A fast-growing specialist pharmaceutical organisation suffered a security breach and needed a quick response with mitigating actions. It was also apparent that the client required a completely independent security operations centre (SOC) that was separate from its IT support functions. This external scrutiny was necessary from both a security and governance perspective.
As part of our Security Operations Centre service, we assembled a Security Incident Response Team to analyse, contain and mitigate the threat. We performed technical investigations to identify points of entry and information which could have been compromised.
We unearthed the causes of the breach, identified residual vulnerabilities within the systems and made recommendations for mitigating actions. All these steps were part of an initial security gap analysis which also included examining the client’s Office 365 estate and highlighting weaknesses in their IT infrastructure.
Finally, we set up and monitored alerts generated by their Office 365 estate and ran further investigations based on our findings. By monitoring the client’s alerts, we were able to identify users’ day-to-day activity and alert them of any suspicious behaviour.
Our SOC service freed up the in-house IT team’s time and resources so they could concentrate on business-critical IT projects. They could rest assured that their IT security was safe in the hands of a specialist.