Case Study

Freemans Grattan Holdings (FGH)

What we did for Freemans Grattan Holdings

Industry: Retail

Published: 17/09/2026

Freemans Grattan Holdings (FGH)

Project Overview

To replace an offshore legacy vendor and eliminate operational friction, FGH turned to SEP2 to implement three services: Wingman MDR Enhanced, Wingman Secure Access, and Wingman Governance, Risk and Compliance (GRC). The move has strengthened threat visibility, protected their brand perimeter, and allowed Information Security Officer Stuart McMillan and his small team to shift their focus from daily alert triage to long-term security strategy.

The Challenge

Time-zone delays and communication friction with an offshore vendor

DDoS attacks, web application risks, and brand spoofing targeting revenue

Alert fatigue tying down a small team with routine log monitoring

The Solution

Proactive 24/7/365 UK Based SOC coverage with dark web monitoring, spoofed domain detection, and IP tracking

Integrated Threat Intelligence turning raw alert noise into actionable insight to hunt threats early

Strategic governance and compliance support freeing up internal bandwidth for core security goals

Who is Freemans Grattan Holdings (FGH)

Freemans Grattan Holdings (FGH), part of the OTTO group, is a major UK online retailer based in West Yorkshire, home to well known e-commerce brands such as Freemans, Kaleidoscope, and Look Again. Serving over 2 million active customers with more than 1.6 million weekly website visits, uninterrupted platform availability and robust cyber resilience are critical to their high-volume trading operation.

Why FGH chose SEP2

FGH needed to transition away from its incumbent overseas IT outsourcing setup and establish a modern, specialised cyber security baseline tailored to a high-volume e-commerce environment. To find the right fit, FGH conducted a comprehensive Request for Proposal (RFP) process, inviting multiple cyber security vendors and Managed Security Service Providers (MSSPs) to benchmark their service models and capabilities.

Ultimately, FGH selected SEP2 due to the strength of the Wingman service suite. Rather than offering standard, reactive perimeter monitoring, SEP2’s Wingman MDR Enhanced provided essential brand protection capabilities. Stuart explains: "Standard MDR often focuses solely on reacting to what happens inside your network perimeter. We chose Wingman MDR Enhanced because it extends protection far beyond traditional boundaries."

Proactive threat intelligence, dark web monitoring, and spoofed domain tracking allow SEP2 to safeguard FGH’s digital brand footprint before external threats reach their core trading infrastructure. Stuart notes the necessity of this approach, stating, "In e-commerce, protecting our brand and proactive external exposure is just as important as securing our internal endpoints."

Working with SEP2

The onboarding process with SEP2 was exceptionally smooth and efficient, transitioning FGH into a "business as usual" state rapidly with zero disruption to daily trading operations.

Partnering with SEP2 has drastically reduced mean-time-to-respond (MTTR) on potential security events and eliminated unnecessary alert noise. SEP2's 24/7 UK based SOC handles monitoring and threat mitigation autonomously, escalating only when true action is required. This hands-off model has freed up FGH's small security team to focus on strategic initiatives.

Stuart highlighted the practical impact of the partnership: "As a lean internal security team, being tied down by day-to-day log monitoring and alert triage was inefficient. Partnering with SEP2 has liberated our bandwidth, allowing us to pivot our focus toward high-value strategic goals, such as overarching IT governance, long-term security strategy, and driving security awareness across the wider business."

By transferring routine threat hunting and log management to SEP2’s 24/7 UK-based SOC, internal teams gain the operational freedom to lead high-impact strategic initiatives without risking burnout. This shift is vital for modern security leaders; as Stuart puts it, "Our primary goal was peace of mind, having a professional, reliable 24/7 SOC that allows us to 'sleep at night.' We wanted a hands-off, trusted relationship where we only escalated to when true action is required, eliminating alert fatigue."

Looking to the Future

Moving forward, the partnership with SEP2 provides FGH with the stability and proactive threat intelligence required to support ongoing business growth safely. By relying on SEP2 to secure external brand exposures, endpoints, and access channels around the clock, FGH can confidently innovate and scale its digital footprint.

Reflecting on the relationship, Stuart concluded: "SEP2 is a reliable, pragmatic, and highly effective security partner. They are easy to deal with, highly skilled, and have proven to be a fantastic strategic move for FGH. If you want a trustworthy outsourced security model that lets your team focus on business growth while ensuring complete peace of mind, SEP2 is the right choice."

Testimonials

Hear From Those We Protect

We spoke to other providers, but SEP2 were the only ones who could offer the integrations and compatibility we needed. Once we chose you, it was clear it was the best choice.

We didn’t want somebody who was just going to ship alerts to us and ask us to look into them. We wanted them to do that kind of filtering out for us and then only allow us to escalate when there was something that they really thought we needed to look at.

Partnering with SEP2 has strengthened our ability to protect both our people and our customers. Their collaborative approach and technical expertise have allowed us to enhance our security posture while giving our internal teams the freedom to focus on innovation and strategic priorities.

We knew we couldn’t do it on our own. We didn’t have the time, and we wanted additional expertise to guide us through the process. If we tried to do it ourselves, we’d probably spend a lot of time and effort in the wrong areas.

Emails take time, people miss them even for small things, and you can end up waiting weeks for a response. Having support through channels like Slack makes a real difference. SEP2’s flexibility around how we communicate is something I really value.

During the evaluation process it was clear to me that SEP2 were the strongest candidate from a technical standpoint. During our first meeting, their ability to give immediate solutions to ongoing issues we were experiencing at the time was a breath of fresh air.

SEP2 are knowledgeable, motivated and switched on; they take ownership and they have a drive for resolution. They know their stuff! They are not merely a firewall partner, they are a cyber security partner. They take a strategic approach. They are approachable and offer additional value outside of their support contract. Working with SEP2 means we are no longer fire-fighting; rather we can now take a step back and proactively get things sorted. SEP2 say they are tech driven and people powered, and that’s exactly what they are! It all comes down to the people you are dealing with.

When we hit the limits of our knowledge, it’s having SEP2 there to say, ‘Try these things first.’ That expertise on hand is really important to us.

You’re vendor agnostic, which is key for growth, and your team are providing really good insights in terms of the alerts raised. They also provide meaningful context behind them, which is great for us as an organisation,”

To have people like that around our account that we can pick the phone up to and ask questions was refreshing. Ultimately, we trusted SEP2 and we trust you with our cyber security.

Often the term used is ‘you can’t see the wood for the trees’. Most organisations implement security tooling tools and you’ve got different dashboards. The idea is you put them into a single place, and leverage expert resource such as the SEP2 SOC that actually understands that data and work with it on a daily basis. They can assess it case-by-case and escalate it back to us at Funding Circle only when necessary. And that whole process has been really, really smooth.

They are phenomenal: both personable and very knowledgeable. Our main contact is like a fountain of knowledge. If you ask him a question, he always comes back with ten answers – all the shades of grey, not just a ‘Yes’ or ‘No.’ To me that shows the level of passion he has, and that he really wants to do things properly.

The original group of people who founded SEP2 were very deep in their knowledge of this type of technology, which can be complicated. It’s become the whole field of firewalls, intrusion prevention, antivirus, ransomware, etc. Cyber security as a whole has really ballooned, and there’s lots of dimensions to it, but you’ve managed to keep up.

They live and breathe the technology. It comes from the top, however, everyone is an expert within SEP2, from sales through to the service desk. We don’t want to wait to be told what more we can get from vendors’ products. SEP2 are great in pro-actively helping us achieve value-add solutions. They aren’t about chasing revenues, they are about providing best possible value.

Get the Latest

Wingman Insights

Photo of Paul Starr

Get thoughtful, people-powered cyber insights in your inbox once a month with our Wingman Insights newsletter

Name(Required)

By submitting this form, you are agreeing to our privacy policy.