Case Studies / Risk and controls
"Are we exposed?" answered in minutes: how a UK insurer connected live threats to its own controls.
A large insurance company in the UK · Security risk and controls function
Use case
Threat-informed risk management: tracking threats to specific assets, technologies and suppliers, and mapping them to mitigating controls.
Goal
Ground control and investment decisions in the threats actually facing the organisation's estate, and find the gaps before they matter.
Challenge
The team could list its assets and its controls, but connecting live threat activity to either was manual, slow, and always out of date.
Solution
Liberty91 monitors the organisation's declared assets, technologies and suppliers continuously, surfaces the techniques used against them, and weighs developing threats against the defences already in place.
The challenge.
The security risk function at this insurer thinks in assets, suppliers and controls, not in threat actor names. Their standing questions are practical ones: what is targeting the technology we actually run? Which of our suppliers is being hit, and with what? And when a technique is trending against our sector, do our controls cover it, or is there a gap? Answering those questions meant an analyst manually joining vendor reports to an asset inventory to a controls framework, and the answer was stale by the time it was assembled.
What changed.
The organisation's estate lives in Liberty91 as monitored assets, technologies and suppliers, each with a continuously maintained threat profile. When a vulnerability lands in a technology they run, or a supplier they depend on is compromised, the relevant threat events surface with the connection to their environment already made. Because ATT&CK techniques on the platform are evidence-grounded, recorded when a report documents an actor actually using them, the team can see the top techniques observed against their sector and their technologies, with dates and sources, rather than a theoretical catalogue. Developing threats are weighed against the defences the organisation already runs, so the team can see which threats matter most against what is coming, identify the mitigating controls most likely to be effective, and spot where their gaps are. Budget conversations moved from "we should invest in this because everyone is" to "this technique cluster is active against our stack and here is where our coverage is thin".
The result.
Threats around specific assets, technologies and suppliers are identified and tracked continuously without manual correlation, the top techniques in use against their estate are visible with supporting evidence, and mitigating controls are prioritised by likely effectiveness against live activity, with the gaps feeding straight into the security investment plan.
260 assets, 40 suppliers
Under continuous, profile-aware threat monitoring from the first week.
Days to minutes
Time to answer "are we exposed to this?" for a breaking vulnerability or supplier compromise.
14
Control coverage gaps identified against live threat activity in the first quarter, each fed into the investment plan.
“It speaks threat on one side and controls on the other. That translation is exactly the work we were doing by hand, and it never kept up.”
Head of Security Risk, a large insurance company in the UK
Evidence gathered through a customer interview, 2026. The customer has asked not to be named; role and organisation verified by Liberty91.
See your estate the way the threats do.
More case studies.
The analyst team
How a UAE energy major's threat intelligence team went from manual collection and days of delay to briefing leadership before anyone else raises it.
The MSSP
How a regional MSSP turned threat intelligence into a priced, sellable service line for 30 customers, delivered under its own brand.
The CISO
How a large UK bank replaced an expensive CTI programme that had no capacity left for analysis with intelligence its stakeholders act on, from day one.
Premium intelligence, operationalised
How a UK financial services group turns CrowdStrike and Google Threat Intelligence reporting into organisation-specific assessment and action.