Skip to main content

Global Aerospace and Defense Company – Consolidating Threat Intelligence & Automating Processes With Playbooks

Industry

Aerospace & Defense

Company Type

Aerospace & Defense Technologies

Company Size

Global Fortune 400

Learn about persistent threats, lessons for the future, and how ThreatConnect is working to protect its customers.

Challenge

This Global Fortune 400 Aerospace & Defense organization works with multiple separate business units that each have their own set of unique use cases for threat intelligence standard operating procedures (SOPs). This includes specific tags per business unit, threat intelligence ingest, and multiple remediation steps based on specific criteria.

The team was having a difficult time keeping up with multiple manual processes, which absorbed a large number of scarce resources.

Prior to ThreatConnect, the company was leveraging open source platforms and Excel spreadsheets for consolidating and organizing threat intelligence. Specific characterization was a major daily task for the entire Intel organization.

Solution

ThreatConnect hosted multiple sessions with the Organization’s business units (30+ attendees per session) to capture and work through multiple manual processes. This led to the development of ThreatConnect Playbooks that automated specific tasks that previously would cost the company significant time and money.

With ThreatConnect Playbooks, the organization was able to document security operations processes more efficiently and consistently. Playbooks also provided the security team with metrics on completions, time, and dollars saved to demonstrate return on investment and the value of individual Playbooks.

Outcome

The end result was that one Playbook “saved us over $1,500/day,” according to the Director of the company’s Information Sharing and Analysis Center. This drove adoption of Playbooks across all supported business units, directly enabling more than 60 analysts to do their jobs more efficiently. These Playbook sessions allowed the security teams, for the first time, to show enterprise stakeholders the ROI of security operations.

Read Next:

Hospitality

Wyndham Improves Threat Detection and Response While Scaling Security Operations

Challenge

The Wyndham security team faced challenges that limited their response times and efficiency. Analysts had to deal with too much context switching and manual data collection to gain context when investigating and triaging alerts. Analysts were challenged to work consistently and efficiently.

Solution

Wyndham implemented ThreatConnect’s TI Ops Platform and Polarity across their security teams to centralize threat intelligence in a single solution, and make it more accessible and actionable.

Technology

Large Enterprise Needed Centralized Threat Intelligence Management

Challenge

This large technology client sought a centralized repository of threat intelligence to unify contextualized data, facilitate collaboration, and drive prioritization. The only viable solution to these challenges had to collect, normalize, and disseminate data while enabling analysis for actionable threat intelligence.

Solution

ThreatConnect automates the aggregation of internal and external threat intelligence, freeing up teams to focus on analysis and response. With in-platform analytics providing context and relevance, actions can be performed automatically or manually. Seamless integration with security tools and customization of workflows helps optimize SOC team processes. ThreatConnect became this company's system of record for threat intelligence processes and collaboration.

Healthcare

Large Hospital and Healthcare System – Phishing Automation and Bulk Importing and Enrichment of Indicators

Challenge

This Large health system's major challenges focused on automating Threat Intelligence collection, IOC enrichment, workflow templates, and Case Management. Use cases included phishing automation, bulk importing, and enrichment of indicators using VirusTotal, with scoring criteria based on VirusTotal results.

Solution

ThreatConnect's intelligence-powered security operations capabilities allowed the security team to streamline operations by creating automated workflows and playbooks, reducing manual steps. This solution involved multiple tool integrations for improved efficiency.