CASE STUDY
Achieving 95% Asset Coverage and Real-Time Vulnerability Management
Custom security solutions empowered a wireless network operator to create a robust, efficient vulnerability management program.


About
Our client is a wireless network operator offering mobile carrier services, broadband, internet services, and IoT products.
Objective
- Modernize vulnerability management program
- Increase share of assets scanned in quarterly assessments
- Expedite remediation of uncovered vulnerabilities
Problem
- Existing program fell behind industry standards
- Lack of internal security resources
- Scanned less than 50% of assets
Solution
- SecureOps Vulnerability Management
- Implemented clear, concise VM strategy
- Creation of a remediation and rapid-response team
Results
- Eliminated backlog of remediation tasks
- Monthly IP scans raised to 1.5M
- High-value systems scanned daily or weekly

OBJECTIVE
Urgent Upgrade for Security Vulnerability Program
Our client, a wireless communication provider, needed security engineers and other security staff to upgrade their vulnerability management program.
The remediation gap between when the client first detected vulnerabilities and when those issues were ultimately resolved was longer than industry standards, giving attackers an opportunity to breach their systems.
Given the size and complexity of the client's network assets—essential for their mobile carrier, broadband, internet, and IoT products—they needed a mature, robust vulnerability management program to rapidly identify and prioritize these weaknesses, to significantly reduce their overall business risk.

PROBLEM
Resource Gaps and Low Scanning Coverage
The client’s internal vulnerability management program had fallen significantly behind industry standards, leaving them exposed to attacks.
Our client was struggling with a lack of security resources, a fragmented scanning and remediation strategy, and inefficient reporting and compliance processes. Their staff was overwhelmed and had lost faith in the process, tools, and the asset owners who failed to remediate identified vulnerabilities.
In addition, the organization faced severe operational hurdles:
- Low Asset Coverage: The team scanned less than 50% of the assets each quarter and could only scan 30,000 IP addresses monthly, leaving many assets with critical vulnerabilities.
- Process Inefficiency: The team contended with a high false positive rate due to poor scanner configuration and had to manage a large and growing scan exclusion and exception list.
- Manual Reporting: The team relied on time-consuming manual preparation of reports and had to conduct ad-hoc scans to plug security gaps between quarterly scans.
However, finding a cost-effective solution by either leveraging local expertise or traditional managed services was not a viable option due to the organization’s need for diverse security expertise, internal control and visibility to the program, and partner flexibility.
They needed a security partner that could adapt to their unique needs.

SOLUTION
SecureOps’ Collaborative Model
SecureOps offered a customer-driven vulnerability management service providing a high-level, diverse, and flexible team of experts at the right time with the right skills.
We delivered the resources they needed to deploy reliable scanning technology, scan their entire environment, and automate their vulnerability management process by prioritizing assets, vulnerabilities, scanning, and remediation.
Partnering with our client’s IT security team, SecureOps empowered the organization to bolster their vulnerability management program with:
- A holistic review of their vulnerability management program, requirements, and objectives with recommendations
- Implementation of a clear, concise vulnerability management strategy geared to improve overall security maturity
- The integration of the client’s scanning tools with CMDB platforms and ITSM standards
- The handling of all scanning operations to ensure a smooth transition with no adverse effect or loss of current stable state service
- A large “Discovery Scan” effort to identify areas of the network that had a large number of unmanaged assets, which resulted in improving the accuracy of data in the CMDB
- Deployment of new scanners and agents into areas that were unreachable before or where the scans were causing network/firewall issues
- Reconfiguration and breaking down of the large scheduled scans into multiple smaller scans to allow custom scanner selection, configuration, policies, frequency, and reporting requirements
- Creation of a vulnerability remediation and rapid-response team

RESULTS
Maximum Return on Investment and Improved Security
Our client transitioned from a fragmented, whack-a-mole vulnerability assessment and patching exercise to a comprehensive, prioritized, and proactive strategy.
The real value was improving the organization’s overall security maturity by having a partner with the specialized experts to implement a best-in-class vulnerability management program.
The client immediately recognized the value of the collaborative model, as noted by their Senior VP of Information Security:
"[SecureOps] have provided a wide range of specialized security services to complement my internal organization. The combination has allowed us to achieve superior service levels very cost effectively. Operating as a 'near shore' solution provider from Canada allows the benefit of same time zone responsiveness at a very favorable price point compared to other managed and professional services alternatives."
SecureOps enhanced our client’s vulnerability management program with measurable results, including:
- The high number of resources committed to running basic operations have evolved or been replaced to now perform higher value functions, such as helping asset owners with remediation, supporting Threat and Incident Response teams, and performing additional automation and the optimization of processes.
- Elimination of on-demand, costly, and inefficient scans in favor of strategic, scheduled scans. The percentage of assets scanned has risen from 50% to 95% through more than 40 scheduled scan types, providing more information about system vulnerabilities sooner.
- The backlog of scans, patching and remediation was eliminated; vulnerability management is now conducted in near real-time.
- Highly critical assets are scanned by priority on a daily or weekly basis rather than quarterly.
- Scoping and reporting are integrated with ITSM and CMDB dashboards, showing a much clearer picture of the vulnerability landscape across the organization.
- Total number of IP scan/rescan monthly increased to 1.5 M.
By partnering with SecureOps, the wireless communication provider overcame severe resource constraints and low scanning coverage to implement a comprehensive, risk-based strategy. The resulting elimination of the remediation backlog and the increase in monthly IP scans to over 1.5 million dramatically reduced the client's exposure to attacks, allowing internal staff to shift focus from basic operations to higher-value security functions.

Build a security function that furthers your business goals
SecureOps is ready to build a partnership centered on your needs and ensure the protection of your most critical systems.