United Kingdom, Oct 16, 2024
Security and Threat Protection Powered By Microsoft Azure Sentinel
The Challenge
The core of Jersey Electricity’s (JE) defence systems were centred on legacy cybersecurity log aggregation platforms. These platforms took up a lot of Security Operations Centre (SOC) man hours to manage. There was a challenge to produce meaningful reports, and vulnerability and correlation though the millions of logs took time. The security team was wasting time operating the tools and not able to dedicate enough time to identifying potential network and endpoint vulnerabilities.
Moreover, the legacy vendor was not investing further into their Security Information and Event Management (SIEM) platform, and the threat intel was no longer forthcoming. The security systems had now become a business risk. Both the JE team and the Logicalis security team acknowledged the requirement for a more modern defence platform that would defend and protect the critical corporate infrastructure whilst integrating more fully with the other layers of the business
The Solution
Once the decision for change had been made and given the increasingly urgent need to improve security, the JE executive team moved quickly. The plan was to migrate to a more modern platform in no longer than three months – a tight timescale. Successful execution required the selection of the right security tools.
Consideration had to be given to the JE’s stated cloud-first strategy whilst also protecting the current critical business system workloads on-premise. Logicalis had been working with Microsoft developing our Secure OnMesh services which are powered at their core by Microsoft Azure Sentinel.
Microsoft Azure Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution. Azure Sentinel delivers intelligent security analytics and threat intelligence across the enterprise for both on-premise and closed based systems, providing a single solution for alert detection, threat visibility, proactive hunting, threat response.
Gary Le Gros, Head of ICT Services, Jersey Electricity commented:
Logicalis understood the operational challenges we faced, and we have been delighted by the expertise and experience they have provided throughout the implementation.
The Outcome
Microsoft Azure Sentinel provides greater visibility, and automatic level one and two response, with high fidelity logging and information for faster response and meaningful outputs. No product and platform are perfect - leveraging Logicalis’ expertise, our pedigree in delivering managed security solutions and years of cybersecurity knowledge – our team were able to deliver a tailored solution that met the customers requirements within budget.
The Logicalis Secure OnMesh Sentinel service brings together our 24x7x365 Jersey based Security Operations Centre with Azure Sentinel and delivered for JE a fully managed security service all within a similar budget of the existing platform and with no interruption to the business and more importantly no downtime in their cyber defences.
- Logicalis reduced the cost of ingesting data sources by over 40%, making sure it is only delivering logs and information that are pertinent to security, thus reducing noise and associated alert fatigue.
- The Logicalis service reviews and monthly reports has given JE greater oversight of all of their environment, reducing stress associated with audits and allowing more focused sessions with the auditors for compliance.
Gary Le Gros commented:
Our move to Azure Sentinel, undertaken by our service provider Logicalis, was managed very professionally, and resulted in a successful project implementation. We have been impressed with their expertise, experience, and collaboration. That’s proved a great foundation for a long-lasting partnership and ensures on-going visibility and management of the service for Cybersecurity risk mitigation.