Download PDF
Case Studies > Digital government solutions security team gains unparalleled visibility with Sumo Logic

Digital government solutions security team gains unparalleled visibility with Sumo Logic

Technology Category
  • Analytics & Modeling - Predictive Analytics
  • Analytics & Modeling - Real Time Analytics
  • Cybersecurity & Privacy - Network Security
Applicable Functions
  • Business Operation
  • Quality Assurance
Use Cases
  • Predictive Maintenance
Services
  • Cybersecurity Services
  • System Integration
  • Training
The Challenge
The government solutions provider’s security team faced significant challenges in maintaining visibility across multiple remote sites. Without addressing the problem at each remote office, it was impossible to detect if an attacker was targeting one office and then expanding efforts throughout the company. The team lacked access at the network level and had no practical way of identifying such threats in real-time. Analysts had to painstakingly go through historical packet capture data to search for past attack patterns while also managing new threats. Despite leveraging AI and machine learning in their antivirus solutions, they needed a more effective way to improve threat detection and network visibility.
About The Customer
The customer is a top digital government solutions provider in the United States, responsible for delivering cutting-edge cybersecurity technology to various government entities. The company’s security team oversees governance across all business units, continuously assesses the current security posture, and hunts for and responds to threats. The team operates in a highly distributed network environment, making deep network visibility a critical component for success. The company is known for its early adoption of advanced technologies, including artificial intelligence and machine learning, to enhance its cybersecurity measures.
The Solution
The security team turned to Sumo Logic’s Cloud SIEM Enterprise solution to address their network visibility issues. Sumo Logic’s ability to create metadata and query traffic in a SQL-type format was identified as a powerful tool for threat hunting. The solution provided real-time data traffic insights and visual representations of patterns and timelines, enabling quick trend analysis. The team integrated Sumo Logic with Carbon Black to enrich threat alerts with additional context, focusing on high-priority indicators. The implementation was swift, with the platform monitoring the corporate headquarters within an hour and expanding to other remote sites in the following days. This deployment allowed the team to uncover threats that were previously undetectable, such as a virus-infected HVAC system communicating with an external server.
Operational Impact
  • Amplification of the security team’s productivity: The small security team dramatically increased its productivity by leveraging Sumo Logic’s capabilities, allowing them to expand deployment to additional remote offices with minimal staff.
  • Cost savings: The networking team avoided the need to purchase an additional tool for network visibility, as Sumo Logic provided the necessary insights.
  • Enhanced government partnerships: The company’s improved security capabilities enabled it to pursue partnerships for threat intelligence exchange with federal entities.
Quantitative Benefit
  • Deployment of Sumo Logic at corporate headquarters within an hour.
  • Expansion of Sumo Logic to other remote sites within a few days.

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.