Bg Shape

Trivium Packaging Case Study

Customer: Trivium Packaging

Contact: Roel Schouten, Vice President Information Security

Industry: Global Metal Packaging Manufacturing

Size: Approx 7,200 employees, operations across 57 locations globally with approximately 50 manufacturing plants.

Partnership: Managed Detection and Response (MDR)

The Customer

Trivium Packaging is one of the world's leading metal packaging manufacturers, producing cans and aerosols for global consumer brands. With manufacturing plants across Europe and the Americas, and approximately 7,200 employees operating in 57 locations, the business runs on uptime. When a plant goes down, the cost is immediate and measurable. For manufacturers facing rising ransomware threats, this partnership shows what enterprise-grade managed detection and response looks like in practice.

The Challenge

For a company like Trivium Packaging, the primary risk is operational resilience. Metal packaging manufacturers hold little intellectual property worth stealing, yet ransomware groups pursue them precisely because production downtime generates leverage fast. Disrupt output, extract a ransom. This is exactly the ransomware protection challenge manufacturing security leaders face today.

Trivium Packaging learned this the hard way. In 2021, the company suffered an enterprise-wide ransomware attack. That incident shaped every security investment that followed.

"Cybersecurity investments are driven by three parameters," Roel explains. "Compliance, risk, and an incident. In our case, it was the risk and the incident that drove us."

The threat landscape has not stood still. Geopolitical instability, AI-assisted vulnerability discovery, and increasingly sophisticated attack groups have made speed of detection, not just prevention, the metric that matters. Roel is direct about this: "I don't think we can patch our way out of the threat. You can patch within an hour and still be vulnerable."

Trivium Packaging needed a multi-layered security strategy covering network segmentation, reduced external exposure, and business continuity planning, and, critically, someone watching the environment around the clock who could act without waiting for a call to be answered.

Why Smarttech247

Trivium Packaging ran a formal RFP process in 2023 and evaluated three shortlisted providers. The technology capabilities across the finalists were broadly comparable. What separated Smarttech247 was the approach.

"It felt like a tailored solution," Roel recalls. "Not like a standard presentation being read from a slide. It felt like Smarttech247 had actually understood our challenges specifically, not just the challenges everyone in manufacturing faces."

That distinction mattered because Roel's internal security team is deliberately lean. With approximately 10 people focused on advisory and analytical work rather than operational tasks, the model only works if the external partner truly functions as an extension of the team, not a separate layer.

"Smarttech247 felt like they were going to be the extended arm of my team. Like they were actually going to be part of the team."

The Partnership in Practice

Smarttech247 provides Trivium Packaging with round-the-clock 24/7 soc monitoring capabilities, filling the gap that a geographically distributed team of 10 cannot maintain alone. Roel has team members in Europe and the US, but an attack at 3am does not wait for a business-hours response.

As part of the MDR solution, Smarttech247 helps Trivium Packaging build use cases, map them against the MITRE Attack frameworks, and continually focuses on extending visibility. Smarttech247 don't just monitor, detect and investigate. A key element of the arrangement is a pre-authorised incident response capability. If Smarttech247 detects a high-confidence attack at any hour, analysts can isolate any system on the Trivium Packaging network without first escalating for approval. This removes the delay that can turn a contained incident into a full breach.

"If they discover a high-confidence attack at 3 o'clock in the night, they can isolate the system, no matter how critical the system is. I don't have 24/7 coverage in my team. It's good to have someone there that we know is helping us around the clock."

Beyond incident response, the partnership has changed how Trivium Packaging's internal team spends its time. With operational security work handled by Smarttech247, the team has shifted from predominantly reactive work to strategic improvement. Over the past two years, that has meant working through Microsoft Secure Score metrics one by one, reducing vulnerability exposure and improving external security ratings through UpGuard.

"We can focus much more on strategic tasks. That wouldn't have been possible if we hadn't had the help from Smarttech247."

The relationship has also extended to red team and purple team exercises, where Smarttech247 analysts have participated actively and learned alongside Trivium Packaging's internal team. That kind of collaboration is closer to a shared security function than a vendor relationship.

The Results

The numbers make the case for managed detection and response investment clear. Response times have moved from hours or days to minutes. In two and a half years of partnership, Trivium Packaging has not had critical incidents, thanks to the approach that Smarttech247 has taken in extending visibility, plugging the gaps and providing a proactive, fast incident response capability. Security posture scores across all three measures Trivium Packaging tracks as guiding indicators have hit their targets. Microsoft Secure Score, internal vulnerability exposure score, and the external UpGuard rating have all improved consistently since the partnership began. Across 5,962 total reports, Smarttech247 identified 1,401 true positives, with just 57 reports (0.96%) escalated to P2 or P3 severity. A false positive rate of 70.1% reflects the inherent noise of a complex global environment, and the value of an MDR partner that filters it before it reaches the internal team.

Since the NoPhish program went live, Smarttech247 has confirmed genuine phishing attacks in roughly one in four submissions reported by Trivium Packaging employees, while triaging out the vast majority as noise so the internal team never had to chase false alarms. Employee reporting volume has grown by more than 80% over the partnership without any drop in triage quality. The confirmed threat rate has stayed consistent every quarter even as volume nearly doubled. Fewer than 1% of all reports ever escalated beyond routine priority, meaning the overwhelming majority of threats were caught and closed before they had any chance to become an incident.

Strategic capacity has grown as the internal team has shifted from reactive operations to proactive security improvement. Work that previously consumed analyst hours now happens within Smarttech247's service, freeing the internal team for higher-value activity.

"At Smarttech247, we build strong partnerships with our customers, and we focus on getting measurable outcomes that help them reduce their security posture. We invest in our relationship with our clients and make it our business to support them in reducing risk and delivering an MDR capability that feels like in-house." Says Raluca Saceanu, CEO Smarttech247.

What Roel Would Tell Another Security Leader

"I can only recommend Smarttech247, and in general the hybrid MDR model. It works very well."

When asked what he would tell a fellow CISO that they would not find in a product sheet, Roel's answer was consistent with how the partnership started. It feels like an internal team.

"That's how it feels. It seems like it's an internal team. They feel very much like real colleagues."

For a security leader running a lean function at a global manufacturer, this is what provides real security value and what separates Smarttech247 from other MDR providers. An external team that feels like an internal one.

See what a true MDR partnership can do for your organisation. Talk to Smarttech247 about extending your security team with 24/7 managed detection and response.