Customer stories

Rheinmetall AG logoRheinmetall AG

Integrated technology group realizes 35% cost savings, enhances productivity, and improves cyber resilience with OpenText™ Enterprise Security Manager

Rheinmetall AG logo

About Rheinmetall AG

Rheinmetall is a leading international systems supplier in the defense industry. It is also a driver of forward-looking technological and industrial innovations in the civilian markets, with a key focus on sustainability.

A person typing on a computer
  • Employees:
    31,000+
  • Locations:
    171
  • Annual sales:
    $9.8 billion

Summary

Challenges

  • Growing risk of cyberattacks made it important to move outsourced cyber defense components in-house.
  • Existing SIEM solution lacked integration capabilities and had disjoined functionality.

Solution

  • Introduced a comprehensive POC on an appliance basis.
  • Leveraged advanced ecosystem integration capabilities.
  • Improved SOC productivity and bolstered security posture with SOAR.

Results

  • Cut operating costs by 35% with flexible licensing
  • Streamlined regulation compliance with automation
  • Partnered successfully on tech and business goals

Challenges

  • Needed to move key outsourced cyber defense components in-house in response to a growing risk of cyberattacks
  • Existing SIEM platform had a lack of integration capabilities and disjointed functionality

The increasing frequency and intensity of conflicts and military disputes are leading to a growing need for security. Rheinmetall is a European systems supplier for armed forces technology. It has many years of experience and innovation in armored vehicles, weapon systems, and ammunition, as well as in the areas of air defense and electronics. This makes Rheinmetall an important partner in this field to the German armed forces, their allies, and friendly armies, along with civil national security forces.

When Vice President of Cyber Defense Markus Malewski joined Rheinmetall in 2021, one of his first priorities was to bring in-house Rheinmetall’s IT security monitoring. He explained, “The defense and automotive government agencies that we partner with recognized the growing concerns around cyberattacks in volatile global times. This, combined with a high media profile for Rheinmetall, warranted moving our infrastructure components, many of which were outsourced, in-house. Our in-house cyber defense division consists of a sophisticated security operations center (SOC), a penetration testing team, and a data analytics team responsible for open-source intelligence and threat intelligence. We felt we had the expertise to bolster our cybersecurity, while gaining deep insight from the intelligence sources available to us.”

The organization used a SIEM solution that is considered a market leader as its security suite. When it was time to implement in-house, the team faced several challenges with it. There was very little clear documentation, so the workflow of how to install the components and configure them was far more time-consuming than expected. The vendor referred Rheinmetall to a local partner for training and support, but there was still not enough guidance for the team to manage, operate, and maintain the security monitoring instance in-house.

Mr. Malewski also noticed missing functionality, “I, as well as other team members, had previous experience with OpenText Enterprise Security Manager. In terms of functionality, including managing data sources and correlation capability, we found the implemented solution lacking. In addition, whereas OpenText provided OpenText Security Orchestration, Automation, and Response (SOAR) as a native component of the platform, with the previous solution we were facing substantial additional license costs to add this.”

Computer screen image

We saw a clear cost savings of 35 percent, thanks to the OpenText flexible licensing structure. We operate a test and production environment. Previously, we were charged for both environments, but with OpenText we did not need to acquire additional licenses for our test environment.

Markus Malewski
Vice President of Cyber Defense, Rheinmetall AG

Solution

A comprehensive proof of concept (POC) highlighted OpenText’s user-friendly interface and single management console, its sophisticated reporting, and native SOAR capabilities. The solution easily used Rheinmetall’s investment in the MITRE ATT&CK framework.

Products deployed

Introducing a comprehensive POC on an appliance basis

The SIEM license was approaching a renewal date, and Mr. Malewski saw this as an opportunity to explore alternatives. Considering the previous experience with OpenText, an extensive POC began to compare functionality, automation opportunities, and ease of use. He commented, “Our priority was to determine if OpenText Enterprise Security Manager can follow our SOC analysts’ workflows and designs. We wanted to see a positive user experience, seamless SOAR and ecosystem integration, and one central system to manage all roles and their access to data sources.”

The Rheinmetall POC was deployed on an appliance basis, with OpenText providing the hardware and software needed to operate the solution. This significantly eased the installation and maintenance effort and ensured that Rheinmetall can run OpenText Enterprise Security Manager fully on-premises in its own robustly secure environment.

Leveraging advanced ecosystem integration capabilities

The POC was supported by local OpenText technical engineers, as well as OpenText Professional Services. Mr. Malewski quickly saw the familiar capabilities he looked for, such as sophisticated dashboards.

“We really appreciated OpenText’s dynamic dashboards,” he said. “I can just click on a bar graph, for example, and the dashboard will dynamically change to focus on this specific element for full transparency.”

Rheinmetall also liked OpenText’s native integration capabilities. The organization uses WebEx, and this was easily incorporated using a simple API. New data sources were straightforward to add, even from external parties, such as the threat intelligence service provider, so that relevant data is readily available for analysis and correlation purposes.

A key component of the OpenText Threat Detection and Response portfolio is OpenText Security Log Analytics. This is a comprehensive SIEM log management tool and security analytics solution that eases compliance burdens and accelerates forensic investigations. Mr. Malewski’s team already leveraged the MITRE ATT&CK framework—a globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used to develop specific threat models. With the MITRE ATT&CK content, the Rheinmetall penetration testing team can quickly see how much coverage it has against the tactics and techniques within the framework and map it to Rheinmetall use cases. OpenText Security Log Analytics helps identify risks, prioritize them, and take timely action.

Improving SOC productivity and bolstering security posture with SOAR

SOAR capability is a natively integrated part of OpenText Enterprise Security Manager, proving a real differentiator compared to the legacy SIEM suite. In the previous environment, the team operated a dedicated ticketing system where all security incidents were managed. Incident alert details were automatically sent to the ticketing system, but the SOC analysts had to conduct manual investigations.

Mr. Malewski explained how SOAR improved this process: “SOAR not only automates alerts, but it also intelligently logs the initial automated investigative actions, such as checking the CMDB or other sources. The documented output shows the exact real-time status of the alert. And thanks to SOAR’s native integration into the SIEM platform, we have a real-time correlation engine that can respond directly to alerts. This is very different from solutions we’ve worked with in the past, where data logs had to be scheduled every five or ten minutes. Because we can respond quickly to a developing threat, we can easily block domains or push information to a certain proxy. The added, coincidental benefit is that the SOAR interface looks very similar to the look and feel of our previous ticketing system, which made migration easy for our SOC analysts.”

A person looking at a tablet

We really appreciated OpenText’s dynamic dashboards. I can just click on a bar graph, for example, and the dashboard will dynamically change to focus on this specific element for full transparency.

Markus Malewski
Vice President of Cyber Defense, Rheinmetall AG

Results

In addition to 35% license cost savings, the appliance deployment model reduced maintenance cost and effort, while OpenText intelligent automation boosted SOC productivity. Cyberattack simulation can successfully anticipate future security threats.

Reduced operating costs by 35% with flexible licensing

Though the decision for OpenText included many aspects, reducing operating costs was an important objective of the project. Mr. Malewski commented, “We saw a clear cost savings of 35 percent, thanks to the OpenText flexible licensing structure. We operate a test and production environment. Previously, we were charged for both environments, but with OpenText we did not need to acquire additional licenses for our test environment. The flexible appliance model reduced our maintenance cost and efforts, and the intelligent OpenText automation, including sophisticated threat search and hunt capabilities, improved the productivity of our SOC analysts.”

Streamlined regulation compliance with automation

As a global organization active in the defense and automotive industries, Rheinmetall is subject to stringent regulation compliance. OpenText Security Log Analytics came with more than 100 out-of-the-box reports and dashboards to reduce the reporting effort with simpler, automated, customizable reports and dashboards.

The team appreciated OpenText’s capability to simulate cyberattacks and better anticipate circumstances that may pose a threat to the organization. OpenText is a reliable and robust solution. This may seem obvious, but Mr. Malewski knows it is not always a given, “In the past we have experienced some data loss when the previous system would automatically stop ingesting data in response to a minor issue. This can leave us potentially exposed, and we have thankfully never seen this happen with OpenText.”

Partnered successfully on technical and business goals

The OpenText implementation is fully managed by the in-house SOC without involvement by or dependencies on any of the other IT departments within Rheinmetall. Mr. Malewski commented on the support received from OpenText during the implementation, “Our OpenText contacts did not just support us with the practicalities of managing data sources and logs, they also helped us create a compelling financial proposition for our senior leadership team that clearly demonstrated how OpenText would be a cost-effective solution for us, while bolstering our cyber defense posture.”

He concluded, “We like OpenText’s cybersecurity vision. The OpenText Threat Detection and Response platform is a truly complete SIEM solution that helps us to simplify our security operations and reduce our threat exposure time with real-time detection and native SOAR. We can clearly see the OpenText investment in cybersecurity as a strategic portfolio to the business.”