Vectra AI Inc. > Case Studies > Government Authority Achieves Complete Cloud Monitoring with Vectra AI and AWS

Government Authority Achieves Complete Cloud Monitoring with Vectra AI and AWS

Vectra AI Inc. Logo
Company Size
1,000+
Region
  • Middle East
Product
  • Vectra Cognito platform
  • AWS Security Hub
Tech Stack
  • AWS
  • AI
  • Machine Learning
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Cost Savings
  • Customer Satisfaction
  • Productivity Improvements
Technology Category
  • Analytics & Modeling - Machine Learning
  • Infrastructure as a Service (IaaS) - Cloud Computing
Applicable Industries
  • Cities & Municipalities
  • National Security & Defense
Use Cases
  • Cybersecurity
Services
  • Cloud Planning, Design & Implementation Services
  • Cybersecurity Services
About The Customer
The Government Authority is a Middle Eastern organization that manages and oversees all of the country's digital assets, information technology, and data programs. It operates similarly to a service provider throughout all government agencies including healthcare, education, traffic, and immigration. The Government Authority owns and maintains IT security for all of its critical systems, delivers statistics, processes payments, and provides user authentication and authorization. It is responsible for maintaining and supporting multiple core business functions at a large scale. The Government Authority is taking a cloud-first approach, and security is no different. It is leveraging Amazon Web Services (AWS) to improve security operations efficiency by storing security metadata in its data lake to perform effective threat hunting and incident investigations.
The Challenge
The Government Authority in the Middle East manages and oversees all of the country's digital assets, information technology, and data programs. It operates similarly to a service provider throughout all government agencies including healthcare, education, traffic, and immigration. Cybersecurity is a fundamental pillar protecting government institutions as they are a prime target for hackers. The Government Authority maintains and supports multiple core business functions at a large scale where compromised data or systems increase the risk of a breach. A breach in a government institution would impact critical systems that citizens rely on, demand remediation costs, and require unplanned spending to close the gaps. The security team needed to reduce the risk of a breach by having the ability to detect and respond to potential threats. However, they were overwhelmed with a large volume of unprioritized alerts, poor capability in detecting unknown threats, and they lacked visibility into their cloud environment.
The Solution
The Government Authority selected the Vectra Cognito platform to detect attacker behavior across the entire footprint, from datacenter to cloud, to protect its operations and manage compliance risks. Vectra’s AI-driven Cognito Platform delivers the most comprehensive insight across cloud including SaaS, IaaS, and PaaS, as well as data center and enterprise networks, uncovering hidden threats and empowering incident responders to act with confidence. The security-enriched data captures network metadata at scale, enriches it with machine learning security information and applies it across the platform, providing necessary details for effective threat hunting all stored in AWS. The deep integration into AWS allows the organization to deploy Vectra sensors and use AWS virtual private cloud (VPC) traffic mirroring to extend AI-driven detection and response to their additional AWS workloads. Full integration with AWS Security Hub means that Vectra detections are also published as findings in Security Hub, enabling the correlation of Vectra attacker detections with other data sources for faster incident investigations and remediation in the cloud.
Operational Impact
  • The Government Authority now has visibility across the entire network and can find active attacker techniques minimizing the high financial and liability risk caused by a breach.
  • This insight has reduced the workload of the security operations team 40x.
  • The number of events has been reduced to 2-3 per day with critical events reduced to 1-2 per day.
Quantitative Benefit
  • Workload of the security operations team reduced by 40x.
  • Number of events reduced to 2-3 per day.
  • Critical events reduced to 1-2 per day.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.