Case study

Hexagon

Hexagon thumbnail 2x
×
 

How Hexagon unified their fragmented security operations and consolidated their security stack with eSentire’s 24/7 SOC-as-a-Service to achieve 24/7 threat detection and response capabilities and improve visibility across their attack surface.

The Business

Hexagon Logo

Hexagon is a global leader in digital reality solutions, integrating sensor, software, and autonomous technologies to empower customers across various industries. They specialise in harnessing data to boost efficiency, productivity, quality, and safety in industrial, manufacturing, infrastructure, public sector, and mobility applications.

Hexagon Logo
  • Global presence with 26,000+ employees and limited security resources
  • Security operations spread across eight siloed business units with distinct security tooling and processes
  • Compliance requirements for 18 different global security certifications including the Essential Eight, Cyber Essentials, NIST, CMMC, DFARS 7012, ISO 27000, and more
  • Looking for expert-level guidance to identify and address gaps in their security program and leverage existing endpoint technology investments

Solution and Results

Hexagon partnered with eSentire to consolidate and streamline their security operations, enhance visibility across their attack surface, and reduce threat detection gaps with 24/7 SOC-as-a-Service, including:

Business and Security Outcomes

  • 24/7 threat detection, investigation, and response capabilities with eSentire’s global SOC operations
  • Best-of-breed security tooling and standardised processes across Hexagon
  • Achieve seamless integration with existing Microsoft security tools
  • Maintain compliance with 18 global security certifications
  • Improved visibility and reduced threat detection gaps across the organisation
  • Alignment of cybersecurity strategy, business objectives and risk through a dedicated eSentire Cyber Risk Advisor

The Challenge

Over the past few years, devastating cyberattacks targeting the software supply chain have crippled business operations for thousands of organisations, costing them tens of millions in lost business revenue, cyber insurance, legal fines, loss of customer loyalty, and diminished brand reputation.

Hexagon’s journey towards consolidating their security operations began with significant hurdles. As a global enterprise with a presence in 60 countries, they operated through eight divisions, which sat on top of four different IT networks that operated in silos. Each IT network functioned like an independent enterprise, with their own CIOs, separate security teams, set of vendors, and independent processes.

This led to a fragmented and inefficient security environment with multiple and disparate endpoint, network detection and SIEM solutions. This lack of cohesion posed serious risks, as inconsistent security measures left gaps in threat detection and response. As a result, the organisation wanted to move towards a One Hexagon approach so they could be more efficient and optimise their overall processes.

Moving into the One Hexagon model also meant they would have to shift from a 20/5 coverage model to a 24/7 coverage model. Unfortunately, running a global Security Operations Center (SOC) is complex and requires 12-15 people, at minimum.

Steve Lorimer, Group Privacy & Information Security Officer at Hexagon, recognized the challenge of building an internal SOC team that could not only provide 24/7 coverage but had the expertise to stay on top of sophisticated cyber threats.

“Maintaining a team with high skills, and keeping that skill set current is very, very complicated if you're going to do it in-house and build it from scratch,” Steve says. “eSentire can bring that service to us, and we can benefit from the shared and the collective knowledge of the team. We needed a company that could match us at a global scale.”

With so much at stake, limited in-house cybersecurity expertise, and the critical need to comply with 18 global security certifications and regulations, Hexagon wanted a trusted partner who could quickly and seamlessly integrate with their team to provide expert-level guidance and comprehensive security coverage.

In addition, Hexagon had already made significant investments in technology so they needed a partner who could leverage and maximise their existing investments in Microsoft E5 and Sentinel and help them consolidate their security tools.

Why Hexagon Chose eSentire As Their Proven MDR Partner

The search for a proven Managed Detection and Response (MDR) solution to complement their shift towards a global security approach led Hexagon to eSentire. The decisive moment came during a tour of eSentire’s SOC facility, which showcased our robust capabilities, deep breadth of expertise, and proactive approach to threat detection and response.

Steve Lorimer was impressed by the level of engagement and expertise at every level of interaction.

Quote Icon

“We’ve always felt that at every level across the business, from the executives to the technical guys speaking with the SOC Analysts, there's a one-to-one working relationship across the board. So, it is very much a partnership with multiple layers of communication all the way through.”

Steve Lorimer

Group Privacy & Information Security Officer, Hexagon

As a result of outsourcing security operations to eSentire, Hexagon also experienced another key benefit: complying with a set of 18 complex, global security frameworks, including NIST, CMMC, DFARS 7012, ISO 27000, Essential 8 in Australia, and Cyber Essentials in the UK.

“Having 24/7 fully monitored SOC alerting us when we have incidents meets many of the controls within those set of frameworks that we have to adhere to,” Steve adds.

Moreover, Hexagon’s priority has also been to standardise their technologies, support tools, and the processes they had in place. Their decision to choose eSentire MDR was further reinforced by eSentire’s ability to seamlessly integrate with their existing technology, providing a unified, robust security framework.

“eSentire is helping us drive down 24/7 monitoring, 24/7 alerting on our networks, and solidify our team,” Steve says. “It's enabling us to really move our processes much closer to the technology so we can standardise them.”

By choosing a provider that can leverage existing tools, Hexagon was able to consolidate and reallocate their budget to support the global security operation, accelerating them towards One Hexagon.

“What we're trying to do is not necessarily reduce the spend, but it's optimise the spend and put better spend into places where we need it.”

Through daily stand-ups, biweekly syncs with Hexagon’s leadership team, and continuous communication, eSentire has become an integral part of Hexagon’s team, delivering consistent support and expertise.

Conclusion

Hexagon’s strategic partnership with eSentire enabled the company to shift away from a divisional security approach and towards the One Hexagon approach. In doing so, they were also able to transition from a reactive to a proactive security stance, ensuring robust protection across its global operations.

By centralising their security operations, and standardising tooling and processes, Hexagon has achieved enhanced visibility, improved threat detection and response capabilities, and a streamlined security posture. This partnership showcases the power of proven, expert-led, 24/7 security solutions in safeguarding complex, dynamic enterprise environments.

Steve Lorimer emphasises the transformative impact of eSentire’s 24/7 SOC-as-a-Service, “As threats and new attack patterns emerge, we’re being protected from the very start.”

Ready to Get Started?

We’re here to help! Submit your information and an eSentire representative will be in touch to help you build a more resilient security operation today.