How British Land Catches Threats Early and Negates Risks Outside of 9-to-5 Work Hours

For British Land, risk comes with the territory—literally. The property company creates, owns, and manages some of the UK's best real estate. Since threat actors actively hunt high-profile organizations for maximum impact, British Land's prestigious public profile brings a different level of exposure and puts a target on their back.
As a FTSE 100 company, there’s a profile attached to us that means hackers are potentially choosing us as a victim.
Julian operates under the assumption that it's not a question of if a high-profile organization will face an attack, but when. For an enterprise managing high-quality offices, corporate campuses, and retail parks across the UK, a cyber incident is a direct threat to daily operations as it could disrupt tenants, expose data, and damage British Land's premium brand reputation. British Land's lean internal security team had mature systems in place, but modern attackers can break into a network and gain a significant foothold within minutes. Without after hours coverage, they were susceptible to attackers accessing their environment undetected.
Strong security is the foundation of business continuity and public trust. British Land needed a way to defend themselves even when the office lights go out.
Connecting the dots across a fragmented toolset
- The 9-to-5 gap: British Land’s “small but strong” cyber team worked 9-to-5 in a 24-hour threat landscape, making it impossible to create an around-the-clock SOC that would stop attackers trying to access their environment at any time.
- Data fragmentation: British Land’s security tools picked up most signals, but lacked a way to connect the disparate data streams and various alerts into a single security story.
- Visibility blind spots: The existing visibility and coverage gaps meant they couldn't identify the "slow and low" signals of an early-stage attack and increased the likelihood that they would miss a threat after hours.
We had a small number of security incidents in the past, we wanted to tighten our security and make sure we had the best solution in place.
What they needed was a security operations partner to help them connect those data dots, become an extension of their existing team, and create more business resilience. By leaning on specialized external expertise to surface hidden risks immediately and transform fragmented data into clear, actionable intelligence, they could drastically accelerate their response times and insulate their commercial operations from more security incidents. British Land launched the selection process with the same rigor they apply to their real estate portfolio solutions: methodically and with no room for error. A long list of vendors became a shortlist of three, and then one. For Julian, the technical capabilities of a solution were top priority, followed by the depth of the partnership. The reference calls with existing customers cemented their decision.
They were extremely complimentary about Rapid7 and noticeably more positive than other shortlisted suppliers. Rapid7 was eager to listen to our requirements and ready to provide a tailored solution to match what we needed.
Beyond a tailored approach, British Land gained a partner with deep macro-level expertise, who would actively apply global threat intelligence gathered across various client environments to decisively identify and catch sophisticated threats before they could impact operations.
A massive step forward in visibility and response
New security implementations can sometimes be painful, but the experience with Rapid7 was straightforward. It started with a proof of concept (POC) for Managed Detection and Response (MDR). Rapid7 offered technical expertise to make the POC run smoothly, allowing the team to get a "good feel" for the service and Rapid7's SIEM technology that underpins it.
With all the assistance Rapid7 gave us, it was a pleasurable experience compared to other projects I've worked on.
British Land continued to feel the difference post-deployment. Rapid7 MDR gives British Land around-the-clock monitoring and support without the complexity or cost of building a large in-house SOC. It continuously investigates suspicious activity, escalates high-risk incidents and helps contain threats quickly.
Once we’ve had an alert, the information is easy to understand within the Rapid7 dashboard. We’ll investigate locally, while liaising with Rapid7’s SOC to come to a strong solution. Before Rapid7, we wouldn’t have had that visibility.
Continuous support that never clocks off
British Land doesn’t have to worry about after-hours coverage anymore. Rapid7 is there to catch anything suspicious between the end of one business day and the start of another.
It gives me peace of mind that Rapid7 are monitoring our environment outside our 9-to-5 and are there to react and alert us if there's a major incident. If they can't get hold of us, they have the ability to act and negate an incident on our behalf.
As for that partnership British Land wanted, Rapid7 delivered on that, too.
Julian describes the relationship as “straightforward, responsive, and collaborative.” Regular meetings never feel like box-ticking exercises. Instead, Rapid7 always brings value to the table.
Monthly catchups are always productive and give us the information we need. The reporting from Rapid7 is particularly strong and helps us justify to leadership that the investment we've made is delivering benefit during critical situations.
Rather than delivering static data, these reporting mechanisms support the team by providing clean operational metrics and statistics. This data tracks the company's security evolution and demonstrates measurable improvement over time. For Julian, it also acts as a kind of insurance policy, one that always pays out.
You hope it'll be there when you need it and we’ve seen evidence that Rapid7 are there, are monitoring, and have always got our backs.
Catching threats long before they become crises
In security, speed matters. Without Rapid7, British Land would be much more exposed with less capacity to move quickly if necessary.
If we didn't have the solution in place, we would be much less likely to identify incidents early. And with all cyber threats, acting early is of critical importance.
Instead, Julian feels peace of mind that they have such a forward-thinking security partner.
My experience with Rapid7 has been very positive,. Their technical expertise, understanding of the threat landscape and the way they support our small cyber team means
they are an extension of our company — and a trusted partner.
The stakes for high-profile companies are huge: reputation, operations, and trust. British Land wanted a partner ready to respond when it mattered most. And Rapid7 is there for that.

