To properly launch this new service, though, Silverfern needed to make some adjustments to how it monitored client environments.
“Traditionally, the types of services that we ran for our clients were pretty much very standard security monitoring—like endpoint detection or firewall managing,” clarifies Eng. “We had all these great tools, but they each had their own interface—their own portal. So we needed a central control panel where our engineers could look at all of the client’s environment and look at everything all at once.”
A long-standing IBM Business Partner, Silverfern quickly chose to deploy IBM Security® QRadar® technology to run its new SOC service. “In the marketplace, every security vendor claims their product is the best,” notes Eng. “Which is fair enough, but we looked at the Gartner Magic Quadrant, and there was IBM. Not only was QRadar the number one product, it had consistently been a leader for the past several years. That and our deep relationship with IBM over the last 20-plus years made the decision a no-brainer.”
Named the QRadar Managed Detection and Response service, the new SOC offering provides a unified, end-to-end service for a company’s cyberthreat needs. “We can typically get a client started within three to four weeks—we only have to bring in their log sources,” says Eng.
He continues: “And after that we watch their environment 24x7 for any indicator of a potential attack. From a single pane of glass, we can see log sources from across their business—from firewalls to endpoints to applications and databases. If it’s in the network, we can see it.”
The new SOC service relies on IBM Security® QRadar SIEM technology to oversee event management, using real-time analytics to sift through contextual threat data and shift to a more proactive monitoring posture. The SIEM solution’s IBM Security QRadar Advisor with Watson® functionality, in turn, harnesses the capabilities of AI to map offenses against a security incident database and better contextualize individual security incidents quickly and accurately.
And if a threat is detected, Silverfern uses IBM Security QRadar SOAR to manage the entire security incident lifecycle from detection through remediation. Much of this happens automatically as the business aligns its response efforts with predefined use cases—such as threat hunting or security-alert triaging.
Both of these QRadar offerings are delivered under an IBM Cloud Pak® for Security license. And in the not-too-distant future, Silverfern intends to further explore the capabilities delivered by the IBM Cloud Pak.