A state government stood up a shared detection-and-response service for 240 agencies and municipalities — on a budget that had priced out a traditional SIEM.
240 Agencies covered | 90 days To first response | 63% Lower cost / seat | 1 Statewide picture |
Counties, school districts, and utilities each ran a sliver of a SOC — or none at all. Attackers hit the weakest and moved sideways across shared state networks, while no one had the staff or money for a per-agency SIEM.
The state ran threatDefendr as a shared service. Small agencies onboarded with prebuilt connectors; a central team ran detection and response for everyone, with each agency seeing only its own data.
From twelve agencies with a SOC to 240 under one coordinated service in a single fiscal year, at 63% lower cost per protected seat. An indicator seen at one county is now blocked everywhere within minutes.
“For the first time, a school district and the state police see the same threat at the same time. We defend as one state now.”