Search

 
 

Fortune 500 company cuts cyber exposure score by 51%

 

40%

Increase in BitSight score, reaching 800 and improving external security posture.

 

51%

Reduction in cyber exposure score through proactive vulnerability management.

 

50%+

Decrease in security alert volume, improving focus on high-risk threats.

 
 

At a glance

 

Client

Natural resources company

 

Industry

Manufacturing

 

Our role

Modernize managed cyber operations

 

Our solution

Proactive, AI-enabled cyber defense model

 
 
 

Improving visibility into cyber risks

 
folder icon

Scenario

A natural resources company needed stronger cyber resilience, greater visibility and faster response capabilities as threats increased.

gears icon

Approach

Grant Thornton | Auxis helped transform security operations through an AI-powered managed security operations center (SOC), threat intelligence capabilities and a vulnerability management program.

graph icon

Result

The organization improved security scores, reduced cyber exposure and achieved faster, more consistent incident response.

 
 

Scenario

 
 

A Fortune 500 natural resources company with thousands of employees and multinational operations sought to strengthen its security posture while maintaining compliance and supporting uninterrupted operations. The organization operates in a highly regulated environment and has extensive cybersecurity regulatory responsibilities.

 

The company’s leadership wanted to move beyond a model centered on ticket processing and gain greater visibility into risk. The organization needed faster threat response and a more proactive approach to cybersecurity. The goal was to better align security operations with evolving business and regulatory requirements while creating a foundation for continuous improvement.

 

To accomplish these goals, the company sought a new managed security service provider that could:

  • Improve threat detection and response capabilities
  • Increase visibility into security operations and risk exposure
  • Strengthen regulatory compliance
  • Provide access to specialized cybersecurity talent and best practices
  • Reduce alert fatigue from a system that was generating more than 3,000 alerts per month and overwhelming internal teams.

The company chose a nearshoring partnership with Grant Thornton | Auxis to build a more strategic, proactive cybersecurity services model powered by AI, best practices and specialized outsourced cybersecurity personnel.

 
 

Approach

 
 

The client transformed its cybersecurity operations into a more proactive, intelligence-driven program designed to support business resilience and regulatory requirements. Departmental stakeholders across the organization partnered with Grant Thornton | Auxis to prioritize remediation efforts. The partnership brought together specialized talent, AI-enabled automation and continuous improvement practices to create a more strategic managed cybersecurity operation.

 

The solution was built around three integrated cybersecurity service towers:

  • Security operations center: Established a dedicated team to provide 24/7 monitoring, threat detection, investigation and response. By implementing structured alert-classification playbooks, the team gained the ability to quickly distinguish routine notifications from genuine threats and focus resources appropriately.
  • Vulnerability management: Introduced a proactive remediation program and enhanced governance and recurring executive reporting to improve visibility into cyber risk, accelerate vulnerability remediation and strengthen accountability across the organization.
  • Threat intelligence: Developed a tailored threat intelligence capability that continuously monitors emerging risks, identifies relevant vulnerabilities and provides actionable intelligence to strengthen detection and response efforts.

To further improve speed, consistency and scalability, the client worked with Grant Thornton | Auxis to implement an automation roadmap focused on high-value security use cases, including:

  • Automated ingestion of threat intelligence feeds to enable near-real-time blocking of malicious indicators.
  • Automated remediation of compromised user accounts, reducing containment times from manual hours to minutes.
  • Automated workstation isolation to rapidly contain ransomware and other fast-moving threats.
  • Automated evidence collection for insider-risk investigations, accelerating investigations and reducing analyst effort.

By combining managed security services, threat intelligence and targeted automation, the company worked with Grant Thornton | Auxis to build a more resilient security operation capable of adapting to an increasingly complex threat landscape.

 

How we can help you

 
 
 

 

Ready to talk? We’re ready to listen.

Request a meeting -->

 
 

Result

 
 

The company used the new operating model to shift from reactive security management to a more resilient, risk-focused approach. Threat intelligence capabilities now help identify and block 2,500 to more than 4,000 potential attack vectors each month, while automation reduces manual effort and improves response speed.

 

Following this transformation, the organization’s security performance improved significantly across key measures. The company’s BitSight score increased by 40% to 800 points out of a possible 900. Its Tenable Cyber Exposure score declined by 51%, and mean time to remediate vulnerabilities dropped to fewer than 40 days, down from more than 100 days at the start of the engagement. Alert volumes were reduced by more than 50%, allowing analysts to focus on critical risks without increasing headcount.

 

The success of the cybersecurity engagement also strengthened trust in the relationship, leading the client to expand its work with Grant Thornton | Auxis into additional IT and infrastructure initiatives and multilingual help desk operations, where nearshoring provides even more benefits.

 
 

Connect with our team

 
 

Content disclaimer

This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.

Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.

For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.

 

Ready to talk? We’re ready to listen.

 

Request a meeting and a member of our team will be in touch to see what we can do to meet your needs.

 

Want to submit an RFP? Please submit your request through our RFP submission page.

 
 
 

Trending topics

 

Follow us