In evaluating the SIEM solution landscape, Novaland’s cyber group considered research from Gartner, Inc. and Forrester, comparing a range of offerings among the leading brands. “Gartner rates IBM Security QRadar particularly high for hundreds of use cases and it supports the largest information security ecosystem,” says Nghia.
The evaluation team liked QRadar’s ability to automate security information analysis to quickly detect threats; its stability and extensibility; and its integration of a variety of components such as extensions, APIs and the IBM QRadar Pulse operational dashboard, which streamlines monitoring and administration. The team also liked that QRadar is open and scalable, and that it offers features in line with Novaland’s operational requirements to ensure business resiliency, data security and privacy.
Request a customized demo of QRadar SIEM
“We decided that IBM QRadar was a highly suitable solution because of its features and its scalability,” explains Nghia. “And the threat detection rules are adaptable to our needs.”
Assisted by IBM Security Services, Novaland’s cyberteam deployed the QRadar SIEM platform. Then, the team used the tool to perfect incident response procedures and scenarios, optimize rule sets to identify attack signs, and develop playbooks for security incident response.
Novaland also uses the QRadar platform to strengthen the IT environment against future threats. Separated into Red, Blue and Purple teams, the cyber group meets weekly to review past threats, note the teams’ responses and use the results to customize QRadar incident response playbooks. In addition, the Red team uses tools and their own scripts to conduct Breach and Attack Simulation (BAS) to verify the Blue team’s efficiency.
“We need to understand how fast the Blue team can respond—does it take 15 minutes or 50 minutes?” Nghia says. He is pleased with typical responses in the 15–30 minute range. “It’s just faster with QRadar.”