Close Menu
geekfence.comgeekfence.com
    What's Hot

    Customer experience management (CXM) predictions for 2026: How customers, enterprises, technology, and the provider landscape will evolve 

    December 28, 2025

    What to Know About the Cloud and Data Centers in 2026

    December 28, 2025

    Why Enterprise AI Scale Stalls

    December 28, 2025
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Cloud Computing»GovWare 2025 Security Operations Centre
    Cloud Computing

    GovWare 2025 Security Operations Centre

    AdminBy AdminDecember 3, 2025No Comments6 Mins Read2 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    GovWare 2025 Security Operations Centre
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The GovWare Security Operations Centre is a collaborative initiative with Cisco for GovWare Conference and Exhibition 2025 — GovWare 2025 Security Operations Centre

    Following the successful Security Operations Centre (SOC) deployments at RSAC 2025, Black Hat Asia, and Cisco Live San Diego 2025, the Cisco ASEAN executive team approved the inaugural SOC for GovWare. This initiative required close collaboration with GovWare, Image Engine, and the Marina Bay Sands (MBS) Network Operations Center (NOC) to establish a secure conference network for attendees, with security provided by the SOC.

    The SOC was founded on three primary missions:

    • To Protect — Ensure the security of the GovWare 2025 network by defending against all forms of threats and attacks, originating from both internal and external sources.
    • To Educate — Enhance attendee understanding and awareness through engaging SOC tours and insightful blog content.
    • To Innovate — Continuously advance security capabilities by developing and implementing new integrations, refining processes, optimizing workflows, and deploying automations, working with AI.

    Attendees were invited to join the complimentary, secure GovWare 2025 network, advised to follow best security practices and asked to accept the Terms & Conditions and Code of Conduct of GovWare Conference & Exhibition 2025 as well as the Data Protection and Privacy Notice.

    GovWare 2025 Network Splash page

    Data Protection and Privacy is a paramount concern to the SOC team. At the conclusion of the conference, the data was destroyed and a certificate of destruction filed with GovWare management.

    The SOC team diligently worked to identify, locate, and help remediate threats whenever an attendee’s device or account was found to be compromised or insecure.

    SOC tour

    The GovWare SOC was successfully deployed in just two days, a testament to extensive prior planning and specialized expertise. This rapid setup was facilitated by:

    • The deployment of the “SOC in a Box,” a custom hardware solution honed through years of experience at the RSAC Conference, enabling rapid connectivity with the MBS, Splunk Enterprise Security, and the Cisco Security Cloud.
    • Drawing upon proven expertise, workflows, and procedures from the RSAC 2025 and Cisco Live San Diego SOCs, with many veteran engineers providing both on-site deployment and dedicated remote support.
    • Integrating advanced innovations and security practices developed through 10 years of safeguarding the Black Hat network, recognized as the world’s most hostile.
    • The partnership with Endace, a highly skilled full-packet capture provider, whose foundational experience at the RSAC Conference and Cisco Live San Diego in 2025 was critical and extended to their commitment for GovWare.
    SOC in a Box diagram

    The SOC Architecture

    The SOC team integrated with the NOC to connect the ‘SOC in the Box’ and Cisco Secure Access virtual appliances for DNS. They created a Switched Port Analyzer (SPAN) feed of network traffic from the inline Cisco Secure Firewall/Firepower protection and sent to the EndaceProbe packet capture platform to record all network traffic, facilitating the analysis of anomalous behavior. The EndaceProbe also generated and ingested metadata, including Zeek logs, into the Splunk Enterprise Security Platform. Endace reconstructed and filtered file content, streaming it to Splunk Attack Analyzer (and onward to Secure Malware Analytics) for sandboxing and analysis.

    SOC architecture

    The following screenshot demonstrates the ingestion of firewall syslog logs and SPAN data from the switch, then sending it to Flow Collector for logs to be stored in Cisco Secure Network analytics. A copy of the logs is also being sent to Cisco XDR cloud for analytics and detections.

    Cisco Telemetry Broker Explorer

    The SOC team used Duo Central for Single Sign-On access to the tools, both on-premises and in the cloud.

    Duo SSO interface

    The implementation of cloud-based solutions, specifically XDR and Splunk Cloud, proved instrumental in optimizing efficiency and reducing labor within the limited setup window. Pre-configured data and settings, notably Splunk dashboards resulting the innovations of Ivan Berlinson, were seamlessly integrated from previous engagements.

    Splunk XDR dashboard for GovWare 2025

    Incidents were investigated by Tier 1 / Tier 2 analysts in Cisco XDR, with threat intelligence provided by Cisco Talos, and licenses donated by alphaMountain, Pulsedive, and StealthMole along with community sources.

    GovWare 2025 XDR incident dashboard

    When escalations to Tier 3 incident responders were required, the enriched Incident was sent from Cisco XDR to Splunk Enterprise Security.

    AI Defense was deployed to secure the SOC cloud infrastructure, along with Cisco Identity Intelligence.

    The Statistics

    Statistics are always a popular part of the SOC Tours. Below are the stats from this year’s event.

    Attendees (GovWare) 14,000+
    Total Packets Captured (Endace) 1.5 Billion
    Total Logs Captured (Splunk) 59.2 Million Events
    Total Sessions (Endace) 34.9 Million
    Total Unique Devices (by MAC address, DHCP) 1,600+
    Total Packets Written to Disk (Endace) 1.4 Terabytes
    Total Logs Written to Cloud (Splunk) 59.2 Million Events
    Peak Bandwidth Utilization (Endace) 200 Mbps
    DNS Requests (Cisco Secure Access) 4.2 Million (162 Blocked)
    Total Clear Text Usernames/Passwords (Endace) 35
    Unique Devices/Accounts With Clear Text Usernames/Passwords (Endace) 5
    Files Sent for Malware Analysis (Endace) 34,705 file objects reconstructed by Endace

    2,581 sent to Splunk Attack Analyzer

    1,382 sent to Secure Malware Analytics

    GovWare 2025 SOC Tour

    SOC Findings and Lessons Learned

    Check out the blogs by the engineers who worked inside the SOC at GovWare:

    Acknowledgements

    Our thanks to the engineers who made the first SOC at GovWare a success, by protecting the network and educating attendees (and you).

    2025 GovWare SOC Team

    Marina Bay Sands Network Operations Center Liaison

    GovWare/Image Engine Liaison

    • Goh Choon Hua, Ivan Lim and Zoe Chin

    Cisco Singapore

    • Sharon Koo, Peter Lye, Juan Huat Koo, David Ong and Ian Lim

    Cisco Security and Splunk SOC Team

    • Innovation, AI Defense, Cloud Protection Suite: Ryan MacLennan
    • Splunk Incident Response: Allison Gallo and Sumit Juyal
    • Splunk Enterprise Security Integrations: Kenneth Bouchard
    • Talos IR Threat Hunter: Yuri Kramarz
    • XDR Integrations: Ivan Berlinson
    • Breach Protection Suite, Agentic AI: Aditya Sankar, Ahmadreza Edalat and Robin Wei
    • User Protection Suite: Claire Fulk
    • Firewall and Security Cloud Control: Adam Kilgore and Carol Trincia Dsouza
    • Splunk Remote Support: Josh Wilson

    Endace SOC Team

    • Co-SOC Leader: Steve Fink
    • VP of Product: Cary Wright
    • Integrations: Barry ‘Baz’ Shaw
    • Engineering: Sundarram Paravata

    About GovWare

    GovWare Conference and Exhibition is the region’s premier cyber information and connectivity platform, offering multi-channel touchpoints to drive community intel sharing, training, and strategic collaborations.

    A trusted nexus for over three decades, GovWare unites policymakers, tech innovators, and end-users across Asia and beyond, driving pertinent dialogues on the latest trends and critical information flow. It empowers growth and innovation through collective insights and partnerships.

    Its success lies in the trust and support from the cybersecurity and broader cyber community that it has had the privilege to serve over the years, as well as organisational partners who share the same values and mission to enrich the cyber ecosystem.


    We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

    Cisco Security Social Media

    LinkedIn
    Facebook
    Instagram
    X





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    New serverless customization in Amazon SageMaker AI accelerates model fine-tuning

    December 28, 2025

    Airbus prepares tender for European sovereign cloud

    December 27, 2025

    Reader picks: The most popular Python stories of 2025

    December 26, 2025

    Sustainability trends for 2026: From boardroom decisions to real-world systems

    December 25, 2025

    Cisco’s MCP Scanner Introduces Behavioral Code Threat Analysis

    December 24, 2025

    In S3 simplicity is table stakes

    December 23, 2025
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 20258 Views

    Microsoft 365 Copilot now enables you to build apps and workflows

    October 29, 20258 Views

    Here’s the latest company planning for gene-edited babies

    November 2, 20257 Views
    Don't Miss

    Customer experience management (CXM) predictions for 2026: How customers, enterprises, technology, and the provider landscape will evolve 

    December 28, 2025

    After laying out our bold CXM predictions for 2025 and then assessing how those bets played out…

    What to Know About the Cloud and Data Centers in 2026

    December 28, 2025

    Why Enterprise AI Scale Stalls

    December 28, 2025

    New serverless customization in Amazon SageMaker AI accelerates model fine-tuning

    December 28, 2025
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    Customer experience management (CXM) predictions for 2026: How customers, enterprises, technology, and the provider landscape will evolve 

    December 28, 2025

    What to Know About the Cloud and Data Centers in 2026

    December 28, 2025

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2025 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.