·Jason Yuan
Addressing Cybersecurity Threats in Ukraine's Energy Sector
DTEK and Reallysec built a new security operations centre on IBM QRadar Suite, with 24/7 threat monitoring and automated response.

DTEK and Reallysec SOC: Building a Cybersecurity Shield for Ukraine's Energy Grid
Defending Against Digital Warfare: Protecting the Energy Lifeline
As Ukraine's largest private energy company, DTEK provides lighting and heating services to millions of people. Since 2022, DTEK has actively supported veterans in reintegrating into civilian life and has been providing energy free of charge to critical infrastructure in regions such as Kyiv, Dnipropetrovsk, and Donetsk.
However, DTEK faces not only continuous physical attacks — with its distribution networks and power generation facilities enduring heavy bombardment — but also an equally deadly yet silent war: cyberattacks targeting energy infrastructure.
At the forefront of this digital battle is DTEK's cybersecurity and information security service provider, Reallysec SOC.
We protect DTEK's business continuity, technological innovation, and customer trust. Ensuring the security of all systems is critical, especially the core systems that handle sensitive data. We are committed to adopting a zero-trust architecture and strengthening security controls at every level. — Reallysec SOC Spokesperson
Establishing a 24/7 Security Operations Center (SOC)
As cyber threats grew more frequent and destructive, Reallysec SOC urgently needed to enhance its threat monitoring and incident response capabilities for DTEK. To this end, the company decided to build a new Security Operations Center (SOC) to achieve round-the-clock infrastructure monitoring and threat defense.
During the SOC design and implementation process, Reallysec SOC identified several key priorities:
- Accelerate threat detection, analysis, and containment
- Implement centralized ticket workflow management
- Introduce behavioral analytics and predictive analysis capabilities
Building a Battle-Ready SOC: Choosing IBM QRadar Suite
Reallysec SOC selected a range of solutions from the IBM® QRadar® Suite as the core technology platform for its next-generation SOC.
We evaluated solutions from multiple leading security vendors and ultimately chose IBM because it best aligned with our core requirements in terms of functionality, stability, and cost-effectiveness. — Reallysec SOC Spokesperson
As an IBM Silver Partner, the Reallysec SOC team brought extensive experience in IBM product implementation. Leveraging this expertise, the entire migration was completed and went live in just three months.
We drew on our previous SIEM implementation experience, prioritizing architectural design, fault tolerance, and analyst workflow optimization. On top of that, we placed special emphasis on system scalability, modular distribution, and process efficiency. — Reallysec SOC Spokesperson
IBM QRadar: The Automation Core of DTEK's Cybersecurity
Today, the IBM QRadar Suite serves as the core engine of DTEK's centralized, automated security management architecture.
- With IBM QRadar SIEM, analysts can collect data from across the enterprise's IT systems and correlate it into a unified security event view.
- The integrated User Behavior Analytics (UBA) module intelligently identifies anomalous behavior, enabling faster threat detection and response.
Through IBM QRadar SOAR, Reallysec SOC further enhanced its Security Orchestration, Automation, and Response (SOAR) capabilities. Analysts can use the SOAR console to perform routine tasks such as ticket processing, KPI tracking, and use case documentation, significantly improving the efficiency and consistency of incident management.
Measurable Results
- 5x improvement in threat detection rate
- 150,000,000+ cyberattacks successfully defended against (since 2022)
With tools like IBM QRadar Suite, we are able to make faster and smarter detection and response decisions. — Reallysec SOC Spokesperson
Forging a Resilient Defense: An Intelligent Platform Supporting a Critical Mission
Since 2022, DTEK has successfully defended against over 150 million cyberattacks. The newly built SOC, combined with IBM technology, has become a powerful weapon in this battle, enabling the enterprise to build a more efficient, visible, and automated security operations framework.
With the centralized interface provided by IBM QRadar Suite, security analysts can access all necessary tools and data from a single pane of glass, accelerating the security incident response process. At the same time, the platform's automated threat detection and response capabilities dramatically reduce response times and boost team effectiveness.
DTEK has achieved significant results across key metrics:
- Mean Time to Threat Detection (MTTTD): 10 minutes
- Mean Time to Triage (MTTT): 30 minutes
- Mean Time to Respond (MTTR): 70 minutes
Centralized security visibility and precise automated detection mechanisms have increased DTEK's overall threat identification rate by five times.
We cannot eliminate all threats, but with tools like IBM QRadar Suite, we can respond to security incidents in a faster and smarter way. This builds a solid security shield for DTEK's infrastructure and its mission — to bring light and warmth to the people of Ukraine. — Reallysec SOC Spokesperson