3
Security Analysts
550+
Employees
1,500+
Endpoints
Étude de cas client
Executive Summary
24/7 monitoring, “It’s like having a full-time on-call analyst”
A financial institution with over $100 billion under its management needed around-the-clock threat detection, but its small security team was under-resourced for on-call coverage and 24/7 endpoint monitoring. Just three analysts were charged with maintaining the company’s overall security posture, ensuring compliance and regulatory standards for frequent audits, keeping systems and hygiene up-to-date, and enabling 600 employees to do their jobs in a secure manner.
The Challenges
The team was using a leading security SIEM provider, but it was only able to monitor logs. Running telemetry through their SIEM would not only have been extremely expensive but would have overwhelmed their appliance, so they also used an endpoint detection and response (EDR) product.
However, keeping up with monitoring the EDR product was too time-consuming for a team also tasked with supporting critical business projects. The infosec team was suffering from alert fatigue and keenly aware of after-hours gaps in coverage. They didn’t have an on-call system in place, which left them feeling vulnerable on weekends and late at night.
The Solution
When the infosec team’s director decided to test out a managed service, Red Canary was at the top of the list. They saw the value proved out right away.
Getting started with Red Canary Managed Detection and Response (MDR) was fast and easy. The team transitioned their portal to be hosted by Red Canary, then reinstalled the sensor. Configuration, testing, and enrolling took just a few days. “On a scale of one to ten in terms of difficulty, it was a one or two,” says one of their security analysts.
The Results
The team saw an immediate return on their investment, with benefits including time savings, stress relief, a greater sense of confidence, and a deeper awareness of what’s happening in their environment.
There has been a dramatic difference from relying on Red Canary MDR as opposed to trying to manage EDR in-house.
The team gained the 24/7 coverage they needed—without hiring more people or implementing an on-call schedule. They recalled one instance when Red Canary’s ability to fill the after-hours gap proved critical.
In addition to time savings, the team gained highly focused expertise to enrich their existing capabilities. They were able to tap into Red Canary analysts with specific skill sets to complement their internal team of security generalists.
Last but not least, the team now has the information they need to be confident about what’s happening in their environment. Red Canary’s analysis of endpoint activity and potential threats helps the team understand the scale and severity of security alerts and confirm they’re not missing anything.
Produits
Solutions




