en flag +1 214 306 68 37
QRadar SIEM and SOAR to Strengthen Threat Visibility and Incident Response for a Major Telecom Provider

QRadar SIEM and SOAR to Strengthen Threat Visibility and Incident Response for a Major Telecom Provider

Industry
Telecommunications
Technologies
QRadar

About Our Client

The Client is a leading IT services provider with a large base of enterprise customers across the Levant region. Its portfolio covers business transformation, enterprise infrastructure, collaboration, and cybersecurity solutions.

Specialized QRadar Services for a Complex Telecom Environment

The Client has partnered with ScienceSoft on IBM QRadar-related cybersecurity projects for several years. As part of this cooperation, the Client engages ScienceSoft to provide QRadar consulting, optimization, integration, automation, and training services to its enterprise customers.

One of the Client’s cybersecurity customers, a major MENA telecommunications provider with around 300 locations, wanted to improve its security monitoring, incident detection, and incident response processes. The telecom company operated a distributed, multi-regional QRadar SIEM environment and needed to optimize and upgrade it. The company also planned to implement QRadar SOAR, integrate it with the QRadar SIEM and other systems, and align the entire cybersecurity solution with its PCI DSS and ISO/IEC 27001 compliance program.

To meet the telecom company’s requirements and tackle the challenges of the distributed, high-availability QRadar SIEM configuration, the Client turned to its long-term partner, ScienceSoft.

QRadar Assessment, Optimization, and Integration

ScienceSoft assigned two senior consultants to deliver IBM QRadar SIEM and SOAR projects for the telecom provider: a senior SIEM/SOAR consultant and a senior SIEM consultant. ScienceSoft’s consultants communicated directly with the telecom provider’s SOC team to accelerate technical discovery, delivery, troubleshooting, and knowledge transfer.

QRadar SIEM optimization and fine-tuning

ScienceSoft started with a health check and assessment of the existing QRadar SIEM environment. The telecom provider’s QRadar SIEM was a distributed, multi-regional, high-availability on-premises deployment with around 20 hosts, including Event Processors, Flow Processors, Event Collectors, Flow Collectors, App Hosts, QNI (QRadar Network Insights), and Incident Forensics appliances.

After the assessment, the team optimized and fine-tuned the existing SIEM configuration while keeping the overall QRadar architecture unchanged. This part of the project included aligning the environment with the telecom provider’s security and compliance requirements for high availability, data retention, and role-based access control, as well as improving the quality and efficiency of security monitoring. To improve the SIEM system’s performance, detection quality, and operational efficiency, ScienceSoft:

  • Connected numerous new log sources, including sources not supported out of the box.
  • Configured custom DSMs to enable QRadar SIEM to correctly process and normalize logs from non-standard sources.
  • Optimized event normalization and correlation rules.
  • Created custom detection rules tailored to the telecom provider’s log sources and security monitoring requirements.
  • Fine-tuned existing and new out-of-the-box use cases (threat detection scenarios).

As the existing QRadar SIEM had a customized high-availability configuration, ScienceSoft coordinated the upgrades with IBM technical teams to preserve system availability and data integrity across the distributed environment.

QRadar SOAR implementation and integration

In addition to SIEM optimization, ScienceSoft set up QRadar SOAR from scratch. The team developed SIEM/SOAR processes and playbooks, designed automation pipelines, and aligned SIEM-SOAR incident escalations with the telecom provider’s risk-based prioritization model.

ScienceSoft enhanced QRadar SIEM and SOAR functionality with IBM-provided and proprietary extensions like QLEAN, a QRadar health check and tuning app used to support deeper SIEM assessment and optimization.

The team also integrated QRadar SIEM and SOAR with:

  • The telecom provider’s in-house systems for richer incident context.
  • Active Directory, firewalls, identity and access management systems, and other response-related systems to enable automatic and manual remediation.
  • The email system to support incident creation, notifications, investigation tracking, and management.

Knowledge transfer and operational support

ScienceSoft’s consultants prepared integration documentation, task-specific how-to materials, best practice notes, and operational guidance to support the telecom company’s SOC team in using and maintaining the updated QRadar SIEM and SOAR environment.

Throughout the engagement, ScienceSoft also provided hands-on QRadar SIEM and SOAR support and troubleshooting, helping the telecom provider’s SOC team address issues related to upgrades, integrations, and fine-tuning.

ScienceSoft delivered a series of QRadar Advanced Training sessions. These sessions helped the telecom company’s SOC specialists deepen their QRadar SIEM and SOAR expertise and use the upgraded environment more effectively.

The engagement encompassing several consecutive QRadar-related initiatives has continued for three years.

Custom QRadar SIEM and SOAR for Enhanced Threat Visibility and Incident Response

By partnering with ScienceSoft, the Client, a leading IT services provider in the Levant region, gained QRadar expertise to support one of its cybersecurity customers, a major MENA telecom provider. By bringing in ScienceSoft’s QRadar consultants, the Client gained access to advanced SIEM expertise without expanding its internal delivery team or increasing management overhead. Throughout the three-year engagement, ScienceSoft worked autonomously with the telecom company’s SOC team and IBM’s technical specialists, helping the Client maintain smooth service delivery.

For the telecom company, ScienceSoft’s work brought the following results:

  • Stronger security visibility across the distributed telecom infrastructure due to optimized threat detection scenarios and new log source integrations.
  • More efficient SOC operations thanks to reduced alert noise, better-tuned event normalization and correlation rules, and clearer incident prioritization.
  • Improved incident response management enabled by QRadar SOAR, automated workflows, enriched incident context, and integrations with key internal systems.
  • Improved alignment of the SIEM environment with security and compliance requirements for high availability, data retention, and role-based access control.
  • Greater self-sufficiency of the internal SOC thanks to SIEM/SOAR playbooks, integration documentation, how-to materials, operational guidance, and QRadar Advanced Training.

Technologies and Tools

IBM QRadar SIEM, IBM QRadar SOAR, IBM QRadar AppHost, IBM QNI (QRadar Network Insights), IBM QRadar Forensics, QLEAN, Active Directory, bash, Python, HTML, JavaScript.

Have a question for our team or need help with your project?

Our team is ready to provide client references, estimate your project, or answer any other question related to your IT initiative.

Drag and drop or to upload your file(s)

?

Max file size 10MB, up to 5 files and 20MB total

Supported formats:

doc, docx, xls, xlsx, ppt, pptx, pps, ppsx, odp, jpeg, jpg, png, psd, webp, svg, mp3, mp4, webm, odt, ods, pdf, rtf, txt, csv, log

Preferred way of communication: