CANHEIT
Bolstering Security Operations�Platform for Operating a 24x7 SOC
A few years back…
It felt like the threat actors knew our schedule.
Every Friday evening, we would see
phishing and network attacks ramp up.
They knew we were not running a 24/7�Security Operations Center.
Higher Ed a Particularly Appealing Target
No Industry Has Been Spared – but Ours Bears the Brunt
We Needed to Change
We expanded our use of DUO Multifactor�Authentication in front of Office 365 and applications with sensitive or confidential information.
We deployed CrowdStrike XDR on�critical infrastructure through a third party �MSP tenant who monitored for critical server alerts after hours.
As a result, we witnessed a decrease in
compromised accounts and exploited
vulnerabilities.
Over time, we realized:
MFA only decreased compromised accounts.
It did not eliminate them.
�Our CrowdStrike footprint only covered critical
assets and needed to expand on campus.
Threats needed 24/7 investigation, and more data was coming into our SIEM than ever before through:
Increasing demands of the SOC team
We Needed a New Approach
We needed to find a way to augment our�staff, replicate what we did throughout the day into an evening and weekend shift�that could:
Challenges that Western University Faced
WESTERN U� SOC
SIEM
EDR
Firewall
Cloud
Too many alerts from too many tools
Slow incident response time
D,I,R process is manual and fragmented
High burnout
Existing MSSP
8
Confidential | ©2024 ReliaQuest
Partnering with ReliaQuest
24/7 Monitoring
Automations
Vendor Agnostic / Transparent
Dashboards, Metrics and Reporting
Confidential | ©2024 ReliaQuest
9
Who is ReliaQuest?
ReliaQuest at a Glance
1,200+�Teammates Globally
6 �Global Operating�Centers
1,000+ �Customers
65+�Patents
90%+�Reduction in�Alert Volume
35%�Improvement in Total Cost of Ownership
33%+�Increase in Visibility
182%+�Increase in Threat Detection Capabilities
1,800+�Hours�Volunteered
$1.5M+�Dollars Contributed �to Community Partners
Investing in the Next Generation
Delivering Customer Outcomes
Confidential | ©2024 ReliaQuest
11
Security Operations is a Data Problem
Business Apps
SIEM
EDR
Security�Operations Team
Cloud
Challenges
Inefficient DIR Process
Teams are stretched thin
Expensive data retention
Confidential | ©2024 ReliaQuest
12
Security Operations Platform
IDS/IPS
DNS
EDR
NAC
Vulnerability Management
SIEM
Business Apps
Cloud
SASE
Cloud Security Tools
Security Operations Platform
SOAR
Foundational Capabilities
Universal Translator
Normalize and parse data across existing systems
Cloud Detections
Centrally-managed and deployed detections across all your security tools
Data-stitching
Automated alert enrichment without data-ingest
Bi-directional Integrations
Enable response actions across multiple tools from GreyMatter
Powered by Artificial Intelligence
AI models trained on 10+ years of proprietary Incidence Response data
Confidential | ©2024 ReliaQuest
13
Security Outcomes: Backed by a world-class Technical Operations Team
Threat Research
Detection
Incident Response
Engineering
Customer Success
Security Architects
Confidential | ©2024 ReliaQuest
14
24/7 Consistent, repeatable investigations with a global 24/7 SOC
Centrally deployed and continuously tuned detections and threat intelligence services
Health Monitoring and management of log sources and SIEM/EDR
Dedicated team road mapping with real-time metrics across DIR
Enabled response via GreyMatter within your own tools with automation via RQ
Investigation
Detections & Threat Intelligence
Engineering
Metrics &
Dedicated Team
Response
PARTNERSHIP TO ACHIEVE SECURITY PROGRAM GOALS
TRANSPARENCY AUTOMATION REPORTING AND METRICS
DETECT
INVESTIGATE
RESPOND
Increase Visibility | Reduce Complexity | Manage Risk |
Confidential | ©2024 ReliaQuest
15
GreyMatter Integrations (135+)
SIEM/ Data Lake/ Security Analytics
Endpoint
IAM
SOAR
OT / IoT
Sandbox
Cloud Management & Security
Threat Intelligence
Firewall / Network
Vulnerability Management
Multiple Product Integrations with GreyMatter
Multiple Threat Feed Integrations with GreyMatter
Included
Malsilo
Danger Rulez
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
Confidential | ©2024 ReliaQuest
16
Integration and Onboarding with ReliaQuest
Implementation Timeline
1
Onboarding Process
3
Configuration and Integrations
Engagement & Escalation Processes
2
4
Reporting
Intel
Coverage Maps
Our first real test
We were aware in February that Ivanti had security patches that needed to go into production. We had scheduled a change event for the Sunday morning to implement the needed patch.
We were hit with the vulnerability on Friday evening at 10 p.m., 36 hours before we planned to update the service.
“Here’s where the Greymatter solution proved it’s value - when the Ivanti VPN vulnerability hit us, ReliaQuest’s Greymatter detected it, and within 15 minutes, we were mitigating the threat—swift and decisive action that exemplified our enhanced capabilities."
Roadmap for Western with ReliaQuest
1
2
3
4
As we become more confident in RQ detections and see fewer false positive results we will look to automate responses.
Actionable Responses by RQ
Expansion beyond our core integrations will give us greater insight and response to threats.
Additional Integrations
…
In the longer term we see this partnership developing to make critical decisions on our behalf while also escalating internally.
SOAR capabilities
Thank You
Questions?