Search

 
 

A Sentinel security optimization boosts efficiency 20%

 

20%

The optimization reduced data ingestion costs by 20% through data rationalization and log deduplication.

 

$95K

The savings totaled $95,000 in monthly baseline cost reduction.

 

18

18 automated rules streamlined incident handling and reduced manual effort.

 
 

At a glance

 

Client

Not-for-profit organization

 

Industry

Not-for-profit

 

Our role

Microsoft Sentinel optimization

 

Our solution

Security monitoring transformation

 
 
 

Optimized security monitoring and threat detection

 
folder icon

Scenario

The organization wanted to improve Microsoft Sentinel efficiency and visibility while managing ingestion costs.

gears icon

Approach

Grant Thornton assessed the environment, rationalized data ingestion and deployed monitoring, detection and automation enhancements.

graph icon

Result

The organization reduced monitoring costs, strengthened detection, streamlined security operations and improved visibility.

 
 

Scenario

 
 

A need for visibility and operational efficiency

 

A not-for-profit organization wanted to gain better visibility into security events while also streamlining its Microsoft Sentinel environment. Duplicate and unparsed log records increased costs and created monitoring gaps. At the same time, manual processes limited efficiency for security teams.

 

Leaders at the organization sought broader coverage across key platforms and a more streamlined approach to security operations. 

 
 

Approach

 
 

A more efficient security platform

 

The engagement focused on three areas: reducing unnecessary data ingestion, expanding monitoring coverage and streamlining security operations. Data ingestion patterns were assessed to identify major cost drivers, and XDR and DCR optimization reduced duplicate data entering Microsoft Sentinel.

 

Additional Oracle, SQL and MongoDB data sources expanded visibility across key systems. Custom parsers and analytics improved insight into security activity, while ingestion health monitoring added oversight across critical data sources. The solution also included Zero Log Alerts and heartbeat monitoring to help identify collection issues.

 

Automation playbooks and analytic rules were deployed to reduce manual triage activities and support more consistent incident response workflows. Microsoft Sentinel, Microsoft Defender XDR and Azure services provided the foundation for the solution.

 

How we can help you

 
 
 

 

Ready to talk? We’re ready to listen.

Request a meeting -->
 
 

Result

 
 

Lowered costs, strengthened detection

 

The organization achieved an estimated 20% efficiency improvement in Microsoft Sentinel data ingestion through data rationalization and log deduplication. The efficiency represented approximately $95,000 in monthly baseline cost savings.

 

The engagement also improved operational visibility through 27 ingestion health monitoring controls, including Zero Log Alerts and heartbeat monitors. Fourteen custom analytic rules strengthened database threat detection, and 199 additional rules were identified for future deployment.

 

Five automation playbooks and 18 automated rules streamlined incident handling and reduced manual effort for security personnel. The organization finished the engagement with a more efficient Microsoft Sentinel environment, broader monitoring coverage and a clearer path to expand threat detection over time.

 
 

Connect with our team

 

Arlington, Virginia

Industries

  • Insurance
  • Technology
  • Transportation & Distribution
  • Banking

Service Experience

  • Advisory Services
 
 
 

Content disclaimer

This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.

Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.

For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.

 

Ready to talk? We’re ready to listen.

 

Request a meeting and a member of our team will be in touch to see what we can do to meet your needs.

 

Want to submit an RFP? Please submit your request through our RFP submission page.

 
 
 

Trending topics

 

Follow us