{"id":16313,"date":"2022-07-07T16:15:04","date_gmt":"2022-07-07T15:15:04","guid":{"rendered":"https:\/\/www.intelligentcio.com\/apac\/?p=16313"},"modified":"2022-07-07T16:15:08","modified_gmt":"2022-07-07T15:15:08","slug":"sandfield-strengthens-it-security-and-automates-monitoring-with-logrhythm","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/apac\/2022\/07\/07\/sandfield-strengthens-it-security-and-automates-monitoring-with-logrhythm\/","title":{"rendered":"Sandfield strengthens IT security and automates monitoring with LogRhythm"},"content":{"rendered":"\n<p><strong><em>Sandfield, a software solutions provider based in New Zealand, has deployed the LogRhythm-based SIEM platform, following a recommendation by managed services provider Advantage. Sandfield is now benefitting from a new security framework that provides better visibility and protection.<\/em><\/strong><\/p>\n\n\n\n<p>Established in 1989, Sandfield has grown to become a leading provider of software applications for operational businesses looking to differentiate themselves through the use of technology.&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>The company\u2019s services and product portfolio includes software and website development, application delivery, database administration, mobile app development and integration services. Sandfield supports clients throughout New Zealand and around the world.<\/p>\n\n\n\n<p><strong>The challenge<\/strong><\/p>\n\n\n\n<p>As it has grown during the past few years, Sandfield has increasingly been taking on larger and more complex client projects. This has required an expansion of the company\u2019s cloud operations\u00a0\u00a0\u00a0\u00a0\u00a0and an increase in processing and storage capacities.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/07\/Justin-Knight.jpg\" alt=\"\" class=\"wp-image-16314\" width=\"236\" height=\"255\" srcset=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/07\/Justin-Knight.jpg 500w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/07\/Justin-Knight-278x300.jpg 278w\" sizes=\"auto, (max-width: 236px) 100vw, 236px\" \/><figcaption><strong>Justin Knight, Head of IT Operations at Sandfield<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p>Justin Knight, Head of IT Operations at Sandfield, said this growth had also led to the need for increased IT security measures to ensure client applications and data were fully protected from external threats. At the same time, the organization benchmarked its protocols against an international standard to ensure their capabilities would be protected.<\/p>\n\n\n\n<p>\u201cAbout 18 months ago, we achieved our ISO27001 certification,\u201d he said. \u201cAs a part of that, and to ensure we had all the required controls in place, we realized we needed better insight into and management of our security measures.\u201d<\/p>\n\n\n\n<p>Initially, the company\u2019s IT team assessed whether this could be achieved using internal staffing and resources. However, it quickly became apparent that this would not be the most effective approach.<\/p>\n\n\n\n<p><strong>The solution<\/strong><\/p>\n\n\n\n<p>After examining a range of alternatives in the IT security space, a decision was taken to engage the services of New Zealand managed services provider Advantage.<\/p>\n\n\n\n<p>Advantage assessed Sandfield\u2019s specific requirements and recommended that the LogRhythm-based Security Information and Event Management (SIEM) platform be deployed. The project began in early 2021 with a proof-of-concept (PoC) before rolling it out to cover all critical systems.<\/p>\n\n\n\n<p>\u201cThe first step for us was to enable LogRhythm to capture all our Windows and firewall logs,\u201d said Knight. \u201cSince then, we have added logs from our AWS and Azure cloud environments as well as Google Workspaces.\u201d<\/p>\n\n\n\n<p>Knight said the fact that Advantage already had a comprehensive knowledge of LogRhythm was invaluable as it allowed the new security framework to be up and running very quickly. \u201cBy using their team of experts, it meant our internal IT team did not have to fully understand the complexities of the platform before we could put it into action,\u201d he said<\/p>\n\n\n\n<p>Advantage also worked to include a stream of New Zealand-specific security data into the system, including Malware Free Networks from the New Zealand Government Security Bureau, to further improve protection. This data helps to identify localized threats that may have already been flagged by other organizations.<\/p>\n\n\n\n<p><strong>The benefits<\/strong><\/p>\n\n\n\n<p>With the LogRhythm SIEM platform now fully functional and receiving logs from a range of core systems, Knight said the biggest benefit has been \u2018peace of mind\u2019.<\/p>\n\n\n\n<p>\u201cWe know that we now have better visibility of all our security logs and events,\u201d he said. \u201cWe can be confident that any misconfigurations, breaches, or unauthorized access of our systems will be quickly picked up.\u201d<\/p>\n\n\n\n<p>Knight said the level and extent of protection enjoyed by the company would simply not have been possible to achieve without LogRhythm. As an example, in a recent month there were more than 191 million logs ingested by LogRhythm, of which 3.5 million were forwarded to a second stage for closer analysis by Artificial Intelligence tools.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/07\/SteveSmith.jpg\" alt=\"\" class=\"wp-image-16315\" width=\"239\" height=\"228\" srcset=\"https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/07\/SteveSmith.jpg 500w, https:\/\/www.intelligentcio.com\/apac\/wp-content\/uploads\/sites\/44\/2022\/07\/SteveSmith-300x286.jpg 300w\" sizes=\"auto, (max-width: 239px) 100vw, 239px\" \/><figcaption><strong>Steve Smith, Auckland Regional Manager, Advantage NZ<\/strong><\/figcaption><\/figure><\/div>\n\n\n<p>\u201cThis then led to 67 alarms being triggered, of which just 37 needed to be investigated by the Advantage security operations team,\u201d he said. \u201cThat is an example of how effective LogRhythm is at spotting potential threats amid very large volumes of alerts. There would be no way to do that manually.\u201d<\/p>\n\n\n\n<p>Knight said the LogRhythm infrastructure has already proven to be invaluable as it recently spotted a misconfiguration that could have led to \u00a0issues if not rectified in a timely manner.\u00a0\u00a0\u00a0\u00a0<\/p>\n\n\n\n<p>\u201cWe were then able to rectify that misconfiguration immediately whereas, prior to LogRhythm, it may have been days or even weeks before it was spotted,\u201d he said. \u201cWe are now much more comfortable that we have the level of visibility we require to ensure our systems and resources are secure at all times.\u201d<\/p>\n\n\n\n<p>Steve Smith, Auckland Regional Manager, Advantage NZ, said the strong working relationship that now exists between the two companies would help to ensure the current high levels of security protection would be maintained.<\/p>\n\n\n\n<p>\u201cWe now have a solid understanding of Sandfield\u2019s requirements and look forward to supporting them as a team with the winning combination of LogRhythm\u2019s technology and expert skills as they continue to grow in the future,\u201d he said.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sandfield, a software solutions provider based in New Zealand, has deployed the LogRhythm-based SIEM platform, following a recommendation by managed services provider Advantage. Sandfield is now benefitting from a new security framework that provides better visibility and protection. Established in 1989, Sandfield has grown to become a leading provider of software applications for operational businesses [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":16316,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,18,55,44],"tags":[3447,559,3448,264,602],"class_list":["post-16313","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis-case-studies","category-enterprise-security","category-oceania","category-top-stories","tag-advantage","tag-logrhythm","tag-sandfield","tag-security-2","tag-siem"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/16313","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/comments?post=16313"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/16313\/revisions"}],"predecessor-version":[{"id":16322,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/16313\/revisions\/16322"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media\/16316"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media?parent=16313"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/categories?post=16313"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/tags?post=16313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}