Customer story · Financial Services
Securonix Helps Golomt Bank to Detect Cyber and Insider Threats
Golomt Bank, one of Mongolia's systemically important banks, replaced an on-premises ArcSight SIEM with Securonix Next-Gen SIEM to gain single-pane visibility across AWS and on-premises sources and detect insider and advanced cyber threats with UEBA.

About Golomt Bank
Golomt Bank was established on 6 March 1995 as a subsidiary of Bodi International LLC, a major player in Mongolia's social and economic sector. The bank has a well-balanced presence across the retail, corporate and SME segments and is one of the systemically important banks in Mongolia, where it is a leader in the country's development. It operates under the motto "Investing for a brighter future" and has built a well-recognized brand over the past few decades.

The challenge
Golomt Bank lacked centralized visibility with its previously deployed SIEM. That solution used a traditional rules-based approach and had none of the behavioral analytics needed to detect insider threats or advanced cyber threats. The bank's environment was also complex: it ran many security solutions for intrusion prevention, distributed denial of service (DDoS) protection, email security and data loss prevention (DLP), alongside an AWS cloud environment, and it wanted all of that data consolidated in one place.
The bank needed a robust, scalable cloud-based SIEM that could ingest huge volumes of data from multiple custom data sources, use advanced analytics to identify complex threats, and cover its top use cases for both cyber and insider threats. Stability and scalability mattered, as did stronger technical support from the vendor, since reliable and secure bank operations depended on it.
The security operations center (SOC) team evaluated several cloud SIEMs, including Securonix, against these requirements.
The solution
Golomt Bank purchased Securonix Next-Gen SIEM for its cloud-native design and its advanced analytics for user and entity behavior analytics (UEBA). Securonix's capacity to ingest more data sources than the bank's prior ArcSight SIEM was a deciding factor, along with its AWS monitoring capabilities.
Securonix ingests all logs from the bank's various data sources, including custom sources, and provides single-pane-of-glass visibility into the environment. Its ability to enrich data with better context gives the security team deeper insight than competing solutions offered. With strong analytics and UEBA, the team now understands how entities behave on the network and can identify deviations from the norm using sophisticated techniques such as peer analysis. That understanding of users and entities, including employee actions, lets the team distinguish malicious insiders from regular employees and detect malicious employee activity.
The platform's flexible, open architecture ingests huge volumes of data and lets the team monitor cloud data for misuse or compromise within the bank's AWS infrastructure. Securonix's pricing includes UEBA at no additional cost, which made a substantial difference to the total cost compared with competing solutions. Securonix's professional technical support handled onboarding and resolves issues promptly, helping the bank detect and respond to threats around the clock.

The results
- Full visibility across cloud, on-premises and hybrid data in a single security dashboard
- Behavioral analytics and UEBA now detect both insider and advanced cyber threats
- More data sources ingested than with the previous ArcSight SIEM, including custom sources
- AWS infrastructure monitored for misuse or compromise alongside security tool logs
- UEBA included at no additional cost, delivering savings versus competing solutions
- Seamless onboarding and timely issue resolution from Securonix support enable 24x7 threat response
Get the full case study
Download the original document as published by Securonix (PDF, 1.4 MB).
Your story could be next
Want results like these?
Every result on this page started with one conversation — let's have yours.


