1 of 23

CANHEIT

Bolstering Security Operations�Platform for Operating a 24x7 SOC

2 of 23

A few years back…

It felt like the threat actors knew our schedule.

Every Friday evening, we would see

phishing and network attacks ramp up.

They knew we were not running a 24/7�Security Operations Center.

3 of 23

Higher Ed a Particularly Appealing Target

No Industry Has Been Spared – but Ours Bears the Brunt

4 of 23

We Needed to Change

We expanded our use of DUO Multifactor�Authentication in front of Office 365 and applications with sensitive or confidential information.

We deployed CrowdStrike XDR on�critical infrastructure through a third party �MSP tenant who monitored for critical server alerts after hours.

As a result, we witnessed a decrease in

compromised accounts and exploited

vulnerabilities.

5 of 23

Over time, we realized:

MFA only decreased compromised accounts.

It did not eliminate them.

�Our CrowdStrike footprint only covered critical

assets and needed to expand on campus.

Threats needed 24/7 investigation, and more data was coming into our SIEM than ever before through:

  • Microsoft 365
  • CrowdStrike
  • DUO Logs
  • Sys Logs

6 of 23

Increasing demands of the SOC team

  • research data security strategy
  • risk assessments
  • penetration tests
  • committees and working groups

  • benchmark reporting
  • security surveys
  • insurance requirements
  • joint security projects

7 of 23

We Needed a New Approach

We needed to find a way to augment our�staff, replicate what we did throughout the day into an evening and weekend shift�that could:

  • continue to monitor
  • alert on critical threats
  • use our tools
  • and synthesize and augment �all that data we were now receiving.

8 of 23

Challenges that Western University Faced

WESTERN U� SOC

SIEM

EDR

Firewall

Cloud

Too many alerts from too many tools

Slow incident response time

D,I,R process is manual and fragmented

High burnout

Existing MSSP

8

Confidential | ©2024 ReliaQuest

9 of 23

Partnering with ReliaQuest

24/7 Monitoring

  • 24/7 ReliaQuest SOC performing root cause analysis on all alert and working directly with the UWO Team during remediation of incidents
  • Reduce alert noise by consolidating duplicate, related tickets, and false positive correlation
  • Recommended actions to speed up response, and configurable escalation paths for all alerts

Automations

  • Streamline the DIR process by auto-populating data and automatically querying existing tools to speed investigations
  • Pre-Built Configurable Response Playbooks and workflows through bi-directional API integration allows for automated execution and validation of Response Playbooks across your SIEM, Endpoint, Network, Cloud, and on-premises solutions

Vendor Agnostic / Transparent

  • Use existing toolset and gain complete visibility into the DIR process
  • Our team has visibility to see what RQ security experts are doing, collaborate with the team, or drive investigations
  • We avoid the conventional "black-box" approach of most MDR providers

Dashboards, Metrics and Reporting

    • Create baseline and allow us to compare to our peers
    • MITRE Detection Coverage
    • Log source coverage and diversity
    • Log ingestion, alert metrics, and tuning metrics around False Positives, True Positives, Anomaly Safe
    • Response metrics around MTTR

Confidential | ©2024 ReliaQuest

9

10 of 23

Who is ReliaQuest?

11 of 23

ReliaQuest at a Glance

1,200+Teammates Globally

6 Global Operating�Centers

1,000+ Customers

65+Patents

90%+Reduction in�Alert Volume

35%Improvement in Total Cost of Ownership

33%+Increase in Visibility

182%+Increase in Threat Detection Capabilities

1,800+Hours�Volunteered

$1.5M+Dollars Contributed �to Community Partners

Investing in the Next Generation

Delivering Customer Outcomes

Confidential | ©2024 ReliaQuest

11

12 of 23

Security Operations is a Data Problem

  • SIEMs & EDRs do not have all the relevant data.
  • Data, required for effective TDIR, is spread across a variety of business systems.
  • Data lakes are not the answer.

Business Apps

SIEM

EDR

Security�Operations Team

Cloud

Challenges

Inefficient DIR Process

Teams are stretched thin

Expensive data retention

Confidential | ©2024 ReliaQuest

12

13 of 23

Security Operations Platform

IDS/IPS

DNS

Email

EDR

NAC

Vulnerability Management

SIEM

Business Apps

Cloud

SASE

Cloud Security Tools

Security Operations Platform

SOAR

Foundational Capabilities

Universal Translator

Normalize and parse data across existing systems

Cloud Detections

Centrally-managed and deployed detections across all your security tools

Data-stitching

Automated alert enrichment without data-ingest

Bi-directional Integrations

Enable response actions across multiple tools from GreyMatter

Powered by Artificial Intelligence

AI models trained on 10+ years of proprietary Incidence Response data

Confidential | ©2024 ReliaQuest

13

14 of 23

Security Outcomes: Backed by a world-class Technical Operations Team

Threat Research

  • Threat Validation & Prioritization
  • Threat Intelligence
  • Threat Hunting
  • Detection Research

Detection

  • Advisement on Security Controls and Visibility 
  • Detection Content
  • Verify your Security Controls

Incident Response

  • GreyMatter Intelligent Analysis powered through the Cyber Analysis Methodology
  • Threat Response and Automated Remediation

Engineering

  • Health Monitoring
  • Architecture & Capacity
  • Security Control/Log Source Integration

Customer Success

  • Dedicated team
  • Drive alignment for Business & Partnership Priorities

Security Architects

  • Technical Strategy Team
  • Recommendations on integrations and maturing TDIR workflows

Confidential | ©2024 ReliaQuest

14

15 of 23

24/7 Consistent, repeatable investigations with a global 24/7 SOC

Centrally deployed and continuously tuned detections and threat intelligence services

Health Monitoring and management of log sources and SIEM/EDR

Dedicated team road mapping with real-time metrics across DIR

Enabled response via GreyMatter within your own tools with automation via RQ

Investigation

Detections & Threat Intelligence

Engineering

Metrics &

Dedicated Team

Response

PARTNERSHIP TO ACHIEVE SECURITY PROGRAM GOALS

TRANSPARENCY AUTOMATION REPORTING AND METRICS

DETECT

INVESTIGATE

RESPOND

Increase Visibility

Reduce Complexity

Manage Risk

Confidential | ©2024 ReliaQuest

15

16 of 23

GreyMatter Integrations (135+)

SIEM/ Data Lake/ Security Analytics

Endpoint

IAM

SOAR

OT / IoT

Sandbox

Cloud Management & Security

Email

Threat Intelligence

Firewall / Network

Vulnerability Management

Multiple Product Integrations with GreyMatter

Multiple Threat Feed Integrations with GreyMatter

Included

Malsilo

Danger Rulez

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

+

Confidential | ©2024 ReliaQuest

16

17 of 23

Integration and Onboarding with ReliaQuest

Implementation Timeline

1

Onboarding Process

3

Configuration and Integrations

Engagement & Escalation Processes

2

4

  • Review of ReliaQuest Customer Access requirements
  • Review and audit of Western environment
  • Integration of Networking infrastructure where relevant for connectivity purposes.
  • Western SOC Training on the use of GreyMatter.
  • On-call procedures and pager coverage
  • Operationalize support of Reliaquest SOC team and Western assets.

  • July 2023 Kick-off
  • Target Completion August 2023
  • Integration of Western SIEM environment
  • Integration of Western Crowdstrike environment with GreyMatter.

18 of 23

Reporting

19 of 23

Intel

20 of 23

Coverage Maps

21 of 23

Our first real test

We were aware in February that Ivanti had security patches that needed to go into production. We had scheduled a change event for the Sunday morning to implement the needed patch.

We were hit with the vulnerability on Friday evening at 10 p.m., 36 hours before we planned to update the service.

“Here’s where the Greymatter solution proved it’s value - when the Ivanti VPN vulnerability hit us, ReliaQuest’s Greymatter detected it, and within 15 minutes, we were mitigating the threat—swift and decisive action that exemplified our enhanced capabilities."

22 of 23

Roadmap for Western with ReliaQuest

1

2

3

4

As we become more confident in RQ detections and see fewer false positive results we will look to automate responses.

Actionable Responses by RQ

Expansion beyond our core integrations will give us greater insight and response to threats.

Additional Integrations

In the longer term we see this partnership developing to make critical decisions on our behalf while also escalating internally.

SOAR capabilities

23 of 23

Thank You

Questions?