Resources/Customer stories/Meridian Financial
FINANCIAL SERVICES

MTTR from four hours
to under a minute.

A top-20 US bank consolidated three detection tools onto one fabric — and finally gave its board a number that stopped moving in the wrong direction.

INDUSTRY
Banking & capital markets
SIZE
34,000 employees
DEPLOYMENT
Single-tenant private cloud
REGION
US · EU
MEAN TIME TO RESPOND↓ 98%
BEFORE4h 12m
WITH THREATDEFENDR48s
treasury beacon · isolated pre-payment
THE CHALLENGE

Three consoles, one blind spot.

Meridian's SOC ran a SIEM, a separate EDR, and a home-grown identity monitor. Correlating a single alert meant three logins, three query languages, and analysts pasting IDs between tabs while the clock ran. The board's quarterly question — “how fast can we contain?” — had no honest answer.

WHERE IT HURT
  • Alerts triaged across three unconnected tools
  • Identity signals arrived hours after the endpoint fired
  • No single timeline an examiner could follow
  • Every tuning change waited on a change-advisory board
THE APPROACH

One fabric, wired to the money.

Meridian moved detection, identity, and response onto threatDefendr's shared data fabric, keeping Splunk as an archive. Behavioral models learned each trading desk's normal, and containment ran through gated playbooks the bank's examiners had pre-approved.

We cut mean time to respond from hours to under a minute. threatDefendr is the first platform our board stopped asking questions about.
DR
Dana Reyes
CISO, Meridian Financial
WHAT CHANGED

The outcome, measured.

48s
MEDIAN CONTAINMENT

A wire-fraud beacon on a treasury workstation was isolated in 48 seconds — before the session could reach the payment rail.

1 timeline
EXAMINER-READY

Every action lands on a tamper-evident timeline an OCC examiner can follow without a translator.

11 → 2
ANALYST HOPS PER CASE

Investigations that once spanned three tools now resolve inside one console.

Resources/Customer stories/Meridian Financial
// FINANCIAL SERVICES

MTTR from four hours
to under a minute.

A top-20 US bank consolidated three detection tools onto one fabric — and finally gave its board a number that stopped moving in the wrong direction.

INDUSTRY
Banking & capital markets
SIZE
34,000 employees
DEPLOYMENT
Single-tenant private cloud
REGION
US · EU
// MEAN TIME TO RESPOND↓ 98%
BEFORE4h 12m
WITH THREATDEFENDR48s
treasury beacon · isolated pre-payment
// THE CHALLENGE

Three consoles, one blind spot.

Meridian's SOC ran a SIEM, a separate EDR, and a home-grown identity monitor. Correlating a single alert meant three logins, three query languages, and analysts pasting IDs between tabs while the clock ran. The board's quarterly question — “how fast can we contain?” — had no honest answer.

WHERE IT HURT
  • Alerts triaged across three unconnected tools
  • Identity signals arrived hours after the endpoint fired
  • No single timeline an examiner could follow
  • Every tuning change waited on a change-advisory board
// THE APPROACH

One fabric, wired to the money.

Meridian moved detection, identity, and response onto threatDefendr's shared data fabric, keeping Splunk as an archive. Behavioral models learned each trading desk's normal, and containment ran through gated playbooks the bank's examiners had pre-approved.

We cut mean time to respond from hours to under a minute. threatDefendr is the first platform our board stopped asking questions about.
DR
Dana Reyes
CISO, Meridian Financial
// WHAT CHANGED

The outcome, measured.

48s
MEDIAN CONTAINMENT

A wire-fraud beacon on a treasury workstation was isolated in 48 seconds — before the session could reach the payment rail.

1 timeline
EXAMINER-READY

Every action lands on a tamper-evident timeline an OCC examiner can follow without a translator.

11 → 2
ANALYST HOPS PER CASE

Investigations that once spanned three tools now resolve inside one console.