CASE STUDY
How a Credit Union’s IT Team Achieved 24×7 Security Coverage and Discovered a Hidden Firewall Gap
Background
A credit union running Cloud and On-Premises production systems across 100 employees and 200 monitored endpoints puts its entire IT function on a team of four. That team handles infrastructure management, endpoint security, vendor relationships, and all business-driven IT projects.
Their existing security stack included CrowdStrike Falcon Complete for endpoint protection. What it did not include was a SIEM, event correlation across network and server infrastructure, or monitoring outside business hours. Coverage stopped at 5 PM on Fridays.
A routine internal audit made the gap undeniable. The organization did not wait for an incident to act.
The Challenge
CrowdStrike Falcon Complete secured the endpoints. Everything beyond the endpoint layer remained invisible. Network activity, server behavior, and cloud workload events produced no correlated view and no alerts. Outside of business hours, the environment ran entirely unmonitored.
Three structural gaps defined the problem:
- No SIEM. CrowdStrike alerts were not ingested into any centralized log management or correlation engine. Events across the network, server, and cloud layers generated no unified picture and no cross-environment detection capability.
- No after-hours coverage. The environment had zero monitoring from Friday at 5 PM through Monday morning. A threat actor operating over a weekend would have had full run of the environment with no detection and no record.
- No proactive alerting. The previous security provider generated no outbound contact with the IT team, including for low-severity alerts. The team had no way to know what had been detected or missed.
The IT team needed full-environment coverage across a hybrid Cloud and On-Premises stack without increasing headcount. The audit set the timeline.
About the Client
Financial Services – Credit Union
UnderDefense Agentic AI SOC
Key Results
The Solution
UnderDefense Agentic AI SOC was engaged to cover monitoring, detection, and incident response across the full hybrid environment. Onboarding completed quickly, with 24×7 coverage standing up from the start of the engagement.
SIEM Implementation
CrowdStrike Falcon Complete remained in place. UnderDefense added a SIEM layer alongside it, ingesting CrowdStrike endpoint alerts and correlating them with network and server telemetry. For the first time, the team had a unified view across Cloud, On-Premises, and endpoint activity in a single correlated environment.
24×7 Monitoring and Incident Response
Monitoring expanded from 8×5 to continuous, including weekends, holidays, and overnight hours. The UnderDefense team handles case ownership and escalates to the client immediately on detection of unexpected activity. Every alert generates a notification, regardless of severity or time of day.
Incident Management
All cases are managed through the UnderDefense platform. The IT team receives structured notifications when activity is flagged — with full context, source attribution, and recommended action included — so the team can make decisions without being the first line of manual response.
Security Guidance
Beyond monitoring and response, the IT team gained access to ongoing security guidance from the UnderDefense team: configuration recommendations, policy review, and best-practice input as part of the regular engagement cadence, not as a one-time deliverable.
Outcomes
Unauthorized Activity Detected in Real Time
A contractor connected to the environment via VPN and ran a network scan. The action was unintentional. The contractor did not know the scanning tool was active on the session.
The UnderDefense team detected the scan as it was running, traced it to the contractor’s VPN connection, and flagged it to the IT team with full context. During the investigation, the team identified the underlying cause: a firewall policy that had not been configured to restrict this class of network activity for VPN-connected users.
The misconfiguration was remediated.
Under the previous 8×5 setup, this scan would have completed without generating any record. The firewall gap would have remained open and unknown.
Coverage and Visibility
The environment moved from 8×5 to 24×7 monitoring. The practical consequence of that shift is not the coverage itself – it is what the coverage closes. Under the previous model, any threat arriving after 5 PM on a Friday had until Monday morning to operate without detection: credential misuse, lateral movement, data access, or configuration changes would have produced no alert and left no record in any monitoring system. That window, which ran across every weekend and public holiday, is now closed. For the first time, the credit union has a correlated view of activity across Cloud, On-Premises, and endpoint layers in a single platform.
Proactive Alerting
Before UnderDefense, the IT team received zero outbound contact from their security provider, including for low-severity alerts. The result was an undefined gap between an event occurring and anyone in the organization knowing about it – in most cases, that gap ran until the next business day or longer. Detection-to-awareness time was unmeasured. Today, any unexpected activity triggers an immediate notification with full case context. That gap is now measured in minutes.
Team Capacity
The 4-person IT team no longer carries manual monitoring as a routine function. For a team of four covering a hybrid environment, manual monitoring is not a background task – it competes directly with everything else. Removing it from the team’s operational load means infrastructure work, vendor coordination, and business-initiated projects get the attention they previously could not. The team did not grow. Its effective output did.
Executive Reporting
Monthly reports give the leadership team a structured view of what is being protected, what was detected, and how each case was handled. The IT Operations Manager has a concrete output for every executive conversation about security.
Business Risks That Were Addressed
Without continuous monitoring and event correlation, the credit union carried real, unquantified exposure:
- A threat actor with VPN access could have moved laterally across the network over a weekend without generating a single alert
- The firewall misconfiguration could have been used intentionally before it was discovered
- After-hours activity, including unauthorized data access or credential misuse, had zero coverage
- Leadership had no structured view of security outcomes and no audit-ready reporting
Since onboarding with UnderDefense, we have greatly appreciated the regular cadence and responsiveness of the team. The onboarding process was smooth and quick. We can also rely on them to provide general security guidance and best practice, which is something we did not have before. The monthly reporting has also been very helpful in terms of demonstrating the value to our executive team.