What challenges did the manufacturer face, and why were they critical?
The manufacturer had established security processes and an internal team responsible for its environment. Preparations for the requirements arising from NIS2 and the amended Polish Act on the National Cybersecurity System (KSC) prompted a broader review of those processes.
For the organisation, this meant assessing both its existing security controls and its practical ability to gather information on cyber threats and vulnerabilities, manage incidents and act once a threat had been identified.
The review revealed a specific gap. The company had good visibility into its own environment, but some information relevant to its security was appearing elsewhere.
One example was employees’ work email addresses found in data from external breaches. Finding an address did not, in itself, mean that the manufacturer’s systems had been compromised. An employee might have used their work email address to register with an external service whose data was subsequently exposed.
The challenge arose at the next stage.
The source of the information, the scope of the exposed data, how current it was and its potential significance for the organisation all needed to be established. This was followed by an assessment of whether the event increased the risk to the company or its employees and whether further action was required.
Suspicious domains, phishing websites, campaigns exploiting the company’s brand and other information appearing in external sources required similar analysis. An alert alone did not resolve the issue.
Key challenges
- Extending visibility beyond the systems and infrastructure directly controlled by the organisation
- Systematically gathering and assessing information on external cyber threats
- Distinguishing between an indicator that required observation and an event that required a response
- Moving from threat identification to analysis and mitigation
- Ensuring access to the necessary expertise without developing every specialism internally
What did we implement, and how did it work in practice?
The manufacturer introduced PREBYTES Cybersecurity Services to complement its existing security model. The scope included Dark Web Investigation, Threat Detection WEB and Threat Response, with PREBYTES SIRT responsible for operational delivery.
When information requiring investigation emerges, PREBYTES SIRT goes beyond forwarding an alert. The team verifies the source, adds context and assesses the significance of the event. As part of Threat Response, it also analyses submitted messages, domains, links, files and websites, prepares indicators of compromise (IOCs) and carries out mitigation activities within the agreed service scope.
The manufacturer therefore receives the findings of the analysis, details of the actions taken and guidance on next steps where action is required within its own environment.
The implementation helps the organisation meet KSC requirements for gathering information on cyber threats, managing incidents and taking measures to limit their impact on its systems.
This model addressed the gap identified during preparations for KSC. The organisation needed more than a greater volume of threat data. It needed the capability to gather and assess that information and handle situations that required a response.
What were the results, and what changed in day-to-day operations?
The manufacturer moved from reacting to isolated indicators discovered by chance to a structured process for handling external threats.
For the internal team, this means less work independently establishing whether a discovered domain, data leak or suspicious campaign is relevant to the organisation. Instead of a raw alert, the team receives an analysed case, details of the actions already taken and a clear indication of anything that remains to be done within the company.
The manufacturer also avoids having to maintain the full range of specialist expertise needed for events that occur only intermittently. PREBYTES SIRT extends the internal security team’s capabilities in the precise area where preparations for NIS2/KSC had revealed limited operational capacity.
Results following implementation
- Structured gathering and analysis of information on external cyber threats
- A process that takes a detected indicator through assessment to further action
- Threat handling and mitigation by PREBYTES SIRT within the agreed service scope
- Less involvement from the internal team in conducting a full analysis of every external event
- Additional operational expertise available when a specific need arises
- Development of capabilities relevant to NIS2/KSC obligations without adding another tool that generates alerts
The analysis provided by PREBYTES SIRT can also help the organisation update its risk assessments, supporting the KSC requirement to assess and manage risk systematically.
Talk to us about how PREBYTES Cybersecurity Services can help develop the operational cybersecurity capabilities needed to prepare for NIS2/KSC requirements: Contact | PREBYTES