“Having another layer of expertise – people whose job is security, who have a true breadth of knowledge and experience – is valuable for us. As we have grown over the last four years, we’ve found that Fortra’s Alert Logic has scaled with us to provide benefits we may not have been able to realize on our own with an organization of our size.”
~ Scott Strait / Chief Technology Officer and Co-Founder, RetireOne
RetireOne is a leading independent platform for the fiduciary annuity and insurance marketplace for registered investment advisors (RIAs) and their clients. A high-growth technology firm in business since 2011, RetireOne provides more than 1,000 RIAs and their clients valuable retirement solutions that are simple to use, easy to understand, and delivered with outstanding service. With more than $1.4 billion of retirement savings and income investments, RetireOne is growing in its mission to revolutionize access to low-cost, innovative insurance solutions that empower investors to retire with confidence.
Operating in a highly regulated industry and with a need to secure customers’ sensitive data, RetireOne knew they needed to demonstrate the strength of their security to customers and find an external partner who could provide 24/7 protection using comprehensive, seamless technology.
Challenge
“As a smaller company, we don’t have the scale that would allow us to have a large, in-house security team nor be able to staff a security desk 24/7,” explained Scott Strait, Chief Technology Officer and Co-Founder of RetireOne. “I take security seriously because it is the right thing to do for the investors who trust us with their data.”
As RetireOne has access to a great deal of personally identifiable information, keeping this data secure is key to their mission as well as meeting all compliance requirements.
RetireOne’s infrastructure is cloud-based. “In the past, we relied on the security tools and alerts built in our vendor’s products with review by our staff. We realized we needed one place that pulls the data in from all our applications, has all the alerts in one place, and would give us a comprehensive view 24/7,” said Strait.
Several service providers’ solutions were evaluated but RetireOne realized Fortra’s Alert Logic Managed Detection and Response (MDR) fit their needs best. “There were several deciding factors that led us to go with Alert Logic including ease of use, comprehensiveness of the MDR solution, cost competitiveness, and the systems and organization controls certification that helps in both security and compliance,” said Strait.
“Fortra’s Alert Logic has kept us safe by monitoring, spotlighting the latest threats, and identifying opportunities for improving our security.”
~ Scott Strait / Chief Technology Officer and Co-Founder, RetireOne
Solution
Alert Logic’s MDR solution integrated seamlessly with RetireOne’s Microsoft Azure environment. They now are confident they have around-the-clock threat detection and security expertise. “Our security posture certainly has improved with the vulnerabilities Alert Logic identified, looking for things we didn’t even know to look for,” said Strait. “Having another layer of expertise – people whose job is security, who have true breadth of knowledge and experience – is valuable for us. As we have grown over the last four years, we’ve found that Fortra’s Alert Logic has scaled with us to provide benefits we may not have been able to realize on our own with an organization of our size. Alert Logic has kept us safe by monitoring, spotlighting the latest threats, and identifying opportunities for improving our security.”
One of the features Strait uses regularly with Alert Logic MDR is the dashboard which provides a visual representation of their security environment. “We review the dashboard daily as we can now stay on top of any vulnerabilities that are identified and push patches that are needed,” said Strait. “The dashboard is practical, useful, and points us in the right direction with a user interface and experience that works well. We’ve come to depend on Alert Logic’s timely notification of new threats in the broader internet and how to proactively protect ourselves against them. Now, we look at what’s happening in the industry where people are having problems because they forgot to do a patch or missed something. We feel more secure knowing we’ll get a reminder from Alert Logic on those kind-of things so we don’t fall behind.”
With Alert Logic, regulatory compliance is not as challenging for as it had been before the partnership began. “Without Alert Logic, it would be hard for me to sign off on our Financial Industry Regulatory Authority (FINRA) reports,” explained Strait. “It’s also easier now to meet our carrier and business partner contractual requirements knowing I have Alert Logic doing what needs to be done.” Whether it’s interacting with the security operations center (SOC) team, reviewing recommendations in the dashboard, or implementing a patch, RetireOne has achieved many of its predetermined security outcomes with Alert Logic MDR. “We rely on Alert Logic’s expertise and their continual monitoring of our network and systems. We appreciate that they are always on the job.”
Summary
RetireOne and Alert Logic have worked together for four years and Strait strongly recommends Fortra’s Alert Logic MDR to anyone looking for an external managed security solution. “Alert Logic has worked so well for us when you combine the value of the service with the price. I know Alert Logic is continuously investing in the platform and raising the level of your performance. I don’t believe that small- or medium-sized companies have the right expertise around security to be able to keep their environments secure as they would with a partner like Alert Logic.”