Enhancing security visibility for a leading asset management firm
A UK-based asset management company wanted to enhance security visibility across its hybrid infrastructure and free up its in-house team to focus on remediating rather than detecting threats.
It sought a proactive monitoring service that could provide centralised visibility across its on-premises networks, endpoints and cloud environments.
By choosing Redscan’s award-winning Managed Detection and Response service, the business now benefits from an extended monitoring capability and additional expertise to identify and respond to security incidents faster and more effectively, 24/7/365.
- No dedicated in-house security team
- A range of compliance requirements
- Past investments not delivering value
The asset management company was looking to gain more complete security visibility and obtain additional resources to supplement its in-house team and enable it to focus on critical security investigations.
The company recognised the significant damage a data breach could pose to its reputation and its client relationships and wanted to minimise the potential risks. Mindful of its compliance responsibilities, the company also wanted to ensure that it was meeting the requirements of the Financial Conduct Authority and other regulatory bodies.
While it had always taken cyber security very seriously, the company had no dedicated security team and was struggling to gain a full picture of security events across its environments. The company wanted to enhance its security capability in order to detect and respond to the latest threats but could not achieve this with the resources it had in-house.
The company had previously trialled a number of Security Information and Event Management (SIEM) and Endpoint Detection & Response (EDR) platforms from different providers, but couldn’t achieve the outcomes it needed from them. This was because the team had to view alerts across multiple disparate systems, meaning there was no cohesive or centralised view. The tools were generating what turned out to be mostly false positives and only retained logs of what was going in the company’s environment for a short period, which meant the in-house team struggled to investigate historical events and trends or conduct threat hunting.
Following unsatisfactory results after trialling various SIEM and EDR tools, the company decided that it needed the support of a specialist provider of Managed Detection and Response. A proof of concept gave it the opportunity to confirm that Redscan’s ThreatDetect™ service was the best solution for its needs and would supply the required security outcomes.
ThreatDetect provides the network and endpoint technologies, expertise and outcome-focused approach that the company needed. Redscan’s Security Operations Centre (SOC) team investigate and triage alerts 24/7/365 and provide actionable remediation advice to enable the company’s team to respond quickly and effectively to incidents.
CyberOps™, Redscan’s threat management platform – included as part of ThreatDetect – has helped the company to centralise visibility as it now receives all threat notifications via one platform, rather than having to pivot across multiple technologies. Because ThreatDetect provides genuine incident notifications, the in-house team now only has to investigate incident alerts that have been validated as requiring attention, rather than waste time investigating potential false positives.
The company’s IT Director said:
“Prior to engaging with Redscan, we only had part of the security picture. Redscan demonstrated that they could join up the dots to help us achieve better security visibility – more so than any other provider we spoke to.”
“Our partnership with Redscan frees up our time and gives us the reassurance that our infrastructure and assets are being proactively monitored. We’re very pleased with the service we receive. Across the whole service, whether it’s the SOC or the technical account management team, Redscan looks after us very well.”