Summary
Key results
Agreed detection and response time targets met every month
Hundreds of incidents triaged monthly
Closing the 24/7 monitoring gap under regulatory pressure
The insurance provider needed to strengthen the protection of customer data and business operations through continuous threat detection and incident response. Its existing setup did not provide an effective 24/7 Security Operations Center service, limiting the organization’s ability to monitor, assess, and respond to cybersecurity incidents at any time.
Regulatory requirements made this gap more urgent. As the company prepared for the Digital Operational Resilience Act, it needed a structured and measurable approach to security operations, with continuous coverage, documented incident response procedures, defined detection and response service levels, and regular reporting.
The service also had to cover both cloud and on-premises environments. The organization therefore selected Sii Poland for its team of cybersecurity experts with experience in delivering complex projects across the financial services sector.
From Microsoft Sentinel implementation to 24/7 security operations
Sii Poland delivered the engagement in 2 stages: a 2-month implementation phase followed by continuous operations. During implementation, the team established the core monitoring and response setup, onboarded cloud and on-premises data sources, and prepared the operating procedures needed to launch the service.
The scope of work included:
- Designing and implementing the incident response process and preparing operating procedures
- Implementing and configuring Microsoft Sentinel as the security information and event management platform
- Onboarding data sources from cloud and on-premises environments, including cloud infrastructure outside Microsoft Azure
- Developing the main correlation and detection rules
- Preparing manual response scenarios and automated incident response and containment playbooks using Microsoft Sentinel and Azure Logic Apps
- Integrating Microsoft Sentinel with Jira to connect security incident handling with the client’s IT service management workflow
- Launching 24/7 monitoring, triage, response, and containment
- Establishing monthly service reporting
Once implementation was complete, the service entered continuous operations. Sii Poland staffed it with Level 1 and Level 2 analysts supported by an engineer and an architect.
Continuous coverage and structured incident handling
The client now has continuous coverage for cybersecurity incidents across cloud and on-premises environments. A defined incident response process guides cases from triage through response and containment, closing the previous 24/7 coverage gap.
Sii Poland triages hundreds of incidents each month and has met the agreed detection and response service levels every month. Automated playbooks support more consistent incident handling, while the Microsoft Sentinel–Jira integration connects security operations with the client’s IT service management process.
Documented procedures and monthly reporting give the client a regular view of service performance. Together, these capabilities strengthen its security posture and support preparation for Digital Operational Resilience Act requirements.
Key results
- 24/7 monitoring, triage, response, and containment for assigned incidents
- Agreed detection and response service levels met every month
- Hundreds of incidents triaged each month
- Monitoring coverage across cloud and on-premises environments
- Automated playbooks and Microsoft Sentinel–Jira integration supporting incident handling
- Monthly security service reporting established