RiverSafe Limited - Experts & Thought Leaders
Latest RiverSafe Limited news & announcements
When it comes to balancing visibility and spending, Security Incident Event Managment (SIEM) licensing models can be somewhat restrictive—something a multinational, born in the cloud technology company was becoming painfully aware of. The organization wanted to improve its security posture by ingesting more data feeds into its SIEM. However, its cybersecurity team found itself hampered by license limitations and prevented from feeding in more data by license utilization caps. Faced with excessive additional licensing costs, the company needed an alternative solution that would optimize the ingestion of data, reduce license usage, and boost visibility across its environment—without breaking the bank. Enter Cribl Looking for the best solution to achieve their data goals, the company reached out to cybersecurity company RiverSafe for advice. Given its ability to optimize, route and enrich data, Cribl was chosen as a possible fit, and RiverSafe began a proof of concept to investigate the potential impact the product could have on the company’s data streams. “We chose four data sources, and deliberately chose some of our most volumetric data sources. We had a success criterion in mind, and that was to send all these data sources to our SIEM environment via Cribl and see what kind of reduction we could get from a percentage perspective,” the head of security program management said. “It’s seemed to be a very good product and much needed in the marketplace. There are many organizations like us who have the same kind of challenges and the same use case issues, whereby they don’t have the budget or inclination to spend more and more money on their SIEM.” Instant data ingestion reduction After a successful proof-of-concept, the company opted to implement Cribl Stream. “I know (Cribl Stream) and I knew its capability, so I had an inkling as to what the reduction rate could potentially be. What really surprised me was how easy it was to reduce the data feeds into the SIEM. I was really shocked at how seamless it was to introduce a layer like Cribl to assist with the data optimization and reduction.” After implementing Cribl Stream as an optimization layer, the company reduced the amount of data being fed into its SIEM from around 750GB to 450GB. “We were able to reduce our data ingest by about 40%, which matched our original success criteria around the percentage we hoped to reduce the data ingestion by. More importantly, what we were reducing were largely blank fields and null values, content that didn’t feed into our detection rules. We’re able to gain this headroom and cost savings without sacrificing visibility or increasing risk.” Streamlining data ingestion An additional benefit the company experienced post-implementation was streamlined data ingestion. By pointing data through Cribl, the company is able to cherry-pick the data that’s sent to its SIEM, simplifying the onboarding process for new data feeds. “Once we’ve pointed the data to Cribl, we’re able to pick and choose what data we send into the SIEM and what data we don’t. That’s made it a lot more efficient in terms of the way we onboard data, and it’s enabled us to be a lot more granular with the data that we ingest into our SIEM.” Greater scalability With the reduction in data ingestion levels, the company is less likely to run into issues due to SIEM licensing limitations. By employing Cribl to help manage its data, the company hopes to benefit from greater scalability and agility in the future. “Going forward, we’ll have scalability from a visibility and coverage perspective without being constrained by a SIEM license.” This flexibility is just one of the wide-reaching benefits that the company has experienced since implementing Cribl, and one that’s made a major difference to its operations. “Cribl gives you the flexibility to reduce data ingest, but also the flexibility to be agile and to move your data sources from one environment to another without much configuration. It’s given us the capability to be less rigid in our architecture; that’s been the biggest impact for us.” Significant cost savings Having cut data ingestion by 40% with Cribl Stream, the company is free to load more data feeds into its SIEM without the need to purchase additional licensing capacity. This has not only allowed the company to increase visibility across its digital environment, but also cut down on licensing costs. “Now that we’ve got Cribl in our architecture, we have the ability to ingest more data feeds without having to buy additional licensing—that’s already saved us money. If we didn’t have Cribl, that additional cost would have been between £120,000 and £150,000 per year, on top of what we’re already paying today for our SIEM.” As well as reducing spending on SIEM licensing, the company has been able to cut costs in other areas. “We’re completely in the cloud, so we’re charged for data that we retain for a longer period. Now that we have Cribl, we can send the data that we want to retain to a cheaper storage solution. And with Cribl Replay and Cribl Search, we still have the ability to easily search that data should we need it for audits or incident investigation. That gives us a cost benefit and more flexibility in the long run.” Smarter resource utilization Cribl is also helping the company put its valuable resources to better use by cutting down on manual data management tasks. Previously, its team had to configure multiple destinations when data was ingested. With Cribl, data from various locations can be ingested once and pointed to numerous locations around the business, eliminating the need for system and platform owners to configure multiple endpoints. FTE effort to implement a data feed “Normally, it would’ve taken us about two days of FTE effort to implement a data feed into Splunk or a similar destination. Since the introduction of Cribl, we’ve cut that down to half a day because now we only need to configure to send to Cribl and Cribl takes care of translating the data into the ideal format for other destinations.” This reduction in time and labor adds up to additional cost savings too. Now, the company can send just the data that’s relevant to a particular end user, rather than shipping the entire data set. This has helped save money on licensing, infrastructure/compute, processing, and effort. “Because we’re a cloud-native organization, processing costs money—if we’re able to save on that, then we are definitely winning from a cost perspective.”
At the client, a multinational Oil and Gas company, the IT team provides technical support and security reporting to over 7,000 retail sites. Their work includes managing all firewalls, switches, VPNs, servers and network appliances, as well as the challenging job of keeping track of operational and compliance status. Due to limitations with its existing SIEM solution, the team in North America struggled to get full visibility on over 40% of the activities within its PCI environment. This significant blind spot left the company vulnerable and at high risk of data breaches. Not only was gaining a complete overview of PCI activity an issue, but the team also had to undertake hours of manual data processing and other activities. This extra workload was partly a result of poor data structuring within the SIEM solution, making it difficult to search. The solution Having already seen the benefits of using Splunk within its European team, the client opted to implement the platform to improve security and observability in North America. To help deploy the new solution, they commissioned RiverSafe due to their expertise with Splunk to deliver the implementation in partnership with its internal team. With the support of RiverSafe, the team created a bespoke design blueprint and built its own Splunk instance within its private cloud environment. This was a significant step for the team, resulting in previously siloed archive data from 15 data sources and 7,000 websites being stored in one space, and creating a one-stop-shop for PCI compliance officers to access the information they need. As an accredited Splunk partner, RiverSafe was able to deliver expertise in demonstrating PCI compliance, providing the in-house team with the ability to verify compliance by improving data handling and automating reporting. The outcome Since RiverSafe successfully implemented Splunk, the team has gained full visibility into their PCI environment, ensuring the security of their data and improving efficiency around reporting. Now, the team is fully equipped to keep on top of both operational and compliance activities. Benefits achieved by the implementation include: 20-30% reduction of time spent on evidence collection for PCI audit 15-20% reduction of operational admin time through the removal of manual processes 24/7 protection of data and the systems processing it thanks to real-time monitoring and alerting capabilities Visibility on the whole environment Improved ability to mitigate potential fraud and prevent security breaches Instant visibility on PCI compliance across the whole environment Immediate notification of any breaches of PCI compliance requirements
Operating in 26 countries, with partnerships in 55 more, Vodafone is one of the world’s pioneering mobile communications providers. The company made the first-ever mobile phone call on 1 January 1985, and now delivers mobile communications to almost 444 million customers. Jake Francis, Head of Technology Security for the Information Security Technology Group (ISTG) for Vodafone in Ghana, initially approached RiverSafe to help with some log monitoring. Team’s monitoring processes The company had been using Splunk in its environment for two years. While some of Vodafone Ghana’s systems were being analysed by Splunk, many crucial systems including Bluecoat, VPN, email servers, routers and switches and firewall logs were not—leaving blind spots in the team’s monitoring processes and leaving them unable to see the complete picture. “There were gaps or loopholes which create opportunities for theft,” Jake explains. “These can then be easily manipulated by those who understand where they are and how to penetrate them.” Real-time anti-fraud capability Jake added: “Every transaction that goes onto the system needs to be vetted to make sure that it’s a legitimate transaction. This is especially important in Ghana where we operate a prepaid market and need to ensure that authorization for data and payments are legitimate.” “For example, if a customer has paid for one gigabit of data then this is what should be issued to their account. What we found, however, was that some of the retail shops were raising fraudulent claims. We now have the ability to see this more easily.” Jake realised that Vodafone needed better real-time anti-fraud capability in order to prevent internal fraud between Vodafone’s retail stores and its back office systems. “We found that there wasn’t a Splunk app available to combat internal fraud,” recalls Jake, “and we needed this so that we could effectively reconcile revenue.” The solution To tackle this costly action, Jake again turned to RiverSafe to develop a new anti-fraud app. RiverSafe developed scripts and analytics that would address Vodafone Ghana’s unique needs. This additional layer of checks and balances is particularly crucial in Ghana, where the IT and telco infrastructure is developing and often underserved. RiverSafe also reviewed Vodafone’s existing log management scripts, including configured searches and logic. This data was then mapped to documented use cases and consumer requirement reporting, enabling the company’s Revenue Assurance team could verify revenue growth against usage. The outcome With RiverSafe’s help, Vodafone have now implemented bespoke new criteria, metrics, analytics and reporting around fraud trends. The team now also has access to in-depth forensic data so that the ISTG can assist other departments with any internal fraud issues. “Now I can store all this information in my server and go back and write a script against these logs to find out what’s happened if I believe there’s an issue. This enables us to look out for possible trends and scenarios. Now we’re being proactive, not just reactive, and helping the fraud department with reconciliation and revenue assurance.” Other parts of Vodafone The anti-fraud app is now being rolled out to other Vodafone Ghana offices, with plans to implement it in other parts of Vodafone in Africa and Asia, where there is also a large prepaid market. “RiverSafe helped us to meet our security audit requirements… now we’re being proactive, not just reactive. The team has been terrific and their expertise and support has been second to none,” Jake Francis, Head of Technology Security for the Information Security Technology Group (ISTG) Vodafone.