Financial Services

Cortex XSIAM reshapes SecOps for Fortune 500 financial giant

SUMMARY

A multinational bank with 6,500 branches and 165,000 endpoints struggled to address growing cyberthreats due to the limitations of its traditional SIEM, QRadar. Insufficient threat detection, operational inefficiencies, and compliance challenges had become the norm.

After running several vendors through a rigorous Proof of Concept exercise, the bank embraced a platform approach from Palo Alto Networks to transform the SOC. With the Cortex XSIAM AI-driven platform, the bank is enabling seamless integration, compliance, and automation while achieving rapid threat detection and response.


results


A revolution in SOC productivity and efficiency that meets strict regulatory and compliance requirements with an AI-driven SecOps platform.

5 to 1

consolidation of SOC tools into one platform

17

actionable incidents per day derived from 19,000 daily alerts

40%

reduction in unnecessary data storage through optimization
challenges

Yesterday’s solutions couldn’t stand up to today’s threat landscape.



  • Inadequate legacy systems: The existing SIEM and SOC tools couldn’t handle the ever-increasing volume and sophistication of cyberthreats and couldn’t measure effectiveness metrics like MTTR.

  • Lack of advanced capabilities: The incumbent SIEM lacked the necessary AI/ML to effectively address complex attacks.

  • Insufficient threat detection: The SOC’s reliance on manually created correlation rules for threat detection was proving insufficient against advanced threats.

  • Regulatory challenges: The bank sought to migrate to a SaaS SOC solution while finding a way to align with the stringent regulatory requirements in its country—including RBI, CERT-IN, NCIIPC, and DPDPA.

“We demonstrated Cortex XSIAM’s ability to integrate critical log sources quickly, streamline alerts, and detect advanced attacks. Tailored compliance, bring-your-own-keys for data security, and custom rules showcased how XSIAM surpasses traditional SIEMs, delivering unmatched performance and regulatory alignment."

- Saurabh Sah

Regional Sales Manager, Palo Alto Networks

SOLUTION

An international bank demands a SOC worthy of its data.


As a global bank expanded its operations and its security challenges grew, so did its SOC—from 20 to over 40 analysts working 24/7. This increase underscored the need for a scalable security platform that could automate routine tasks, allowing analysts to focus on strategic security initiatives. Initially, the bank considered upgrading its existing SIEM, but it soon recognized the need for an overhaul of the SOC. This decision was driven by the desire to achieve high levels of security and efficiency that could not be accomplished with traditional SIEM solutions alone.

Passing the test with flying colors.


During the Proof of Concept phase, Cortex XSIAM proved itself to be the ideal solution for modernizing the bank’s SOC, delivering capabilities that exceeded its detection, remediation, and analytics requirements:

  • Compliance with strict regulatory standards

    Cortex XSIAM was tailored to efficiently meet the rigorous and diverse national and international regulations of the bank’s regulatory environment.

    • Localized data storage: Cortex ensures compliance with regional data localization regulations by keeping sensitive data stored within each country where it does business. This aligns with the FSI requirements set by regulatory bodies such as the RBI, CERT-IN, NCIIPC, and DPDPA. Additionally, Cortex XSIAM is SOC 2 Type II certified, which facilitates adherence to various industry and geographical data retention regulations.

    • Audit trails and compliance transparency: Cortex XSIAM facilitates comprehensive auditing capabilities, offering detailed and transparent audit trails. Financial institutions can access annual SOC2 Type II audit reports and have the option for onsite audits, ensuring ongoing compliance verification and transparency.

    • Data retention and purging policies: The platform adheres to strict data retention policies, configurable to meet specific regulatory requirements. Data is retained for a default period of 30 days and can be extended if needed. Alerts are retained longer for detailed investigation, and a full deletion of data is ensured within 180 days post-termination, complying with data retention regulations.
  • Bring your own keys (BYOK) capability

    Cortex can enable the bank to transition from relying on Google Keys to owning and managing its own encryption keys (BYOK), empowering the bank to maintain stringent control over its data security protocols and ensuring that sensitive information remains protected under its direct oversight.
  • Rapid integration and data ingestion

    alert

    Cortex XSIAM was rapidly deployed into the bank’s environment. In just three days, it successfully connected with 20 critical log sources and plan to increase data ingestion from 7 TB to 150 TB. This enhancement improved advanced threat detection, streamlined incident response, and provided comprehensive visibility across the bank’s entire attack surface.

  • Optimized data ingestion and SOC efficiency

    alert

    Palo Alto Networks demonstrated how the bank could lower data storage costs with Cortex XSIAM’s capability to selectively ingest crucial telemetry data, reducing unnecessary data ingestion by 35-40%. Additionally, automation features reduce the need for manual interventions, enhancing SOC analyst productivity and allowing financial institutions to allocate resources more effectively.
  • Comprehensive threat intelligence and automation

    alert

    Cortex XSIAM seamlessly integrated 9+ threat intelligence sources, with 21+ custom and out-of-the-box playbooks configured for automated response—immediately improving threat analysis and response times.

  • Advanced analytics and detection

    Analytic capabilities include cloud-based identity analytics, user and entity behavior analytics (the only solution to offer them in the cloud), and cloud analytics for O365 and related services to identify anomalies.
  • Empowered threat-hunting capabilities

    Cortex XSIAM enabled proactive security measures and customization with bring-your-own-machine-learning (BYOML) capabilities for hypothesis-driven threat hunting, significantly increasing efficiency by reducing false positives. The customization capability provides a flexible solution that can evolve with the institution.
  • Streamlined incident management

    Cortex consolidated approximately 19,000+ alerts into 17 actionable incidents—a 99.9% reduction—and employed automated scripts for rapid investigations, dramatically optimizing the process of managing and responding to security incidents.
  • Rigorous detection in live attack simulations

    Using AI-driven capabilities, Cortex successfully detected over 5,000 attack scenarios—many more than the competitor solutions—during live simulations of sophisticated cyber threats, giving the bank confidence that it could achieve an exceptionally strong security posture.
  • Custom content creation

    To respond to the bank’s question about Cortex XSIAM’s suitability for traditional SIEM use cases, our team developed 50+ custom correlation rules, aligned with MITRE, offering enhanced logic and capabilities over and above traditional solutions.

A best-in-class, AI-driven SOC.


With Cortex XSIAM at the center, the bank is taking its SOC to a new level—achieving rapid threat detection and response, dramatically reducing false positives, and meeting all of its compliance requirements. By automating routine tasks, analysts can focus on strategic initiatives, while new baselines for MTTD, MTTI, and MTTR will drive continuous improvements in threat management. XSIAM will also provide valuable insights for strategic decision-making related to security posture and investment, supporting the long-term security strategy for the financial institution.

"Cortex XSIAM is especially suited for financial institutions in that it delivers AI-driven threat detection, advanced analytics, seamless integration across diverse ecosystems, and operational efficiency while meeting stringent compliance requirements—all of which empowers financial institutions to adapt to evolving threats and maintain a resilient security posture."

- Abhishek Mahadik

Domain Consultant, Palo Alto Networks

Join the Champions Program

Become an advocate for Palo Alto Networks and gain exposure for your organization.