North American Manufacturer Reduces Cyber Risk and Insurance Costs with Quorum Cyber
Highlights
- North American manufacturer operating complex, always-on production environments
- Microsoft security estate enhanced with 24×7 monitoring and response
- Improved cyber resilience with ~30% reduction in insurance costs
Supported by Clarity Extend and Incident Response Retainer
.
A leading North American manufacturer operating across multiple states needed to strengthen cybersecurity across a complex, always-on environment. Supporting thousands of employees and production sites, the business uses Microsoft technologies as part of its wider estate. With operations running around the clock, any serious cyber incident could disrupt production immediately and cost thousands of dollars an hour.
While Microsoft Defender XDR introduced a new challenge: turning these high volumes of security data into clear, actionable insight. The organization needed a specialist partner to interpret signals, prioritize risk, and guide a more proactive security strategy.
“Through our collaboration with Quorum Cyber, we implemented a robust, proactive security strategy, using data to drive decisions and optimize our Microsoft Security investments,” said the Director of Cyber Security and IT Infrastructure.
Turning visibility into action
Quorum Cyber provided 24×7 monitoring and managed detection and response through Clarity Extend, giving the organization continuous oversight of its environment and the expertise to act quickly on emerging threats.
This partnership enabled the team to move beyond reactive security and establish a more structured, data-led approach to investment and operations.
“Quorum Cyber helped us understand our needs, set accountability standards, and establish clear benchmarks for our security budget. Now we know exactly what we’re getting for what we’re paying.”
To further strengthen preparedness, the organization also set up an Incident Response Retainer, ensuring immediate access to expert support in the event of a breach.
The result was a lean, focused internal team, able to prioritize prevention and cyber hygiene while relying on Quorum Cyber for specialist expertise.
“I’d rather have a smaller team with a great cybersecurity partner than a large team. My team can now focus on maintaining strong cyber hygiene across the organization.”
Expert support when it mattered most
That partnership proved critical when a social engineering attack gave a threat actor access to part of the environment.
Quorum Cyber’s Incident Response team rapidly investigated, contained the threat, and uncovered activity the internal team had not identified.
“They were some of the best incident response professionals I’ve seen in 30 years of working in security. When I realized we’d been compromised, my stress levels went through the roof, but once Quorum Cyber got involved, I felt much more confident.”
A third-party security team engaged by the organization’s cyber insurer later validated the response, confirming that the combined efforts successfully identified attacker activity and strengthened security controls.
Protecting operations and reducing costs
In a manufacturing environment, even brief downtime can result in losses of hundreds of thousands of dollars. A prolonged incident could have halted production, delayed shipments, and disrupted the wider supply chain.
“If it weren’t for Quorum Cyber, we’d have been down for months. We wouldn’t have been able to ship products, and the cost would have run into the millions.”
Following the incident, the organization estimates that its improved security posture, supported by Quorum Cyber and enhanced endpoint detection and response, contributed to a reduction in cyber insurance premiums of approximately 30%.
A long-term security partner
Today, Quorum Cyber is embedded as a core part of the organization’s long-term security strategy, providing continuous protection, strategic guidance, and peace of mind.
“This is the first time in a long time that I’ve felt truly confident in our security posture. Quorum Cyber feels like an internal partner rather than a third-party supplier. They protected us during a critical moment faster than anyone else could have; I’ve already recommended them to others.”
Modern MDR, Made Clear: 10 Questions Every CISO Should Ask
The cyber threat landscape has fundamentally changed. Attackers are faster, more automated, and increasingly exploiting identity and cloud complexity – leaving traditional detection and response approaches struggling to keep pace.
Modern MDR, Made Clear is a practical playbook designed to help CISOs build future-ready detection and response programmes – and ask the critical questions needed to select a partner that delivers measurable protection, prevention, and resilience.

Global Manufacturing Organisation Strengthens Security Resilience by Consolidating on Microsoft with Quorum Cyber
A North America–based manufacturing organisation with a large Windows and Microsoft 365 footprint set out to simplify security operations while improving visibility and resilience across its environment.
Over time, the organisation’s security stack had grown fragmented. Signals were spread across multiple tools, increasing investigation time, complicating operations, and creating dependency on point solutions for critical controls.
Following a major industry-wide endpoint disruption, leadership initiated a strategic review of endpoint and detection platforms, with a focus on operational resilience, vendor risk, and reducing single points of failure. The organisation engaged Quorum Cyber to help modernise its security operating model and consolidate around the Microsoft security platform.
The challenge
The organisation faced three interrelated challenges:
- Fragmented visibility: Security data was spread across multiple tools, slowing investigations and making it difficult to maintain a consistent view of risk
- Endpoint platform risk: A third-party endpoint detection and response (EDR) platform had become a critical dependency. After a high-impact industry incident, leadership reassessed the potential operational blast radius and the recovery implications of relying on a single endpoint control at scale
- Transition complexity: The organisation wanted to move to a new endpoint approach without disrupting day-to-day operations, duplicating cost, or creating gaps in detection coverage during the changeover.
From a commercial perspective, the status quo was anchored in the incumbent EDR deployment, long regarded internally as a best-of-breed control.
The solution
Quorum Cyber designed and delivered a phased consolidation strategy built on the Microsoft security platform, focused on resilience, clarity, and operational control.
Key elements included:
- Adoption of Quorum Cyber Clarity Extend as the MXDR managed service aligned to the customer’s Microsoft estate
- Enablement of Microsoft Sentinel in the customer’s tenant to centralise security analytics, investigations, and response
- A structured transition to Microsoft Defender for Endpoint, with telemetry and detections brought online in a controlled sequence to maintain continuity, avoid coverage gaps, and prevent unnecessary overlap.
This approach brought endpoint, SIEM, and wider security signals into a single operating model, reducing complexity while increasing confidence in day-to-day security operations.
Why this approach worked
The organisation’s priority was not adding new tools but reducing operational risk while improving outcomes.
Consolidating on Microsoft delivered:
- Unified visibility across endpoint, identity, and cloud signals
- Reduced vendor dependency for a critical control, lowering the risk associated with single-vendor update or sensor failures
- Predictable economics, supported by clear Sentinel ingestion modelling and better utilisation of existing Microsoft licences.
Importantly, many core Microsoft security signals could be ingested into Sentinel without additional cost, allowing the organisation to scale visibility while maintaining a predictable run-rate.
Decision criteria focused on three outcomes: resilience and availability, operational simplicity, and strong alignment with the Microsoft ecosystem.
Why Quorum Cyber
The organisation selected Quorum Cyber for its deep Microsoft security specialisation and its ability to translate platform capability into a practical operating model.
Quorum Cyber provided:
- A clear transition roadmap -what to consolidate first, how to stage implementation, and how to maintain service continuity.
- Outcome-led positioning of Clarity Extend, focused on visibility, resilience, and simplification rather than tool management alone.
- Commercially sensible migration planning that avoided prolonged dual-running of endpoint platforms.
This combination reassured stakeholders that the endpoint platform change could be managed with control, minimising risk, avoiding disruption, and maintaining continuity throughout.
Commercial and operational impact
The move to a consolidated Microsoft security model involved a modest increase in Microsoft licensing to support the target posture. Managed service costs remained broadly flat or slightly reduced.
The primary value came from consolidation:
- Reduced tooling sprawl
- Improved security visibility
- A clearer, more resilient foundation for detection and response using Microsoft Defender and Sentinel.
Operationally, the organisation established a centralised security data strategy, enabling more efficient investigations and a scalable foundation for future security maturity.
Delivery approach
Quorum Cyber and the customer followed a structured six-week onboarding programme with clear milestones and ownership:
- The customer led the endpoint platform transition to Microsoft Defender for Endpoint
- Quorum Cyber enabled Microsoft Sentinel and onboarded required telemetry into Clarity
- Delivery was phased to increase visibility incrementally while maintaining operational stability.
This approach ensured the organisation strengthened security posture without introducing unnecessary risk during change.
“By consolidating on Microsoft security with Quorum Cyber, we’ve strengthened resilience, improved visibility, and simplified how we operate security day to day, with a foundation we can trust long term.”
Director of Information Security, North America-based manufacturing organisation.
Managing Multiple Stakeholders During Ransomware Response
Introduction
The network of a small, privately held provider of heating, ventilation and air conditioning (HVAC) services was infected with Ryuk ransomware, leaving the company unable to run backend sales processes such as quoting and billing. Quorum Cyber was called in to clear the malware from all affected devices and restore their systems.
The challenge
The customer’s entire IT environment was managed by a regional managed service provider (MSP), which was found to be running legacy systems on the customer’s servers, including Windows 2003. In addition, the only risk management measures in place were a firewall and basic anti-virus software. Ten months prior to the incident, two banking trojans, Emotet and Trickbot, had been installed on the system via a phishing email. These enabled the attackers to subsequently install the Ryuk ransomware variant in late January 2020.
The MSP detected the ransomware attack and notified the company, which then contacted their insurer. By the time Quorum Cyber became involved, 12 servers were encrypted and 58 workstations were infected with either banking trojans or ransomware. This represented about 75% of the customer’s total endpoints, and left them unable to perform crucial financial transactions. No customer data was accessed or stolen.
Quorum Cyber’s response and solution
The majority of Quorum Cyber’s work was conducted remotely, linking to the customer’s onsite data centre via secure online connections. Quorum Cyber coordinated communication between the customer and the MSP, which struggled to provide system information and backups due to insufficient technical expertise. During the engagement:
- Quorum Cyber sent two incident response (IR) analysts for the initial IR phase, followed by five PBR responders for the remediation phase
- The IR team ran forensic imaging, collected evidence, and deployed KECT and endpoint detection and response (EDR) software
- The PBR team reimaged and decrypted the servers and workstations, ultimately deploying the backups to restore the company’s systems.
Outcome
Despite the incurred costs, the overall business interruption was significantly reduced by Quorum Cyber’s quick IR and remediation work paired with EDR deployment. In summary:
- No ransom had to be paid, as Quorum Cyber restored systems from backups
- EDR was installed and ran for a month to prevent secondary attacks
- Fifty-eight workstations were restored within four days over the weekend and were back online and fully operational by close of business on Monday
- The period of loss caused by business interruption was reduced by three weeks.
Outmanoeuvring Persistent Threat Actors in the Chemical Industry
Introduction
A small US-based chemical manufacturer with a supply chain comprising 50+ household names in chemicals was hit with a creative new twist on the HAFNIUM threat targeting Microsoft Exchange Servers. This new threat, coined ProxyShell, opened companies’ on-premise email to a new present danger. Acquired by Quorum Cyber in 2024, Kivu’s 24x7 cyber security monitoring service flagged ProxyShell and dispatched it. Within 48 hours, Kivu and the chemical company worked to remediate and evolve the stance against this attack surface and future attacks.
The challenge
HAFNIUM is a Chinese state-sponsored threat intent on information theft and espionage. Following HAFNIUM techniques that utilised mutability and suitability ProxyShell, was discovered by security researcher Orange Tsai, who showed it in detail at a security conference in August 2021. The researcher found that by chaining together three different vulnerabilities, threat actors could establish a web-shell-based backdoor access into a company’s email server. The actor could then perform unauthenticated, remote-code execution – or potentially gain the “keys to the castle” – to release emails, exfiltrate data and then move on to owning the whole company network from the inside out.
Kivu’s response and solution
Alerted to the true nature of the threat (vs. known bad actors) by the monitoring service, Kivu’s team acted immediately. By conducting analysis of log and server files, the team identified the new indicators of compromise (IOCs) associated with ProxyShell activity. Kivu isolated the problem in a safe form separate from the company’s operational systems (but still connected to Kivu), preventing further spread.
Kivu then worked with the company’s two-person IT department, following Microsoft plus industry guidance to rebuild the mail server into a hardened, refined form. Kivu consultants consolidated techniques used in this ProxyShell attempt, as well as input from Microsoft and future recommendations, into a shared threat intel and reporting platform, ensuring the knowledge was shared quickly internally and then to other Kivu clients that may have been affected or about to be attacked. Much of this work was undertaken in 48 hours over the weekend.
Kivu used this threat profiling against all of its customers, identifying those with “on-premise” Exchange mail servers, alerting nine others at risk, stopping ProxyShell attempts from further exploit, and assisting Kivu’s digital forensics and incident response efforts at large.
Outcome
Because it had Kivu’s Cyber-as-a-Service 24x7 threat monitoring in place, the company:
- Rapidly identified a brand new risk (under two days old) and remedied the situation
- Prevented hijacking and man-in-the-middle attacks risks, which could have led to fraud
- Avoided business downtime and maintained its 99% service level agreement (SLA).







