Customer Case Study · Security Operations
A fully operational SOC —
built in one month, not one year
How Small Robot took a national essential-services organisation from no detection capability to a tuned, playbook-driven Splunk SOC — with the internal team able to run it themselves by the end of the engagement.
Client name and logo withheld at the customer's request(name withheld)
The starting point
A national organisation, an essential service, and a security operation still finding its feet.
The client operates critical infrastructure at national scale — the kind of organisation where a security incident is not just a cost, it is a service disruption the public notices. Like many organisations outside the finance and defence sectors, its security function had grown ahead of its tooling: real risk, real regulatory pressure, but a security operations team still early in its journey with enterprise-grade SIEM and SOAR platforms.
The business had made the right call at the platform layer — Splunk Enterprise Security for detection, Splunk SOAR for response. What it didn't have yet was the detection content, the playbooks, or the in-house experience to stand either platform up and run it with confidence.
The challenge
Two enterprise platforms to stand up together, with a team still building its SOC muscle.
An inexperienced SOC team
The internal team was responsible for security operations but had not yet run Splunk Enterprise Security or Splunk SOAR at production scale. Standing up either platform alone is a substantial undertaking for a team still building that experience.
Two platforms, one deadline
Enterprise Security and SOAR needed to go in together, not sequentially over separate projects. Detection without response is a dashboard nobody acts on; response without tuned detection is automation with nothing worth automating.
Why this is harder than it looks
Most Splunk ES and SOAR deployments run as two separate initiatives, often a year or more apart, because detection engineering and playbook development pull on different skills and neither is quick to get right. Doing both together, well, in a single sprint is the exception rather than the rule — and it's the reason the team could not have reasonably taken this on alone in the same timeframe.
What Small Robot did
Deploy, detect, respond, and hand it all over — in that order, in one sprint.
- Deployed Splunk Enterprise Security. The platform went in configured for the client's environment, not a generic template.
- Developed detections. Built the detection content the environment actually needed, rather than relying on out-of-the-box rules tuned for someone else's network.
- Tuned and optimised detections. Reduced noise and false positives so the SOC team could trust what fired and act on it, instead of learning to ignore alerts.
- Developed response playbooks. Documented the exact response steps for each detection, so response stopped depending on institutional memory.
- Implemented playbooks in Splunk SOAR. Turned those documented steps into orchestrated, repeatable automation inside SOAR.
- Built a custom insider threat detection suite. A dedicated set of detections and playbooks for insider threat — a risk category generic SIEM content rarely covers well, delivered as part of the same engagement rather than a separate project.
- Conducted knowledge transfer and handover. Walked the internal team through the detections, the playbooks and the reasoning behind both, so the platforms are run by the client's own SOC, not left dependent on Small Robot to operate.
Delivered in one sprint
Illustrative build sequence — the whole programme, start to handover, inside one month.
Week boundaries are indicative of a typical build sequence for this scope, not a confirmed internal schedule. Replace with the actual week-by-week breakdown before this is shown to the client for sign-off.
The results
A working SOC programme, delivered at a pace most teams don't attempt.
| Area | Before | After |
|---|---|---|
| Detection capability | Splunk Enterprise Security not yet deployed; no tuned detection content | ES deployed and tuned to the environment, with false-positive noise reduced |
| Response capability | No documented playbooks; response depended on individual knowledge | Response playbooks documented and implemented as automation in Splunk SOAR |
| Insider threat coverage | No dedicated insider threat detections or playbooks | Custom insider threat detection suite live, with matching response playbooks |
| Team capability | SOC team new to operating Splunk ES and SOAR at production scale | Team walked through detections and playbooks via structured knowledge transfer |
In their words
“The team at Small Robot are as capable as the big consultancies and they are also small enough to care about our business.”
Where things stand today
The SOC team now operates Splunk Enterprise Security and Splunk SOAR themselves, using the detections and playbooks built during the engagement — including the insider threat suite delivered as part of the same sprint. The handover was built into the timeline from the start, not added at the end, which is why the team was in a position to run the platforms on day one after go-live.