25/08/2026
Why aren’t growing businesses using cyber security to unlock revenue?
Many businesses view cyber security as an insurance policy: a cost with minimal visible upside, but catastrophic potential downside. You…
Published: 27/08/26
One year ago, SEP2 officially announced our strategic partnership with Google Cloud to embed Google Threat Intelligence (GTI) directly into our cyber security operations.
Since we made that announcement, our goal has been to integrate the combined telemetry of Google, Mandiant’s frontline intelligence, and VirusTotal’s massive malware corpus into our 24/7/365 UK-based Security Operations Centre (SOC).
Twelve months later, this partnership has transformed from a milestone announcement into a core driver of proactive defence for our customers. Here is a look at what we’ve achieved, how our SOC has evolved, and how we are delivering tangible protection to organisations across diverse industries and complex tech stacks.
Over the past year, uptake for GTI-powered services has accelerated rapidly:
The threat landscape in 2026 requires catching early-stage reconnaissance before it escalates into active intrusion. Our Digital Threat Monitoring, powered by GTI, has provided critical early warning indicators across the deep and dark web.
Nearly every organisation (all but one) operating on Wingman MDR Enhanced had employee credentials surfaced on dark web forums or illicit leak sites during the past 12 months.
These detections ranged from targeted “sale-of-access” listings to massive third-party SaaS data dumps containing corporate email addresses.
Real-World Case Study: Dark Web Credential Interdiction
Threat actors continue to shift tactics away from generic, mass-Phishing campaigns toward targeted edge exploitation and interactive social engineering.
According to frontline threat metrics from the latest Mandiant M-Trends reporting alongside SEP2 SOC telemetry, actor activity remains heavily concentrated across specific sectors while maintaining a broad reach across the entire market.
| Industry Vertical | Targeting Frequency | Common Attack Vectors Observed |
| Legal & Professional Services | 8.9% | Third-party SaaS token theft, Edge VPN exploitation, Dark Web access sales |
| Manufacturing | 8.0% | Supply chain compromises, Network perimeter abuse, Ransomware hand-offs |
| Education | 6.5% | Credential harvesting, Session hijacking, ClickFix social engineering |
| All Other Sectors | 78.0% | Diverse spread including High-Tech, Financial, and Healthcare targets |
Operating across diverse geographies, our SOC monitors a wide array of threat clusters. In recent weeks, SEP2 analysts directly intercepted and contained Russian-nexus disruption campaigns specifically targeting UK infrastructure and enterprise organisations.
Having access to Mandiant frontline insights allows our analysts to perform accurate attribution on common and state-aligned threats. Understanding the specific threat actor’s motivations and typical TTPs allows both our SOC team and our clients to clearly assess residual risk and execute targeted remediation steps rather than relying on generic playbooks.
Integrating the full VirusTotal corpus has fundamentally altered how our analysts triage, enrich, and sandbox incoming alerts.
By having immediate access to VirusTotal’s contextual data, file reputation engines, and automated detonation pipelines, our SOC has established a solid baseline of telemetry that cuts through investigative noise.
Powered by Wingman AI (Casey)
Following our GTI partnership, we launched our Agentic SOC powered by Wingman AI, featuring our autonomous AI Investigation Agent, Casey.
Casey natively ingests Google Threat Intelligence feeds and is trained on Mandiant’s security incident data lakes. When an alert fires:
The attack surface is rapidly evolving. Threat actors are blending perimeter edge targeting, hyper-personalised vishing, cloud-native identity hijacking, and ClickFix techniques into complex, multi-stage campaigns.
Whether you are looking to enhance your MDR capabilities through Wingman MDR or want to deploy Google Threat Intelligence / Google Security Operations Enterprise+ inside your own estate, SEP2 is ready to guide your journey.
Want to learn more about how Google Threat Intelligence and SEP2’s Wingman MDR can protect your organisation? Contact the SEP2 Cyber Security Team today.
25/08/2026
Many businesses view cyber security as an insurance policy: a cost with minimal visible upside, but catastrophic potential downside. You…
19/08/2026
Explore key insights from Spectrum and SEP2 on the innovative Detection-First Agentic SOC and its impact on cyber security strategies.
23/07/2026
At SEP2, we are firm believers that world-class cyber security relies just as much on human empathy and strong relationships…
Get the Latest