42-second containment
across 60,000 endpoints.
A federal civilian agency met its EO 14028 logging tiers and automated containment agency-wide — inside a FedRAMP boundary, across fourteen bureaus.
A mandate without the machinery.
The agency had the EO 14028 mandate and the audit calendar, but no way to reach Event Logging tier EL3 or automate containment across a fleet spanning fourteen bureaus and three clouds. Every incident was a manual, after-hours scramble.
- Logging fragmented across fourteen bureaus
- Containment needed a human in every loop, at every hour
- No unified retention that met M-21-31
- Cloud and on-prem watched by different teams
One boundary, every bureau.
threatDefendr deployed inside the agency's GovCloud boundary, normalizing logs to the EL3 tier and running pre-authorized containment playbooks. A shared graph tied identities, endpoints, and cloud events into one investigable picture.
The outcome, measured.
All fourteen bureaus normalized to the Event Logging EL3 tier within two quarters.
A credential-stuffing wave was contained agency-wide in 42 seconds without paging an analyst.
Every privileged action is retained on a tamper-evident ledger for the full M-21-31 window.
More proof, more sectors.
See how threatDefendr is configured for public sector.
A 14-hospital system quarantined a ransomware canary in 39 seconds with zero care disruption.
A high-growth SaaS platform shipped detections in CI and cut false positives 71%.