About Merrow
The specialist your specialist calls.
“Every vendor was selling visibility. Nobody was selling judgement. We wanted to be the people who could look at nine thousand alerts and tell you which four matter, and what to do about them before lunch.”
— Elena Marsh, Co-Founder & CEO
Terms of Service
Last updated: 1 July 2026
1. Acceptance of terms
By accessing this website, you agree to these terms. If you do not agree, please do not use this site. These terms apply to website use only — engagement-specific terms are set out separately in each client's service agreement.
2. Use of content
Content on this website is provided for general informational purposes and does not constitute professional advice specific to your organisation. Reproduction of substantial content without permission is not permitted.
3. No warranty
This website is provided “as is”. While we take care to keep content accurate and current, we make no warranty as to completeness or fitness for a particular purpose.
4. Governing law
These terms are governed by the laws of England and Wales.
Core values
What that means in practice.
Judgement over noise
Every deliverable is filtered through: would this change what the client does on Monday morning?
Say the uncomfortable thing
Analysts are contractually protected to tell a client their control environment is inadequate, even mid-engagement.
Speed is a safety feature
Response time is treated as a security control in its own right, reflected in SLA design across every service.
Independence is non-negotiable
No vendor kickbacks. If the right tool for a client isn't one we resell, that's what gets recommended.
Leadership
Founders and leadership team.
Elena Marsh
Co-Founder & CEO
Former GCHQ threat-intelligence analyst. Left the public sector frustrated that private tooling was excellent at collection and poor at judgement. Leads Merrow's detection engineering philosophy and speaks regularly at CyberUK on the gap between alert volume and alert value.
Tomás Reyes
Co-Founder & Head of Incident Response
Built his career on the incident-response side of GCHQ-adjacent work before founding Merrow with Elena. Still leads live engagements personally on the firm's highest-severity retainer cases.
Priya Shah
Head of SOC Operations
Runs the day-to-day operating model for Merrow's 24/7 SOC across both offices, including the analyst caseload-cap policy she helped design.
Daniel Okafor
Head of Offensive Security
Leads the penetration testing and red-team practice, and the analyst rotation programme that keeps SOC detection engineers current on real attacker behaviour.