Expedition Growth Capital is a growth equity firm with around $1bn in assets under management, investing in software companies that have already proven they can grow without much outside help. With offices in London and Boston, they are a regulated firm with a transatlantic team that’s rarely in one place for long. Will Sheldon, Partner and Jenny Calbraith, Head of Office there, both share their account on partnering with ThreatSpike.
Provisioned, Never Visible
For over a year, Expedition ran on an external MSP for core IT, plus a handful of point solutions covering email and other pieces of the security stack. The billing alone was a recurring headache, but the real problem sat underneath it, in the visibility nobody had built.
Jenny had no straightforward way to answer basic questions: which devices belonged to which employees, what was installed on them, whether security patches were actually going out. The MSP had provisioned the hardware well enough, but nobody had thought to build the reporting that should have come with it.
“Security and IT in general is critically important to us,” Will says. “We’re a regulated firm, we have a lot of compliance requirements but also operational complexity. We have a transatlantic footprint and our team is constantly travelling.”
Add in a team experimenting with new AI tools every week, and the gaps in coverage weren’t staying theoretical for long.
The Weekend Microsoft Went Dark
Then it stopped being theoretical altogether. Microsoft access went down, followed by SharePoint not long after, and Expedition’s team found themselves locked out of the systems they run an investment firm on, on a weekend, with no clear way back in.
“We had a specific incident where our external website and internal IT resources went down over a weekend,” Will says. “It was a lightbulb moment. We’re paying for a number of different providers, but actually not getting what we needed for our operational resilience.“
Jenny says “Not knowing what’s happened to your IT is terrifying”. “You don’t want it on a weekend, and you definitely need to have the information you need in one place when that happens.” The outage itself didn’t create the problem, it just made the cost of carrying on with it impossible to justify any longer.
One Partner Instead of Managing Many
So Expedition went back to the market and found ThreatSpike with a holistic offering – housing fully managed IT and security in one platform, run by one team. They weren’t shopping for a better helpdesk, but for one place where IT and security lived together, rather than several vendors who could each point at one another the next time something broke.
From Blind Spots To Full Visibility
The improvements started happening almost immediately. In place of a support ticket queue, Jenny got a live, structured view of the whole estate: who was logged into which device, the security posture of each endpoint, the updates and applications running across the firm.
“I am the IT team at Expedition,” she says. “Having the ThreatSpike team as the extension of our IT department has been wonderful. They’re proactive. They come to me with recommendations and implementations I haven’t thought of yet. Or if I raise something, ask a question, put in feedback, I get a response as if they’re reporting it to me.“
When new FCA guidance landed, Jenny raised it as a concern, and within days ThreatSpike had produced a full analysis of what it meant operationally for Expedition, with a clear implementation plan attached. It also caught things nobody had asked it to catch. ThreatSpike doesn’t manage Expedition’s website, a separate provider does, but its monitoring flagged an issue there ahead of that provider, weekend included, giving Expedition the kind of early warning the old setup never managed.
The smaller, more human risks didn’t slip through either. Staff testing new AI tools, as staff everywhere now do, occasionally put sensitive or personal data into them without thinking twice, and ThreatSpike alerts on that instantly, alongside the more routine security baseline.
Costs Down 38% & Everything Faster With It
IT costs dropped 38% once ThreatSpike replaced the main MSP and the stack of point solutions sitting alongside it. Most of that saving came from collapsing several contracts, several bills and several vendors into one, and with it, the admin overhead of keeping them all pointed in the same direction.
Due diligence tells the same story from a different angle. What used to mean several days spent digging for answers that should have taken minutes now takes a single working day, because the data and the controls behind it are already documented, rather than assembled from scratch each time someone asks.
Why Expedition Are Recommending ThreatSpike
Expedition has recommended ThreatSpike across the industry since, for reasons Jenny puts down to more than just the cost saving.
“Somebody in a similar position to me, or as I was, I’d highly recommend you go and have that conversation with ThreatSpike,” she says. “Find out what their team can bring to your team. The expertise, the knowledge, the peace of mind. It’s made my job less stressful. Just have that conversation.
For lean teams carrying IT and security responsibility on top of everything else, the choice usually looks like more vendors or more risk. Expedition found a third option instead: one platform, built to run and defend at the same time, at a price that doesn’t move.