Aegis Console

←  Customer stories

Meridian Public Works

Two people, forty-one services, and nobody to outsource to

Meridian's entire security function is two people who also run the platform. They did not need a SOC. They needed the six alerts a week that were actually worth reading.

Sector
Local government
Estate
Azure · 310 workloads · AKS + App Service
Regions
uksouth
Plan
Team
Customer since
January 2026
  • 6Pages per weekwas 38 from the previous cloud-native tool
  • 2People on the security teamboth also on platform on-call
  • 9 daysRollout to full coverage310 workloads, one engineer, part time
  • £10.8kAnnual costTeam plan, 3 subscriptions, unlimited read-only seats

We were sold a managed SOC twice. Both times the pitch assumed we had someone to receive the phone call. We don't. We needed fewer, better alerts — not a stranger reading the same noise back to us at four in the morning.

Callum BeattieLead Platform Engineer, Meridian Public Works

Meridian runs the digital services for a metropolitan council of 480,000 residents: waste booking, planning applications, licensing, parking, a benefits portal. Forty-one services, 310 workloads, and a security team of two who are also the platform team of two.

Why the usual answer does not work

The standard advice for a team this size is to buy a managed detection and response service. Meridian priced two. Both quoted more than their entire tooling budget, and both assumed a 24/7 receiving function on Meridian’s side — someone whose job is to be woken up. That person does not exist and cannot be hired into a local authority pay band.

The other standard answer is a cloud-native security tool from their cloud provider, which Meridian had. It generated 38 alerts a week. Callum’s honest description: “We read them for five months and then we stopped, which is worse than not having it, because we were paying for the feeling of being covered.”

What the nine-day rollout looked like

Day one to three: connect three Azure subscriptions, Entra ID, and Azure DevOps. Read-only at first. Aegis spent the time learning baselines and opened nothing.

Day four to seven: deploy the AKS sensor to the four clusters, one per day, with a rollback after each. Observed CPU overhead on their nodes was 0.6% median, 1.3% at p99 — Callum measured it himself rather than take our number, which we encourage.

Day eight and nine: tune. Eleven detections were disabled outright because they describe patterns Meridian does not have (no Kubernetes secrets in env vars — they use CSI driver; no long-lived service principals — everything is workload identity). Disabling a detection you have read and understood is a better outcome than muting an alert you have not.

Six a week

Across the first six months, Meridian has averaged six situations a week. Of those, roughly four are self-inflicted — a developer testing something in the wrong subscription, a misapplied network policy, a certificate nobody renewed. Two a week are worth a conversation. One a month is worth an incident ticket.

Nobody has been paged at four in the morning. Two of the six months contained genuine attempted account takeovers against Entra ID, both caught during working hours, both resolved in under an hour, neither escalated beyond the two of them.