Summary is AI-generated, newsdesk-reviewed
  • RiverSafe deploys Exabeam for enhanced cybersecurity in financial services, reducing false positives.
  • Exabeam's UEBA tools improve monitoring, visibility, and security data management for financial clients.
  • Client reduces threat assessment time by 30% using Exabeam, improving phishing and brute force defense.

In a bid to fortify its cybersecurity posture, a global financial services group has turned to RiverSafe for the deployment of Exabeam, a security information and event management (SIEM) solution. Operating in the highly regulated and frequently targeted financial industry, the group needed to enhance its infrastructure protections while ensuring customer data remained secure from potential threats.

The company's previous threat detection solution presented challenges, notably generating a high volume of false positives. Without a robust SIEM tool and relying on less efficient user and entity behavior analytics (UEBA) processes, the team realized the necessity to bolster their security framework to meet stringent industry standards.

Improving Security Visibility and Oversight

Exabeam’s smart timeline feature, which consolidates all user activity into one stream

Enhancing visibility within the security infrastructure was identified as a focal point. The existing system showed possibilities for improvement, specifically in consolidating monitoring into a unified interface. The team also sought to improve the oversight of active directory actions, focusing on enumeration attacks and controlled export of company data by internal users.

RiverSafe recommended Exabeam for its efficient data processing, simple architecture, scalability, and ease of deployment. The off-the-shelf content provided by Exabeam's UEBA dashboards and reporting tools offered pre-built models and statistics, facilitating immediate event monitoring and flagging. Exabeam’s smart timeline feature, which consolidates all user activity into one stream, also addressed visibility issues effectively.

Deployment and Customization

Upon client approval, RiverSafe implemented Exabeam in their AWS environment, adhering to best practice guidelines. The process involved mapping relevant log sources and onboarding all necessary data streams. This ensured only pertinent information was ingested for security and monitoring purposes, reducing noise from the SIEM and decreasing the occurrence of false positives.

RiverSafe developed and deployed custom use cases in collaboration with the client to maximize the value derived from the Exabeam implementation. This included creating custom roles, models, parses, additional search filters, and guidance on maintenance and monitoring techniques.

Enhanced Threat Detection and Data Integrity

The client now benefits from an integrated monitoring workflow that seamlessly supports routine security tasks

The client now benefits from an integrated monitoring workflow that seamlessly supports routine security tasks. The security team can quickly monitor the entire environment, significantly reducing the time required to assess and respond to threats such as phishing, brute force attacks, and unusual internal behaviors.

Thanks to RiverSafe's expertise, the client successfully scaled its Exabeam solution by accessing the appropriate hardware needed for efficient operation. The optimization of log source onboarding has decreased complexity and facilitated easier access to critical information.

Consolidated Security Data

Security insights have been centralized, eliminating silos and increasing perceptibility across the organization. The integration enables the team to monitor email, endpoint, active directory, and web activity, frequently targeting these areas for suspicious activities. This visibility also extends to file activity, which safeguards the company from potential data loss and helps maintain data integrity.

By equipping the team with a more straightforward approach to managing security data and identifying trigger points, the deployment of Exabeam has led to a 30% reduction in time spent on threat hunting.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...

rf IDEAS Supports Gallagher Badge In Apple Wallet
rf IDEAS Supports Gallagher Badge In Apple Wallet

rf IDEAS, a global manufacturer of RFID credential readers, announces that its WAVE ID® readers support Gallagher Employee Badge in Apple Wallet, expanding the range of credent...