Inside an industrial enterprise's blind spot: catching threats before they became a breach
How Progression's SOC as a Service gave a distributed enterprise centralized threat correlation across its Windows, Linux, firewall, and network estate — turning raw log data into a working, actioned incident pipeline.
A wide attack surface, with no centralized way to correlate it
The client operates a mixed Windows, Linux, firewall, and network estate with internet-facing services such as TallyServer and VNC access, giving attackers multiple potential entry points. Without centralized correlation across these assets, threats were going undetected until they escalated.
- ! Internet-facing services, including TallyServer and VNC access, expanded the attack surface with no centralized way to correlate suspicious activity against them.
- ! Insecure protocol usage was found running on the non-guest network in nearly 50 related instances — a systemic weakness with no mechanism in place to surface it.
- ! An ANONYMOUS LOGON account was seen authenticating successfully from two countries at once — invisible without log correlation across firewall, endpoint, and directory sources.
- ! Without a centralized SOC function, brute-force attempts, malware call-back traffic, and Active Directory abuse could escalate well before the internal team became aware.
- ! The client needed a managed security partner to bring 24/7 correlation and detection across its full asset landscape, converting scattered log data into actionable incidents.
Full-estate onboarding into FortiSIEM, with continuous correlation
Progression's SOC integrated 23 assets into FortiSIEM and applied continuous correlation rules across firewall, Windows, and Linux telemetry.
- ✓ End-to-end onboarding of 23 assets across Windows, Linux, firewall, and switch infrastructure into FortiSIEM for centralized log correlation.
- ✓ Continuous correlation rules applied across firewall, endpoint, and directory sources to surface threats invisible when sources are reviewed in isolation.
- ✓ Over the reporting month, the SOC identified and triaged 36 high- and medium-severity cases, including malware call-back traffic, brute-force attempts, exposed VNC, and cross-country ANONYMOUS LOGON activity.
- ✓ Each incident was delivered with a full breakdown — description, likely cause, and a concrete remediation path — so the client's team could act immediately instead of starting from raw log data.
A working incident pipeline, from day one of reporting
The SOC as a Service engagement gave the client a working incident pipeline and measurable security outcomes within the first reporting month.
Working incident pipeline
35 of the 36 cases raised in the month were investigated and closed, replacing a backlog of unreviewed alerts with a functioning, actioned process.
Full-estate visibility
23 assets across Windows, Linux, firewall, and switch infrastructure brought under continuous, correlated monitoring.
High detection volume
1,333 incidents detected in a single month (August '26), demonstrating the depth of visibility the correlation engine provides.
Early threat containment
Malware command-and-control activity and unauthorized remote-access paths were surfaced early, well before they could progress to data loss or lateral movement.
Prioritized hardening roadmap
Correlation of insecure-protocol usage and anonymous-logon abuse gave the IT team a clear, prioritized roadmap for hardening AD and network segmentation.
Actionable, not just detected
Every case was paired with a concrete remediation path — host isolation, credential reset, MFA enforcement, or perimeter blocking.
Not sure what's crossing your firewall, endpoints, and directory unseen?
See how Progression's SOC as a Service can bring your full IT estate under one correlated, continuously monitored view.
Talk to Our Team Download Case Study