Global research: Security leaders’ priorities for cloud integrity, the talent gap and the most urgent attack vectors.
Streamlining alerts
The SLCC is inundated with thousands of alerts each year, and it needed a solution to filter, categorize, and prioritize each potential threat. Splunk's Risk-Based Alerting (RBA) solution fit all these needs, and also cut the average time of alert processing to just 13 minutes. (From the time it takes the SLCC to receive the alert to the time it forwards it to the next relevant branch).
How did La Poste achieve this? The SLCC used Splunk Enterprise Security’s capabilities and customized it according to its needs, tailoring every alert dashboard, function, rule, and search. ES’s risk-based alerting capabilities also assign risk scores to events and issue an alert if the risk score reaches a certain threshold. This means the SLCC can now comprehensively detect potential threats and suspicious activity. The team has also seen a tenfold reduction in the rate of false positives, which empowers analysts to focus on real, urgent threats and work more efficiently.
Facing new threats together
In the ever-evolving risk landscape, Splunk Enterprise Security's threat intelligence management feature has been a valuable tool in La Poste’s arsenal. When the SLCC team detects a novel threat, the threat intelligence management feature analyzes it and converts it into a technical metric. This metric is then used to enhance the alerts, so the new threat can be identified and classified going forward. Importantly, it also conducts retroactive detection, combing back through events to see if the newly detected threat had occurred before.
It takes a village to stave off threats and secure an organization, and La Poste is no exception. Its cybersecurity organization of 200 includes the SLCC and various SOC members among its branches. Adopting Splunk means that all the teams can consolidate insights and use a common tool with tailored interfaces, depending on whatever use cases were needed — advanced analysis, KPI monitoring, manual searches, you name it. Splunk has let the cybersecurity teams not only conduct faster, more thorough investigations, but also better collaborate with other teams.