GovernmentSecurity Operations

How California’s EDD Cut Security Response Time by 99% with Elastic Security

California’s Employment Development Department, which administers unemployment, disability, and paid family leave programs for millions of residents, deployed Elastic Security on AWS to unify cybersecurity monitoring across 3,000 servers and 850 billion records. AI-driven threat detection reduced mean time to response by 99% while enabling a 60-person security team to manage over 80,000 alerts per month.

Outcomes

99%Reduction in mean time to response
850 billionRecords secured in Elastic
3,000Servers connected to Elastic
80,000+Monthly alerts managed

Tools & Technologies

1EC
Elastic Cloud
Managed cloud hosting for the Elastic Stack, enabling search, observability, and security workloads without infrastructure management.
2ES
Elastic Security
SIEM and security analytics platform for threat detection, investigation, and response at scale.

AI Categories

Challenge

EDD’s 60-person security team managed over 80,000 monthly alerts across 14,000 endpoints and 850 billion records with no unified visibility — forcing analysts to jump between disconnected systems to investigate threats, slowing detection and leaving the benefit programs relied on by millions of Californians exposed to fraud and cyber risk.

Solution

EDD deployed Elastic Security on Elastic Cloud and AWS across 3,000 servers, unifying log ingestion and threat detection in a single SIEM with AI-driven Alert Discovery that automatically prioritizes critical threats and reduces mean time to response, supported by Elastic Consulting for model training and staff onboarding.

Full Story

California’s Employment Development Department runs the benefit programs that residents turn to during unemployment, illness, and family leave. The Department handles billions of data points across high-availability state systems, making it a significant target for fraud and cyber threats. Its 60-person security team, led by Chief Information Security Officer Douglas Leone, must simultaneously ensure that legitimate applicants can access support without friction while preventing bad actors from exploiting the same systems.

Access 442+ AI use cases, 407+ tools, and adoption signal rankings.

Source

Similar Cases

1C
How CACI's DarkBlue Uses Elasticsearch and Claude to Accelerate Dark Web Criminal Investigations
CACI
Seconds per query regardless of data age or volumeCriminal investigation acceleration
2C
How Cypris Uses Elasticsearch to Power AI R&D Research Across 500 Million Data Points
Cypris
Weeks → 15 minutesResearch report generation time
3M
How ManTech Cut IT Tier 1 Support Workload by 50% with Moveworks AI
ManTech
50%IT Tier 1 FTE reduction
4NM
How New Mexico County Uses C3 AI to Boost Property Appraisal Accuracy by 50%
New Mexico County Assessor
+50 percentage pointsImprovement in model accuracy
5BL
How Bank Leumi Cuts Security Detection Time 60% with Elastic
Bank Leumi
-60%Log detection and analysis time
6ME
How Massachusetts Education Office Saves $1.5M Annually with Snowflake
Massachusetts Executive Office of Education
$1.5MAnnual cost savings from Oracle to Snowflake migration
7E
How ECI Uses Elastic to Protect 130 Financial Services Clients Against Cyber Threats
ECI
130 in 18 monthsClients onboarded on SIEM platform
8NH
How NYC Health + Hospitals Uses Snowflake to Cut Data Delivery from Days to Minutes
NYC Health + Hospitals
5 days → 5 minutesData delivery time for membership and claims data
9ME
How Massachusetts EOE Uses Snowflake to Save $1.5M Per Year
Massachusetts Executive Office of Education
$1.5 millionAnnual cost savings from Oracle migration
10TA
How Texas A&M System Cuts Incident Resolution by 99% with Elastic Security
Texas A&M University System
99%Incident resolution time reduction
See all use cases →