DEGOOLCYBER SECURITY SOLUTIONS
CASE STUDIES

Incidents, in detail

Anonymised engagements with timelines and measured outcomes. Client names withheld under NDA — reference calls available on request.

BANKING14,000 STAFF · 9 COUNTRIES

Ransomware staged and stopped in four minutes

An initial-access broker sold credentials to a regional bank’s VPN. The affiliate had 90 minutes inside the estate before deploying an encryptor. Sentinel correlated the impossible-travel sign-in, the LSASS access and the SMB spread into one incident, then executed containment within the agreed policy envelope.

  1. T+00:00Anomalous VPN sign-in from unassigned ASN, entity risk raised
  2. T+00:41LSASS memory access on finance workstation flagged critical
  3. T+01:22Lateral SMB enumeration across 14 hosts correlated to same entity
  4. T+04:11Playbook isolated 14 hosts, revoked sessions, blocked egress
  5. T+22:00Forensic report and regulator notification drafted from evidence timeline
4:11
TIME TO CONTAINMENT
0
SYSTEMS ENCRYPTED
0
HOURS DOWNTIME
HEALTHCARE6 HOSPITALS · 4,200 STAFF

From no visibility to ISO 27001 in eleven weeks

A hospital network had 38 unmanaged log sources and an audit eight weeks out. We inventoried the estate, onboarded telemetry, mapped controls to Annex A and automated evidence collection — while running 24/7 monitoring in parallel.

  1. WEEK 1Asset and log-source discovery; 38 sources inventoried, 11 previously unknown
  2. WEEK 3Telemetry onboarded, clinical-system detection pack tuned
  3. WEEK 6Control gaps closed, evidence automation live
  4. WEEK 11Certification achieved with zero major nonconformities
11 wks
TO CERTIFICATION
0
MAJOR NONCONFORMITIES
38
LOG SOURCES ONBOARDED
ENERGY / OT12 SITES · PURDUE L0–L3

Passive OT monitoring without touching production

An energy operator needed visibility into industrial segments where any active scan risked a safety event. Passive taps and protocol parsing gave full asset inventory and anomaly detection with zero production impact.

  1. PHASE 1Passive taps installed at 12 sites, no configuration changes to PLCs
  2. PHASE 2Asset inventory built from traffic: 2,140 devices, 190 unaccounted for
  3. PHASE 3Baseline established; anomalous Modbus writes alerted to operators
  4. PHASE 4Purdue segmentation review; 9 flat-network violations remediated
2,140
OT ASSETS DISCOVERED
Zero
PRODUCTION IMPACT
9
SEGMENTATION FIXES
PROFESSIONAL SERVICES900 STAFF · CO-MANAGED

A three-person team gets 24/7 coverage

An internal team of three was drowning in a SIEM queue they could only read during office hours. Co-managed delivery kept their engineers in control of the estate while our SOC absorbed the night and weekend load.

  1. MONTH 1Existing SIEM content migrated to detection-as-code repository
  2. MONTH 2Out-of-hours monitoring transferred to DeGooL SOC
  3. MONTH 4Auto-triage retires 62% of benign alert volume
  4. MONTH 6Phishing click rate down from 22% to 3.1% after training programme
−62%
ALERT QUEUE VOLUME
3.1%
PHISHING CLICK RATE
24/7
COVERAGE ACHIEVED

Find out what your telemetry is already telling you.

Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.