Just Launched Gruve PulseAI Platform, your private AI infrastructure, production-ready in under 2 weeks.PulseAI is live — private AI, ready in 2 weeks.

See PulseAI

Case study / Healthcare

County health system turns a modern Cisco security stack into a governed 24×7 SOC operation

Splunk ES, Cisco XDR and managed device operations stood up in under 90 days.

Under 90 days

Kickoff to steady-state SOC operations

217 MITRE-mapped detections

Splunk Enterprise Security use cases built, enabled and mapped to MITRE ATT&CK

160 incidents triaged

First full-quarter SOC activity, including 65 true positives actioned and 95 benign alerts closed

A modern security stack was generating signals faster than the operating model could absorb

The Challenge

A modern security stack was generating signals faster than the operating model could absorb

A large county health system had invested across firewall, identity, endpoint, email and cloud controls, but the operation behind those tools had not caught up to the environment they were protecting. Alerts from Cisco ASA and FTD, Cisco ISE, Azure AD, CrowdStrike, Zscaler and email security sources were landing without consistent 24×7 triage, normalization and response.

The stakes were bigger than alert volume. Public sector healthcare teams have to protect care delivery systems, identity, endpoints, email, cloud access and network infrastructure while maintaining continuity, compliance and auditability. Without a governed SOC motion, the health system risked leaving valuable telemetry trapped across tools, underusing Cisco XDR workflows, and asking internal teams to keep absorbing fragmented alert intake and manual device operations.

The constraint was operational, not just technical. The customer needed normalized telemetry, MITRE-aligned detections, weekly hunts, daily security advisories, managed Cisco device operations, escalation discipline and an executive governance rhythm that could make the existing security investment measurable.

Before this engagement, our security tools were in place, but the operation around them was fragmented. We now have 24×7 coverage, normalized telemetry, MITRE-aligned detections, weekly threat hunts, managed device operations and a clear escalation model. That changed the stack from a set of alerts into a disciplined security operation.
Security leader Security leader Large county health system

Why Gruve

Gruve connected Cisco security expertise to the managed operating model the customer needed

Gruve was selected to operationalize the stack as a managed security service, not just advise on the tooling. The differentiator was the ability to combine Cisco security specialization, Splunk Enterprise Security operations, detection engineering and managed device services into one follow-the-sun SOC motion.

That mattered because the customer did not need another layer of recommendations. They needed a staffed operating model with normalized telemetry, clear escalation, ITSM integration, daily advisories, monthly and quarterly business reviews, and joint governance with Cisco.

The Approach

Four steps turned distributed security telemetry into a managed SOC program

Step 1

Build the SOC foundation

Gruve established a 13-person tiered SOC operating model across India and the United States, with redundant site-to-site VPN access, role-based access controls and escalation paths mapped from L1 analyst to L3 and SOC admin.

Step 2

Normalize the telemetry layer

Gruve implemented a hybrid Splunk architecture using on-prem heavy forwarders for Cisco ASA and ISE syslog, cloud HEC and API integrations for Zscaler, Proofpoint, Abnormal Security, Azure AD and CrowdStrike, plus integrations across Cisco XDR, Secure Firewall, FMC, ISE, Duo and Secure Client NVM.

Step 3

Engineer MITRE-aligned detections

Gruve built and enabled 217 Splunk Enterprise Security use cases, each mapped to MITRE ATT&CK and engineered around Secure Firewall intrusion and EVE events, Secure Client NVM behavior, ISE change monitoring and Duo policy bypass.

Step 4

Turn response into an operating rhythm

Gruve formalized incident-handling workflows, weekly threat hunts, daily security advisories, monthly and quarterly business reviews with Cisco, and high-priority IOC blocking through Extended Dynamic Lists on Secure Firewall.

What the SOC covers now

24×7 SIEM and XDR monitoring, detection engineering, threat hunting, threat intelligence, incident triage, escalation governance and managed Cisco device services.

Where it runs

Follow-the-sun delivery from India and the United States over redundant VPN paths, with Cisco XDR, Secure Firewall, Firepower Management Center, ISE, Duo, Secure Client NVM and Splunk Cloud with Enterprise Security connected into the operating workflow.

The outcomes

The first full quarter turned the security stack into measurable operations

Speed to production

Steady-state SOC operations reached in under 90 days from kickoff, with a staffed 13-person SOC model, escalation paths, role-based access and governance cadence in place.

Baseline: Security telemetry was distributed across firewall, identity, endpoint, email and cloud tools without consistent 24×7 eyes-on-glass coverage.

Risk reduced

160 incidents triaged in the first full quarter, including 65 true positives actioned and 95 benign alerts closed. 11 threat hunts were delivered, all with true-positive findings.

Baseline: Alerts landed across sources without a repeatable triage, hunting and response workflow.

Control and sovereignty

100% of in-scope sources integrated into SIEM and XDR workflows, with ITSM integration, daily advisories, escalation matrices and monthly and quarterly business reviews established.

Baseline: Leadership had less visibility into whether the security stack was producing governed, auditable operating outcomes.

Cost per outcome

101 Cisco device incidents and change orders closed within SLA, reducing the internal burden of ad hoc firewall changes, IP blocking, upgrades and device operations.

Baseline: Internal teams would have continued absorbing fragmented alert intake and manual Cisco device operations without a dedicated managed service cadence.

The path not taken

Without the managed SOC, the customer would still own the tools without the operating rhythm

Without Gruve, the health system would have continued operating a modern Cisco and Splunk security environment without the staffing, detection engineering and response workflows needed to make it productive around the clock. Alerts would still land across firewall, identity, endpoint, email and cloud systems, but the customer would lack a consistent triage model to normalize, validate, escalate and act on those signals.

The old path also meant keeping more of the operational burden inside the customer’s team: fragmented onboarding, inconsistent normalization, underused Cisco XDR workflows, manual firewall changes and device operations handled without a dedicated managed service cadence. The stack would exist, but the organization would still be responsible for turning that stack into an always-on security operation.

What would have happened

The cost of the old path was a modern stack without measurable SOC outcomes

Staying on the old path meant the first full quarter would not have produced 217 MITRE-mapped detections, 160 triaged incidents, 11 threat hunts, 101 SLA-closed device incidents and change orders, or 100% in-scope source integration as one governed operating program. The customer would have kept the tools, but not the measurable rhythm that made them operational.

What's next

The same operating model can expand across detection coverage, hunting and executive reporting

The health system now has a managed SOC foundation that can keep expanding across detection coverage, threat hunting, device operations and executive reporting. The model gives the customer a repeatable way to convert Cisco security telemetry into governed security operations, with a cadence leadership can review and teams can act on.

Who else this applies to: public sector healthcare organizations and enterprise security teams with a broad Cisco security footprint, Splunk Enterprise Security, and a need to move from deployed tooling to measurable 24×7 operations.

Unlock your
true speed to scale

Accelerate what data and AI can do together.