2
Kestrel Aerospace Manufacturing 14 plants 9 h 05 m 22 m 64% 2
Lumen Grid Utilities Energy 2.1M customers 7 h 30 m 9 m 70% 1
Vantage Retail Group Retail 1,240 stores 3 h 15 m 6 m 81% 4
National Transit Authority Government 11 agencies 11 h 20 m 17 m 69% 5
Orbital Systems Technology Multi-cloud 2 h 05 m 3 m 88% 3
Halden University Education 61,000 students 8 h 45 m 14 m 72% 2
Corvus Logistics Logistics 42 countries No baseline 8 m 76% 3

Scroll the table sideways to see every column.

Corvus Logistics had no reliable pre-deployment baseline; the organisation was recovering from a destructive incident when Guardian was engaged. Full methodology is documented in the Economics of Autonomous Response whitepaper.

The first year

Where the value actually shows up, and when

The pattern repeats across almost every deployment. Visibility arrives in days and is immediately uncomfortable — customers routinely discover 20 to 30 percent more assets than their inventory claimed. Noise reduction lands in the first month. The containment numbers that make the business case only appear once autonomous response is trusted enough to run without a human gate, which typically takes a quarter of evidence.

DAY 1 — 7

Deploy and discover

Agents roll out at a median of 11,000 endpoints per day with no reboot. Unmanaged assets, forgotten cloud accounts and orphaned service principals surface immediately. Eight of the nine customers here found live systems nobody owned.

WEEK 2 — 6

Noise collapses

Correlation replaces per-alert triage. Alert volume reaching a human drops 60 to 80 percent, and the analyst conversation shifts from queue depth to investigation quality for the first time in years.

MONTH 2 — 4

Autonomy earns trust

Response runs in recommend-only mode while the team compares its decisions with their own. Containment is then enabled class by class, starting with commodity malware and ending with the highest-consequence environments.

MONTH 5 — 12

Consolidation and return

Overlapping products are retired, SIEM ingest falls, and the security team starts measuring itself on incidents prevented rather than tickets closed. Median return across these deployments crosses break-even at month nine.

guardian / value-realisation.median

Median outcome curve across nine deployments

100% 75% 50% 25% 0 Go-live Month 3 Month 6 Month 12 Detection coverage Alert volume Analyst capacity

In their words

What the teams running it say

The discovery phase was humbling. We thought we had 19,000 devices. Guardian found 24,600 in four days, and about 900 of them were running an operating system we had decommissioned two years earlier.

Priya Anand
Director of Security Operations, Meridian Health Network

My plant managers had one question: will it stop the line. Eleven months in, the answer is still no. That single fact is why security finally has credibility with operations here.

Tomas Okafor
Head of OT Security, Kestrel Aerospace Components

We went from a security review that took eleven days to one that resolves inside the pull request. Engineers stopped routing around us, which was worth more than any detection metric.

Ruth Kelemen
VP Platform Engineering, Orbital Systems

Methodology

How these numbers were produced

Who verified the metrics?

Every figure was extracted from the customer's own platform tenant and reviewed by their security operations lead before publication. Where a customer's internal definition of a metric differed from ours, we used theirs and noted it in the full case study document.

What counts as containment?

Containment is the point at which the adversary can no longer act on the affected asset or identity — process terminated, host isolated, session revoked or key rotated — confirmed by post-action verification. Ticket closure, alert acknowledgement and analyst assignment do not count.

Why do some organisations have no before baseline?

Two of the nine were engaged during an active incident and had no trustworthy historical measurement. Rather than estimate a flattering baseline, we publish the post-deployment figure alone and mark the comparison as unavailable.

Are these organisations paid or incentivised?

No. Guardian does not pay for references, and no commercial concession was offered in exchange for participation. Customers review and approve every published sentence, and several have redacted operational detail for their own security reasons.

Can I speak to a reference customer?

Yes. During an evaluation we will introduce you to a customer of comparable size and industry for a direct conversation without Guardian on the call. Ask your account team to arrange it.

Related

Go deeper

Whitepapers & reports

The cost model behind the ROI figures on this page, plus the 2026 Global Threat Landscape Report these customers are defending against.

Read the research

Customer sessions on demand

Recorded walkthroughs where these teams present their own architecture and answer unscripted questions from the audience.

Watch the recordings

Managed detection & response

Four of the nine organisations here run Guardian MDR alongside their own team, with a three-minute escalation service level.

Explore MDR

Run the same comparison on your own traffic

Deploy Guardian Sentinel alongside your current stack for 30 days. Same telemetry, same incidents, side-by-side results — and no obligation when it ends.