Contact Us

Contact Us

Please get in touch using the form below

1000 characters left
View our privacy policy

Overview

Supplying the notifications and insight your team needs to respond effectively

The Redscan Platform is Redscan’s proprietary customer portal. As the virtual interface between our Cyber Security Operations Centre (CSOC) and your in-house team, The Redscan Platform enables us to comprehensively monitor your environments to identify and manage security incidents, and deliver the security outcomes you need – all through a single unified platform.

CyberOps incident displayed on desktop and mobile

How it works

01. Ingestion

The Redscan Platform collects telemetry from across your environments by integrating with your assets and underlying security technologies. This data is then analysed using the latest behavioural detection engines and enriched with threat intelligence to generate alerts.

02. Analytics

Proprietray algorithms within The Redscan Platform intelligently group alerts by common attributes to create high-fidelity ‘cases’. Cases enhance contextual awareness by providing a more comprehensive view of security incidents and reduce noise.

03. Investigation

The Redscan Platform presents cases to our 24/7 Security Operations Centre experts for analysis. Cases which are validated as genuine incidents are raised for your security team with accompanying mitigation guidance.

04. Response

The Redscan Platform’s security orchestration capabilities accelerate incident response by automating threat containment and disruption in a variety of scenarios. Response actions can be also be triggered manually from within the platform.

Benefits

Technology agnostic

Whichever technologies form part of your service, The Redscan Platform ingests and aggregates all security alert information and presents it for analysis via a single pane of glass.

Alert enrichment engine

The Redscan Platform’s alert correlation and enrichment engine uses the latest threat intelligence to add greater context to alerts and help distinguish genuine incidents from false positives.

Swift incident notification

Once an alert is identified as being a true positive and raised as an incident by our SOC, The Redscan Platform generates a message to ensure that your team members are promptly notified.

Automated response actions

Integration with preventative security controls enables automated incident response actions to be triggered automatically or on demand at the click of a button.

Customisable dashboards

The Redscan Platform’s widget-based dashboards enable your users to view security information in real-time and measure key metrics to ensure service levels are being achieved.

Seamless workflow integration

Support for a range of ITSM tools enables security incidents raised via The Redscan Platform to be managed alongside tickets relating to other aspects of your organisation’s IT estate.

Workflow

Seamless workflow integration

The Redscan Platform supports integration with widely used IT service management tools, including:

Interested in learning more?

Request a demo

Our Approach

Identifying genuine security incidents out of millions of alerts

The Redscan Platform’s automated alert correlation and enrichment engine reduces the number of low value alerts generated by security tools to enable security teams to focus on the ones that really matter.

Cyberops Approach
Approach

Millions

Events observed

A turnkey technology stack collects and analyses security events across your environment and generates alerts

Hundreds

Alerts generated

Alerts are ingested into The Redscan Platform where they are enriched with the latest threat intelligence and analysed by Redscan’s SOC team

Tens

Incidents investigated

Genuine security alerts are raised as security incidents for your attention, with actionable mitigation guidance. Automated response actions help quickly contain and disrupt incidents.

Outcomes

Actionable security insight

The information you need to quickly and effectively respond to security incidents.

Example Redscan Platform incident notification

Redscan Platform screenshots of security analytics

Security analytics

A real-time snapshot of your security status

The Redscan Platform’s customisable dashboards provide a real-time overview of your organisation’s security posture. Choose from a range of customisable widgets to view risk level trends, alarm timelines, and key activity metrics.

Kroll Responder MDR

Reducing breach detection time from months to minutes

More about Kroll Responder

Get a Redscan Platform demo

Please complete the form and our team will be in touch.

1000 characters left
View our privacy policy

Resources

Discover our latest content and resources

From the blog
From the blog Case studies Latest news
18th March 2024
Prioritise the security of perimeter products, says NCSC
Securing perimeter products must be a priority for organisations as threat actors are increasingly targeting insecure self-hosted products at the corporate network perimeter, according to the UK's National Cyber Security Centre (NCSC).
4th March 2024
Insider threats an increasing concern for UK companies
More than half of UK business decision-makers surveyed for a new study stated that they were concerned about the likelihood of their employees being approached by cybercriminals, leading to a rise in insider threats.    
26th February 2024
78% of organisations hit by repeat ransomware attacks after paying
A new report shows that almost four in five organisations that paid a ransom demand were hit by a second ransomware attack, often by the same threat actor. Almost two-thirds (63%) of those organizations were asked to pay more the second time.
19th February 2024
UK companies lost £31bn due to security breaches in 2023
More than 1.5 million UK businesses were compromised by threat actors in 2023, with a total cost of more than £31.5bn, according to new research.