Case Study

Motorway

What we did for Motorway

Industry: Automotive

Published: 07/09/2026

Motorway

Project Overview

Motorway required a robust, scalable security operations function to protect its rapidly expanding automotive marketplace and new financial services entity, Motorway Pay. By partnering with SEP2, the organisation sought to eliminate critical visibility gaps by deploying SEP2’s Wingman MDR service. The project focused on transitioning from no established security operations to a high-maturity detection and response capability, powered by Google SecOps and driven by SEP2’s 24/7/365 UK-Based SOC to manage, triage, and remediate threats in real-time.

The Challenge

  • Zero threat monitoring visibility.
  • No established security operations.
  • Rapidly scaling payment entity.
  • High-volume transaction data risks.

The Solution

  • SEP2’s Wingman MDR service.
  • Managed 24/7/365 UK-Based SOC.
  • Proactive threat remediation playbooks.
  • Google SecOps platform integration.

Who is Motorway?

Motorway is a UK-based online used-car marketplace that connects private sellers directly with a network of over 8,000 professional dealers. Founded by serial entrepreneurs to fix the "middleman" model, Motorway has rapidly scaled into an ambitious, high-growth organisation, facilitating over £2 billion in annual sales. With the recent launch of Motorway Pay, the company now handles significant volumes of financial transactions alongside its daily national auctions, with more than £10B of transactions processed to date. Operating in a fast-paced "scale-up" environment with 450 employees, the business faced a monitoring visibility gap. They needed to build out their security function, enabling it to scale alongside a rapidly changing, high-growth organisation while protecting sensitive financial transaction data.

Why Motorway Chose SEP2

Motorway required a partner that could match the technical requirements of their platform while providing the flexibility needed for a high-growth business. Stavros Eleftherakis, Security Operations Lead at Motorway explained: “The technology had to be a good fit, but also the ability to scale up and down depending how the plans change, and this partnership offered both, that's why it was a big win.” Beyond the tech, the choice was driven by a desire for a local, personal connection. Stavros went on to say, “We are a UK company as well so it was a good plus to have a UK company. We didn't want to go with some of the bigger players because we wanted to have that communication and connection.

The deciding factor was the flexibility of SEP2’s Wingman MDR and its adaptable approach to support, which aligned with Motorway's fast-paced internal culture. “The biggest factor was that it felt like whatever we needed, it would be covered,” Stavros says. “This sort of approach was really good for us because as a scale up startup organisation, inherently we are chaotic. There's no way you can pre-plan things and have a clear plan, it is chaotic and it constantly changes and we needed a partner that can do that dance.”

Working with SEP2

The partnership delivered value immediately, through a seamless transition to the Wingman MDR service and high-quality operational support. Reflecting on the start of the engagement, Stavros said: “I was really impressed with the onboarding, it sold it to me because I was in the vendor world. I know what you can do... so I knew the struggles and what good and bad looks like, and this felt like I didn't even have to spend any time on it.” This efficiency extended to the platform's usability, with Stavros noting that compared to other tools, the learning curve for Google SecOps is “literally non-existent.”

Day-to-day operations are supported by a structured, consistent team that understands Motorway’s unique environment. “We worked with the same people from implementation all the way from the first steps,” Stavros explained. “So the people knew the history and everything you were talking about had context. You don't have to constantly go around in circles.” This consistency, paired with the sophisticated structure of SEP2’s 24/7/365 UK-Based SOC, has ensured a high standard of protection. As Stavros concludes: “Other things that we've seen afterwards with how the SOC works, there's a clear escalation line. There's different niches, different teams that do different areas... communication has been excellent. You can't really ask for anything more.”

Looking to the Future

For Motorway, the priority is to ensure their security posture evolves as quickly as their business model. As they continue to expand the capabilities of Motorway Pay and handle increasing transaction volumes, the focus remains on maintaining a proactive and innovative defense. Stavros highlights that the long-term success of the project relies on a partner that shares their vision for constant improvement: “You want to see that the other company is trying to evolve and get better. We definitely see that... [SEP2 is] not afraid of change and looking to improve things constantly rather than saying 'this works, let’s leave it for now.' Even scary changes, like changing how playbooks work by default, show that someone is looking at it and saying, 'this is not clean enough, we need to do a better job here.'”

This commitment to "good housekeeping" and technical adaptation, such as SEP2’s early adoption of new technologies, gives Motorway the confidence to scale. As Stavros puts it, seeing a partner that is "already on it" when new challenges emerge is exactly what a high-growth business needs to "keep moving together" into the future.

Testimonials

Hear From Those We Protect

We spoke to other providers, but SEP2 were the only ones who could offer the integrations and compatibility we needed. Once we chose you, it was clear it was the best choice.

We didn’t want somebody who was just going to ship alerts to us and ask us to look into them. We wanted them to do that kind of filtering out for us and then only allow us to escalate when there was something that they really thought we needed to look at.

Partnering with SEP2 has strengthened our ability to protect both our people and our customers. Their collaborative approach and technical expertise have allowed us to enhance our security posture while giving our internal teams the freedom to focus on innovation and strategic priorities.

We knew we couldn’t do it on our own. We didn’t have the time, and we wanted additional expertise to guide us through the process. If we tried to do it ourselves, we’d probably spend a lot of time and effort in the wrong areas.

Emails take time, people miss them even for small things, and you can end up waiting weeks for a response. Having support through channels like Slack makes a real difference. SEP2’s flexibility around how we communicate is something I really value.

During the evaluation process it was clear to me that SEP2 were the strongest candidate from a technical standpoint. During our first meeting, their ability to give immediate solutions to ongoing issues we were experiencing at the time was a breath of fresh air.

SEP2 are knowledgeable, motivated and switched on; they take ownership and they have a drive for resolution. They know their stuff! They are not merely a firewall partner, they are a cyber security partner. They take a strategic approach. They are approachable and offer additional value outside of their support contract. Working with SEP2 means we are no longer fire-fighting; rather we can now take a step back and proactively get things sorted. SEP2 say they are tech driven and people powered, and that’s exactly what they are! It all comes down to the people you are dealing with.

When we hit the limits of our knowledge, it’s having SEP2 there to say, ‘Try these things first.’ That expertise on hand is really important to us.

You’re vendor agnostic, which is key for growth, and your team are providing really good insights in terms of the alerts raised. They also provide meaningful context behind them, which is great for us as an organisation,”

To have people like that around our account that we can pick the phone up to and ask questions was refreshing. Ultimately, we trusted SEP2 and we trust you with our cyber security.

Often the term used is ‘you can’t see the wood for the trees’. Most organisations implement security tooling tools and you’ve got different dashboards. The idea is you put them into a single place, and leverage expert resource such as the SEP2 SOC that actually understands that data and work with it on a daily basis. They can assess it case-by-case and escalate it back to us at Funding Circle only when necessary. And that whole process has been really, really smooth.

They are phenomenal: both personable and very knowledgeable. Our main contact is like a fountain of knowledge. If you ask him a question, he always comes back with ten answers – all the shades of grey, not just a ‘Yes’ or ‘No.’ To me that shows the level of passion he has, and that he really wants to do things properly.

The original group of people who founded SEP2 were very deep in their knowledge of this type of technology, which can be complicated. It’s become the whole field of firewalls, intrusion prevention, antivirus, ransomware, etc. Cyber security as a whole has really ballooned, and there’s lots of dimensions to it, but you’ve managed to keep up.

They live and breathe the technology. It comes from the top, however, everyone is an expert within SEP2, from sales through to the service desk. We don’t want to wait to be told what more we can get from vendors’ products. SEP2 are great in pro-actively helping us achieve value-add solutions. They aren’t about chasing revenues, they are about providing best possible value.

Get the Latest

Wingman Insights

Photo of Paul Starr

Get thoughtful, people-powered cyber insights in your inbox once a month with our Wingman Insights newsletter

Name(Required)

By submitting this form, you are agreeing to our privacy policy.