How California’s EDD Cut Security Response Time by 99% with Elastic Security
California’s Employment Development Department, which administers unemployment, disability, and paid family leave programs for millions of residents, deployed Elastic Security on AWS to unify cybersecurity monitoring across 3,000 servers and 850 billion records. AI-driven threat detection reduced mean time to response by 99% while enabling a 60-person security team to manage over 80,000 alerts per month.
Tools & Technologies
1AI Categories
Challenge
EDD’s 60-person security team managed over 80,000 monthly alerts across 14,000 endpoints and 850 billion records with no unified visibility — forcing analysts to jump between disconnected systems to investigate threats, slowing detection and leaving the benefit programs relied on by millions of Californians exposed to fraud and cyber risk.
Solution
EDD deployed Elastic Security on Elastic Cloud and AWS across 3,000 servers, unifying log ingestion and threat detection in a single SIEM with AI-driven Alert Discovery that automatically prioritizes critical threats and reduces mean time to response, supported by Elastic Consulting for model training and staff onboarding.
Full Story
California’s Employment Development Department runs the benefit programs that residents turn to during unemployment, illness, and family leave. The Department handles billions of data points across high-availability state systems, making it a significant target for fraud and cyber threats. Its 60-person security team, led by Chief Information Security Officer Douglas Leone, must simultaneously ensure that legitimate applicants can access support without friction while preventing bad actors from exploiting the same systems.
Access 442+ AI use cases, 407+ tools, and adoption signal rankings.