Enhancing Security Visibility - Case Study | Redscan
Contact Us

Contact Us

Please get in touch using the form below

1000 characters left
View our privacy policy

Overview

Enhancing security visibility for a leading asset management firm

A UK-based asset management company wanted to enhance security visibility across its hybrid infrastructure and free up its in-house team to focus on remediating rather than detecting threats.

It sought a proactive monitoring service that could provide centralised visibility across its on-premises networks, endpoints and cloud environments.

By choosing Redscan’s award-winning Managed Detection and Response service, the business now benefits from an extended monitoring capability and additional expertise to identify and respond to security incidents faster and more effectively, 24/7/365.

Case Study - Enhancing security visibility for a leading asset management firm
Industry
Finance

The Challenge

Summary

  • No dedicated in-house security team
  • A range of compliance requirements
  • Past investments not delivering value

The asset management company was looking to gain more complete security visibility and obtain additional resources to supplement its in-house team and enable it to focus on critical security investigations.

The company recognised the significant damage a data breach could pose to its reputation and its client relationships and wanted to minimise the potential risks. Mindful of its compliance responsibilities, the company also wanted to ensure that it was meeting the requirements of the Financial Conduct Authority and other regulatory bodies.

While it had always taken cyber security very seriously, the company had no dedicated security team and was struggling to gain a full picture of security events across its environments. The company wanted to enhance its security capability in order to detect and respond to the latest threats but could not achieve this with the resources it had in-house.

The company had previously trialled a number of Security Information and Event Management (SIEM) and Endpoint Detection & Response (EDR) platforms from different providers, but couldn’t achieve the outcomes it needed from them. This was because the team had to view alerts across multiple disparate systems, meaning there was no cohesive or centralised view. The tools were generating what turned out to be mostly false positives and only retained logs of what was going in the company’s environment for a short period, which meant the in-house team struggled to investigate historical events and trends or conduct threat hunting.

"We’re very pleased with the service we receiveAcross the whole service, whether it’s the SOC or the technical account management team, Redscan looks after us very well.”
IT Director
Asset Management Firm

The Solution

Following unsatisfactory results after trialling various SIEM and EDR tools, the company decided that it needed the support of a specialist provider of Managed Detection and Response. A proof of concept gave it the opportunity to confirm that Redscan’s ThreatDetect™ service was the best solution for its needs and would supply the required security outcomes.  

ThreatDetect provides the network and endpoint technologies, expertise and outcome-focused approach that the company needed. Redscan’s Security Operations Centre (SOC) team investigate and triage alerts 24/7/365 and provide actionable remediation advice to enable the company’s team to respond quickly and effectively to incidents.  

CyberOps™, Redscan’s threat management platform – included as part of ThreatDetect – has helped the company to centralise visibility as it now receives all threat notifications via one platform, rather than having to pivot across multiple technologies. Because ThreatDetect provides genuine incident notifications, the in-house team now only has to investigate incident alerts that have been validated as requiring attention, rather than waste time investigating potential false positives.

The company’s IT Director said: 

“Prior to engaging with Redscan, we only had part of the security picture. Redscan demonstrated that they could join up the dots to help us achieve better security visibility – more so than any other provider we spoke to.”

“Our partnership with Redscan frees up our time and gives us the reassurance that our infrastructure and assets are being proactively monitored. We’re very pleased with the service we receive. Across the whole service, whether it’s the SOC or the technical account management team, Redscan looks after us very well.” 

The Benefits

Unified visibility
By choosing our MDR service, the company has been able to achieve more comprehensive and centralised visibility across its environments. Without the service, the company's IT team would not have the time to check whether all the security alerts it receives are genuine. Redscan’s CyberOps threat management platform enables the company to comprehensively monitor its environments to identify and manage security incidents and deliver the security outcomes it needs, through one unified solution.
Enhanced security capability
Before working with Redscan, the company’s small IT team did not have the capacity to respond to and assess all of the security alerts generated by the detection technologies it was trialling. The support provided by Redscan’s SOC team now provides peace of mind that important security events aren’t missed and that incidents are responded to swiftly and effectively, 24/7/365.
Greater return from security tools
The company had previously invested in a number of security technologies but wasn’t gaining the value it needed from them. Working with Redscan has enabled it to achieve the best outcomes and achieve a better return on investment.
Historical overview
While the company’s previous threat detection tool didn’t retain a long history of security events captured across its environment, Redscan stores and analyses security logs and data for 12 months, to help enhance threat detection and observe trends over a longer period.
Secure cloud migration
Redscan supported the company in its goal to transition safely from private to public cloud and ensure continuity of service, as well as enabling it to monitor on-premises infrastructure and services in the cloud. This includes proactive monitoring of Microsoft 365.
The latest threat intelligence
The company values the weekly Threat Intelligence updates Redscan provides to its clients as it helps them to obtain a clearer overview of the security landscape and vulnerabilities they need to prioritise.