Cyber Case Study
NewSpace

Supported by its partner, a start-up from the NewSpace industry protects its heterogeneous IT fleet of over one hundred endpoints with HarfangLab.

Context

The company operates in the space monitoring sector. Its technology enables space mapping based on data from active or inactive objects in space. This data can then be aggregated with data from other sources.

Their aim is to anticipate collisions (among satellite constellations, for example), or to identify hostile satellite maneuvers to set up an appropriate defense system.

Data protection and protection against advanced threats are paramount for this start-up, which counts both private companies and public institutions among its customers. Given the sensitivity of the business sector and the geopolitical context, security and sovereignty are at the heart of their mission.

“The attack surface of information systems is constantly increasing. Today, protection is not the only stake, we also must be able to rely on optimal detection. EDR thus plays a central role in a cyber strategy.”
Chief Security Officer – NewSpace Start-up

Why HarfangLab?

The role of an MSSP is to support CISOs and CIOs in their technological choices by proposing solutions in line with their roadmap. In the case of start-up NewSpace, which is already mature in terms of cybersecurity, interoperability and sovereignty were identified as essential criteria, in addition to high requirements in terms of protection and detection. A migration to HarfangLab was an obvious choice.”
CEO – MSSP

 

“An EDR is essential to understanding what’s happening in an information system and reacting in the event of a security incident. We also need network probes and therefore an NDR, as well as other security assets that are part of Open XDR.
The interoperability between the solutions in this ecosystem
is a great perk for security teams, thanks in particular to facilitated exchanges between publishers who are actively pooling expertise.”
Chief Security Officer – NewSpace Start-up 

Deployment and Support

HarfangLab was deployed over a period of 2 months and, in total, 5 to 6 days. During the run phase, MSSP analysts access the console directly to manage alerts, carry out investigations, classify alerts and remediate threats if necessary.

This access to the console enables very rapid and precise processing. For its part, the NewSpace start-up spends an average of 1 hour a week managing the console, fine-tuning parameters and continuously improving detection.

“Deployment was a 4-handed process with our client. We used a GPO and proceeded in stages, validating the deployment on endpoints representative of the IT fleet with a view to gradually extending it to the entire infrastructure. Once the solution has been deployed and configurations optimized, HarfangLab offers a particularly interesting ratio between the effort required to operate the solution and the level of protection. This is an important criterion to take into account – bearing in mind that ongoing fine-tuning is required as the threats constantly evolve.”
CEO – MSSP

Results

Many assets requiring different skills are necessary to protect an entire information system: network, system, virtualization, firewall, SecOps, Active Directory… By relying on its MSSP, the NewSpace start-up benefits from all these areas of expertise.

“Migration to HarfangLab has enabled us to cover our protection needs and to add detection capabilities, which is especially important for Internet-connected workstations. EDR is an additional source for our XDR and meets our security requirements given our budget and available resources.”
Chief Security Officer – NewSpace Start-up