Progression Case Study — SOC as a Service: Industrial Estate Threat Correlation
Case Study

Inside an industrial enterprise's blind spot: catching threats before they became a breach

How Progression's SOC as a Service gave a distributed enterprise centralized threat correlation across its Windows, Linux, firewall, and network estate — turning raw log data into a working, actioned incident pipeline.

23
Assets integrated
1,333
Incidents detected (Aug '26)
36 / 35
Cases raised / closed
Client Profile
Distributed enterprise operating a mixed IT estate across Windows, Linux, firewall & network infrastructure, including internet-facing apps & remote access services
Industry
Industrial / Manufacturing
Engagement Scope
SOC as a Service — 24/7 monitoring, correlation & incident response across 23 integrated assets (Windows, Linux, Firewall, Switch)
Progression's Role
Managed Security Services Partner — SOC as a Service (Threat Detection, Correlation & Incident Response)
The Challenge

A wide attack surface, with no centralized way to correlate it

The client operates a mixed Windows, Linux, firewall, and network estate with internet-facing services such as TallyServer and VNC access, giving attackers multiple potential entry points. Without centralized correlation across these assets, threats were going undetected until they escalated.

  • ! Internet-facing services, including TallyServer and VNC access, expanded the attack surface with no centralized way to correlate suspicious activity against them.
  • ! Insecure protocol usage was found running on the non-guest network in nearly 50 related instances — a systemic weakness with no mechanism in place to surface it.
  • ! An ANONYMOUS LOGON account was seen authenticating successfully from two countries at once — invisible without log correlation across firewall, endpoint, and directory sources.
  • ! Without a centralized SOC function, brute-force attempts, malware call-back traffic, and Active Directory abuse could escalate well before the internal team became aware.
  • ! The client needed a managed security partner to bring 24/7 correlation and detection across its full asset landscape, converting scattered log data into actionable incidents.
The Solution

Full-estate onboarding into FortiSIEM, with continuous correlation

Progression's SOC integrated 23 assets into FortiSIEM and applied continuous correlation rules across firewall, Windows, and Linux telemetry.

  • ✓ End-to-end onboarding of 23 assets across Windows, Linux, firewall, and switch infrastructure into FortiSIEM for centralized log correlation.
  • ✓ Continuous correlation rules applied across firewall, endpoint, and directory sources to surface threats invisible when sources are reviewed in isolation.
  • ✓ Over the reporting month, the SOC identified and triaged 36 high- and medium-severity cases, including malware call-back traffic, brute-force attempts, exposed VNC, and cross-country ANONYMOUS LOGON activity.
  • ✓ Each incident was delivered with a full breakdown — description, likely cause, and a concrete remediation path — so the client's team could act immediately instead of starting from raw log data.
The Outcome

A working incident pipeline, from day one of reporting

The SOC as a Service engagement gave the client a working incident pipeline and measurable security outcomes within the first reporting month.

Working incident pipeline

35 of the 36 cases raised in the month were investigated and closed, replacing a backlog of unreviewed alerts with a functioning, actioned process.

Full-estate visibility

23 assets across Windows, Linux, firewall, and switch infrastructure brought under continuous, correlated monitoring.

High detection volume

1,333 incidents detected in a single month (August '26), demonstrating the depth of visibility the correlation engine provides.

Early threat containment

Malware command-and-control activity and unauthorized remote-access paths were surfaced early, well before they could progress to data loss or lateral movement.

Prioritized hardening roadmap

Correlation of insecure-protocol usage and anonymous-logon abuse gave the IT team a clear, prioritized roadmap for hardening AD and network segmentation.

Actionable, not just detected

Every case was paired with a concrete remediation path — host isolation, credential reset, MFA enforcement, or perimeter blocking.

Not sure what's crossing your firewall, endpoints, and directory unseen?

See how Progression's SOC as a Service can bring your full IT estate under one correlated, continuously monitored view.

Talk to Our Team Download Case Study
  • Home
  • Services
  • About Us
  • Partnerships
  • Our Brands