Read the Report — State of Applied AI →
GovernmentSecurity Operations

How California’s EDD Cut Security Response Time by 99% with Elastic Security

California’s Employment Development Department, which administers unemployment, disability, and paid family leave programs for millions of residents, deployed Elastic Security on AWS to unify cybersecurity monitoring across 3,000 servers and 850 billion records. AI-driven threat detection reduced mean time to response by 99% while enabling a 60-person security team to manage over 80,000 alerts per month.

Impact

99%

Reduction in mean time to response

850 billion

Records secured in Elastic

3,000

Servers connected to Elastic

80,000+

Monthly alerts managed

Challenge

EDD’s 60-person security team managed over 80,000 monthly alerts across 14,000 endpoints and 850 billion records with no unified visibility — forcing analysts to jump between disconnected systems to investigate threats, slowing detection and leaving the benefit programs relied on by millions of Californians exposed to fraud and cyber risk.

Solution

EDD deployed Elastic Security on Elastic Cloud and AWS across 3,000 servers, unifying log ingestion and threat detection in a single SIEM with AI-driven Alert Discovery that automatically prioritizes critical threats and reduces mean time to response, supported by Elastic Consulting for model training and staff onboarding.

Tools & Technologies

What Leaders Say

Moving to Elastic Cloud on AWS speeds up performance for the security team, eliminating downtime and providing faster search and analysis of data. EDD currently has over 850 billion records in Elastic, and even as data volumes grow, performance remains strong.

Douglas Leone, Chief Information Security Officer, California Employment Development Department

Often SIEMs can be seen as a black box, but Elastic provides more clarity by integrating into lines-of-business data. Elastic allows us to ingest vast amounts of data in a unique way and apply data science to make intelligent decisions about security.

Douglas Leone, Chief Information Security Officer, California Employment Development Department

Elastic elevated the value of a SIEM for us. Teams trust us for insights into cybersecurity detection and anomalous activity, helping us become a value add for lines of business.

Douglas Leone, Chief Information Security Officer, California Employment Development Department
Get the full context.

Sign up to read complete case studies, access detailed metrics, and unlock all use cases.

Full Story

California’s Employment Development Department runs the benefit programs that residents turn to during unemployment, illness, and family leave. The Department handles billions of data points across high-availability state systems, making it a significant target for fraud and cyber threats. Its 60-person security team, led by Chief Information Security Officer Douglas Leone, must simultaneously ensure that legitimate applicants can access support without friction while preventing bad actors from exploiting the same systems.

Before deploying Elastic Security, the Department lacked unified visibility across its complex, multi-program IT environment. Security investigations required analysts to jump between disconnected systems, slowing down threat detection and response. With 14,000 endpoints, 10,000 employees, and over 80,000 alerts arriving per month, the security team struggled to distinguish genuine threats from noise efficiently — a problem that had real consequences for the millions of Californians depending on uninterrupted access to critical services.

EDD deployed Elastic Security on Elastic Cloud and AWS as the backbone of its SIEM operation, integrating it across nearly 3,000 servers spanning all programs and lines of business. Elastic collects and normalizes system and transactional data from across the environment into a single location, giving analysts a unified view of activity, traffic, and alerts through advanced dashboards that each line of business can customize. AI-powered features including Attack Discovery automatically prioritize cybersecurity alerts by detecting unknown threats and surfacing the most critical ones, allowing the team to focus attention where it matters most rather than triaging manually.

The impact on the security team’s effectiveness was immediate and significant. Mean time to response dropped by 99% as AI-assisted alert prioritization eliminated the need to comb through noise manually. Elastic’s speed in searching across 850 billion records — including six months of log history — gave investigators the reach they needed without performance degradation. Teams across EDD began requesting customized Elastic dashboards of their own, reflecting how deeply the platform embedded itself into operations beyond the core security function.

EDD is continuing to expand its Elastic footprint, with plans to add application performance monitoring to extend the same observability to its business applications. Elastic Consulting has been instrumental in onboarding new staff, training ML and AI models, and developing deep-freeze storage strategies to meet strict data retention requirements. Leone describes the relationship as central to the Department’s path toward self-reliance: a public agency protecting its most vulnerable residents by making AI-driven security a permanent operational capability.

Similar Cases

NM
New Mexico County Assessor
+50 percentage points
improvement in model accuracy

New Mexico's largest county by population deployed C3 AI Property Appraisal to modernize its commercial property valuation process. By unifying millions of data points and applying AI-based Automated Valuation Models, the county achieved a 50-percentage-point improvement in model accuracy and a 3x gain in appraisal equity — all within weeks of going live.

GovernmentCAC3 AI Property AppraisalCAC3 AI Platform
M
ManTech
50%
it tier 1 fte reduction

ManTech deployed Moveworks' AI assistant to 8,000 federal government employees, cutting Tier 1 IT workload by 50%, reducing call center volume by 68%, and achieving 93% customer satisfaction in year one.

GovernmentMMoveworksASAgent Studio
SD
Seattle Department of Transportation (SDOT)
90%+
reduction in collision analysis time

Seattle Department of Transportation deployed C3 AI Safety Analysis to power its Vision Zero initiative, unifying data from 7,800+ intersections across 4,000 miles of roadway. The AI-driven platform replaced manual, siloed workflows with machine learning-based collision severity analysis and interactive dashboards. Within 12 weeks, SDOT achieved a 90%+ reduction in collision analysis time, enabling near real-time identification of safety hotspots.

GovernmentMLMachine Learning-Based Collision Severity Factor AnalysisCAC3 AI Platform
GC
Garden City Public Schools
$150,000+
annual cost savings

Garden City Public Schools in Kansas operates one of the state's largest student transportation fleets, transporting more than 2,000 students daily across 900+ square miles. After deploying the Samsara Connected Operations Platform with AI dash cams and connected maintenance tools, the district achieved over $150,000 in annual savings, cut maintenance costs by 66%, and reduced preventable accidents by 87% in just 18 months. The transformation replaced paper-based inspection workflows and unreliable DVR cameras with a single cloud-connected platform.

GovernmentEducationSCSamsara Connected Operations PlatformSASamsara AI Dash Cams
CO
City of Poughkeepsie
25%
accident reduction

The City of Poughkeepsie’s Public Works Department manages over 100 vehicles serving 30,000 residents in New York. After deploying Samsara AI Dash Cams, Asset Tag, and Fleet Telematics across its fleet, the City reduced accidents by 25% within four months and gained real-time visibility into $200,000 in specialized equipment—while cutting repair costs from $10,000 to $2,000 per incident through in-house maintenance.

GovernmentSFSamsara Fleet TelematicsSASamsara Asset Tag
BL
Bank Leumi
-60%
log detection and analysis time

Bank Leumi, Israel’s leading bank with more than 7,000 employees and $195 billion in assets, replaced its aging SIEM with Elastic Security to gain unified visibility across a cloud-and-on-premises infrastructure generating vast volumes of semi-structured data. By deploying Elastic Security alongside Kibana dashboards and MITRE ATT&CK-aligned detection rules, the bank cut log detection and analysis time by 60%, reduced security incident resolution time by 50%, and lowered total cost of ownership by 40%.

Financial ServicesESElastic SecurityEElasticsearch
TA
Texas A&M University System
99%
incident resolution time reduction

The Texas A&M University System is one of the largest higher education systems in the United States, encompassing 11 universities, 8 state agencies, and a statewide emergency management network that collectively educates over 153,000 students while defending against state-sponsored hackers and cybercriminals. Faced with a massive threat surface spanning 25,000 endpoints, the system’s cybersecurity team deployed Elastic Security for Endpoint, using its machine learning capabilities and automation layer to unify data from hundreds of sources into a single interface. The result: incident resolution time dropped from months to two hours—a 99% reduction—while automated documentation saved over 100 analyst hours per month.

EducationESElastic Security
T(
THG (The Hut Group)
60%
reduction in mean time to respond (mttr)

THG (formerly The Hut Group) is a UK-based ecommerce retail company with revenues exceeding £2 billion, selling its own-brand and third-party cosmetics, dietary supplements, and luxury goods online while also providing ecommerce infrastructure to third parties through its Ingenuity division. Facing a rapidly expanding threat surface as it grew through acquisitions and added SaaS platforms, THG deployed Elastic Security as its unified SIEM, using machine learning capabilities to surface novel attack vectors and automation to eliminate manual triage overhead. The outcome: mean time to respond to security events dropped by 60%, first-line triage burden fell from 90% to 50% of analyst time, and physical storage costs declined by 60% through intelligent data tiering.

RetailESElastic Security