Financial Services
Meridian Trust
Incident Response & Breach SupportManaged Detection & Response
Challenge
A mid-sized wealth management firm detected unusual encryption activity on a file server at 2:40am. In-house IT had no incident playbook and no forensic capability to determine scope.
Approach
- Retainer team on-site within the contracted SLA window
- Affected segment isolated within the first hour, containing lateral spread before it reached the core policy administration system
- Parallel forensic investigation to establish initial access vector while containment was underway
- Coordinated communication with the firm's cyber insurer and legal counsel from hour one
47 min
From alert to full containment
Outcome
Contained before any client-facing system was affected, with a full root-cause report delivered inside five days — used directly in the firm's insurance claim and FCA notification.