Turbocharged security resilience and compliance confidence for an East African bank

Our client was an East African bank offering a range of commercial banking services and products. It was reputed for its private banking, investment management, wealth management and asset management services and personal and commercial loan products. They were reputed across Rwanda for helping individuals and businesses build wealth through their financial services and products.

Download Case Study
RESULTS

Results at a glance

  • A fully operationalized security stack aligned with compliance expectations
  • Centralized visibility and control across staff
  • 96.7% improvement in Mean Time to Detect and 95% faster Mean Time to Respond.
  • ~91% reduction in alerts generated
The challenge

An approaching audit and a security stack that wasn’t operationalized

Our client had invested heavily in security, with a stack that was built with IBM QRadar SIEM, Cortex XDR, and a Fortinet firewall and managed by a SOC provider. However, despite having the people, process, and technology in place, our client was struggling with a stack that wasn’t operationalized and was emitting a high volume of alerts (close to 700 alerts a month) without having a reliable way to separate threats from noise. It not only exhausted their security team’s bandwidth but also affected their ability to timely and accurately detect and respond to threats.

 

Without timely insights reaching the right people, our client’s security stayed reactive and delayed, as opposed to the proactive and continuous security that regulators expected to see. As a bank handling sensitive financial and personal data of customers, it was critical for them to address the security gaps before they turned into threats to their information assets and reputation. They were looking for a partner with the technical and regulatory expertise to help them operationalize their security stack and align it with compliance needs without having to build one in-house.

  • A stack that was not operationalized despite having a SOC
  • Fragmented visibility across SIEM and other solutions
  • High volume of alerts
  • Lack of timely security insights
  • Identifying and addressing security and compliance gaps

Speak with US

CONTACT US
The solution

Operationalized, optimized, and audit-ready security stack

Despite having an external SOC provider, our client’s security stack was never fully operationalized and was causing visibility, control, and alert context issues. Through our MDR service, we integrated, configured, and managed our client’s existing stack (including IBM QRadar, Cortex XDR, and Fortinet firewall) on our vendor-agnostic, open-architecture STRIEGO platform. We identified and remediated misconfigurations and managed their stack using industry best practices. This helped our client gain centralized visibility and control that the regulators expected to see. We offered them the dedicated vendor and domain expertise to optimize alerts, correlate rules, and customize playbooks for automated response.

 

This helped improve their MTTD by 96.7%, MTTR by over 95%, and brought down the overall alerts from ~700 to ~60 alerts monthly without having to upgrade or replace their stack. Our threat hunters proactively investigated emerging campaigns like the FortiBleed campaign through credential exposure searches, dark web reconnaissance, and infrastructure mapping. With dedicated compliance expertise, we helped them identify & treat security and compliance risks and align security posture to Rwanda’s data protection expectations.

  • Integrated, designed, configured, and operationalized security stack
  • Built a whole set of customizations for IBM QRadar – Detection engineering, alert optimization, and automation
  • Proactive threat hunting – for threats like the FortiBleed vulnerability
  • Continuous threat intelligence & security advisory
  • End-to-end compliance management to Rwanda’s data protection and security regulations
SOME FACTS WORTH CONSIDERING
96.7%

reduction in Mean Time to Detect 

91%

reduction in alert noise

95%

improvement in Mean Time to Respond

Results

Before

Security tools (including SIEM, endpoint security, and firewall) ran in silos without any shared context across the security stack.

Fully integrated security stack, offering unified visibility and centralized control, providing a complete picture of security posture health.

with high volume of alerts (close to 700 alerts a month) and no context.

Massive reduction in volume of alerts (fell to ~60 alerts a month) with MTTD improving by 96.7%.

without any accurate information on threats.

Customized playbooks for quick and accurate automated response, improving the MTTR by over 95%.

Lag in reporting made security reactive, making continuous monitoring more challenging to demonstrate.

With STRIEGO, our client got the timely insights, global threat intelligence, and customized advisories they needed to proactively address risks before they turned into threats.

Multiple hidden security and compliance gaps and no dedicated expertise to align with Rwanda’s data protection expectations.

Compliance built into security (from detection engineering, alert management, to reporting) from the start.

Don’t miss out on 99% of critical alerts.
Get your SIEM tuned for supercharged outcomes!

SPEAK WITH OUR TEAM