“The first sweep found a global admin who had left the company seven months earlier. That one finding paid for the year.”
SOC 2 Type II · ISO 27001 · 1,400 security teams
SOC 2 Type II · ISO 27001 · 1,400 security teams
Palisade
Palisade
Risk score82/100open
Next page/
Home
Case 03 · Hospitality · 860 seats
An open port, closed before breakfast.
Harbour & ValeSofia Marchetti · Group IT Director

- 4minutes from alert to contained
- 6days the first incident ran, before Palisade
- 34hotels on one timeline
- 01
Challenge
Found openHarbour & Vale has 34 hotels and a two-person IT team. A phishing mail to a night manager led to a mailbox rule that forwarded invoices for six days before anyone noticed.
- 02
Approach
In progressRespond was switched on with three playbooks: lock the account, revoke its sessions, and tell the on-call engineer what happened and why.
- Suspicious sign-ins are contained automatically
- Mailbox rules that forward outside the company raise a finding
- Every incident ends in a one-page report
- 03
Result
SecuredThe next attempt, four months later, was contained in four minutes at 3 am. The IT director read about it at breakfast.
Case 03 · Hospitality · 860 seats
An open port, closed before breakfast.
Harbour & ValeSofia Marchetti · Group IT Director

- 4minutes from alert to contained
- 6days the first incident ran, before Palisade
- 34hotels on one timeline
- 01
Challenge
Found openHarbour & Vale has 34 hotels and a two-person IT team. A phishing mail to a night manager led to a mailbox rule that forwarded invoices for six days before anyone noticed.
- 02
Approach
In progressRespond was switched on with three playbooks: lock the account, revoke its sessions, and tell the on-call engineer what happened and why.
- Suspicious sign-ins are contained automatically
- Mailbox rules that forward outside the company raise a finding
- Every incident ends in a one-page report
- 03
Result
SecuredThe next attempt, four months later, was contained in four minutes at 3 am. The IT director read about it at breakfast.
Case 03 · Hospitality · 860 seats
An open port, closed before breakfast.
Harbour & ValeSofia Marchetti · Group IT Director

- 4minutes from alert to contained
- 6days the first incident ran, before Palisade
- 34hotels on one timeline
- 01
Challenge
Found openHarbour & Vale has 34 hotels and a two-person IT team. A phishing mail to a night manager led to a mailbox rule that forwarded invoices for six days before anyone noticed.
- 02
Approach
In progressRespond was switched on with three playbooks: lock the account, revoke its sessions, and tell the on-call engineer what happened and why.
- Suspicious sign-ins are contained automatically
- Mailbox rules that forward outside the company raise a finding
- Every incident ends in a one-page report
- 03
Result
SecuredThe next attempt, four months later, was contained in four minutes at 3 am. The IT director read about it at breakfast.
What teams say
The first sweep usually pays for the year.
Security and IT leads on what turned up in week one, and what they stopped worrying about after.
“It ranks by what an attacker would do next. My team stopped arguing about severity and started closing things.”
“Our auditor logged in, read the evidence and left. No screenshots, no spreadsheet, no three-week scramble.”
“A key hit a public repository at 2 am. Palisade had it revoked before I had found my glasses.”
“Depot managers fix their own devices now, because the message tells them exactly what to press.”
What teams say
The first sweep usually pays for the year.
Security and IT leads on what turned up in week one, and what they stopped worrying about after.
“The first sweep found a global admin who had left the company seven months earlier. That one finding paid for the year.”
“It ranks by what an attacker would do next. My team stopped arguing about severity and started closing things.”
“Our auditor logged in, read the evidence and left. No screenshots, no spreadsheet, no three-week scramble.”
“A key hit a public repository at 2 am. Palisade had it revoked before I had found my glasses.”
“Depot managers fix their own devices now, because the message tells them exactly what to press.”
What teams say
The first sweep usually pays for the year.
Security and IT leads on what turned up in week one, and what they stopped worrying about after.
“The first sweep found a global admin who had left the company seven months earlier. That one finding paid for the year.”
“It ranks by what an attacker would do next. My team stopped arguing about severity and started closing things.”
“Our auditor logged in, read the evidence and left. No screenshots, no spreadsheet, no three-week scramble.”
“A key hit a public repository at 2 am. Palisade had it revoked before I had found my glasses.”
“Depot managers fix their own devices now, because the message tells them exactly what to press.”
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected
Start here
Run the sweep on your domain.
Tell us where to look. We set up a read-only connection with you on a short call, and you see your own findings the same day.
We will sweep
- Identity providerNot connected
- Cloud accountsNot connected
- DevicesNot connected
- Code repositoriesNot connected