Case Study

Plum

What we did for Plum

Industry: Finance

Published: 29/09/2025

Plum

Project Overview

Plum Fintech were dealing with multiple compliance requirements, and in 2024 onboarded SEP2 to improve their security infrastructure by utilising Wingman MDR Google SecOps. This case study highlights the initial challenges faced by Plum, SEP2’s seamless implementation process, and the collaborative efforts that made it all possible.

The Challenge

Struggled to scale security with the company’s growth

Needed to meet compliance requirements for licensing and audits

Faced delays due to complex budget approval processes

Lacked efficient communication channels for implementation support

The Solution

Implemented Wingman MDR with Google SecOps to centralise and automate security operations

Integrated SEP2’s SOAR platform into DevOps to streamline compliance and audit readiness

SEP2’s Enterprise Account Executive enabled flexible payment options via Google TCP Profile

Used Slack for real-time communication, reducing delays and improving collaboration

Who is Plum

Plum, founded in 2016, is a financial technology company that offers smart tools for saving, investing, and budgeting with an aim to help people take control of their finances through automation and intuitive tools. They have been recognised for their innovative approach to personal finance, helping millions of users globally save and invest more efficiently.

Why Plum Chose SEP2

Before discovering SEP2, Plum needed to obtain certain licenses that required compliance with various regulations, one of the key requirements being centralised log management and monitoring. Ozan Ozgar, CISO at Plum, relies mainly on Google’s products, having found that using Google’s tools simplifies their operations, providing easy-to-use dashboards and enabling centralised and automated processes. This approach allows his small team to manage tasks efficiently without spending a large amount of time on them.

Like many security professionals in financial services, Ozan had to navigate a lengthy process of reviewing and comparing solution partners, alongside securing budget approval, before implementation could begin. He remarks that working with one of our Enterprise Account Executives at SEP2 was a great help to him throughout this process. “Budget approvals can be quite difficult, and this team member has been really helpful and flexible during this time.” This support enabled them to get part of the payments through their Google TCP Profile, which helped secure the green light to move forward from stakeholders.

Working with SEP2

During the implementation process, Ozan and his team were required to monitor privilege accounts as well as generic admin accounts. He needed the SEP2 team to create a custom dashboard for their SIEM solution before they went live. To do this efficiently, he reached out to our SIEM Deployment and Support Lead at SEP2. “They did it in a day or two, which meant I was able to use that in my audit as evidence as well. That was really helpful.”

Consistent communication has been a key highlight for Ozan during the implementation process. “Emails take time, people miss them even for small things, and you can end up waiting weeks for a response. Having support through channels like Slack makes a real difference. SEP2’s flexibility around how we communicate is something I really value.”

Plum is currently undertaking a major project involving complex financial regulations, which will impact the expansion of the business not only through monetary value but also by supporting one of the largest IT requirements. Audits require a significant amount of time and energy for a company, so having everything integrated into one place is crucial for Plum. When it comes time for the audit, Ozan will need to demonstrate that they have a robust system in place. He is confident the audit will go well thanks to the support of SEP2’s SOAR platform integrated into their DevOps environment. This integration will be key in meeting compliance requirements efficiently.

Looking to the Future

Ozan and the team at Plum are looking forward to utilising SEP2’s round-the-clock SOC team, a new and promising service for them. They are excited to see how SEP2’s experts will enhance their security posture, providing real-time insights and alerts. This collaboration marks a significant step forward in Plum’s journey towards robust and efficient security management. With SEP2’s continuous support, Plum is well-positioned to tackle future challenges and maintain a strong security framework.

Testimonials

Hear From Those We Protect

We knew we couldn’t do it on our own. We didn’t have the time, and we wanted additional expertise to guide us through the process. If we tried to do it ourselves, we’d probably spend a lot of time and effort in the wrong areas.

Emails take time, people miss them even for small things, and you can end up waiting weeks for a response. Having support through channels like Slack makes a real difference. SEP2’s flexibility around how we communicate is something I really value.

During the evaluation process it was clear to me that SEP2 were the strongest candidate from a technical standpoint. During our first meeting, their ability to give immediate solutions to ongoing issues we were experiencing at the time was a breath of fresh air.

SEP2 are knowledgeable, motivated and switched on; they take ownership and they have a drive for resolution. They know their stuff! They are not merely a firewall partner, they are a cyber security partner. They take a strategic approach. They are approachable and offer additional value outside of their support contract. Working with SEP2 means we are no longer fire-fighting; rather we can now take a step back and proactively get things sorted. SEP2 say they are tech driven and people powered, and that’s exactly what they are! It all comes down to the people you are dealing with.

When we hit the limits of our knowledge, it’s having SEP2 there to say, ‘Try these things first.’ That expertise on hand is really important to us.

You’re vendor agnostic, which is key for growth, and your team are providing really good insights in terms of the alerts raised. They also provide meaningful context behind them, which is great for us as an organisation,”

To have people like that around our account that we can pick the phone up to and ask questions was refreshing. Ultimately, we trusted SEP2 and we trust you with our cyber security.

Often the term used is ‘you can’t see the wood for the trees’. Most organisations implement security tooling tools and you’ve got different dashboards. The idea is you put them into a single place, and leverage expert resource such as the SEP2 SOC that actually understands that data and work with it on a daily basis. They can assess it case-by-case and escalate it back to us at Funding Circle only when necessary. And that whole process has been really, really smooth.

They are phenomenal: both personable and very knowledgeable. Our main contact is like a fountain of knowledge. If you ask him a question, he always comes back with ten answers – all the shades of grey, not just a ‘Yes’ or ‘No.’ To me that shows the level of passion he has, and that he really wants to do things properly.

The original group of people who founded SEP2 were very deep in their knowledge of this type of technology, which can be complicated. It’s become the whole field of firewalls, intrusion prevention, antivirus, ransomware, etc. Cyber security as a whole has really ballooned, and there’s lots of dimensions to it, but you’ve managed to keep up.

They live and breathe the technology. It comes from the top, however, everyone is an expert within SEP2, from sales through to the service desk. We don’t want to wait to be told what more we can get from vendors’ products. SEP2 are great in pro-actively helping us achieve value-add solutions. They aren’t about chasing revenues, they are about providing best possible value.