Sometimes what you have isn't enough. A large IP law firm had perimeter-based protection, network monitoring, and logging in place (via managed service providers). Their executive team feared it wasn’t fully comprehensive and could not cover cyber attacker techniques such as lateral movement of privilege escalation.
Download the case study to learn more
Challenge
When your business is intellectual property, you know how important it is to protect sensitive data. That’s why when one global law firm that serves information-sensitive industries needed to fortify its security stack and protect client data, they took immediate action.
While the law firm had perimeter-based protection, network monitoring, and logging in place (via managed service providers), their executive team feared it wasn’t enough. There was grave concern regarding exposure from the techniques that attackers often use in ransomware and supply chain attacks: lateral movement and privilege escalation techniques.
Penetration tests confirmed their suspicions and showed more was needed.
Solution
Within days, QOMPLX helped the firm identify and stop ransomware and supply chain attacks before a data disaster could occur. To provide relief, the QOMPLX team:
- Used QOMPLX Privilege Assurance software to map the firm’s critical active directory infrastructure and identify vulnerabilities that needed immediate repair
- Installed QOMPLX Identity Assurance software on all networked domain controllers to validate user identity before gaining network access
- Integrated alerting capabilities into the firm’s Managed-Security-ServiceProvider’s (MSSP’s) workflows, including feeds to downstream SIEM tools
Impact
With QOMPLX Privilege Assurance and Identity Assurance software solutions protecting their firm, the client began identifying and mitigating its biggest risks within days. And, just six months after retaining QOMPLX, the client purchased the QOMPLX Managed Assurance service to monitor and triage security alerts flagged by their security stack.
Altogether, the QOMPLX suite of solutions monitors hundreds of thousands of client events daily. But for the client, the most significant benefits are prioritized alerts, which allow them to be proactive and control their operational environment.