Circle K Achieves Detection as Fast as 4 Seconds with GreyMatter Transit

Circle K is one of the world's largest convenience and fuel retail operators, managing 17,000+ store locations and 25 fuel distribution centers across North America, Europe, and Asia.

Turning obstacles into outcomes
Challenges
A 35-person global security team responsible for securing a $74 billion operation spanning corporate, retail, fuel distribution, and customer data environments
25–35 minute mean time to detect on firewall data—a delay that could cost millions in lost revenue at fuel terminals
Manual containment requiring senior analysts with 15+ years of domain knowledge to classify devices and determine appropriate response actions across distinct environments
Threat actors moving faster than the team could investigate and contain, with alert noise burying real signals
Results
SOC analysts shifted from reactive incident response to proactive threat hunting across the organization
Mean time to detect reduced to sub-10 seconds—as fast as 4 seconds—on firewall data flowing through GreyMatter Transit
Mean time to contain reduced to under 1 minute by combining Transit, Agentic Teammates, and automated workflows
99% reduction in alert noise over 6 months through 20 new Agentic Memories encoding senior analyst decision logic
Overview
Circle K is a proud low-cost operator. Its 35-person security team covers governance, third-party risk, security operations, architecture, and cloud for a $74 billion company operating across four distinct data environments: fuel distribution, corporate, customer, and workforce identity. With no room to scale through headcount, the team needed to implement AI that could carry the operational knowledge of a 15-year veteran and act on it autonomously.
“We needed to reduce the threat actor's time in our environment to reduce overall exposure and potential loss of data or operational activities."
Patrick O'KeefeHead of Global Cybersecurity Operations & Risk Management,
Alimentation Couche-Tard (Circle K)
Firewall data at fuel terminals alone carried a 25–35 minute detection delay—every minute of which compounded that exposure across environments where a wrong response carries seven-figure consequences.
Detection Delays at Fuel Terminals: A Million-Dollar Exposure
Circle K's most sensitive detection challenge sat at 25 fuel distribution centers—critical infrastructure sites where every minute of undetected attacker activity compounds exposure. Firewall data from these environments followed the traditional path: collected, shipped to centralized storage, indexed, then finally correlated and detected. By the time an alert surfaced, threat actors already had a 25–35 minute head start.
How Transit Detects in 4 Seconds—Before Data Lands
GreyMatter Transit runs single- and multi-event detection logic against data while it's still streaming from connected technologies—before it's parsed, indexed, or stored. Transit holds partial event sequences in temporary storage and waits for subsequent events to complete a pattern, creating real-time detection with no ingestion dependency.
Circle K deployed Transit against the highest-consequence data source first: firewall logs from fuel terminals and corporate environments. Upon initial deployment, Transit delivered sub-30-second detection. As GreyMatter learned Circle K's environment, detection times continued to drop[MG1] —landing at sub-10 seconds on average, with detections as fast as 4 seconds.
"As we look to the future of what the SIEM is and what it's going to be, it's not going to go away. It needs to be there for compliance reasons, but in true incident response and threat detection, Transit is the way forward."
Patrick O'KeefeHead of Global Cybersecurity Operations & Risk Management, Circle K
From Detection to Containment in Under One Minute
Sub-10-second detection created the opening—but at Circle K, containment decisions carry environment-specific consequences that previously demanded 15+ years of domain knowledge to navigate. Which device lives in a fuel terminal versus a corporate office? What's the right response action for each?
"Shutting down a store versus shutting down someone's laptop is different. Shutting down a fuel terminal that costs millions—that is very critical. We have to be very cautious in our playbooks and responses to make sure we're doing the right thing for the right type of environment."
Over just 6 months, Circle K deployed 20 new Agentic Memories: which devices live in which segments, what constitutes normal behavior at a fuel terminal versus a retail location, and which response actions are appropriate for each context. With that environmental knowledge in place, GreyMatter resolves alerts autonomously—identifying known-benign patterns and closing them without analyst intervention—reducing noise by 99%. Those Memories, combined with Agentic Teammates, automated response playbooks, and custom workflows, drove mean time to contain under one minute.
"With the tools we've deployed with ReliaQuest, we've been able to show value to our audit committee. They recognize that value—in our overall security posture and being able to strengthen our environment. If you're not using AI to fight AI, you're going to lose—and you'll lose fast."
Patrick O'KeefeHead of Global Cybersecurity Operations & Risk Management, Circle K
Learn More About GreyMatter Transit
See how GreyMatter Transit, a first-of-its-kind data pipeline capability, allows security teams to immediately detect threats in transit while giving them optionality in how their data moves in their architecture.


