STATE & LOCAL

One SOC for the whole
state, in 90 days.

A state government stood up a shared detection-and-response service for 240 agencies and municipalities — on a budget that had priced out a traditional SIEM.

INDUSTRY
State government
SIZE
240 agencies & munis
DEPLOYMENT
State private cloud
REGION
US
AGENCIES ON ONE SOC↑ 20×
BEFORE12
WITH THREATDEFENDR240
school district & state police · one picture
THE CHALLENGE

Everyone a target, no one a budget.

Counties, school districts, and utilities each ran a sliver of a SOC — or none at all. Attackers hit the weakest and moved sideways across shared state networks, while no one had the staff or the money for a per-agency SIEM.

WHERE IT HURT
  • 240 agencies, wildly uneven security maturity
  • Ransomware pivoting across shared networks
  • No shared visibility between state and local
  • Per-agency SIEM licensing was unaffordable
THE APPROACH

A shared fabric, funded once.

The state ran threatDefendr as a shared service. Small agencies onboarded with prebuilt connectors; a central team ran detection and response for everyone, with each agency seeing only its own data.

For the first time, a school district and the state police see the same threat at the same time. We defend as one state now.
AC
Angela Cho
State CISO, Civic Grid
WHAT CHANGED

The outcome, measured.

240
AGENCIES COVERED

From twelve agencies with a SOC to 240 under one coordinated service in a single fiscal year.

63%
LOWER COST PER SEAT

Shared infrastructure delivered enterprise detection at a price small munis could actually fund.

One picture
CROSS-JURISDICTION

An indicator seen at one county is blocked everywhere within minutes.

// STATE & LOCAL

One SOC for the whole
state, in 90 days.

A state government stood up a shared detection-and-response service for 240 agencies and municipalities — on a budget that had priced out a traditional SIEM.

INDUSTRY
State government
SIZE
240 agencies & munis
DEPLOYMENT
State private cloud
REGION
US
// AGENCIES ON ONE SOC↑ 20×
BEFORE12
WITH THREATDEFENDR240
school district & state police · one picture
// THE CHALLENGE

Everyone a target, no one a budget.

Counties, school districts, and utilities each ran a sliver of a SOC — or none at all. Attackers hit the weakest and moved sideways across shared state networks, while no one had the staff or the money for a per-agency SIEM.

WHERE IT HURT
  • 240 agencies, wildly uneven security maturity
  • Ransomware pivoting across shared networks
  • No shared visibility between state and local
  • Per-agency SIEM licensing was unaffordable
// THE APPROACH

A shared fabric, funded once.

The state ran threatDefendr as a shared service. Small agencies onboarded with prebuilt connectors; a central team ran detection and response for everyone, with each agency seeing only its own data.

For the first time, a school district and the state police see the same threat at the same time. We defend as one state now.
AC
Angela Cho
State CISO, Civic Grid
// WHAT CHANGED

The outcome, measured.

240
AGENCIES COVERED

From twelve agencies with a SOC to 240 under one coordinated service in a single fiscal year.

63%
LOWER COST PER SEAT

Shared infrastructure delivered enterprise detection at a price small munis could actually fund.

One picture
CROSS-JURISDICTION

An indicator seen at one county is blocked everywhere within minutes.