Financial Services
From 40,000 alerts to 40 real cases
A security operations team of nine reviewing roughly 40,000 alerts a month, with mean time to contain measured in hours and a growing backlog nobody could clear.
Before and after
BeforeAfter92%
Alert noise cleared pre-review
41 sec
Credential compromise dwell time
3
Material incidents caught pre-exfiltration
100%
Autonomous actions with audit records
The challenge
What they were dealing with
The tooling was good and the coverage was reasonable. The problem was arithmetic: nine analysts could not investigate 40,000 alerts, so triage became pattern-matching on alert titles. Two genuine incidents in the preceding year had been closed as noise and only found later during a routine hunt.
Services involved
What we did
- 01
Spent three weeks tuning detections before automating anything — the queue was 91% false positive and automating that would have industrialised the wrong answer
- 02
Correlated identity, endpoint, cloud and SaaS telemetry into a single timeline per entity
- 03
Built triage agents that gather the same context an analyst would and write up a case with an explicit dismissal rationale
- 04
Limited autonomous containment to reversible actions — session revocation, token invalidation, host isolation. Destructive actions still require a named human
- 05
Validated with a purple-team exercise before granting any autonomous authority
The outcome
2.8 min mean time to contain
Measured against the pre-engagement baseline and re-verified at the 90-day review.
- 92% — Alert noise cleared pre-review
- 41 sec — Credential compromise dwell time
- 3 — Material incidents caught pre-exfiltration
- 100% — Autonomous actions with audit records
We did not add analysts. We stopped asking the ones we had to prove that 36,000 things were fine.
More work
Other engagements worth reading.
Start the conversation
Bring us the process that keeps breaking.
Ninety minutes with our engineers and strategists. You leave with a systems map, an automation shortlist and an honest read on what AI should and should not touch in your business.
What to expect
- No pitch deck, no obligation
- Senior engineers in the room
- A written plan within five days
Prefer email?
support@cyberxsolutions.us