1 July 2026

Building a Foundation for Risk

Case studies

How Apto Solutions helped a global fintech move from ad hoc security monitoring to a structured, risk-based approach — with a clear line of sight from business assets to detections. 

 

The Situation 

The customer is a major global fintech and financial services company, processing payments and financial transactions across multiple markets. Operating under the obligations of PCI DSS 4.0 and other regulatory requirements, the Customer had invested in Splunk Enterprise Security as the platform at the heart of its security operations. 

But the potential of that investment was not being realised. Despite ingesting a large volume of log data daily, the majority of it — with the exception of Microsoft 365 logs — was not being actively used for detection or investigation. There was no structured process to guide what the security team should be monitoring for, no operational model defining how alerts should be handled, and no clear link between the organisation’s key assets, the threats they faced, and the detections in place to catch them. 

The result was a security function spending resources on data it could not use, approaching its ingest and storage limits, and without a framework for prioritising its efforts against what mattered most to the business. 

 

The Challenge 

The security team in this business faced a set of interconnected challenges that were compounding over time: 

  • No risk management lifecycle: security monitoring was not grounded in a structured assessment of business risk, meaning detection priorities had not been systematically derived from the organisation’s actual threat exposure. 
  • Underutilised log data: the vast majority of ingested logs were not mapped to any active use case, consuming ingest capacity and pushing archived storage toward its limits without contributing to detection coverage. 
  • No operational model: there was no documented process for how the security team should respond when alerts fired — creating uncertainty and inconsistency in how incidents were handled. 
  • Limited Splunk ES utilisation: the full capability of Splunk Enterprise Security — including Risk-Based Alerting (RBA) and Analytical Stories — was not being leveraged by the internal team. 
  • Visibility gaps: the SOC’s XSOAR platform was not mirrored into Splunk ES, leaving security incident data siloed and limiting end-to-end visibility across the response workflow. 

 

The Apto Approach 

Apto delivered a structured engagement across three complementary workstreams, designed both to address immediate gaps and to leave the team with the tools and knowledge to sustain the improvement independently. 

Risk Management Lifecycle Framework 

Apto facilitated a Risk Management Lifecycle (RML) workshop with Customer, establishing the methodology and tooling to systematically identify business risk and translate it into actionable security controls. Anchored to PCI DSS 4.0 as a regulatory reference point, the engagement built: 

  • An asset and service inventory, mapping key assets and the business impact of their loss or compromise — from cardholder data environments to third-party provider dependencies. 
  • A risk register, with each risk scored by probability and impact (pre- and post-mitigation), defined ownership, and estimated completion timelines. 
  • A threat register and threat modelling exercise, derived from the risk register and drawing on frameworks such as MITRE ATT&CK to enumerate credible attack vectors against each identified risk. 
  • A mitigation framework, distinguishing between SIEM-based detections and policy or process controls — each with defined evidence requirements to support compliance. 

The workshop materials and scoring framework were designed to be repeatable, enabling the Customer to continue the exercise internally across additional asset scopes as its security programme matures. 

Operational Model Workshop 

Apto facilitated a structured operational modelling session with Customer stakeholders, working through the end-to-end response process for a selected security scenario. The session established a shared understanding of what an operational model is, the steps required to build one, and produced a fully worked example for Notable Event Monitoring. 

The workshop deck, materials, and worked example were handed over in full — enabling Customer to replicate the exercise internally across its remaining security workflows and Splunk detections without requiring further Aptoinvolvement. 

Log and Data Review 

Apto reviewed the Customer’s current log ingestion posture and surfaced findings through a Qualys-integrated vulnerability dashboard. The review identified a significant volume of data being ingested with no corresponding detection use cases — contributing directly to the pressure on daily ingest and archived storage limits. 

The findings provided a clear basis for a data discovery exercise to map all ingested sources to active use cases, identify redundant data flows, and bring ingest volumes under control — with corresponding benefit to both cost and platform performance. 

 

Outcomes and Value Delivered 

Across the three workstreams, Apto helped this customer move from an ad hoc security monitoring posture to one with a structured foundation and a clear path for ongoing development. 

Critically, the engagement was designed for transfer rather than dependency. Every methodology, workshop deck, and scoring framework produced during the engagement is owned by the Customer and ready to be applied independently — giving the internal security team the capability to run subsequent risk modelling exercises, extend operational models, and continue maturing its security posture without requiring ongoing Apto facilitation. 

 

About Apto Solutions 

Apto Solutions are specialist consultants in security monitoring and observability, with deep expertise in Splunk, Microsoft Sentinel, and Cribl. As a leading Splunk and Cribl partner with over 20 years’ experience, Apto helps organisations in financial services, healthcare, and the public sector design, deploy, and operate world-class monitoring platforms.

Find out more

    Stay updated with the latest from Apto

    Subscribe now to receive monthly updates on all things SIEM.

    We'll never send spam or sell your data, see our privacy policy

    See how we can build your digital capability,
    call us on +44(0)845 226 3351 or send us an email…