CiberseguridadOperaciones de Seguridad

Cómo ECI Usa Elastic para Proteger a 130 Clientes de Servicios Financieros contra Ciberamenazas

ECI (antes Eze Castle Integration), proveedor de servicios de seguridad gestionada para empresas financieras con más de 3 billones de dólares en activos bajo gestión, construyó su plataforma SIEM sobre Elastic para ingestar y analizar eventos de seguridad en su base de clientes. La plataforma ingesta más de 2.000 millones de eventos al día, permite despliegues de nuevos clientes en dos semanas o menos, y ayudó a ECI a incorporar 130 clientes en 18 meses.

Impacto

130 in 18 months

Clientes incorporados en la plataforma SIEM

2B+

Eventos de seguridad ingestados diariamente

≤2 weeks

Tiempo de despliegue para nuevos clientes

Desafío

Los equipos de seguridad de ECI gestionaban sistemas de registro separados para cada cliente en diferentes formatos, creando silos de datos que ralentizaban la detección de amenazas y dificultaban garantizar la retención de registros para el cumplimiento normativo financiero.

Solución

ECI construyó su servicio SIEM gestionado sobre Elastic Cloud Enterprise, usando Elasticsearch para la ingestión y búsqueda de registros, Kibana para la visibilidad unificada de amenazas y la investigación de incidentes, y Elastic Security para la inteligencia de amenazas.

Herramientas y tecnologías

Lo que dicen los líderes

Lo que más me preocupaba era el registro de eventos y la seguridad en nuestros propios sistemas. Si podíamos resolver eso, entonces podríamos ofrecerlo como producto para ayudar a los clientes a proteger sus sistemas y hacer el proceso de cumplimiento más eficiente.

Kamyar Kojouri, Director de Operaciones de Seguridad, ECI

Supongamos que hay una importante brecha de seguridad que afecta a varias organizaciones y se publica en la prensa. Con Elastic podemos buscar rápidamente todos los datos relevantes de nuestros clientes SIEM y asegurarles que no están afectados o mantenerlos protegidos si están bajo ataque.

Kamyar Kojouri, Director de Operaciones de Seguridad, ECI

Trabajar con Elastic en una palabra, ¿recompensante. La tecnología funciona bien, el soporte es excelente y es emocionante trabajar con software que está a la vanguardia de la ciberseguridad.

Kamyar Kojouri, Director de Operaciones de Seguridad, ECI
Entiende todo el contexto.

Regístrate para leer casos de estudio completos, acceder a métricas detalladas y recibir todos los reportes.

Historia completa

ECI serves financial services organizations across the globe as a managed services provider, handling IT infrastructure, cybersecurity, and business transformation for clients who collectively oversee more than $3 trillion in assets under management. For these clients—hedge funds, asset managers, and financial firms—security isn’t a compliance checkbox; it’s a business-critical requirement where a breach or audit failure has direct financial and reputational consequences.

Before building its unified SIEM offering, ECI’s internal security had fragmented across teams. Each department managed its own event logs in different formats for different clients, creating data silos that made threat detection slow and log retention for regulatory compliance difficult to guarantee. Kamyar Kojouri, Director of Security Operations, identified the core problem: event logging was becoming unmanageable as the client base grew, and the patchwork approach couldn’t scale.

ECI’s engineering team evaluated Elasticsearch and assembled a proof of concept in just a few days—a complete cluster with agent deployment, log ingestion, and dashboards. An Elastic engineer worked on-site with the team for a week to configure the production system. Elastic Cloud Enterprise became the deployment backbone, enabling ECI to add new clients quickly with consistent configuration. Kibana provides a “single pane of glass” for security alerts, incident investigation, and threat hunting. Elastic Security transforms event feeds into actionable threat intelligence, and cross-cluster search lets ECI’s Security Operations Center run threat hunting queries across all client clusters from a single node—a critical capability for responding to widely reported security incidents across many clients simultaneously.

The results validated the architecture. ECI onboarded 130 clients in 18 months. The platform now ingests more than 2 billion events per day across client environments spanning ECI Cloud, Microsoft Azure, and on-premises systems. New clients are operational in two weeks or less. When major hacking incidents make the news, ECI can immediately search all client SIEM data to confirm whether any client is affected and respond proactively.

Looking ahead, ECI is evaluating real-time threat response automation using machine learning, XDR (eXtended Detection and Response) capabilities for unified endpoint and SIEM security, and a single data ingestion pipeline to further consolidate client environments. The Elastic platform’s scalability has made cybersecurity one of ECI’s fastest-growing service lines.

Casos similares

C
CACI
Seconds per query regardless of data age or volume
criminal investigation acceleration

CACI's DarkBlue Intelligence Suite is a cloud-based platform that enables national security agencies, law enforcement, and intelligence teams to search and analyze dark web and open-source intelligence (OSINT) data to identify and deanonymize criminals. Built on Elasticsearch and Elastic Observability, DarkBlue's newest feature, CluesAI, harnesses Anthropic Claude LLMs via AWS Bedrock to generate automated intelligence reports that connect criminal personas across the dark web in seconds.

GovernmentCybersecurityABAmazon BedrockEElasticsearch
B
BigID
120x
query speed improvement

BigID, a data security, privacy, compliance, and AI data management platform founded in 2016, deployed Elasticsearch on Elastic Cloud and AWS to overcome severe query performance degradation as its customer data volumes grew. By migrating its core data-driven modules to Elasticsearch, BigID cut query times from 20 minutes to seconds — a 120x speedup — eliminated all query timeouts on search, dashboard, and reporting modules, and built a foundation capable of handling billions of records with complex filtering and aggregation.

CybersecurityEElasticsearch
C
Cogent
97% faster
vulnerability resolution speed

Cogent built an AI-powered cybersecurity platform with Claude as the reasoning layer, reducing critical vulnerability exposure from days/weeks to minutes — a 97% reduction — while reclaiming 40+ hours monthly from manual reporting.

CybersecurityCAClaude API
T
Trellix
Days → minutes
log parsing time

Trellix, a global cybersecurity firm serving 40,000+ enterprise customers, built Sidekick — an internal agentic platform powered by LangGraph and LangSmith — to automate log parsing and security integration development. What previously took engineers 2–3 days per request now takes minutes, and plugin development that spanned multiple days now completes in a single afternoon.

CybersecurityLLangSmithLLangGraph
S
Stairwell
40,000+ characters
security data processed per claude request

Stairwell, a cybersecurity company, integrated Claude into its Maleval threat detection platform to summarize complex security findings for analysts. Claude's large context window allows it to process 40,000+ character API responses in a single pass, converting dense technical data into clear, actionable insights with minimal prompt engineering.

CybersecurityTechnologyCClaude
BL
Bank Leumi
-60%
log detection and analysis time

Bank Leumi, Israel’s leading bank with more than 7,000 employees and $195 billion in assets, replaced its aging SIEM with Elastic Security to gain unified visibility across a cloud-and-on-premises infrastructure generating vast volumes of semi-structured data. By deploying Elastic Security alongside Kibana dashboards and MITRE ATT&CK-aligned detection rules, the bank cut log detection and analysis time by 60%, reduced security incident resolution time by 50%, and lowered total cost of ownership by 40%.

Financial ServicesESElastic SecurityEElasticsearch
L
Lusha
300%
increase in outbound leads

Lusha is a B2B sales intelligence platform with 1.5 million users and a database of over 200 million business contacts. By deploying Elasticsearch as both a full-text search engine and a vector database for AI-powered lead recommendations, Lusha helps customers generate 300% more leads, achieve conversion rates up to 10x higher, and realize return on investment of up to 1,000%.

TechnologyEElasticsearch
D
Doctolib
50%
reduction in false positives

Doctolib, Europe’s leading e-health platform connecting 90 million patients with 400,000 healthcare professionals, replaced an outsourced OpenSearch-based SOC with an in-house security operations center built on Elastic Security. The migration cut false positives by 50%, extended data retention from one month to one year, and enabled Doctolib to manage 12 times more log data while reducing cost per terabyte by 83%.

HealthcareESElastic Security