Case Studies | Netenrich

Citrix and Cloud Software Group Transforms Security Operations with Netenrich

Written by Netenrich | Apr 10, 2025, 7:00:12 AM

Cloud Software Group (CSG), a $4.5 billion global software leader, embarked on a transformative security operations modernization journey. Faced with skyrocketing costs and operational challenges from its Splunk and XSOAR-based security architecture, the company sought a more scalable, cost-effective solution to align with its rapid growth and acquisition strategy.

Within an ambitious 12-week timeline, Netenrich successfully migrated CSG's entire security operations across all its subsidiaries to Google SecOps Enterprise with Mandiant Breach Analytics and UEBA, achieving remarkable results. By shifting CSG's security model to be more data-driven, agent-led and powered by the Resolution Intelligence Cloud™; CSG achieved more than a 50% reduction in security operational expenses, enhanced its visibility across its business units, and moved from reactive alert handling toward provable, continuously validated readiness. The transformation delivered enhanced threat detection efficacy, faster response times, and a proactive security posture, positioning CSG for long-term scalability and operational excellence.

Customer Profile

Cloud Software Group (CSG) is a $4.5 billion holding company managing Citrix, TIBCO, NetScaler, JasperSoft, Spotfire, XenServer, and Information Builders. With a global footprint spanning over 100 countries and a workforce of 8,500+, CSG supports more than 100 million users in critical industries such as healthcare, finance, manufacturing, and retail.

As the company expanded through acquisitions, its legacy security operations struggled to keep pace, exposing limitations in cost, scalability, and performance. These underscored the need for a modernized and unified security solution. As a leader in business-critical software solutions, CSG's security infrastructure needed to maintain the highest standards of protection while supporting rapid business growth.

Challenges

CSG's existing SOC architecture had become a costly and potentially detrimental bottleneck:

  1. Excessive Costs: CSG's annual security expenditures were considerable, with a significant portion allocated to Splunk licensing and infrastructure maintenance. As the company expanded through acquisitions, the need to scale the system placed additional pressure on the budget. Furthermore, the rising cost of talent became the largest expense, largely due to high turnover and the ongoing struggle to retain skilled personnel.
  2. Talent Retention Issues: Limited career growth opportunities for SOC team members led to frequent turnover, resulting in a constant need to onboard and train new hires.

  3. Scalability Roadblocks: Each new subsidiary required custom configurations for detection rules and log ingestion, resulting in inconsistent processes and longer onboarding times. This hindered CSG's ability to efficiently integrate acquisitions.
  4. Operational Complexity: The SOC team managed 40+ disparate playbooks, tailored for individual business units, leading to unnecessary complexity and duplication of effort. Each playbook demanded significant manual intervention, stretching resources thin.
  5. Limited Visibility and Efficacy: Siloed architecture and inconsistent data ingestion created blind spots, reducing situational awareness and delaying threat detection and response. The lack of standardized data formats further complicated integration with new tools.
 

The Netenrich Solution

To address this, Netenrich implemented a data-driven, agent-led security model, powered by the Resolution Intelligence Cloud™.

  1. From Playbook Sprawl to Agent-Led Response: Netenrich consolidated CSG's 40+ playbooks into three standardized, agent-executed workflows: incident triage, threat investigation, and response automation — replacing tiered, human hand-offs with continuous, always-on execution. These were aligned across all subsidiaries, ensuring consistency and streamlining operations.
  2. Enhanced Data Engineering: Every downstream detection is only as good as the data behind it, so Netenrich started with the foundation. Netenrich implemented a Universal Data Model to unify data ingestion, normalize logs from disparate sources, and eliminate blind spots. The system expanded from 24 to 40 log sources, now ingesting and processing more than 2 TB of data daily, providing comprehensive visibility. Eight custom parsers were built to standardize data formats, complemented by the implementation of 194 out-of-the-box (OOTB) detection rules and 212 custom detection rules to ensure thorough coverage across all data sources.
  3. Behavior-Based Detection, Not Static Rules: Advanced machine learning models were deployed to replace 234 Splunk search queries with behavior-based detection coverage, consolidating into 26 behavior-based rules — trading narrow, precision rules that miss novel attacker behavior for broader, MITRE ATT&CK-aligned coverage that surfaces the low-and-slow, non-alerted activity a rules-only SIEM would have left invisible. This improved detection efficacy, achieving 99% coverage of critical alerts. The transition from traditional query-based detection to behavior-based analysis significantly enhanced the system's ability to identify and respond to emerging threats.
  4. Machine-Speed Triage, Not Manual Hand-Offs: The solution introduced continuous monitoring, signal analysis, and impact-based workflows that let the system decide and act instead of queueing alerts for the next human tier, reducing mean time to detect and respond by 60–70%. This improvement allowed CSG to transition from reactive measures to a proactive security approach, enhancing threat anticipation and mitigation capabilities.
  5. No Ingestion Penalty, No Blind Spots: Effectively used unlimited storage capabilities to address scalability concerns, enabling unrestricted data ingestion. Additionally, Mandiant's integrated threat intelligence provided enriched data insights, minimizing manual enrichment efforts and improving detection accuracy.

 

Netenrich Approach

Netenrich executed the migration in three phases over 12 weeks, ensuring minimal disruption to CSG's ongoing operations:

  1. Foundation — Data Engineering: Netenrich assessed CSG's existing log sources, built eight custom parsers, and aligned them with a Universal Data Model. This eliminated inconsistencies across subsidiaries.
  2. Intelligence — Detection Engineering: Threat models were redesigned to focus on behavior-based rules, ensuring comprehensive coverage with minimal noise. AI and machine learning capabilities were integrated for adaptive threat identification.
  3. Autonomy — Response Engineering: Playbooks were streamlined and automated using native SOAR capabilities, reducing manual interventions and enabling rapid responses. Custom SOAR integrations further enhanced operational workflows.

Across all three phases, the goal was the same: let AI agents absorb the operational noise so CSG's own team could focus on the decisions that actually require human judgment.

Netenrich's data-driven, agent-led approach was instrumental in overcoming CSG's legacy challenges. The solution emphasized:

  • Signal Analysis: Comprehensive signal correlation and prioritization improved the SOC's ability to identify and address threats with precision.
  • Automation: AI-driven workflows and impact-based routing reduced the dependency on manual intervention, increasing performance.
  • Integration Readiness: Custom parsers and playbooks were designed to accommodate future acquisitions and scale dynamically with business growth.
 

Outcomes and Impact

The transformation delivered measurable results across several dimensions — the kind of shift from measuring activity to measuring outcomes that the results below reflect: fewer tools, far less manual triage, and detection coverage mapped to real attacker behavior rather than static rules, turning what used to be invisible, non-alerted risk into something CSG's team could actually see and act on.

  1. Cost Savings
    • Annual security expenses decreased by over 50%
    • Reduced SOC staffing requirements by 80% leading to smarter resource management and lower turnover-related costs.
  2. Data-Led Security Transformation
    • Full correlation of data sources delivers contextual insights, reducing noise and prioritizing critical alerts.
    • Improved ability to detect trends, anomalies, and potential risks in real time.
    • Future-ready infrastructure supports continuous improvements and organization updates.
  3. Enhanced Threat Detection
    • Detection coverage improved by 147%, supported by the ingestion of diverse data sources.
    • Mean time to detect and respond reduced from hours to 15 minutes, ensuring faster containment of threats.
  4. Operational Efficiency
    • Monthly security incidents requiring manual intervention dropped from 1,920 to fewer than 10.
    • Playbook management became 90% more efficient, enabling the SOC team to focus on proactive threat hunting.
  5. Scalability and Flexibility
    • Reduced the acquired subsidiaries onboarding time from 3 months to under 5 days.
    • The standardized workflows allowed seamless integration of new business units, enhancing operational workflow.
  6. Improved Visibility
    • Real-time dashboards provided comprehensive insights into security posture, operational stability, and threat landscapes.

Want to learn more about how CSG completely modernized its SOC architecture in just 12 weeks?

Download Detailed Case Study
 

Future Vision

This approach positions CSG to embrace a digital workforce of specialized AI agents — autonomous security operations—a future where systems self-manage, adapt, and respond to threats with minimal human intervention. With its scalable architecture and data-driven approach, CSG is now equipped to move beyond managing alerts to managing risk, ready for tomorrow's evolving and enigmatic threat landscape.