ThreatCenter at Work
Enterprise Security Information Management Return on Investment (ROI)
Running to stand still, the security team at one of the nation’s largest legal firms had to
face the cold, hard evidence. In order to continue to manage the IT security of their
dozen offices in the US and abroad they were going to have to hire extra people – or
figure out how to better manage the workload created by their 100 or so firewalls,
intrusion detection systems and other security infrastructure. The sheer volume of event
data necessary to properly manage all the security incidents was exceeding the capacity
of this small, highly skilled and motivated team.
Working smarter, not harder. The cliché was proven true when they chose to install
OpenService’s ThreatCenter. In less than five working days the team
had ThreatCenter monitoring their firewall logs, quickly proving that its advanced correlation,
threat management and reporting features could effectively reduce their workload while
enhancing their ability to protect the company and its sensitive client data.
Winning the case for the defense, the team has aggressively rolled ThreatCenter into production, monitoring other security
systems. Instead of working with multiple point-solution consoles, they manage all alarms using ThreatCenter’s single webbased
management console. At the office or after hours, they work more effectively and collaboratively over the web.
They have reduced the number of time-consuming and expensive on-call visits to the data center after hours, and
have reduced their workload across the entire team by one full time equivalent (FTE) in a matter of months – and they
use this time to better focus on proactive defensive work. Finally, they also found a previously undetected issue in a
firewall cluster that they were able to quickly resolve.
The Verdict. By deploying ThreatCenter, in a matter of months this firm saved the equivalent of three FTEs (two not hired and
one freed up from the existing team). ThreatCenter has made them more effective, more efficient, and better able to protect
their company’s secrets and their clients’ data. ThreatCenter turned their existing deployed security systems into effective
enterprise protection, and improved their working practices in the process. As the security manager for the form
observed:
"The rapid implementation and outstanding results from
ThreatCenter
have surpassed our expectations."


