Healthcare
38 hospitals
Meridian Health Network
Challenge. 24,000 connected clinical devices that
could not take an agent, a flat network between imaging and administration, and a
ransomware attempt that reached the radiology VLAN before anyone noticed.
Approach. Passive device fingerprinting plus network
enforcement isolated unmanaged medical equipment without touching device firmware.
Response playbooks were written with clinical engineering so containment never
interrupts an active procedure.
0Cancelled procedures since go-live
11 minMean time to contain
Manufacturing
14 plants
Kestrel Aerospace Components
Challenge. A tier-one supplier under contractual
obligation to prove segmentation between engineering IP and the shop floor, running
twenty-year-old programmable logic controllers that fail on aggressive scanning.
Approach. Read-only OT protocol inspection on
Purdue levels 2 and 3, IP exfiltration monitoring on the engineering estate, and
change-window-aware response that queues actions until the line stops.
100%Line uptime maintained
6,340OT assets discovered, 1,900 unknown
Energy & utilities
2.1M customers
Lumen Grid Utilities
Challenge. A regional transmission operator facing
sustained reconnaissance from a state-linked group, with substation networks reachable
through a vendor remote-access path nobody had inventoried.
Approach. Third-party access was collapsed into a
brokered, recorded path with per-session approval. Guardian MDR took 24/7 monitoring of
substation telemetry, with escalation directly to the control room supervisor.
3 minMDR escalation SLA met at p99
118Unmanaged vendor paths eliminated
Retail & e-commerce
1,240 stores
Vantage Retail Group
Challenge. Card-skimming scripts kept reappearing on
the checkout journey through a tag manager, and seasonal credential-stuffing traffic
regularly overwhelmed the fraud team during peak trading.
Approach. Client-side script integrity monitoring
with automatic rollback, identity analytics tuned for shared store terminals, and a
frozen change policy enforced automatically from mid-November.
19 sMedian script rollback time
-84%Account takeover attempts succeeding
Government
Public sector
National Transit Authority
Challenge. Eleven agency subdivisions with separate
security teams, no shared incident view, and a statutory 24-hour breach notification
requirement that nobody could reliably meet.
Approach. Multi-tenant deployment with per-agency
data boundaries and a federated incident view for the national coordination centre.
Notification packets are generated from incident evidence within minutes of triage.
52 minMedian time to notification-ready packet
11Agencies on one console, data still segregated
Technology & SaaS
Multi-cloud
Orbital Systems
Challenge. Four hundred engineers shipping to
production 90 times a day across three cloud providers, with security review
consistently identified as the slowest gate in the delivery pipeline.
Approach. Runtime detection on every workload,
infrastructure-as-code scanning wired into pull requests, and risk-scored findings that
only block a merge when an exploitable path to production data exists.
-97%Security review time per release
4.2 sMedian container drift detection
Education
61,000 students
Halden University
Challenge. An intentionally open research network,
30,000 unmanaged personal devices each September, and a grant-funded research group
holding data subject to export control.
Approach. Tiered policy separating the open campus
network from a hardened research enclave, with data classification driving egress
controls rather than blanket blocking that would break legitimate research.
-91%Compromised student accounts per term
2.5 FTESecurity team, unchanged after growth
Financial services
Insurance
Ardent Mutual Insurance
Challenge. A claims platform holding 14 million
medical records, a broker network of 3,000 independent agencies with variable security
hygiene, and a cyber-insurance renewal that had doubled in price.
Approach. Data protection first: classification of
the claims estate, then egress controls and third-party access scoring for the broker
portal, with evidence packaged for the underwriter.
-34%Cyber-insurance premium at renewal
14.2MRecords classified in 9 days
Logistics
42 countries
Corvus Logistics
Challenge. A freight operator recovering from a
wiper incident that took warehouse management offline for nine days, with no reliable
record of how the adversary had entered or how far they had moved.
Approach. Guardian incident response led recovery
and rebuild, then the platform was deployed with immutable telemetry retention so the
next investigation starts with evidence rather than guesswork.
9 days → 4 hProjected recovery time objective
365 dImmutable telemetry retention