A federal civilian agency met its EO 14028 logging tiers and automated containment agency-wide — inside a FedRAMP boundary, across fourteen bureaus.
42s Median containment | 60K Endpoints watched | EL3 Logging tier | 100% Privileged logged |
The agency had the mandate and the audit calendar, but no way to reach Event Logging tier EL3 or automate containment across a fleet spanning fourteen bureaus and three clouds. Every incident was a manual, after-hours scramble.
threatDefendr deployed inside the agency’s GovCloud boundary, normalizing logs to the EL3 tier and running pre-authorized containment playbooks. A shared graph tied identities, endpoints, and cloud events into one investigable picture.
A credential-stuffing wave was contained agency-wide in 42 seconds without paging an analyst. All fourteen bureaus reached EL3 within two quarters, with every privileged action retained on a tamper-evident ledger for the full M-21-31 window.
“We went from an executive order on paper to containment we can prove in seconds. threatDefendr is the machinery the mandate assumed we already had.”