IT outsourcing
Managed security operations for a regional insurer
An insurance group operating across several GCC markets, holding substantial volumes of personal and health-related data.
- Industry
- Banking and Financial Services
- Pillar
- IT outsourcing
- Client geography
- Gulf Cooperation Council
- Delivery location
- Abu Dhabi security operations centre
- Languages
- English C1, Arabic B2
- Engagement model
- Managed service, 24 by 7
- Timeline
- Fifteen weeks to full monitoring coverage
The challenge
The insurer had bought good security tooling and could not staff it. A two person internal team monitored alerts during business hours, which left the majority of every week uncovered, including the hours when attacks are most likely. Alert volume was high and largely untuned, so the team spent its time on false positives. Regulatory expectations across the group's markets were tightening, and the board had asked a question the team could not answer with evidence: are we actually being monitored.
What Corpshore did
We stood up 24 by 7 monitoring from our Abu Dhabi security operations centre, integrating the insurer's existing SIEM, endpoint detection and cloud telemetry rather than replacing tooling the insurer had already invested in.
The first ninety days focused as much on tuning as on monitoring. Detection rules were rewritten against the insurer's actual environment and mapped to relevant attacker techniques, which cut alert noise substantially and made the remaining alerts worth investigating. We built and tested incident response runbooks with the insurer's own team, including two tabletop exercises with executive participation.
Reporting was designed for two audiences at once: technical detail for the security team and a monthly board-level view that answers the question the board actually asked.
Delivery model
Managed service, 24 by 7 from Abu Dhabi, with defined escalation into the insurer's internal team and named response time commitments by severity.
Results
- Monitoring coverage moved from business hours only to continuous.
- False positive volume reduced by roughly 60 percent following the tuning programme, which allowed the same analyst capacity to investigate far more real signal.
- Mean time to detect and mean time to contain both improved substantially against the insurer's pre-engagement baseline.
- Two genuine incidents were detected and contained during the first year, both outside business hours, both of which would previously have gone unnoticed until the following morning.
- The insurer passed its subsequent regulatory review on security monitoring with no findings.
Why it worked
The insurer's problem was never tooling. It was coverage, tuning and the ability to evidence both. Buying more technology would have made the alert problem worse.
Discuss an engagement like this
All UAE enquiries answered within six hours.
This is a representative engagement. The client is anonymised, and the figures are drawn from engagement reporting. We do not name a client without written consent, and we do not publish a number we cannot evidence.
