A prominent UK retailer, recognised for its offerings in clothing, home products, and premium food, has recently overhauled its security approach by migrating its Security Information and Event Management (SIEM) platform to Microsoft Sentinel.
This transition was complemented by integrating other Microsoft security tools, including Defender. Initially, the shift resulted in the accumulation of numerous configurations, adding complexity to the system.
The alert overload challenge
Following the migration, the retailer's SOC team faced an overwhelming number of alerts
Following the migration, the retailer's Security Operations Centre (SOC) team faced an overwhelming number of alerts, many identified as false positives.
This inundation not only burdened resources but also compromised the effectiveness of their security measures, as it hampered the team’s ability to conduct thorough investigations.
RiverSafe's intervention: Configuration optimisation
In response, RiverSafe was enlisted to assist the retailer by evaluating Microsoft Defender configurations and refining Microsoft Sentinel queries. The consultant embarked on an in-depth review, offering practical recommendations to the SOC team.
While some adjustments were straightforward, others necessitated coordination with various departments—an area where the SOC team had previously encountered challenges.
Enhancing communication for implementation
RiverSafe consultant played a key role in bridging contact between the SOC team and other organisational units
The RiverSafe consultant played a pivotal role in bridging communication between the SOC team and other organisational units.
By providing comprehensive documentation and clear rationales for necessary changes, they ensured that these were finally executed and documented to high standards.
Key outcomes
Within weeks, the changes that had eluded implementation for several months were achieved, fostering improved collaboration between networking and security teams.
Alert volume decreased by 62%, which significantly enhanced team efficiency by eliminating persistent, low-significance alerts. As a result, the company's security posture was strengthened, enabling the SOC team to concentrate on genuine threats and improve response efficacy.
