Download PDF
Case Studies > Real Estate Company Enhances Cybersecurity with Arctic Wolf for Security Operations

Real Estate Company Enhances Cybersecurity with Arctic Wolf for Security Operations

Technology Category
  • Cybersecurity & Privacy - Endpoint Security
  • Cybersecurity & Privacy - Network Security
  • Cybersecurity & Privacy - Security Compliance
Applicable Functions
  • Business Operation
Use Cases
  • Cybersecurity
  • Regulatory Compliance Monitoring
  • Remote Asset Management
Services
  • Cybersecurity Services
  • System Integration
  • Training
The Challenge
Prior to considering a managed detection and response solution, the company had no comprehensive approach to holistically monitor infrastructure or glean security insights from log data generated by its various IT systems. Its IT team had a small set of internal monitoring tools to monitor specific systems, but knew it lacked visibility and risked missing significant threats. According to an information security manager for the firm: “We told the board we had to improve how we monitored the environment. In particular, we needed to be more responsive to threats and to the unique nature of AWS environments.” The firm considered various options. The choices narrowed down to: (1) Establishing their own security operations center (SOC) on-premises using a LogRhythm security information and event management (SIEM) platform or (2) Leveraging a managed security service offering. It didn’t take long, however, to realize that going the LogRhythm route and then needing to hire a dedicated staff to run an inhouse SOC was cost-prohibitive. This remained true even when considering a LogRhythm SIEM co-managed through a third party. The firm then evaluated the managed security service provider (MSSP) model from AT&T, but found the AT&T offering lacked the “named” team provided by Arctic Wolf and might not provide the necessary attention to the company’s needs.
About The Customer
This top five global real estate company has over 400 employees with multiple offices. The firm provides tools and support to thousands of franchisee agents. The real estate company has more than 75 on-premises servers, as well as an extensive Amazon Web Services (AWS) server infrastructure with over 370 instances. Its IT team manages, secures, and monitors a diverse infrastructure that includes workstations, servers, firewalls, and network infrastructure comprised of switches, routers, and wi-fi access points. The team also must maintain compliance with regulatory regimes including the Sarbanes-Oxley Act (SOX) and the Payment Card Industry Data Security Standard (PCI DSS). The company has various applications handling sensitive financial and human resources data, and personally identifiable information (PII) in on-premises and cloud servers could trigger state data breach laws once compromised.
The Solution
In came Arctic Wolf and its managed detection and response (MDR) solution. The company’s IT team soon determined that Arctic Wolf® Managed Detection and Response provided the best option to meet its ongoing challenges and ramp up its cybersecurity posture. Arctic Wolf Managed Detection and Response was initially deployed in early 2019 across the company’s on-premises environment, rolling out the AWS deployment over time. Today, Arctic Wolf provides the firm with visibility across both environments. This monitoring has helped it to better understand its environment and sustain compliance with SOX and PCI DSS mandates. The Arctic Wolf MDR solution has helped the firm’s IT team validate security changes, and notified the company when an unexpected—though legitimate—root login occurred. This is one of numerous examples where Arctic Wolf has raised the company’s capabilities and removed the burdensome load of cybersecurity off of its internal IT team. The company’s AWS environment includes a variety of pieces, including Amazon Elastic Compute Cloud (Amazon EC2) instances, Amazon Simple Storage Service (Amazon S3) buckets, Amazon ElastiCache, and Amazon Relational Database Service (Amazon RDS) instances. The firm uses a microservices approach to its AWS applications with Amazon EC2 instances in Kubernetes. “AWS is a big focus of our development efforts given the value of the cloud, so we must ensure the same sort of protections around our AWS environment that we have on premises,” the information security manager said. After consulting with the Arctic Wolf Concierge Security Team, the firm decided to deploy Amazon GuardDuty to better monitor its environment. GuardDuty monitors for malicious activity and unauthorized behavior in AWS accounts and workloads. Arctic Wolf MDR is now ingesting GuardDuty telemetry to obtain better visibility to the firm’s AWS environment. GuardDuty can generate a considerable volume of alerts, and Arctic Wolf MDR ingests and distils those alerts to arrive at actionable threat information. Looking forward, the company has plans to extend Arctic Wolf monitoring to its Salesforce infrastructure.
Operational Impact
  • Arctic Wolf provides the firm with visibility across both on-premises and AWS environments, helping it to better understand its environment and sustain compliance with SOX and PCI DSS mandates.
  • The Arctic Wolf MDR solution has helped the firm’s IT team validate security changes and notified the company when an unexpected—though legitimate—root login occurred.
  • Arctic Wolf has raised the company’s capabilities and removed the burdensome load of cybersecurity off of its internal IT team.
Quantitative Benefit
  • The real estate company has more than 75 on-premises servers and over 370 AWS instances.
  • The firm has over 400 employees with multiple offices.
  • The company’s AWS environment includes Amazon EC2 instances, Amazon S3 buckets, Amazon ElastiCache, and Amazon RDS instances.

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.