Turning Microsoft security tools into an operational defense
As part of the onboarding process, Quorum Cyber conducted a customized threat intelligence exercise. The team interviewed Data Trust stakeholders about the organization’s work, geographies, and data types, then produced a report focused on the threat actors most relevant to the business.
With the threat landscape rigorously diagnosed, Quorum Cyber began work on a platform designed for visibility and rapid response. At the center of the solution was Microsoft Sentinel, the cloud-native security information and event management (SIEM) platform that powers the company’s managed detection and response services.
Rather than exporting logs to an external platform, Simpson and his team deployed Microsoft Sentinel directly within Data Trust’s own Azure environment. Using Azure Lighthouse, Quorum Cyber’s security operations team could monitor and manage the environment while ensuring that data remained inside the customer’s tenant.
For its managed detection and response service, pentesting, and an annual cybersecurity audit to support governance, Quorum Cyber deployed their Clarity Extend solution. This included an incident response service that could connect with Quorum Cyber’s security experts day and night, alerting them and triggering a human-led investigation if there was ever a breach of the company’s systems. Simpson described Clarity Extend as “a single pane of glass for anything security incident-related,” one that’s operated by Quorum Cyber within Data Trust’s Azure environment, giving both teams visibility and shared responsibility.
“The in-house incident response capability was a standout feature for us,” O’Rourke said. “We really appreciated that it was included within the service and not hidden behind a paywall.”
At every stage, the solution was tailored to Data Trust’s unique environment, workflows, and risk profile. “It’s not a one-size-fits-all solution,” said Simpson. “We don’t just deploy them out of a box of tricks that we have. We start off with a broader detection capability and then tailor those detections based on the individual nuances of any customer environment.”