by Cognyte
CHALLENGES • Ongoing targeted attacks • Lack of visibility into deep and dark web • Risk of data leaks SOLUTION • Continuous monitoring and analysis of deep & dark web sites and forums • Continuous stream of intelligence about threat actors’ capabilities and intents • Access to proprietary historical intelligence • Near real-time targeted intelligence about indications of leaked records and potential data breaches • Strategic intelligence enrichment reports OUTCOME • Discovery of the telco's leaked records and exposed servers • Exposure of planned targeted attacks on the telco • Identification of attack groups directly targeting the telco and the nation • Strengthening the telco's position as a national and commercial cybersecurity leader How a Large European Telco Uses LUMINAR to Protect a Nation from Cyber AttacksCASE STUDY A large European national telecom company, with over 21,000 employees and subsidiaries across the continent, is a prime target for cyber attacks, as it serves national assets. The telco maintains an advanced SOC, and as it considers cybersecurity strategic to its operations, aims to always improve its security resilience. In a recent incident, a significant cyber attack targeting high- profile national organizations took place. There were signs indicating that nation-state actors or their proxy groups may have been behind the attacks. Although the attacks were not directed at the telco, the government’s security agencies reached out to the telco's SOC, and used the SOC’s advanced technologies and resources for defense operations. INCREASE IN TARGETED CYBER ATTACKS In recent years, the telco has seen a rise in attacks on the country and on their organization specifically. The risk of being a target for nation-state attackers isn’t new to any national telco that is part of a country’s critical infrastructure. They are used to being a prime target of various attack groups, including cybercriminals, nation-state actors and hacktivists/terrorist groups. While assessing their overall cyber defense capabilities, the telco concluded that in order to improve their resilience they needed to expand their monitoring capabilities to cover existing blind spots. For example, the telco lacked the ability to monitor threat actors’ activities outside of the organization, including on the deep and dark web. Within just a few short months, the telco evaluated LUMINAR, Cognyte's external threat intelligence solution and the solution was deployed. The telco chose LUMINAR due to its combination of superior intelligence, built-in methodologies, ongoing support and high-end reports. In addition, the telco chose LUMINAR due to its potential to introduce new revenue streams should the company decide to offer CTI services to their customers in a managed service provider (MSP) model.
![]()
TIMELY DISCOVERY AND MITIGATION OF THREATS From the time LUMINAR became operational, it quickly provided tangible value. Following deployment, the telco's SOC analysts were able to uncover leaked records, discover exposed and vulnerable servers and identify planned attacks on both the telco and at the national level. In addition, the telco was able to identify several attack groups that were directly targeting the company and was able to reveal and mitigate the attacks in a timely manner.CONTINUOUS MONITORING OF CLEAR, DEEP AND DARK WEB FOR AN INTELLIGENCE BOOST LUMINAR was deployed within a few days, with no interference to the telco's operations. Following onboarding and training for the telco's internal teams, the system was operational. LUMINAR automatically gathers and ingests relevant data from external threat intelligence sources, based on the telco's critical assets, industry, region and predefined threat hunting requirements. By monitoring and analyzing clear, deep and dark web sites, as well as technical intelligence sources, LUMINAR uncovers malicious activities in the earliest stages. THREAT ACTOR PROFILING Access to threat intelligence insights about threat actors’ nature and motives, in order to better understand and mitigate threatsSTRATEGIC INTELLIGENCE ENRICHMENT Support for specific investigations, such as analysis of state-sponsored threat actors, regional/industry-specific risks and global ransomware activitiesDEEP AND DARK WEB MONITORING Near real-time targeted data about threat actors’ activities and indications of leaked records and potential breachesTHE TELCO USES LUMINAR TO SUPPORT VARIOUS USE CASES, INCLUDING: About Cognyte Cognyte, a global leader in data processing and investigative analytics solutions, helps government agencies and other organizations generate Actionable Intelligence for a Safer World™. With offerings that leverage state-of-the- art technology, including artificial intelligence, big data analytics and advanced machine learning, Cognyte helps customers eliminate the unknown and make smarter, faster decisions with their data for the best possible outcomes. Use of these products or certain features may be subject to applicable legal regulation. Users should familiarize themselves with any applicable restrictions before use. These products are intended only for lawful uses by legally authorized users. Not all features may be available in all jurisdictions and not all functionalities may be available in all configurations. Unauthorized use, duplication, or modification of this document in whole or in part without the prior written consent of Cognyte is strictly prohibited. By providing this document, Cognyte is not making any representations regarding the correctness or completeness of its contents and reserves the right to alter this document at any time without notice. Features listed in this document are subject to change. Contact your Cognyte representative for current product features and specifications. 2025 Cognyte
![]()