Skip to content
Corpshore Emirates
All case studies

IT outsourcing

Managed security operations for a regional insurer

An insurance group operating across several GCC markets, holding substantial volumes of personal and health-related data.

Industry
Banking and Financial Services
Pillar
IT outsourcing
Client geography
Gulf Cooperation Council
Delivery location
Abu Dhabi security operations centre
Languages
English C1, Arabic B2
Engagement model
Managed service, 24 by 7
Timeline
Fifteen weeks to full monitoring coverage

The challenge

The insurer had bought good security tooling and could not staff it. A two person internal team monitored alerts during business hours, which left the majority of every week uncovered, including the hours when attacks are most likely. Alert volume was high and largely untuned, so the team spent its time on false positives. Regulatory expectations across the group's markets were tightening, and the board had asked a question the team could not answer with evidence: are we actually being monitored.

What Corpshore did

We stood up 24 by 7 monitoring from our Abu Dhabi security operations centre, integrating the insurer's existing SIEM, endpoint detection and cloud telemetry rather than replacing tooling the insurer had already invested in.

The first ninety days focused as much on tuning as on monitoring. Detection rules were rewritten against the insurer's actual environment and mapped to relevant attacker techniques, which cut alert noise substantially and made the remaining alerts worth investigating. We built and tested incident response runbooks with the insurer's own team, including two tabletop exercises with executive participation.

Reporting was designed for two audiences at once: technical detail for the security team and a monthly board-level view that answers the question the board actually asked.

Delivery model

Managed service, 24 by 7 from Abu Dhabi, with defined escalation into the insurer's internal team and named response time commitments by severity.

Results

  • Monitoring coverage moved from business hours only to continuous.
  • False positive volume reduced by roughly 60 percent following the tuning programme, which allowed the same analyst capacity to investigate far more real signal.
  • Mean time to detect and mean time to contain both improved substantially against the insurer's pre-engagement baseline.
  • Two genuine incidents were detected and contained during the first year, both outside business hours, both of which would previously have gone unnoticed until the following morning.
  • The insurer passed its subsequent regulatory review on security monitoring with no findings.

Why it worked

The insurer's problem was never tooling. It was coverage, tuning and the ability to evidence both. Buying more technology would have made the alert problem worse.

Discuss an engagement like this

All UAE enquiries answered within six hours.

This is a representative engagement. The client is anonymised, and the figures are drawn from engagement reporting. We do not name a client without written consent, and we do not publish a number we cannot evidence.