Imagination Technologies transforms SOC operations with Cortex XSIAM
How one security team went from closing 10% of incidents to 100%. This case study shows how Imagination Technologies uses Palo Alto Networks Cortex XSIAM to unite endpoint, network, cloud, and identity data, ingest 18 sources instead of two, and automate the noise away -- cutting median resolution time from months to five hours. Read the story to learn from Imagination Technologies' experience.
How did Cortex XSIAM change Imagination Technologies’ SOC performance?
Cortex XSIAM helped Imagination Technologies reimagine how their SOC works day to day, with measurable improvements:
- Incident closure rate: Automation now allows the team to close 100% of incidents, up from less than 10% with the previous SIEM.
- Speed of response: Median time to resolution dropped from months to around five hours, with further reductions expected as the system continues to learn.
- More data, better outcomes: Despite incidents now coming from more sources, the SOC is handling them more efficiently thanks to AI-driven correlation and automation.
By uniting endpoint, network, cloud, and identity data in one platform, XSIAM removed much of the manual, reactive work that previously slowed investigations. Analysts now spend less time chasing logs and more time on higher-value security work and strategy.
How did Imagination improve visibility and data use in the SOC?
Before Cortex XSIAM, Imagination’s SIEM struggled with the scale and variety of data. They were typically looking at a single data type or log source at a time, which made it hard to connect signals and derive real intelligence.
With Cortex XSIAM, they reshaped their visibility and data strategy in several ways:
- Expanded data sources: They moved from ingesting just 2 sources (~100GB/day) in the old SIEM to 18 sources (~300GB/day) in XSIAM, plus 315GB/day of in-line endpoint data.
- Broader coverage: Data now comes from endpoints, networks, cloud environments, HR systems, identity providers, firewalls, and SaaS platforms such as Microsoft 365.
- Single pane of glass: All SecOps processes run through one console, reducing context switching and making it easier for a lean team to stay on top of threats.
- Real-time insight: The team now gets real-time visibility across offices worldwide, mixing up to 15 sources at once to understand what’s happening and act proactively.
Because XSIAM is cloud-native and tightly integrated, Imagination can quickly onboard new log sources, normalise and enrich the data, and turn raw telemetry into actionable information for analysts.
What role do AI and automation play in Imagination’s new SOC model?
AI and automation sit at the core of Imagination’s new SOC model with Cortex XSIAM. They use the platform to:
- Automate repetitive analysis: Routine data analysis and low-risk alerts are handled automatically, freeing analysts to focus on a smaller set of high-risk incidents.
- Group and prioritise alerts: AI groups related alerts into incidents and uses risk-based scoring (SmartScores) to prioritise triage.
- Drive proactive security: Built-in threat intelligence and attack surface management help the team identify exposed assets and patch vulnerabilities before attackers can exploit them.
- Use modular playbooks: Prebuilt, modular playbooks make automation accessible. The team can simply turn features on or off instead of building complex workflows from scratch.
The impact on the team is tangible:
- 100% of incidents can now be closed using automation, compared with less than 10% before.
- Manual effort is reduced, onboarding and offboarding are faster, and processes are fully audited and repeatable.
- Analysts spend less time on low-grade, repetitive tasks and more time on SOC strategy and personal development, which has improved morale and engagement.
In practice, Cortex XSIAM has helped Imagination reshape their SOC into a more mature, efficient operation that makes better use of data and gets more done in the same timeframe.
Imagination Technologies transforms SOC operations with Cortex XSIAM
published by TeamLogicIT of NB
In less than a decade, TeamLogic IT has grown into the nationwide network businesses rely on or Managed IT Services. Our success is driven through one core mission - to leverage technology to your advantage. Thousands of businesses across North America are taking advantage of our ability to deliver highly available, secure and flexible IT systems, filling the void in the market for a trusted technology advisor. Here at TeamLogic IT, our philosophy is simple - we work with you the way we'd want someone to work with us.
Best-practices drive decisions and action. Expansive capabilities serve a wealth of needs. Relationship flexibility enables work arrangements that accommodate different levels of service: fully-outsourced IT, supplemental IT or project-based.
We are committed to the exploration, immersion and specialization required by the evolving spectrum of technology. If you're ready to move your business forward, do it with The Color of Confidence. TeamLogic IT.