Skip to main content

·Sevion Xia

Reallysec Drives Intel's Security Architecture Transformation, Reshaping Its Defense System

Work with Intel's InfoSec team to rebuild the architecture, putting stream processing and machine learning to work on threat triage.

Key Challenges

Intel urgently needed to transform from a traditional PC-driven enterprise into a data-driven enterprise, enhancing data value while reducing data security vulnerabilities.


Key Outcomes

Leveraging a network built on Splunk and Apache Kafka, Intel launched the Cyber Intelligence Platform (CIP), achieving comprehensive visibility across the entire InfoSec organization and fundamentally transforming its information security management system.

With Splunk as the core platform, Intel's IT team built a brand-new Cyber Intelligence Platform that not only accelerated data analysis but also unlocked business value through stream data processing and machine learning.


Strategic Transformation Background

Intel's contribution to the global technology ecosystem cannot be underestimated.

The company continues to leverage engineering expertise to provide security, computing, and connectivity capabilities for billions of devices worldwide and intelligent connected infrastructure. Over time, Intel has been transitioning from a traditional PC-centric enterprise to a data-centric enterprise, vigorously innovating its security and operational models while continuously developing new products, expanding into new markets, and exploring new customers.

Data is everything; data is the core driving force. It drives our business, it drives everything. — Brent Conran, Intel Chief Information Security Officer

Conran noted that from traditional industries to cloud-native industries, data insight is the key differentiator between successful and failing enterprises.

This trend compelled Intel's Information Security organization (InfoSec) to build and maintain a comprehensive "defense-in-depth" strategy. The team automated prevention and detection mechanisms across multiple layers — network perimeter, internal network, endpoints, applications, and data — to address 99% of security threats in their environment.


Results Overview

  • Reduced advanced threat detection time from days or weeks to minutes or hours
  • Established a unified collaboration platform to improve cybersecurity management efficiency
  • Leveraged stream data processing and machine learning to create business value in security operations and system health

By putting the right data in the right place and upskilling our people, we achieved a force multiplier effect. Machine learning has dramatically enhanced the depth and speed of our intelligence analysis. — Brent Conran, Chief Information Security Officer


Precision Hunting the "1%" Advanced Threats

Advanced threats continue to surge and grow increasingly sophisticated. Intel's legacy SIEM system struggled to keep pace with data growth demands, and only a handful of experts could operate it.

The InfoSec team proposed a "hunt the 1%" strategy, focusing on identifying the most threatening attackers. This strategy led to the construction of the Cyber Intelligence Platform (CIP) built around Splunk and Apache Kafka.

The platform runs on high-performance servers powered by Intel® Xeon® Platinum processors, combined with Intel 3D NAND SSDs and Intel® Optane™ SSDs, ingesting over 12TB of data daily with a cumulative storage capacity of 15PB. Data flows from hundreds of sources into the Kafka bus and then into the Splunk platform, with users initiating over 1.3 million searches per week.


Intel Leverages Data Intelligence Innovation to Chase the 1%

With the Splunk platform and hundreds of third-party tools, the Intel InfoSec team gained a deeply contextualized visualization interface and established a unified collaborative workspace, significantly enhancing the organization's overall response capabilities.

The team can now respond to threats within hours or even minutes, far faster than the previous response cycles that took days or weeks.

We saw the platform's potential, so we kept investing resources to realize it. We want Splunk to succeed because it helps us accomplish our mission. — Brent Conran


Platform Expansion Journey

As CIP succeeded, more data sources, use cases, and models were incorporated, with usage expanding to vulnerability management, compliance, risk control, and other teams, placing higher demands on infrastructure performance.

To achieve optimal performance, Intel's security architects collaborated with Splunk to jointly develop reference configurations based on the latest Intel technologies, guiding compute, memory, and storage scaling.

Splunk and Intel are sharing their platform-building experience to help other enterprises efficiently scale their Splunk and Apache Kafka architectures, transforming raw data into actionable business and security intelligence.


Empowering the Present and Future

Intel's InfoSec team continues to expand its use of Splunk and Kafka. Analysts and data scientists transform, join, filter, and model data streams in real time, while also introducing more machine learning tools to support end-to-end capabilities from incident response and operations monitoring to system health and alert orchestration.

We are now more agile than ever before. We deployed a brand-new Splunk data lake and modernized all our tools. Through proper data governance and personnel retraining, we created a security intelligence force multiplier. — Brent Conran


Solution Overview

  • Security Analytics
  • Observability
  • Data Intelligence
  • Stream Processing
  • Machine Learning Enablement

Start with an assessment, then talk scope

Security, data and AI each start with a review of where you stand. The report and its findings are yours, whether or not the engagement continues.