Business Requirement & Challenges​
An industry leader in Investment specialist providing financial advisers, wealth managers and high net worth offices in ANZ region wanted to consolidate security incidents from their multiple accounts in the AWS Landing Zone along with different set of security tools stack. Planning to have automation in place for responding effectively to certain security findings, the customer wanted to have security controls to reduce the time taken in the manual response process. They also wanted to strength the overall security posture of their environment by mitigating the risks by fixing all the open vulnerabilities.​
- Wazuh Vulnerability Management.  ​
- Wazuh SIEM​
- Network Firewall.​
- Threat Intelligence.​
- Governance, Risk and Compliance of AWS accounts​
-  Cloud resource performance​  ​
Solution Provided ​
- Wazuh SIEM solution provided with integration with all the accounts in the landing zone and various security tools like DLP, EDR, WAF, etc. ​
- Wazuh Vulnerability Management to scan all the resources in the environment for vulnerabilities and help mitigate the risks associated with it.​
- Wazuh scan all the resources in the cloud to meet standards like ISO 27001, etc.​
- Threat Detection based on the MITRE ATT&CK framework that provide high level overview of the tactics and techniques occurring in devices monitored by Wazuh agent on all accounts.​
- Sophos Firewall which combines robust protection , performance and adaptability to safeguard their network effectively.​
- Implement Amazon CloudWatch to provide actionable insights, reliability and operational excellence for monitoring their AWS resources.​
- Implement AWS CloudTrail to monitor, audit, and retain account activity associated with actions across their AWS Infrastructure, enhancing security and compliance​
Business Benefits​
- Automated the Security Operations.​
- Next generation tools to automate quick remediation of the cyber-threats.​
- Customized compliance dashboards.​
- Complete Vulnerability Management solution to mitigate risks.​
- 24*7 Real time threat monitoring based on the MITRE ATT&CK framework.​
- Protection from attacks on the network.​
Outcome/Results​
- Enhanced Threat Detection which improved the ability to detect and respond to cyber threats promptly.​
- Risk Mitigation through continuous monitoring of the vulnerabilities ​
- Improved performance, increased IPsec VPN throughput and protection from attacks on the network.​
- Enhanced logging and monitoring approach on CloudWatch allowed quick identification diagnosis and response to workload issues​ ​
Technology Stack​
- Wazuh SIEM and VM.​
- Amazon CloudWatch.​
- AWS CloudTrail.​
- Sophos Firewall.​
PUBLISHED: 14th November 2024