Fintech
A Renowned Fintech Company Gets SOC Expertise Onboard
At a glance
INDUSTRY
Fintech
CLIENT PROFILE
A well-recognized Australian fintech responsible for personnel data, customer data, business systems and brand integrity
SERVICES
SOC Monitoring
ENGAGEMENT
24x7 outsourced Security Operations Center build and monitoring

key Numbers
1,072,772
926,960
19/19
Key Takeaways
Client – A well-recognized Australian fintech responsible for personnel data, customer data, business systems, intellectual property and brand integrity.
Problem – The client needed round-the-clock monitoring, detection and response across its devices, cloud services and applications, with no existing SOC infrastructure in place.
What Payatu did – Stood up a 24x7 SOC covering CrowdStrike, Splunk, Azure Sentinel, AWS CloudTrail, Salesforce, Office 365 and Fortinet, deployed honeypots on-prem and in AWS, and ran every alert through an SLA-bound Jira workflow.
Outcome – The client gained continuous visibility into its threat landscape, with 100% of triggered alerts investigated and proactive threat intelligence, including CVE advisories such as Follina, shared on an ongoing basis.
the challenge
Why the client called us in
Fintech cyberattacks don't just cost money, they erode customer trust and put compliance obligations at risk. This well-recognized Australian fintech understood that responsibility and wanted round-the-clock monitoring, protection, detection, investigation and response for its personnel data, customer data, business systems, intellectual property and brand. The company had no existing SOC infrastructure, so everything, from tooling to process to staffing, needed to be built from scratch, under a limited timeline and strict regulatory constraints on permissions.
- Get complete visibility into the threat landscape across endpoints, software, servers and third-party services
- Establish 24x7 monitoring, detection and response capability where none existed before
- Investigate and close every alert within defined SLAs
scope of engagement
What was in scope
- Devices allotted to employees, such as mobiles and laptops
- Applications installed on all devices
- Device activities such as logins from an unexpected user, IP address or application
- Cloud services such as Azure and AWS
- Azure Outlook, One Drive and audit log monitoring to detect and respond to phishing and brute-force attempts
- Access to files shared outside the client's organization
- Logging of all operational infrastructure devices (mobiles, laptops, AWS servers) to CrowdStrike
- Salesforce, Fortinet, Sentinel and Office 365 monitoring
- AWS device and application logging to Splunk
- Proactive automated and manual monitoring of logged data
- WordPress site logging to Splunk
- Honeypot deployment and alerting across on-prem and AWS infrastructure
- 24x7 staff availability to respond to emergencies
- Alert investigation and closure within agreed SLAs
Our Approach
How Payatu ran the engagement
01
02
03
04
Key findings
What we found
the outcome
Results and Impact
Payatu's SOC team gave this Australian fintech the always-on visibility it didn't have before, turning a blank slate into a fully monitored environment spanning endpoints, cloud services and SaaS applications. Every alert moved through a defined SLA workflow, and the team kept the client ahead of emerging threats with proactive intelligence.
Built a 24x7 SOC from scratch, covering endpoints, cloud, SaaS and network infrastructure
Monitored over 1 million Fortinet log entries and close to 930,000 Salesforce log entries every week
Investigated and closed 100% of the 19 alerts triggered by Azure Sentinel
Delivered proactive threat intelligence, including CVE advisories such as Follina, to keep the client ahead of active threats
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







