PUBLIC SECTOR

42-second containment
across 60,000 endpoints.

A federal civilian agency met its EO 14028 logging tiers and automated containment agency-wide — inside a FedRAMP boundary, across fourteen bureaus.

INDUSTRY
Federal civilian agency
SIZE
60,000 endpoints
DEPLOYMENT
GovCloud · FedRAMP High (in process)
REGION
US
AGENCY-WIDE CONTAINMENT↓ 99%
BEFORE6h
WITH THREATDEFENDR42s
credential-stuffing wave · auto-contained
THE CHALLENGE

A mandate without the machinery.

The agency had the EO 14028 mandate and the audit calendar, but no way to reach Event Logging tier EL3 or automate containment across a fleet spanning fourteen bureaus and three clouds. Every incident was a manual, after-hours scramble.

WHERE IT HURT
  • Logging fragmented across fourteen bureaus
  • Containment needed a human in every loop, at every hour
  • No unified retention that met M-21-31
  • Cloud and on-prem watched by different teams
THE APPROACH

One boundary, every bureau.

threatDefendr deployed inside the agency's GovCloud boundary, normalizing logs to the EL3 tier and running pre-authorized containment playbooks. A shared graph tied identities, endpoints, and cloud events into one investigable picture.

We went from an executive order on paper to containment we can prove in seconds. threatDefendr is the machinery the mandate assumed we already had.
MB
Marcus Bell
Deputy CISO, Astra Federal
WHAT CHANGED

The outcome, measured.

EL3
LOGGING TIER REACHED

All fourteen bureaus normalized to the Event Logging EL3 tier within two quarters.

42s
MEDIAN CONTAINMENT

A credential-stuffing wave was contained agency-wide in 42 seconds without paging an analyst.

7 yr
IMMUTABLE RETENTION

Every privileged action is retained on a tamper-evident ledger for the full M-21-31 window.

// PUBLIC SECTOR

42-second containment
across 60,000 endpoints.

A federal civilian agency met its EO 14028 logging tiers and automated containment agency-wide — inside a FedRAMP boundary, across fourteen bureaus.

INDUSTRY
Federal civilian agency
SIZE
60,000 endpoints
DEPLOYMENT
GovCloud · FedRAMP High (in process)
REGION
US
// AGENCY-WIDE CONTAINMENT↓ 99%
BEFORE6h
WITH THREATDEFENDR42s
credential-stuffing wave · auto-contained
// THE CHALLENGE

A mandate without the machinery.

The agency had the EO 14028 mandate and the audit calendar, but no way to reach Event Logging tier EL3 or automate containment across a fleet spanning fourteen bureaus and three clouds. Every incident was a manual, after-hours scramble.

WHERE IT HURT
  • Logging fragmented across fourteen bureaus
  • Containment needed a human in every loop, at every hour
  • No unified retention that met M-21-31
  • Cloud and on-prem watched by different teams
// THE APPROACH

One boundary, every bureau.

threatDefendr deployed inside the agency's GovCloud boundary, normalizing logs to the EL3 tier and running pre-authorized containment playbooks. A shared graph tied identities, endpoints, and cloud events into one investigable picture.

We went from an executive order on paper to containment we can prove in seconds. threatDefendr is the machinery the mandate assumed we already had.
MB
Marcus Bell
Deputy CISO, Astra Federal
// WHAT CHANGED

The outcome, measured.

EL3
LOGGING TIER REACHED

All fourteen bureaus normalized to the Event Logging EL3 tier within two quarters.

42s
MEDIAN CONTAINMENT

A credential-stuffing wave was contained agency-wide in 42 seconds without paging an analyst.

7 yr
IMMUTABLE RETENTION

Every privileged action is retained on a tamper-evident ledger for the full M-21-31 window.