Advertisement
Advertisement
SendPulse

A1 Pharmaceuticals, Oxford Cancer Analytics and Neville UK: What ‘Managed Detection and Response’ Actually Means in Three Sectors

By Chris Jones · 24 September 2026

Two of these three companies used the same vendor and bought the same technology, one after real financial damage, the other before anything had gone wrong. The third arrived at the same category of product through a decade-long relationship with no incident named at all.

Advertisement
Advertisement

Key Takeaways

  • Three UK businesses, A1 Pharmaceuticals, Oxford Cancer Analytics and Neville UK, all deployed Managed Detection and Response as their central cyber security investment, but each arrived at it from a completely different starting position: one after real financial damage, one as a foundation built in before any incident occurred, and one as the latest chapter in a decade-long relationship with no specific breach mentioned at all.
  • A1 Pharmaceuticals’ investment was reactive in the most direct sense possible. The company suffered a ransomware attack that cost three days of business, then a coordinated Christmas-season breach that cost more than £50,000 and forced it to disconnect its external connectivity entirely. “Cyber security has to be taken seriously,” said Chris Dancer, the company’s Managing Director. “Thanks to the support of Arc and the insights from our past experiences, the changes we’ve made have genuinely paid off.”
  • Oxford Cancer Analytics, working with the same vendor, Arc, took the opposite path: building Sophos MDR, XGS firewalls and GPU-capable infrastructure in from the outset as a young healthcare technology company handling sensitive medical and scientific data, rather than responding to an incident after the fact. “Handling sensitive medical and scientific data requires absolute trust and, from day one, the Arc team provided the infrastructure and expertise we could rely on,” said Luke Hankey, the company’s Head of IT and Software.
  • Neville UK’s story is different again: a decade-long relationship with a different provider, Air IT Group, protecting around 300 users across a 24/7 global operation, with Managed Detection and Response and Managed SIEM layered onto an existing partnership rather than triggered by any single event this publication’s own case study names. “Air IT Group have shown to be the best partner we could have for many years,” said Brian Westfall, the company’s IT Manager.
  • Read together, the three cases show Managed Detection and Response isn’t one kind of purchase with one kind of trigger. It’s the same category of product solving three different organisational problems: recovering trust after real damage, building credibility before it’s tested, and sustaining a long, ongoing relationship. For a UK C-suite, the useful question when evaluating a similar investment isn’t which MDR provider to choose, it’s which of these three starting positions actually describes the organisation making the decision.

Managed Detection and Response shows up as the headline technology in a lot of UK cyber security case studies, and it’s easy to read that repetition as evidence the product itself is the interesting part. Three case studies published on this site, at A1 Pharmaceuticals, Oxford Cancer Analytics and Neville UK, suggest the more useful story is what each company was actually starting from when it bought the same category of product.

A1 Pharmaceuticals: MDR bought after the damage was already done

A1 Pharmaceuticals‘ path to Managed Detection and Response ran directly through two costly incidents. A ransomware attack cost the company three days of business, and a later, coordinated Christmas-season breach cost more than £50,000 and forced the company to disconnect its external connectivity entirely to contain it. That second incident deepened an existing cyber security partnership with Arc rather than starting a new one. “Cyber security has to be taken seriously,” said Chris Dancer, A1 Pharmaceuticals’ Managing Director. “Thanks to the support of Arc and the insights from our past experiences, the changes we’ve made have genuinely paid off; we’ve stopped further attacks, protected our data and strengthened the business.” The resulting deployment combined Managed Detection and Response, multi-factor authentication across every system, upgraded Sophos firewall and antivirus protection, regular penetration testing, and bi-weekly staff cyber awareness emails backed by real-time monitoring. “I now make time for every cyber security conversation, because I know just how much it matters,” Dancer said, a direct statement about how the incidents changed his own attention to the subject, not just the company’s technical posture. The new defences have since caught a financial fraud attempt involving compromised credentials before any money moved, and flagged several other threats early enough to prevent disruption.

Oxford Cancer Analytics: the same category of product, built in before there was anything to react to

Oxford Cancer Analytics, working with the same vendor, Arc, tells a structurally different story with the same underlying technology. As a young healthcare technology company handling sensitive medical and scientific data, OXcan needed secure, high-performance infrastructure that could support rapid expansion while maintaining a strong security posture from the start, not after an incident forced the issue. “Handling sensitive medical and scientific data requires absolute trust and, from day one, the Arc team provided the infrastructure and expertise we could rely on,” said Luke Hankey, OXcan’s Head of IT and Software. The build covered a managed environment for 19 users with endpoint protection and Sophos MDR, Sophos XGS firewalls across six network devices, and high-performance, GPU-capable servers to support machine learning workloads, alongside a migration to Mimecast for email with DMARC improvements. “Their proactive approach and well-designed solutions have played a key role in strengthening our overall security posture,” Hankey said. Nothing in OXcan’s own case study describes a breach, an attack, or a specific triggering event; the investment is framed entirely as groundwork laid ahead of scale, the inverse of A1 Pharmaceuticals’ sequence with the same vendor.

Neville UK: the same product, arrived at through a decade of relationship rather than a single decision

Neville UK PLC, a family business running a 24/7 global operation with roughly 300 IT users, reached the same category of technology, Managed Detection and Response paired with a Managed SIEM, through a different route again: a decade-long IT partnership with Air IT Group, a different vendor from Arc, rather than a single event or a from-day-one build. The case study names no specific incident driving the decision, instead describing an ongoing need for continuous protection, proactive IT support and a stable foundation for the company’s wider technology investment, including a migration to Microsoft Azure delivered as part of the same engagement. “Air IT Group have shown to be the best partner we could have for many years,” said Brian Westfall, Neville UK’s IT Manager. “They provide 24/7 Managed IT Support as well a variety of Cyber Security Services and their deep understanding of our infrastructure and commitment to 24/7 monitoring gives us real peace of mind that we are protected.” “With Air we feel well and truly protected and supported,” Westfall added. “Anytime we need them, they’re there for us!” Where A1 Pharmaceuticals’ quotes describe relief after damage and OXcan’s describe confidence built in advance, Neville UK’s describe something closer to accumulated trust over time, the product of a long relationship rather than a discrete before-and-after moment.

What a UK C-suite should actually take from reading these three together

Two of these three companies used the same vendor, Arc, and arrived at nearly identical technology, Managed Detection and Response layered with Sophos tooling, from opposite starting points: one recovering from real financial and operational damage, the other building the same defences in before anything had gone wrong. The third reached a comparable outcome, MDR and Managed SIEM, through neither a crisis nor a from-day-one build, but a decade of accumulated partnership with a different provider entirely. None of the three case studies describes MDR itself as the differentiator; each one’s own account centres on when and why the decision got made, not which specific product was chosen. For a UK C-suite weighing a similar investment, the practical lesson these three cases suggest is to be honest about which of these three positions actually describes the organisation, already damaged and rebuilding trust, early-stage and building credibility ahead of scale, or established and extending a long relationship, because that starting position, more than the product category itself, is what each of these three companies’ own case studies actually describe as the reason the investment mattered.

Join the CEOs, CIOs, CTOs and CISOs who rely on our insights.

Stay up to date with emerging threats, network infrastructure strategy, compliance and the latest tools.