Zeus Capital validates its cyber defences with Thrive risk assessment

Customer story · Financial Services

Thrive Fortifies Zeus Capital's Secure Expansion in the UK Financial Services Sector

Zeus Capital, a Manchester-based investment bank, engaged Thrive for a Cybersecurity Risk Assessment against the CIS framework and an autonomous penetration test, remediating gaps and presenting a robust security strategy to its board.

  • Originally published by Thrive (Thrive Networks) · June 2024
  • Posted here September 13, 2026
  • 3 min read
Zeus Capital case study

About Zeus Capital

Zeus Capital is a Manchester-based, FCA-regulated investment banking firm. The company operates with a limited internal IT team and has been expanding while increasing its reliance on technology. In the wake of significant changes, Zeus prioritised aligning its cybersecurity practices with financial services industry standards and wanted an independent third-party evaluation to demonstrate its commitment to secure digital operations.

The challenge

Zeus Capital faced the challenge of managing its information security with a limited internal IT team. As the company expanded and its reliance on technology grew, it wanted to strengthen its security measures and needed a comprehensive assessment that stayed within budget and adhered to specific requirements. It lacked the expertise and resources to carry out that work internally.

In the wake of significant changes, Zeus prioritised aligning its cybersecurity practices with financial services industry standards. As an FCA-regulated investment bank, it wanted an independent third-party evaluation of its cybersecurity to demonstrate its commitment to secure digital operations and to give its board clarity on regulatory compliance.

Zeus also wanted a partner focused on its actual needs. Some competitors pushed unnecessary services, whereas Zeus was looking for a receptive approach, a transparent methodology and the breadth of capability to support future cyber initiatives as part of a long-term partnership.

Thrive's approach was not just about ticking boxes; it was about truly understanding our security posture and helping us navigate the complexities of cybersecurity in our industry. Their partnership has been instrumental in affirming our security foundations and identifying areas for improvement.

David Boulton, Head of IT, Zeus Capital

The solution

Zeus selected Thrive for its extensive expertise in the investment sector and its proven strategic consulting capabilities. Thrive developed a customised cybersecurity framework for Zeus, aligned with the firm's unique business model and risk appetite, and committed to understanding the company's objectives rather than pushing services it did not need.

Thrive conducted a Cybersecurity Risk Assessment, evaluating Zeus's security policies, processes and controls against the globally recognised CIS framework. The assessment gave Zeus a clear understanding of its security posture and identified areas for improvement. Thrive then carried out an autonomous penetration test, a simulated cyber attack on Zeus's systems, to identify potential security gaps so the firm could take proactive measures to address them.

With this knowledge, Zeus remediated its weaknesses and presented a robust security strategy to its board. Thrive's services also enhanced staff awareness of cybersecurity, equipping employees with the knowledge and skills to identify and respond to potential threats. Thrive's expertise, collaborative approach and commitment to ongoing support position the engagement as the beginning of a long-term strategic partnership focused on keeping Zeus ahead of emerging threats.

The results

  • Security policies, processes and controls assessed against the CIS framework, giving a clear view of the firm's posture
  • Autonomous penetration test identified potential security gaps, which Zeus then remediated
  • Board reassured about regulatory compliance and presented with a robust security strategy
  • Staff awareness of cybersecurity improved, with employees better equipped to identify and respond to threats
  • Effectiveness of pre-existing security measures affirmed while areas for improvement were identified

Get the full case study

Download the original document as published by Thrive (Thrive Networks) (PDF, 194.3 KB).

Download the case study

Your story could be next

Want results like these?

Every result on this page started with one conversation — let's have yours.