Helped a Malaysian critical infrastructure organization uncover a hidden compromise with SOC-as-a-service

Our client was a Malaysian water utility provider known for its massive and longest distribution network. It is one of the oldest providers in the country, offering an uninterrupted supply of water across 10 states, making it an essential part of the critical infrastructure.

Download Case Study
RESULTS

Results at a glance

  • Improved Mean Time to Detect – from months to detect to same-day detection.
  • Reduced alert noise by 99%, improving the overall focus on critical escalations.
  • Security stack including perimeter firewalls and Sangfor EDR unified and operationalized
  • 300+ endpoints secured across the entire infrastructure.
The challenge

Blind spots to exposure – a critical infrastructure exposed to an active adversary

Our client’s monitoring only covered a fraction of their infrastructure. There was no telemetry from the rest of the IT infrastructure, including workstations and several hundred endpoints. Their most sensitive systems, including the billing database and GIS infrastructure, were invisible to detection tools. This blind spot was an advantage to a threat that was already inside the network. With domain-level access and Active Directory weaponized, the actor was targeting the most vulnerable and sensitive part of their infrastructure – the billing systems and was preparing for a ransomware attack, adapting to the defensive maneuvers.

 

Their existing stack, comprising the perimeter firewall and Sangfor EDR, operating in alert-only mode with high false positives and inconsistent policy enforcement. Without a clean baseline to work from, and no formal incident response activity conducted despite two prior security incidents, it was challenging for them to identify, contain, or remediate threats. There was also no dedicated in-house expertise to meet the compliance expectations placed on national critical infrastructure. Due to all these challenges, our client was exposed not just technically but also operationally and regulatorily, without any internal expertise to identify and close the gaps.

  • Limited/no visibility across critical systems and wider environment.
  • Unconfigured tooling with high alert volume and false positives.
  • Limited expertise to operationalize existing stack.
  • No systematic IR in place to identify, contain, and remediate an active threat.
  • No expertise in place for meeting compliance expectations.

Speak with US

CONTACT US
The solution

Sanitized, secured, and operationalized – built for critical infrastructure

Since our client experienced two prior cyber incidents and had no formal incident response in place, we began with comprehensive threat hunting and investigation. This uncovered a skilled, domain-level threat actor and the TTPs, including propagation mechanisms, anti-forensic, and defense evasion techniques. We found that the attacker was staging a ransomware attack targeting the production billing database. We immediately escalated our findings with isolation guidance for forensic preservation and domain credential reset. We provided a detailed remediation roadmap that continuously updated as the attacker adapted. Once the environment was sanitized, we integrated their existing stack, including Sangfor EDR and perimeter firewall, into our vendor-agnostic STRIEGO platform.

 

We reconfigured their Sangfor EDR, which was operating in alert-only mode, and addressed gaps like excessive alert generation, inconsistent policy enforcement, and high false positives. This extended their visibility and monitoring by tenfold. Next, we operationalized their stack with whitelist recommendations, resolved policy inconsistencies, and realigned detection categories. As a part of the nation’s critical infrastructure, our client faced obligations under regulations like Malaysia’s Personal Data Protection Act 2010, CNII obligations, and broader operational expectations. Therefore, instead of bolting on compliance afterwards, we aligned all our client’s detection, response, and reporting practices with compliance requirements from the start.

  • Comprehensive threat hunting and investigation
  • Threat containment and environment sanitization
  • Integrated, configured, and operationalized security stack
  • Continuous incident response and advisory support
  • End-to-end compliance support
SOME FACTS WORTH CONSIDERING
97%

improvement in Mean Time to Detect 

99%

reduction in alert noise

300+

endpoints secured

Results

From month-long blind spots to same-day detections

Before

There was no systematic mechanism to detect threats. Result – two incidents that went undetected for months.

Proactive threat hunting and tuned detection. Result – overall MTTD down to same-day detection, with critical escalations flagged immediately.

Unconfigured tooling with high alert volume. Result – challenging for the team to distinguish between real threats and false positives.

Alert correlation and tuning eliminated the majority of noise. Result – improved focus on genuine and critical alerts.

Fragmented visibility across security stack with low visibility across critical systems. Result – 300+ endpoints and critical systems, including billing database and GIS infrastructure, exposed.

Integrated and unified security stack on STRIEGO for centralized visibility and control. Result – Centralized visibility and unified telemetry from security stack for 24/7 security of infrastructure including sensitive systems.

No formal mechanism to identify, contain, and remediate cyber threats. Result – compromised environment with an active threat actor having gained domain-level access.

Clearly defined processes, procedures, roles & responsibilities for incident response. Result – improved IR and compliance readiness against ransomware and other cyber threats.

The security stack was not demonstrable as per regulatory requirements applicable to critical infrastructure. Result – Unknown security and compliance gaps increasing the exposure to security, legal, and financial risks.

Formal, compliance-friendly IR mechanism, IR/EDR analysis reports, and end-to-end support for compliance. Results – Significant improvement in regulatory readiness.

Don’t miss out on 99% of critical alerts.
Get your SIEM tuned for supercharged outcomes!

SPEAK WITH OUR TEAM