Octa1neOcta1ne
REQUEST CONSULTATION
Case StudiesFinancial Services
FINANCIAL SERVICESSOC · Identity · Reporting

Global Investment Firm Reduces
Threat Dwell Time by 94%
with 24/7 Managed SOC

A 400-person regulated investment management firm managing $3bn in assets had no dedicated security function, no 24/7 monitoring and no visibility into threats targeting their environment. A near-miss phishing incident that almost resulted in a $420,000 fraudulent wire transfer changed everything.

94%
Reduction in threat dwell time
< 8 min
Mean time to detect
3
Active threats found in Month 1
100%
Regulatory audit passed

Background & Context

The client is a regulated investment management firm with approximately 400 employees operating across offices in North America, Europe and Asia Pacific. Managing a portfolio in excess of $3 billion on behalf of institutional investors, pension funds and high-net-worth individuals, the firm operates under strict financial regulatory requirements across multiple jurisdictions.

Despite the sensitivity of the data they handle and the regulatory scrutiny they operate under, the firm had no dedicated security team. Microsoft 365 had been deployed without security configuration. Microsoft Sentinel had never been activated, despite being included in their enterprise licence.

The firm had conducted one penetration test eighteen months prior but had no mechanism to track or verify remediation of the findings. Three of the five critical vulnerabilities identified in that assessment remained unpatched at the time Octa1ne was engaged.

The Incident That Triggered Engagement

A sophisticated spear phishing campaign targeting the firm's finance team deployed AI-generated emails impersonating the Chief Financial Officer. The transfer was prevented only because a finance analyst happened to call the CFO directly to confirm — not because of any technical control. Investigation revealed the attacker had been inside the environment for at least 47 days, had accessed internal financial documents and had exfiltrated a partial client contact list.

The Challenge

The board commissioned an emergency security assessment immediately following the incident. The findings were severe. The environment had no centralised logging or alerting capability. Identity governance was absent — 34 former employees still had active accounts. Endpoint protection across 400 devices was a mix of consumer-grade antivirus and unmanaged corporate devices.

The board needed to manage regulatory notification while simultaneously rebuilding their security posture. Octa1ne was selected following a competitive evaluation of three providers, primarily on the basis of Microsoft specialisation, 24/7 global SOC capability and the quality of board-level reporting.

The Octa1ne Programme

01

Incident Containment & Forensics

Octa1ne's incident response team began containment within 4 hours of engagement. The compromised vendor account was identified and disabled. All active sessions associated with the attacker were terminated. A full forensic investigation identified the complete scope of the breach.

02

Microsoft Sentinel SIEM Deployment

Microsoft Sentinel was deployed and fully configured within the first week. Over 340 custom detection rules were deployed, mapped to the MITRE ATT&CK framework and tuned specifically to the threat actors known to target asset management firms. All Microsoft 365, Azure, Entra ID and endpoint data sources were connected.

03

Microsoft Defender XDR Deployment

Defender for Endpoint was deployed across all 400 devices within 12 days. Defender for Office 365 Plan 2 was configured — enabling safe links, safe attachments, anti-phishing policies and attack simulation capabilities. Defender for Identity was connected to the on-premise Active Directory environment.

04

Identity Governance & Zero Trust

Microsoft Entra ID was hardened comprehensively. The 34 orphaned accounts were disabled within 48 hours. MFA was enforced for all 400 users within 10 days. Conditional Access policies were implemented. Privileged Identity Management was deployed for all administrative accounts.

05

24/7 SOC Monitoring

Octa1ne SOC analysts assumed continuous 24/7 monitoring responsibility from Day 15. Every alert is reviewed by a trained human analyst. Mean time to detect across all threat categories was measured at under 8 minutes from Day 30 onwards.

06

Executive Reporting Programme

Monthly executive security reports are delivered to the CEO, COO and Board Audit Committee on the first business day of each month. Reports are written entirely in plain language — covering risk score, threats detected and resolved, compliance posture and programme effectiveness metrics.

Outcomes & Results

Within the first month of deployment, Octa1ne detected and contained three active threats that had been present in the environment undetected. Mean time to detect fell to under 8 minutes by the end of the first month. Threat dwell time dropped by 94% compared to the pre-Octa1ne baseline.

The firm successfully completed its regulatory operational resilience assessment six months after engagement began — with the regulator specifically noting the quality of the firm's cybersecurity monitoring capability as an area of positive practice.

94%
Reduction in mean threat dwell time versus pre-engagement baseline
< 8 min
Mean time to detect across all threat categories from Month 1
3
Previously undetected active threats identified and contained in Month 1
34
Orphaned accounts disabled within 48 hours of engagement
400
Devices fully protected under Defender for Endpoint by Day 12
100%
MFA enforcement across all users completed within 10 days
CLIENT TESTIMONIAL

“We went from having no idea what was happening inside our environment to having complete, real-time visibility and a team we genuinely trust monitoring it around the clock. Within the first month alone Octa1ne found three threats we had no idea existed.”

Chief Operating Officer
Global Investment Management Firm, $3bn AUM
ENGAGEMENT DETAILS
Sector
Financial Services
Organisation
400 employees, $3bn AUM
Jurisdictions
North America, Europe, APAC
Services
SOC, Identity, Incident Response, Reporting
Time to SOC
Monitoring live in 15 days
Time to MFA
100% enforcement in 10 days
Regulatory
Multi-jurisdiction financial regulation
Engagement type
Ongoing managed programme
SERVICES DEPLOYED
Threat Detection & Hunting
Microsoft Sentinel SIEM
Identity & Access Security
24/7 SOC Monitoring
Incident Response
Security Reporting & Analytics
Book Free Assessment →← All Case Studies

More case studies

View all →