Inspira’s Cyber Fusion Centers automate incident response with Cortex XSOAR

The Objective

Our Optimized frameworks result in automation, orchestration, and faster response time for incident management thus benefitting our end customers.

The Challenge

SOC optimisation, reduction of manual processes, and lowering time spent on incident resolution. Explaining how Inspira manages the entire cyberthreat management landscape for customers on one hand and its security operations centers – called Cyber Fusion Centers (CFCs) – as an MSSP player on the other, Gaurav highlights the challenges he faced on both fronts. The company wanted a managed security service offering that could automate the CFCs, allowing faster deployments and onboarding of clients. As Inspira manages security services for customers across multiple layers, it was imperative to provide a unified view of the cyberthreats they encountered daily and their response mechanism. “Parameters like what the incident lifecycle is, the mean time taken to detect or MTTD, and mean time to respond or MTTR, are integral to customers from a security service provider’s standpoint,” Gaurav said. “As an MSSP, we sought to harness the power of automation to optimize operations through a mature security orchestration, automation, and response (SOAR) technology in our own environment.” Having implemented SOAR solutions for their customers, Gaurav and his team had seen the advantages an operations team could derive from them. Hence, the thought process was to replicate the same within the CFCs at Inspira to optimize the incident management process and reduce the incident handling timeline. In addition, as a service provider, Inspira strives to offer continuous improvement. “We wanted to ensure that the time taken to resolve any incidents was minimal as more time taken to resolve an incident only meant more bandwidth taken away from critical functions,” explained Gaurav.

Requirements

Improved operational efficiencies and mature security posture When Inspira looked at threat management as a concept, it needed to work at two levels: As a security solutions provider:

  • Reduce manual activities for P1 and P2 security incidents (lower severity incidents).
  • Automate and orchestrate security response to reduce incident remediation time.
  • Invest in a solution that could offer customers an integrated security automation platform.

As an MSSP:

  • Optimise incident management in its own environment with a stable and mature SOAR solution to be able to offer better turnaround times to end customers.
  • Global presence to scale to different geographies as and when needed.

  “Parameters like what the incident lifecycle is, the mean time taken to detect or MTTD, and mean time to respond or MTTR, are integral to customers from a security service provider’s standpoint. As an MSSP, we sought to harness the power of automation to optimize operations through a mature security orchestration, automation, and response (SOAR) technology in our own environment.”— Gaurav Deshpande, Vice President of International Sales and Global Leader for Integrated Cyber Threat Management Practice, Inspira

The Inspira Solution

A comprehensive SOAR platform offers automation, realtime collaboration, unified case management, and security incident management. Since Inspira was looking at a solution that could optimize incident management within its CFCs as well as the CFCs built and operated for their customers across regions, it evaluated multiple solutions. Inspira needed to ensure that the solution selected had the required integration capabilities to mesh with multiple technologies in the CFCs. “Cortex XSOAR from Palo Alto Networks demonstrated integration capabilities far superior to other platforms,” Gaurav said. In addition, the complete Cortex portfolio of Cortex® XSOAR, plus XDR and other components, made it crystal clear that this was the solution Inspira needed to opt for. With 300 plus engineers in its CFCs, Inspira was looking at building the right use cases and playbooks that could be deployed for its customers to optimize its operations. Many of the company’s engineers had already worked with Cortex XSOAR in customer environments and had seen its effectiveness. Cortex XSOAR helped Inspira achieve increased efficiencies by unifying case management, automation, and real-time collaboration in the industry’s first extended SOAR offering. Inspira creates playbooks in its own environment that can be implemented by the customer. At this stage, Inspira has developed over 15 playbooks for each of its 10 top customers. In its own CFCs, it has more than 20 playbooks. “With Cortex XSOAR, Inspira can manage alerts across all sources, standardize processes with playbooks, take action on threat intelligence, and automate response for any security service, thereby reducing the average incident resolution time from a total of 12 hours to 1.5–2 hours or by as much as 70 percent,” Gaurav explains. Inspira also wanted a partner with a successful track record across all regions worldwide, as they wanted to scale the solution to other global offices when necessary. “With Cortex XSOAR, Inspira can manage alerts across all sources, standardise processes with playbooks, take action on threat intelligence, and automate response for any security service, thereby reducing the average incident resolution time from a total of 12 hours to 1.5–2 hours or by as much as 70 percent.” — Gaurav Deshpande, Vice President of International Sales and Global Leader for Integrated Cyber Threat Management Practice, Inspira

Key Benefits

Reduction in time taken for end-to-end incident handling (time from incident identification to resolution) After deploying Cortex XSOAR, the end-to-end incident handling seen across P1 and P2 incidents (which are on the lower scale of criticality) has reduced drastically with automation, saving analyst time to focus on more critical tasks. “With Cortex XSOAR, Inspira can manage alerts across all sources, standardise processes with playbooks, take action on threat intelligence, and automate response for any security service, thereby reducing the average incident resolution time from a total of 12 hours to 1.5–2 hours or by as much as 70 percent,” Gaurav explained. Increased efficiencies as resources are freed up for alternative tasks The auto-remediation and automation of responses have enabled team members who earlier used to work on incident handling and triage to now be available to conduct a deeper analysis of critical incidents. The same team members can now develop use cases to optimise activities further. They can also design playbooks and increase Inspira’s asset library of use cases and playbook campaigns such as the rapid breach response playbook (against new attacks), phishing response playbook, endpoint malware infection playbook, threat hunting, rapid IoC hunting playbook, and vulnerability management playbook that can be implemented for customers. Provision of an integrated security automation platform Moving from a siloed solution integrated together to a more unified view dashboard mechanism has been another significant benefit. With Cortex XSOAR, Inspira can automate responses and offer multiple use cases across various stages of the cyber kill chain. Gaurav put it brilliantly, saying, “Once you can define playbooks and implement these playbooks in the Cortex XSOAR solution, we can truly offer our customers an integrated security automation platform. Customers are not looking for information in a piece-meal manner. With Cortex XSOAR, an integrated story can be stitched together and offered as a powerful security incident management service solution.”

  • Abiding by the regulatory compliances
  • Proactively migration and mitigating frauds
  • Advanced cross channel platform for uncovering hidden patterns, trends and outliers.
  • Platform with forensics capabilities

Conclusion

Picture of Sreenivas T

Sreenivas T

Leave a Replay

Our Top Services:

CYBERSECURITY SERVICES

Top CyberSecurity Services | Secure your business with Inspira Enterprise’s expert CyberSecurity services.

DATA ANALYTICS SERVICES

Expert Data Analytics Services | Harness the power of data with Inspira Enterprise’s advanced Data Analytics services.

DIGITAL TRANSFORMATION SERVICES

Transform Your Business with Digital Transformation Services | Accelerate your business growth with Inspira Enterprise’s  Digital Transformation services.

Our Top Offerings:

Managed security services

Reliable Managed Security Services | Enhance your business security with Inspira Enterprise’s Managed Security Services.

Identity & access management

Secure Identity & Access Management Services | Ensure robust security and compliance with Inspira Enterprise’s Identity & Access Management services.

Third party risk management

Comprehensive Third Party Risk Management Services | Mitigate risks and ensure compliance with Inspira Enterprise’s  Third Party Risk Management services.