Cyber
Case Study
Public Administration

HarfangLab protects 46,000 workstations and 8,000 servers belonging to a public administration managing a heterogeneous environment.

The visibility provided by the EDR enables security teams to address external threats while also securing the workspace that spans on-site, remote work, and mobile settings – across more than 200 different job functions.

Context

The public administration was equipped with an antivirus solution, and the organization of a large-scale international event heightened the need for improved visibility across workstations.

User practices within the information system vary greatly depending on the job function, and the heterogeneous environment – spanning multiple operating systems and versions, including Windows, Linux, and macOS – made standardization challenging. The goal was to preserve the user experience while being able to distinguish legitimate usage from security risks.

Phishing represents the most significant threat, along with the use of external storage devices that may contain malicious files, and more broadly, the personal use of corporate equipment.

“Securing a workspace requires knowing what is happening on endpoints. HarfangLab provides precise visibility into actions, commands, and processes, and also makes it possible to detect whether AI agents are deployed – one of our top monitoring priorities.”

Head of the Cyber Defense Team and SOC Manager

Why HarfangLab?

The administration had two priorities in addition to the imperative of strategic autonomy: detection and protection capabilities, and agent performance.

Furthermore, given the volume of endpoints to manage, the number of security tools in use, and limited available resources, the administration sought a platform that could both integrate with third-party tools and automate investigation and remediation tasks.

“HarfangLab’s ongoing developments deliver increasingly broad, consistent, and well-integrated cyber coverage within a single platform.”

Head of the Cyber Defense Team and SOC Manager

Deployment

The platform was deployed On-Premises within 3 months across 90% of the environment, mobilizing only 2 resources, with one instance dedicated to workstations and one to servers, each running distinct policies.

The administration relies on an external SOC but manages the platform internally to maintain optimal visibility over the console and the data it surfaces.

Support

“We have regular exchanges with HarfangLab’s teams, who support us with excellent responsiveness – for example, in handling tickets or configuring whitelists at the initial rollout stage, which is critical given the very large number of endpoints to protect. HarfangLab is also receptive to our feature requests. Following our feedback, their technical teams implemented remote shell capabilities and support for certain legacy operating systems.”

Head of the Cyber Defense Team and SOC Manager

Results

HarfangLab has enabled the administration to strengthen its security posture. It can now easily generate detailed workspace maps, build custom detection rules, and run automated jobs to investigate or block threats.

Using its remote shell feature, the platform is also valuable for troubleshooting issues that arise during the deployment of other solutions or software updates.

Additionally, the administration can more easily monitor Shadow IT and the use of external USB storage devices, and isolate endpoints when necessary.

“Users do not have administrator rights on their workstations, but we strive to strike the right balance between security requirements and the operational flexibility they need for their daily activities. For example, the use of external USB devices remains permitted while being monitored by HarfangLab, which allows us to detect and block suspicious behaviors such as attempts to communicate with malicious IP addresses or websites.

Furthermore, to improve our security posture against Shadow IT risks, HarfangLab’s EDR enables us to automatically generate a detailed map of the applications installed across our environment. We can thereby identify unauthorized software, block its execution, or – when the risk level justifies it – isolate the endpoints concerned. This capability also contributes to raising user awareness of cybersecurity issues when isolation is required.

Finally, thanks to the transparency of detection rules and the level of detail provided by the platform, we can precisely understand the origin of alerts and implement targeted remediation actions. The richness of the data collected also allows us to identify weak signals and efficiently trace back to the root cause of a security incident.”

Head of the Cyber Defense Team and SOC Manager

The administration continuously fine-tunes its detection rules to keep pace with evolving usage patterns and threats, pushing protection well beyond what was achievable with an antivirus solution alone.

“Beyond malicious files, user behaviors pose the primary security risks. We write a large number of Sigma rules ourselves to tailor them to our specific needs and move toward maximum, meaningful automation.”

Head of the Cyber Defense Team and SOC Manager

Try out our platform in your workspace