Skip to content
Merrow

Financial Services

Meridian Trust

Incident Response & Breach SupportManaged Detection & Response

Challenge

A mid-sized wealth management firm detected unusual encryption activity on a file server at 2:40am. In-house IT had no incident playbook and no forensic capability to determine scope.

Approach

  • Retainer team on-site within the contracted SLA window
  • Affected segment isolated within the first hour, containing lateral spread before it reached the core policy administration system
  • Parallel forensic investigation to establish initial access vector while containment was underway
  • Coordinated communication with the firm's cyber insurer and legal counsel from hour one

47 min

From alert to full containment

Outcome

Contained before any client-facing system was affected, with a full root-cause report delivered inside five days — used directly in the firm's insurance claim and FCA notification.