• >
  • >
  • >
  • >
  • >

Case Studies.

Add Case Study

Our Case Study database tracks 22,657 case studies in the global enterprise technology ecosystem.
Filters allow you to explore case studies quickly and efficiently.

Download Excel
Filters
  • (61)
    • (31)
    • (30)
    • (21)
    • (16)
    • (10)
    • (6)
    • (3)
    • (1)
    • View all
  • (11)
    • (6)
    • (3)
    • (2)
  • (10)
    • (10)
  • (8)
    • (3)
    • (2)
    • (2)
    • (1)
    • (1)
    • View all
  • (5)
    • (4)
    • (1)
  • View all 9 Technologies
  • (22)
  • (11)
  • (8)
  • (7)
  • (6)
  • (5)
  • (5)
  • (5)
  • (4)
  • (4)
  • (3)
  • (3)
  • (2)
  • (2)
  • (2)
  • (1)
  • (1)
  • (1)
  • (1)
  • (1)
  • (1)
  • (1)
  • View all 22 Industries
  • (40)
  • (23)
  • (14)
  • (6)
  • (4)
  • (3)
  • (2)
  • (2)
  • (1)
  • (1)
  • View all 10 Functional Areas
  • (26)
  • (22)
  • (20)
  • (17)
  • (12)
  • (5)
  • (5)
  • (3)
  • (2)
  • (2)
  • (1)
  • (1)
  • (1)
  • (1)
  • (1)
  • (1)
  • (1)
  • (1)
  • (1)
  • View all 19 Use Cases
  • (48)
  • (39)
  • (26)
  • (11)
  • (7)
  • (4)
  • View all 6 Services
  • (69)
Selected Filters
69 case studies
Sort by:
Rapid7 Enables Qlik's Expanding Multi-Cloud Security and Compliance Strategy - Rapid7 Industrial IoT Case Study
Rapid7 Enables Qlik's Expanding Multi-Cloud Security and Compliance Strategy
Qlik, a leading data integration and analytics platform, was facing the challenge of expanding their cloud footprint while ensuring a cohesive, enterprise-level cloud security strategy. The company, which has grown significantly since its inception in 1993, was already using cloud services across various departments, including Research and Development (R&D) and Security teams. However, they recognized the need for holistic guidance to ensure the adequate protection of their cloud resources and data. As Qlik continued to grow as a Software as a Service (SaaS) technology provider, the use of cloud providers like Azure and Google Cloud Platform also expanded. The challenge was to maintain consistent control of their cloud environments and expand their cloud security best practices into these new environments.
Download PDF
Experity's Security Operations Scaling with Rapid7 Managed Services - Rapid7 Industrial IoT Case Study
Experity's Security Operations Scaling with Rapid7 Managed Services
Experity, a dynamic Health Information Technology company, was formed from the merger of the two largest urgent care Electronic Medical Records (EMR) companies in the country. The merger led to a rapid expansion of personnel, office locations, software, and services, creating unique challenges for the security team. The team was tasked with protecting the company from loss events of any kind, requiring business continuity and standardization. The small security team was overwhelmed with the task of managing security operations and building resilience in their security program. The company's growth also meant that the security team needed a platform to vet alerts from the increasing number of employees and contractors. The existing Managed Detection and Response (MDR) platform was inadequate as it only monitored network and server activity and not endpoint activity.
Download PDF
User Monitoring and Log Search: Rapid7 InsightIDR Delivers for UK Investment Bank Evercore - Rapid7 Industrial IoT Case Study
User Monitoring and Log Search: Rapid7 InsightIDR Delivers for UK Investment Bank Evercore
Neil Johnson, security manager at Evercore, needed a robust SIEM solution to handle user behavior monitoring and provide comprehensive log search capabilities for data analysis. The existing vulnerability management solution managed by a third party was not meeting their requirements, prompting the need for a more effective solution. The primary drivers for selecting InsightIDR included the ability to alert on anomalous user logins and provide detailed log search functionalities. The head of IT was particularly interested in monitoring user activities to ensure that employee credentials were not compromised.
Download PDF
Zoopla's Application Security Enhancement with Rapid7 InsightAppSec - Rapid7 Industrial IoT Case Study
Zoopla's Application Security Enhancement with Rapid7 InsightAppSec
Zoopla, a London-based real estate portal, faced a significant challenge in maintaining the security of its applications. With over 60 million visits a month to its flagship property website and application, the company had to ensure the utmost security for its users. The company's security team, led by Application Security Engineer Alikhan Uzakov, was responsible for guiding hundreds of Zoopla developers through the application security testing process. This included conducting training and helping developers embed security tooling into their processes to ensure the security testing of new features and products before their release. However, with only three staff members, the security team found it challenging to support the vast number of developers.
Download PDF
Securing a City: Corpus Christi Assesses, Prioritizes, and Monitors Threats - Rapid7 Industrial IoT Case Study
Securing a City: Corpus Christi Assesses, Prioritizes, and Monitors Threats
Bob Jones, the Information Security Manager for the City of Corpus Christi, Texas, faced the challenge of increasing security awareness across the organization and detecting and investigating attacks more easily. The city’s infrastructure is unique, akin to about 30 separate SMBs operating under a larger parent company, each with different requirements and compliance regulations. Bob's role was multifaceted, involving duties of an analyst, engineer, and penetration tester. He had to change an embedded culture and establish credibility with the CIO and IT Director. The primary challenge was the lack of visibility into assets on the Corpus Christi network, making it difficult to accurately qualify or quantify the level of risk. Bob needed to prioritize remediation to add value and avoid placing a greater burden on the business.
Download PDF
Rapid7 UserInsight Enables Acosta Sales & Marketing to Effectively Manage and Reduce User Risk for a Highly Mobile Workforce - Rapid7 Industrial IoT Case Study
Rapid7 UserInsight Enables Acosta Sales & Marketing to Effectively Manage and Reduce User Risk for a Highly Mobile Workforce
Acosta has a highly mobile, geographically distributed workforce. They needed an efficient way to gain actionable insight into user behavior, effectively identify when a user’s account may have been compromised, and shorten the time needed for investigation of security incidents. The company’s large remote workforce and high degree of travel create a complex security environment, necessitating vigilant detection of compromised credentials and unusual user behavior. The challenge is further compounded by the need to manage user risk in a distributed work environment where employees frequently perform in-store marketing evaluations using mobile devices.
Download PDF
Rapid7 InsightVM and InsightIDR Integrate to Drive 60% Time Savings and Ease Compliance for Energie Suedbayern - Rapid7 Industrial IoT Case Study
Rapid7 InsightVM and InsightIDR Integrate to Drive 60% Time Savings and Ease Compliance for Energie Suedbayern
One of Benjamin Nawrath’s biggest challenges is maintaining compliance with Germany’s IT Security Act (ITSG), which became law in 2015 but applies from July 2017 onward. The law requires all critical infrastructure providers to run an advanced cybersecurity program designed to ensure the availability, integrity, authenticity, and confidentiality of their IT infrastructure. It also demands that organizations regularly provide certification proving their compliance. Failure to do so could result in a fine of hundreds of thousands Euro. With a large and complex environment to monitor (including 2,000 IP addresses), limited IT staff resources, a growing compliance burden, and ever-determined hackers to keep at bay, Benjamin Nawrath needed robust technology solutions to help overcome these major challenges.
Download PDF
Rapid7 Metasploit Changes the Security Mindset at AutomationDirect - Rapid7 Industrial IoT Case Study
Rapid7 Metasploit Changes the Security Mindset at AutomationDirect
AutomationDirect, a proactive company, wanted to change the security mindset of its IT staff to stay ahead of the latest threats. The company needed to ensure that its IT security practices were robust enough to prevent both internal and external threats. Tim Lawrence, IT security analyst at AutomationDirect, recognized that administrators often prioritize getting systems up and running over security, which could lead to vulnerabilities. After attending the Black Hat convention in July 2010, Lawrence devised a long-term security strategy to address these issues. The goal was to anticipate and thwart potential hackers and eliminate internal oversights that could create inadvertent vulnerabilities. AutomationDirect was not under any immediate known security threat, but the IT security team needed to promote overall security best practices to the entire IT staff to prevent any possible worst-case scenarios.
Download PDF
Rapid7 Conducts a Penetration Test for Eyelock - Rapid7 Industrial IoT Case Study
Rapid7 Conducts a Penetration Test for Eyelock
Recently, Eyelock set out on a new project: making security airtight for logical access devices. They wanted an external team to take a very close look at their security architecture to implement a design that would allow for access to computers, websites, online banking, and the like. The RFP process kicked off, and the Eyelock team began evaluating various third-party vendors. The top three qualifications were extensive experience with embedded products, a high level of security expertise, and a strong overall reputation within the industry. Through a combination of these factors, Rapid7 won out.
Download PDF
Nexpose Enables a Small IT Staff to Manage a Large IT Infrastructure at Norwich University - Rapid7 Industrial IoT Case Study
Nexpose Enables a Small IT Staff to Manage a Large IT Infrastructure at Norwich University
With a constantly growing network environment, Norwich University’s IT department found it increasingly difficult to have a clear view into all network equipment and servers—and their vulnerabilities—while still only conducting manual scans.
Download PDF
Leveraging Dynamic Asset Groups in Rapid7 Nexpose - Rapid7 Industrial IoT Case Study
Leveraging Dynamic Asset Groups in Rapid7 Nexpose
Identifying how many servers and systems were affected by Heartbleed and other OpenSSL vulnerabilities without having to scan every server manually. PNM Resources needed a way to quickly and accurately identify vulnerabilities across their extensive network of servers and systems. The manual process of scanning each server individually was time-consuming and inefficient, especially during critical incidents like Heartbleed. The challenge was to find a solution that could provide rapid, accurate, and comprehensive visibility into the security status of their assets, enabling timely remediation and risk reduction.
Download PDF
Domino’s Pizza Enhances Security Operations with Rapid7's Detection and Response Workshop - Rapid7 Industrial IoT Case Study
Domino’s Pizza Enhances Security Operations with Rapid7's Detection and Response Workshop
Domino’s Pizza, the world's largest pizza company, relies heavily on technology for its online ordering and delivery services. The company's security operations center operates 24/7, and one of the biggest security challenges they face is phishing. Spear phishing, in particular, is a significant threat due to the craftiness of threat actors. The company also has a wide attack surface due to its domestic and international markets, making threat hunting a critical task. The company wanted to train its security operations center (SOC) analysts to think like attackers, as many analysts focus solely on detection and response and lack understanding of the tactics used by attackers.
Download PDF
InsightUBA on a University Campus - Rapid7 Industrial IoT Case Study
InsightUBA on a University Campus
The University of Texas at Dallas faced significant challenges in managing vulnerabilities across its campus network. The primary goal was to reduce vulnerabilities, detect and investigate security incidents faster, and manage threat exposure effectively. The security team needed a solution that could provide comprehensive visibility into information security risks, correlate user behavior with events, and improve incident response times. Additionally, they wanted to ensure that new technology purchases underwent thorough security assessments before going into production.
Download PDF
Rapid7 Nexpose Enhances PCI Compliance and Overall Network Security for Bob’s Stores - Rapid7 Industrial IoT Case Study
Rapid7 Nexpose Enhances PCI Compliance and Overall Network Security for Bob’s Stores
In 2008, Bob’s Stores faced the challenge of meeting new PCI compliance standards, particularly requirement 11 of the PCI DSS, which mandated regular tests of security systems and processes through internal and external scans. The IT department, led by Nick Sorgio, Assistant Vice President and technology manager, needed a vulnerability management system to meet these standards and protect customer data. The pressure to quickly comply with these new requirements was significant, and Bob’s Stores had no existing vulnerability management system in place. This made finding a suitable tool a top business priority. Bob’s Stores conducted a comprehensive assessment of various vulnerability management vendors, ultimately selecting Rapid7 due to its ability to identify vulnerabilities across networks, operating systems, databases, web applications, and a wide range of system platforms. Rapid7 Nexpose provided the necessary vulnerability assessment scanning and monitoring capabilities to meet PCI data security standards and offered sound vulnerability management practices as part of a comprehensive security program.
Download PDF
Nexpose Busts Security Violations at Redflex Traffic Systems - Rapid7 Industrial IoT Case Study
Nexpose Busts Security Violations at Redflex Traffic Systems
When Eric Nooden joined Redflex as Information Security Specialist, he found many out-of-date server operating systems. Because system stability was a priority with Redflex proprietary solutions, no one wanted to risk outages. The systems administrators were nervous about patching servers, fearing they might break them. The Redflex team had multilayer security in place, with firewalls, anti-virus software, and other technologies, but no dedicated security personnel to manage them. The undermanaged security posture was more reactive than proactive, and Nooden joined Redflex to change that. Additionally, because Redflex passes financial transactions to processing institutions, its systems must pass SAS 70 audits and comply with data protection standards such as Payment Card Industry Data Security Standard (PCI DSS) to avoid fines.
Download PDF
Italian University Gains a “Panorama” View of Overall Risk with Rapid7 InsightIDR - Rapid7 Industrial IoT Case Study
Italian University Gains a “Panorama” View of Overall Risk with Rapid7 InsightIDR
The University of Palermo faced significant challenges in managing and securing a vast number of assets with a small IT team. They needed a solution that could provide comprehensive visibility into vulnerabilities and overall risk, as well as streamline the process of querying and analyzing log data. The university also required a secure method for log retention to meet compliance requirements and sought flexible visibility across a range of operating systems, including Windows, Mac, Linux, iOS, Android, and Windows phones. Prior to adopting Rapid7's solutions, the university relied on Snort and AlienVault OSSIM for incident detection and response, which proved to be less efficient and intuitive.
Download PDF
Modine Manufacturing Enhances Cybersecurity with Rapid7’s Portfolio of Security Services and Solutions - Rapid7 Industrial IoT Case Study
Modine Manufacturing Enhances Cybersecurity with Rapid7’s Portfolio of Security Services and Solutions
Modine Manufacturing Company, a global leader in thermal management technology and solutions, faced a significant challenge in protecting its digital assets and those of its customers. As the business grew, so did the risks. The company's small security team found themselves monitoring thousands of event sources, up from a few hundred. They needed a partner that could help them improve various parts of their security program, addressing both proactive and reactive security needs. This required a strategic partner with multiple centers of product and service excellence.
Download PDF
Pearl Data Direct Leverages Rapid7 Insight Platform for Enhanced Security and Compliance - Rapid7 Industrial IoT Case Study
Pearl Data Direct Leverages Rapid7 Insight Platform for Enhanced Security and Compliance
Pearl Data Direct LLC (PDD), a FinTech company and subsidiary of LuLu Financial Holdings, faced two major security challenges. Firstly, as a company managing millions of dollars through their application, they were an attractive target for cyber attackers. Secondly, their business operates in the heavily regulated financial sector, requiring strict compliance with central bank regulations. The company needed to ensure the security of thousands of transactions flowing through their system every second, while also complying with stringent cybersecurity regulations. They also had to protect the personal identifiable information (PII) of their customers, which they were required to collect for compliance purposes. Furthermore, their core banking system was connected to a variety of banks, adding to the complexity of their security challenges.
Download PDF
Nexpose Identifies Vulnerabilities, Assists Remediation at LoneStar College System - Rapid7 Industrial IoT Case Study
Nexpose Identifies Vulnerabilities, Assists Remediation at LoneStar College System
Before 2008, LSCS supported separate campus IT operations at each of its five campuses with distributed IT support services. Then a new CIO joined the college, and within a month, the Lone Star College System had completely centralized its IT services to support a new vision. Associate Vice Chancellor of Technology Services Link Alander explains, “Through that process we had a series of changes and challenges that had to be achieved to improve reliability and security.” While the college had so far avoided any significant security incident or data breach, it understood the need for a proactive security posture that would maintain user trust. It also needed tools to help prove compliance with regulations such as the Family Educational Rights and Privacy Act (FERPA), the Health Insurance Portability and Accountability Act (HIPAA), and other regulations. The LSCS security initiatives are part of 11 strategic technology initiatives, incorporated into the overall LSCS strategic plan for 2009 through 2011. One of its primary security goals is to use ISO 27000 standards as a framework.
Download PDF
Vulnerability Management at Diebold: Automation, Prioritization, Remediation - Rapid7 Industrial IoT Case Study
Vulnerability Management at Diebold: Automation, Prioritization, Remediation
Diebold needed an effective threat exposure management solution that would offer scalability and visibility. Given the pivotal role vulnerability management plays at Diebold, selecting a vulnerability management solution was an important task which the team did not undertake lightly. A main priority for them was the effectiveness of the vulnerability scanner. Diebold needed accurate, up-to-date, real-time data. Scalability was also an important factor; being a global company, they needed the ability to reach around the world without adding administrative overhead.
Download PDF
Essentia Health Reduces Risk with Nexpose and Metasploit - Rapid7 Industrial IoT Case Study
Essentia Health Reduces Risk with Nexpose and Metasploit
Securing the Essentia Health network is a complex task due to its multi-billion dollar integrated health system that spans multiple states and roughly one hundred facilities in the Midwest. The network includes fifty thousand IPs, from facilities to medical device equipment. The security team must locate and resolve high-risk vulnerabilities to safeguard patient data and other critical information. Compliance with HIPAA, HITECH, and PCI DSS adds another layer of complexity. Despite compliance, security holes such as weak credentials and improper patches were prevalent. The team needed a solution to perform thorough testing against all active systems and demonstrate risk to secure necessary resources for a vulnerability management program.
Download PDF
Vulnerability Management assists with compliance for Hillsborough County - Rapid7 Industrial IoT Case Study
Vulnerability Management assists with compliance for Hillsborough County
Before Hillsborough County acquired a vulnerability management solution, ensuring that their over 250 servers were secure and compliant proved difficult for ITS’ team of three security engineers. The County’s process was to contract with outside vendors to run periodic vulnerability assessment scans. With new security requirements increasing the need for more frequent auditing, they needed an in-house solution. The County’s security engineers required detailed reports that identified vulnerabilities to be remedied before they could pose substantial risk to the network environment. To evaluate vulnerability management solutions, ITS defined a set of technical requirements against which to measure selected vulnerability assessment scanners. The desired solution would need the ability to perform stealth scans, schedule routine scans, support multiple platforms including Windows and Linux, scan multiple platforms, applications and devices, support unauthenticated and authenticated scans, scan all systems without installing an agent, perform incremental scans, and provide future support for wireless protocols.
Download PDF
MCPHS University Saves Time and Effort with Nexpose - Rapid7 Industrial IoT Case Study
MCPHS University Saves Time and Effort with Nexpose
When Allen Basey joined MCPHS University over two and a half years ago, he was tasked with developing new security procedures and policies, including comprehensive vulnerability scanning. As the sole person dedicated to maintaining security, he needed to improve the University's overall security posture without being overburdened. Initially, he opted for Tenable's Nessus due to its low cost, but found it required manual scans and lacked critical context for prioritizing vulnerabilities. This made it difficult to get IT support teams to take action, and researching how to patch vulnerabilities consumed valuable time, leading to crucial patches being neglected.
Download PDF
Permission Interactive Turns to Rapid7 for Help Enhancing its Security with Comprehensive Vulnerability Management - Rapid7 Industrial IoT Case Study
Permission Interactive Turns to Rapid7 for Help Enhancing its Security with Comprehensive Vulnerability Management
Permission Interactive, an e-commerce company handling sensitive customer information, faced challenges in meeting PCI compliance standards. Their existing McAfee vulnerability management solution was only helping them 'check the box' for PCI compliance without improving their overall security landscape. A full audit revealed significant gaps in security best practices and overall compliance, prompting the company to seek a more robust solution.
Download PDF
Weill Cornell Medical College Relies on Rapid7 Nexpose for a Secure Environment - Rapid7 Industrial IoT Case Study
Weill Cornell Medical College Relies on Rapid7 Nexpose for a Secure Environment
Weill Cornell Medical College, located separate from the main university campus, serves as an academic medical center requiring HIPAA compliance. They have complex IT security needs and needed a solution to prioritize and protect from threats as well as grow with the college.
Download PDF
WildTangent's Successful Implementation of Mobilisafe for BYOD Security - Rapid7 Industrial IoT Case Study
WildTangent's Successful Implementation of Mobilisafe for BYOD Security
WildTangent, an online games service company, faced significant security challenges due to its bring-your-own-device (BYOD) policy. The company had a highly mobile and geographically dispersed workforce, which necessitated the use of personal mobile devices for work purposes. While this approach increased productivity and employee satisfaction, it also introduced security risks. The initial mobile device management (MDM) solution implemented by WildTangent was difficult to configure, had a non-intuitive user interface, and required frequent manual updates. Additionally, not all features were available on every mobile platform, making it an inefficient solution for the company's needs.
Download PDF
Specialized Security Service, Inc. Discusses Their Strategic Partnership with Rapid7 - Rapid7 Industrial IoT Case Study
Specialized Security Service, Inc. Discusses Their Strategic Partnership with Rapid7
As a Managed Security Service Provider, S3 needs to offer clients a security portfolio with the best tools and provide great value, all while maintaining a trusting relationship with the vendor. With attackers becoming more sophisticated, IT environments growing increasingly complex, and a shortage of skilled cybersecurity professionals, it’s no wonder that businesses are increasingly turning to Managed Security Service Providers (MSSPs) to ensure their security program stays current with industry best practices. The MSSP relationship offers a cost-efficient way to mitigate risk, combat threats, and keep pace with compliance regulations.
Download PDF
US Naval Academy Alumni Association & Foundation Relies on Rapid7 UserInsight for Identifying Compromise and Risky User Behavior - Rapid7 Industrial IoT Case Study
US Naval Academy Alumni Association & Foundation Relies on Rapid7 UserInsight for Identifying Compromise and Risky User Behavior
In a non-profit organization, cost-effectiveness is essential. The USNA Alumni Association & Foundation needed to build a security architecture to protect personal information of alumni. Ken Kurz, the Director of Information Services, faced the challenge of managing an infrastructure that supports 70,000 living alumni without leveraging government resources. The primary concern was to ensure the security of personal information while operating within the constraints of a non-profit budget. Ken's extensive background in information assurance and high-level security engineering made him well-suited for the task, but the challenge remained significant due to the unique constraints of the non-profit sector.
Download PDF
Rapid7 Nexpose Meets Carnegie Mellon University’s Requirements for Vulnerability Management, Co-Development and Higher Education Expertise - Rapid7 Industrial IoT Case Study
Rapid7 Nexpose Meets Carnegie Mellon University’s Requirements for Vulnerability Management, Co-Development and Higher Education Expertise
Carnegie Mellon University needed a vulnerability management solution that would scan its assets broadly and offer centralized control for close monitoring and analysis of security threats, as well as the ability to create and export customized reports.
Download PDF
American Chemical Society Lauds Rapid7 Customer Support, Nexpose® Reporting Features - Rapid7 Industrial IoT Case Study
American Chemical Society Lauds Rapid7 Customer Support, Nexpose® Reporting Features
Shackerah, the primary user of Rapid7 Nexpose at the American Chemical Society (ACS), faced challenges in ensuring security holes were quickly plugged and handling PCI DSS compliance requirements. Initially using Qualys, the ACS team sought a new solution due to dissatisfaction with customer service. They needed a vulnerability management solution with robust reporting features, comprehensive vulnerability coverage, and excellent customer support.
Download PDF

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that AGP may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from AGP.
Submit

Thank you for your message!
We will contact you soon.