Case study by Defensys — Power generating company

24/09/2026

Power generating company

A large enterprise with a geographically distributed infrastructure and a continuous production cycle. The Company operates a hybrid SOC model that combines incident monitoring delivered by a managed security service provider with incident response performed by its internal information security team.

IT infrastructure: 10,000 assets

16 response scenarios for different incident types

> 50 tenants

> 15 integrations for incident data collection, contextual enrichment, and active response

 

Objectives

  • Simplify workflows and accelerate reporting for both internal governance requirements and regulatory compliance.
  • Organize asset data and establish effective information security asset management.
  • Improve incident response efficiency by increasing the speed and quality of decision-making.

 

Implementation

Stage 1

The Company developed a long-term strategy to enhance its information security processes. The first stage focused on asset management and the automation of information security reporting. Defensys SGRC was selected as the technology platform after demonstrating strong performance during the proof of concept phase.

The Company highlighted the following factors that influenced its decision:

  • Built-in regulatory content and ready-to-use audit workflows.
  • Out-of-the-box functionality, including multi-tenancy.
  • Flexible inventory and reporting capabilities.
  • Expert support provided by the vendor.

During implementation, a centralized asset inventory system was established based on the Organization's hierarchical structure. Integration with the existing security infrastructure enabled automatic collection of endpoint data, while the built-in capabilities of Defensys SGRC ensured comprehensive asset inventory.

Automated reporting processes were also configured for both internal use and submission to supervisory organizations.

 

Stage 2

The second stage of the project focused on further developing the Company's incident response processes. The Organization operates a hybrid Security Operations Center model in which security event monitoring is performed by a managed service provider, while incident response is handled by the internal information security team. It is worth noting that the Company independently manages incidents involving OT assets, resulting in separate incident data streams.

As part of its cyber resilience strategy, the Company deployed additional tools for event analysis and proactive threat hunting. To improve the convenience and speed of incident management, the Company required a system that would allow its information security specialists to work from a single pane of glass interface. The Company chose the Defensys SOAR platform.

Defensys SOAR aggregates incident data received from both internal monitoring tools and the managed service provider. Through configured integrations, the platform automatically enriches incidents with additional analytical context, validates indicators of compromise (IoCs) for malicious activity, and performs response actions on endpoint hosts. As a result, analysts receive the full operational context required to make decisions and execute the necessary response actions.

 

Results

A unified system for managing asset and business process data was established, providing complete inventory and accounting of critical assets. Preparation of recurring reports for management and supervisory organizations was significantly simplified, while compliance with regulatory requirements is now continuously monitored with automated report generation.

The project resulted in significantly faster and more streamlined incident response.

"The Company follows the principle of efficient resource utilization and therefore actively implements automation tools to reduce the effort required for information retrieval and routine tasks such as report preparation. By deploying Defensys solutions, the Organization consolidated asset and business process data into a single system and gained a transparent security-centric view of its infrastructure. At the same time, the project eliminated the managed service provider's blind spots, significantly improving both the speed and the quality of incident response decision-making" – noted Andrey Chechetkin, Defensys CEO.