Case study · Financial services · MalaysiaMalaysian Commercial Bank
A licensed commercial bank operating under Bank Negara Malaysia, running retail and SME banking from a Kuala Lumpur head office and 18 branches. A 400-person organisation with a 6-person security team — small enough that every analyst hour counts, but regulated to exactly the same RMiT standard as institutions ten times its size. That asymmetry, not headcount, was the core problem: twenty separate security tools generating evidence no one had time to consolidate.
400Users
20Inbound sources
18Branches
9 weeksDeployment
Inbound data sources · what EdgeBridge ingests
SIEM & Log ManagementMicrosoft SentinelSplunk
Endpoint ProtectionCrowdStrike FalconMicrosoft Defender
IAM & IdPActive DirectoryEntra IDCyberArk
Network SecurityPalo Alto NGFWCisco ISEF5 BIG-IP
Cloud PlatformsAWSMicrosoft Azure
Vulnerability ManagementTenable NessusQualys
Email & CollaborationMicrosoft 365Proofpoint
ITSM & TicketingServiceNow
Compliance & GRCRSA Archer
Threat IntelligenceRecorded Future
IT & Security DataMicrosoft SCCM
Business challenges
- Twenty tools, twenty consoles — a 6-person team could not watch them all, so alerts were triaged by whoever noticed first
- RMiT evidence scattered across Archer, Sentinel, AD and branch spreadsheets; each BNM submission consumed 3–4 weeks of the security lead’s time
- Three identity stores (AD, Entra ID, CyberArk) with no single answer to “what can this user actually reach?”
- Privileged-access reviews ran quarterly by hand across 400 accounts — a control that was accurate on the day it was signed and stale a week later
- MTTR of 3–4 hours on phishing and malware, driven almost entirely by manual correlation between Sentinel, CrowdStrike and Proofpoint
Key capabilities delivered
- EdgeBridge deployed in the DMZ, ingesting all 20 sources across 11 domains — normalised into one schema, no rip-and-replace
- Identity Fabric resolved AD, Entra ID and CyberArk into one canonical record per human, service and machine identity
- RMiT control library mapped to live telemetry — continuous control monitoring replacing point-in-time evidence collection
- SOAR playbooks for the three highest-volume scenarios: phishing triage, malware containment, impossible-travel logins
- Board pack generated on demand: posture score, control health and open risk, in plain language for the audit committee
How it rolled out
Weeks 1–2EdgeBridge deployed; SIEM, endpoint and identity sources connected first (8 of 20)
Weeks 3–5Remaining 12 sources onboarded; Identity Fabric and Asset Registry resolved
Weeks 6–7RMiT control mapping and evidence automation configured against live data
Weeks 8–9Playbooks tuned in shadow mode, then enabled; board dashboard signed off
Impact
70%
less audit-preparation time
<30 min
MTTR, down from 3–4 hours
20 → 1
consoles for daily operations
1,900+
identities resolved into one record
“We are a small team held to a large bank’s standard. Converge360 did not add another tool — it made the twenty we already had work as one. Our RMiT evidence is now a report we run, not a project we survive.”
Head of Information Security · Malaysian Commercial Bank