Imagination Technologies transforms SOC operations with Cortex XSIAM
How one security team went from closing 10% of incidents to 100%. This case study shows how Imagination Technologies uses Palo Alto Networks Cortex XSIAM to unite endpoint, network, cloud, and identity data, ingest 18 sources instead of two, and automate the noise away -- cutting median resolution time from months to five hours. Read the story to learn from Imagination Technologies' experience.
How did Cortex XSIAM change Imagination Technologies’ SOC performance?
Cortex XSIAM helped Imagination Technologies reimagine how their SOC works day to day, with measurable improvements:
- Incident closure rate: Automation now allows the team to close 100% of incidents, up from less than 10% with the previous SIEM.
- Speed of response: Median time to resolution dropped from months to around five hours, with further reductions expected as the system continues to learn.
- More data, better outcomes: Despite incidents now coming from more sources, the SOC is handling them more efficiently thanks to AI-driven correlation and automation.
By uniting endpoint, network, cloud, and identity data in one platform, XSIAM removed much of the manual, reactive work that previously slowed investigations. Analysts now spend less time chasing logs and more time on higher-value security work and strategy.
How did Imagination improve visibility and data use in the SOC?
Before Cortex XSIAM, Imagination’s SIEM struggled with the scale and variety of data. They were typically looking at a single data type or log source at a time, which made it hard to connect signals and derive real intelligence.
With Cortex XSIAM, they reshaped their visibility and data strategy in several ways:
- Expanded data sources: They moved from ingesting just 2 sources (~100GB/day) in the old SIEM to 18 sources (~300GB/day) in XSIAM, plus 315GB/day of in-line endpoint data.
- Broader coverage: Data now comes from endpoints, networks, cloud environments, HR systems, identity providers, firewalls, and SaaS platforms such as Microsoft 365.
- Single pane of glass: All SecOps processes run through one console, reducing context switching and making it easier for a lean team to stay on top of threats.
- Real-time insight: The team now gets real-time visibility across offices worldwide, mixing up to 15 sources at once to understand what’s happening and act proactively.
Because XSIAM is cloud-native and tightly integrated, Imagination can quickly onboard new log sources, normalise and enrich the data, and turn raw telemetry into actionable information for analysts.
What role do AI and automation play in Imagination’s new SOC model?
AI and automation sit at the core of Imagination’s new SOC model with Cortex XSIAM. They use the platform to:
- Automate repetitive analysis: Routine data analysis and low-risk alerts are handled automatically, freeing analysts to focus on a smaller set of high-risk incidents.
- Group and prioritise alerts: AI groups related alerts into incidents and uses risk-based scoring (SmartScores) to prioritise triage.
- Drive proactive security: Built-in threat intelligence and attack surface management help the team identify exposed assets and patch vulnerabilities before attackers can exploit them.
- Use modular playbooks: Prebuilt, modular playbooks make automation accessible. The team can simply turn features on or off instead of building complex workflows from scratch.
The impact on the team is tangible:
- 100% of incidents can now be closed using automation, compared with less than 10% before.
- Manual effort is reduced, onboarding and offboarding are faster, and processes are fully audited and repeatable.
- Analysts spend less time on low-grade, repetitive tasks and more time on SOC strategy and personal development, which has improved morale and engagement.
In practice, Cortex XSIAM has helped Imagination reshape their SOC into a more mature, efficient operation that makes better use of data and gets more done in the same timeframe.
Imagination Technologies transforms SOC operations with Cortex XSIAM
published by GingerSec
GingerSec, LLC was founded with a passion for helping others stay secure in the digital world. We continuously strive to ensure our clients are as secure as they possibly can be, protecting their digital life. Because of this passion, our IT consulting to focus on providing you with security and operational function.
Because knowledge is power, we a full line of certification preparation courses and user awareness training. If you are an industry professional, allow us to help prepare you for the next certification exam. If you need security awareness training for your staff, you have you covered there as well.
GingerSec is also a reseller for your technology needs. We have the resources to provide you technology needs, whether at a personal use or enterprise-level we have the sources to help you. We have access to some of the more popular computer manufactures Dell, HP, and Lenovo.
#GingerSec