Rosendin Electric simplifies incident investigation with Log360

About Rosendin Electric

Rosendin Electric is one of the largest electrical contractors in the United States. Founded in 1919 by Moses Rosendin, the employee-owned company provides building information modeling, engineering, instrumentation and controls, and service and maintenance. The company serves a vast array of customers in industries across audio and visual systems, biotech and pharma, commercial, data centers, education, entertainment, and healthcare. It supports more than 100 charitable organizations nationwide. Rosendin Electric has offices in California and a handful of other states, mostly in the west.

Company

Rosendin Electric

Industry

Electrical

Location

USA

Business challenges

The organization, being one of the largest electrical contractors in the United States, is subject to continuous monitoring by competitors, regulators, and the public. It's imperative that it remains vigilant against cyberattacks around the clock.

With over 6,000 people working for Rosendin, different users have varying levels of access privileges to systems and data. The risk arises when a user with elevated privileges misuses their permissions to gain unauthorized control over critical systems or data. This could potentially lead to data leaks, privacy violations, and legal and financial liabilities.

Additionally, adversaries try to gain unauthorized access to these users' accounts in the network. Weak passwords, phishing attacks, or credentials that have been stolen could all result in account compromise. Once inside, the attacker may alter sensitive information, disrupt operations,or even compromise other accounts. Hong Zhao, a senior administrator from Rosendin Electric, was looking to solve the issue of account compromise within the organization.

Wired for security: How Log360 has strengthened Rosendin Electric's cyberdefense

The organization primarily wanted a solution that could help them analyze failed logons and failed authentication attempts. That's where Log360 came into play. Zhao stated that the implementation of Log360 helped the organization in the following ways:

  • Monitoring its log data continuously from various sources, such as servers, network devices, and applications.
  • Detecting patterns of failed logon attempts and authentication errors.
  • Mitigating advanced security threats within its network by promptly receiving alerts regarding critical events.
  • Archiving logs at regular intervals with flexible archiving options, and storing them in an encrypted form for as long as needed.

Rosendin Electric guarding the grid against cyberattacks

Since using Log360, Rosendin Electric has been able to effectively thwart cyberthreats that come its way. Right from analyzing log data through Log360's dashboard to meeting its compliance needs, Log360 covers it all. According to Zhao, "Log360 is an integral part of our organization's cybersecurity operation."

Overall, Rosendin Electric was very happy with how efficient Log360 has been and the technical support that it has received.

Other significant features of Log360

Security orchestration, automation, and response: Compile all security data from different platforms such as Exchange Server, Microsoft 365, Infrastructure as a Service solutions, Platform as a Service solutions, Software as a Service solutions, on-premises network devices, servers, and applications, all in a single console. Expedite threat resolution by automating your response to detected incidents using workflow options.

User and entity behavior analytics: Collect and analyze the data of users, machines, and other entities in a network, like event logs and packet capture data. Continuous monitoring and analysis of data from different sources will help to detect anomalies easily and instantly.

Active Directory change auditing: Monitor and audit critical Active Directory changes in real time. Utilize detailed information on Active Directory objects, track suspicious user behavior, monitor critical changes to groups and OUs, and more to proactively mitigate security threats.

About Log360

Log360 is a unified SIEM solution with integrated DLP and CASB capabilities that detects, prioritizes, investigates, and responds to security threats. Vigil IQ, the solution's TDIR module, combines threat intelligence, an analytical Incident Workbench, ML-based anomaly detection, and rule-based attack detection techniques to detect sophisticated attacks, and it offers an incident management console for effectively remediating detected threats. Log360 provides holistic security visibility across on-premises, cloud, and hybrid networks with its intuitive and advanced security analytics and monitoring capabilities. For more information about Log360, visit manageengine.com/log-management/ and follow the LinkedIn page for regular updates.

Similar case studies

 

Take control of your identity security posture with ADSelfService Plus

Discover how ADSelfService Plus helps your organization manage and protect identities through a personalized self-service experience

Get your copy now!

Fill in the details below and get instant access to the case study.

  •  
  •  
  • By clicking " Submit now", you agree to processing of personal data according to the Privacy Policy.
Email Download Link