Aegis / Pinnacle Insurance - Detect Roadmap Review
74 turns · 13 min captured of 48 min stated?Only the captured portion exists in the database. The remaining 35 min of this call was never transcribed, so nothing said in it appears anywhere in this application.
Showing 74 of 74 turns · 40 turns were used as evidence for at least one fact.
- Rachel TorresAegisCloud0:04turn 0ASR 97%
Hi Sandra, thanks for making time this afternoon — I know Tuesdays tend to get a little chaotic.
- Sandra KeatingCustomer0:11turn 1ASR 91%
Yeah, no kidding, I had three back-to-backs before this so I appreciate you being flexible on the time.
- Rachel TorresAegisCloud0:18turn 2ASR 90%
Of course, absolutely — okay so, I've got the agenda pulled up, we wanted to walk through some of the Detect roadmap items, and I know you had some specific feature requests you wanted to put on the table today.
- Sandra KeatingCustomer0:33turn 3ASR 96%
Right, yeah, that's the main thing I want to get into.
- Rachel TorresAegisCloud0:37turn 4ASR 95%
Before we jump in — how are things going on your end generally, like from a security posture standpoint, anything major come up since we last spoke?
- Sandra KeatingCustomer0:48turn 5ASR 90%
I mean it's been a pretty busy quarter, we had an internal audit wrap up last week, and honestly the compliance side of things has been eating a lot of our bandwidth, but we can get to that in a sec.
- Rachel TorresAegisCloud1:04turn 6ASR 90%
Sure, sure, yeah we can definitely touch on that — I know the Comply v2 launch just happened last week actually, so there might be some relevant stuff there.
- Sandra KeatingCustomer1:16turn 7ASR 90%
Yeah I saw that announcement, I want to circle back to that, but let's do Detect first because that's kind of the more pressing thing for my team right now.
- Rachel TorresAegisCloud1:27turn 8ASR 92%
Totally, let's do it — so do you want to just kick us off with what you're seeing as the gaps, or would it be helpful if I first walked through what's on the roadmap for the next two quarters?
- Sandra KeatingCustomer1:43turn 9ASR 92%
Let me start with the gaps because I think it'll be useful context for whatever you're about to tell me.
- Rachel TorresAegisCloud1:51turn 10ASR 92%
Perfect, go ahead.
- Sandra KeatingCustomer1:53turn 11ASR 90%
So the primary thing — and I've been saying this for a couple of quarters now — is that we really need more granular alerting thresholds by entity type.
- Rachel TorresAegisCloud2:05turn 12ASR 90%
Right, can you walk me through specifically what you mean by entity type in your context?
- Sandra KeatingCustomer2:12turn 13ASR 96%
Sure, so — in the insurance world we're dealing with a lot of different categories of users and systems, right, so you've got your claims processing systems, your underwriting platforms, your customer-facing portals, and the risk profile for each of those is very different.
- Rachel TorresAegisCloud2:28turn 14ASR 90%
Mm-hmm.
- Sandra KeatingCustomer2:30turn 15ASR 92%
But right now in Detect, when we're setting alert thresholds, it's basically a one-size-fits-all situation, and that creates a ton of noise on the low-risk endpoints and then potentially under-alerts on the high-value systems.
-1Describes one-size-fits-all thresholds creating noise and under-alerting on high-value systems. · product capability
- Rachel TorresAegisCloud2:43turn 16ASR 95%
Yeah that's — that's a fair point and actually that lines up with feedback we've been getting from a few other financial services customers as well, so it's definitely something that's been getting traction internally.
- Sandra KeatingCustomer2:56turn 17ASR 88%
Good, because it should be, honestly — the alert fatigue is real, my SOC team is dealing with a lot of false positives and it affects their ability to respond to the things that actually matter.
-1Cites real alert fatigue and false positives affecting SOC response. · product capability
- Rachel TorresAegisCloud3:10turn 18ASR 89%
Understood, and I don't want to get too far ahead without checking — are we talking about thresholds on the behavioral side, like anomaly detection thresholds, or also on the signature-based rules?
- Sandra KeatingCustomer3:22turn 19ASR 96%
Both, but honestly the behavioral side is where it's most painful because the baselines are being calculated across everything and they just don't reflect the actual behavior patterns of, say, a claims adjuster versus a network admin.
-1Says behavioral side is most painful because baselines don't reflect actual patterns. · product capability
- Rachel TorresAegisCloud3:36turn 20ASR 90%
Got it, okay — so what you'd really want is the ability to define entity groups and then have separate baseline models trained per group, essentially.
- Sandra KeatingCustomer3:46turn 21ASR 95%
Exactly, yes, that's exactly it — and ideally you'd be able to map those groups to your own org hierarchy, not just some generic taxonomy.
- Rachel TorresAegisCloud3:56turn 22ASR 93%
Okay, I'm noting all of this down — and I do want to be upfront with you, Sandra, that the entity grouping with custom baselines is something our product team has been scoping, it's not GA yet, it was targeted for Q3 in the roadmap I have, but I want to get you connected with our product team directly so they have this context.
- Sandra KeatingCustomer4:19turn 23ASR 89%
Q3, so like July-September timeframe?
- Rachel TorresAegisCloud4:23turn 24ASR 96%
That's the current target, yeah — but I want to be careful not to commit to that because roadmaps shift, as you know.
- Sandra KeatingCustomer4:32turn 25ASR 92%
Yeah, I appreciate the honesty, I'd rather know the real situation than get a date that slips.
+1Appreciates Rachel's honesty about roadmap timing. · support experience
- Rachel TorresAegisCloud4:39turn 26ASR 90%
Right, exactly — okay so that's the first item, what else is on your list?
- Sandra KeatingCustomer4:45turn 27ASR 88%
The second thing, um, this is a little more sensitive to bring up but I think it needs to be on the table — the outage in March.
- Rachel TorresAegisCloud4:55turn 28ASR 96%
Yeah, I was going to bring that up too — I know we sent the incident report and the RCA but I wanted to make sure you had a chance to ask questions directly.
- Sandra KeatingCustomer5:08turn 29ASR 90%
So we were dark for, what, six hours — and look, I understand things happen, infrastructure fails, I've been in this industry long enough to know that, but for us specifically, that's six hours where we had no visibility into threats across our environment, and given our regulatory obligations that's not a small thing.
-1Highlights six-hour outage as a regulatory concern. · service reliability
- Rachel TorresAegisCloud5:27turn 30ASR 91%
No, absolutely not, and I want to acknowledge that directly — that outage was a significant failure on our part, it was a cascading failure in the event ingestion pipeline, single point of failure that we should have architected around, and we did not.
- Sandra KeatingCustomer5:43turn 31ASR 94%
Right, that's what the RCA said.
- Rachel TorresAegisCloud5:46turn 32ASR 96%
And the fix — we've implemented redundant processing nodes and a circuit breaker pattern so that if one node in the pipeline degrades, it doesn't take everything down with it, and that's been live since mid-March.
- Sandra KeatingCustomer6:00turn 33ASR 90%
Okay, so my follow-up question on that is — and this goes to the feature request angle — is there any way for customers to have visibility into the health of the Detect pipeline itself, like a status indicator within the product?
- Rachel TorresAegisCloud6:17turn 34ASR 89%
That's actually a really good one and it's something I've heard from a couple of other accounts too — right now the status page is external and it's sort of — it's not surfaced inside the product itself.
- Sandra KeatingCustomer6:31turn 35ASR 96%
Yeah because we only found out about the outage because someone on my team noticed the alert volume had dropped to zero and then went and checked the status page — that's not a great discovery mechanism.
-1Notes alert volume dropping to zero is not a good discovery mechanism. · product capability
- Rachel TorresAegisCloud6:45turn 36ASR 89%
No, I completely agree, and that's — I'll be honest, that's a gap in the product experience, and I'm going to log that as a formal feature request, in-product pipeline health status with proactive alerting if ingestion drops below a threshold.
- Sandra KeatingCustomer6:59turn 37ASR 90%
Yeah, even just like a banner or an indicator in the UI that says hey, we're experiencing reduced capacity, something — anything — would have saved my team a lot of confusion that morning.
-1Says even a simple banner would have saved confusion. · support experience
- Rachel TorresAegisCloud7:12turn 38ASR 94%
Understood, and I think that's a very reasonable ask — I'm going to make sure that goes to the right product team with your name on it so they have the customer context.
- Sandra KeatingCustomer7:25turn 39ASR 96%
Appreciate that.
- Rachel TorresAegisCloud7:27turn 40ASR 91%
Okay so let me also share a few things that are on the Detect roadmap that I think are relevant to what you're describing — there are two items I want to highlight specifically.
- Sandra KeatingCustomer7:40turn 41ASR 95%
Sure, go ahead.
- Rachel TorresAegisCloud7:42turn 42ASR 97%
First one is expanded SIEM integration — we're adding native connectors for a couple of the major SIEM platforms in Q2, which I know you're running LogVault, so that should reduce the time from event to alert in your existing workflow.
- Sandra KeatingCustomer7:58turn 43ASR 89%
That would actually be helpful, yeah — right now the LogVault integration is a little manual, we're doing some custom scripting to get the data in there.
+1Welcomes native LogVault integration as helpful versus manual scripting. · product capability
- Rachel TorresAegisCloud8:09turn 44ASR 97%
Yeah so that should get a lot cleaner — I'll send you the details on that after this call, it's a Q2 item so should be coming up relatively soon.
- Sandra KeatingCustomer8:21turn 45ASR 92%
Okay, and the second thing?
- Rachel TorresAegisCloud8:23turn 46ASR 91%
Second one is — we're building out a threat intelligence correlation layer, so essentially Detect will be able to cross-reference events against external threat intel feeds in near real-time, which should improve the signal-to-noise ratio on the alerts that are actually meaningful.
- Sandra KeatingCustomer8:39turn 47ASR 91%
That's interesting — what feeds are you pulling from?
- Rachel TorresAegisCloud8:43turn 48ASR 97%
The initial launch is going to include a few of the major ones — I don't want to get into specifics that I haven't confirmed with the product team, so let me get you the accurate list rather than guess.
- Sandra KeatingCustomer8:58turn 49ASR 89%
Fair enough, yeah, please do send that over — the feeds matter a lot, some of them are better for financial services specific threat actors than others.
- Rachel TorresAegisCloud9:08turn 50ASR 91%
Absolutely, I'll include that in the follow-up — and actually, is there a specific feed you're already using or want to see prioritized?
- Sandra KeatingCustomer9:18turn 51ASR 92%
We're subscribed to FS-ISAC feeds and I'd want to see that included, that's probably the most relevant for our threat landscape.
- Rachel TorresAegisCloud9:27turn 52ASR 89%
FS-ISAC, got it, I'm writing that down — that's a very reasonable ask for a financial services customer and I'll flag that specifically to the product team.
- Sandra KeatingCustomer9:37turn 53ASR 95%
Yeah I mean that one feels like a no-brainer for any insurance or banking customer you're working with.
- Rachel TorresAegisCloud9:44turn 54ASR 89%
Agreed — okay, you mentioned the compliance audit earlier, do you want to spend a few minutes on Comply before we wrap up?
- Sandra KeatingCustomer9:53turn 55ASR 96%
Yeah just quickly — we're coming up on a SOC 2 Type II renewal and honestly the reporting process last time was pretty painful, lots of manual exports and spreadsheet work.
-1Describes SOC 2 report process as painful with manual exports and spreadsheets. · compliance reporting
- Rachel TorresAegisCloud10:05turn 56ASR 89%
So this is actually really timely because Comply v2 launched last week — April 7 — and one of the headline features is on-demand SOC 2 reporting, so you can generate the report without the manual export process, it pulls directly from the data in the platform.
- Sandra KeatingCustomer10:22turn 57ASR 91%
Okay, that's — yeah that could actually save us a lot of pain, when can we see that in action?
+1Says on-demand SOC 2 reporting could save a lot of pain. · compliance reporting
- Rachel TorresAegisCloud10:30turn 58ASR 89%
I can set up a demo for your team, I'm thinking we loop in your compliance lead too — would that be the right person to have in the room?
- Sandra KeatingCustomer10:42turn 59ASR 93%
Yeah, definitely bring in Marcus, he's the one who's actually doing the evidence gathering so he'd want to see the workflow.
- Rachel TorresAegisCloud10:51turn 60ASR 90%
Perfect, I'll reach out to coordinate schedules — okay let me just do a quick recap of the action items before we lose track of everything.
- Sandra KeatingCustomer11:01turn 61ASR 89%
Yeah please.
- Rachel TorresAegisCloud11:04turn 62ASR 95%
So from my side — I'm logging two formal feature requests: entity grouping with custom behavioral baselines, and in-product pipeline health status with proactive degradation alerts.
- Sandra KeatingCustomer11:14turn 63ASR 88%
Correct, yes.
- Rachel TorresAegisCloud11:16turn 64ASR 92%
I'm also going to send you the confirmed list of threat intel feeds for the correlation layer, including whether FS-ISAC is on the roadmap, and the details on the LogVault native connector timeline.
- Sandra KeatingCustomer11:29turn 65ASR 89%
That all sounds right.
- Rachel TorresAegisCloud11:31turn 66ASR 88%
And then I'll set up the Comply v2 demo with you and Marcus — I'm thinking we can probably do that within the next two weeks?
- Sandra KeatingCustomer11:40turn 67ASR 95%
Two weeks works, yeah — try to avoid the last week of April if you can, I think we've got some internal stuff happening.
- Rachel TorresAegisCloud11:50turn 68ASR 93%
No problem, I'll aim for the week of the 20th — I'll send a calendar invite.
- Sandra KeatingCustomer11:56turn 69ASR 95%
Perfect, that works — and Rachel, I do appreciate you actually listening on the feature requests, sometimes these calls feel like they go into a black hole so.
+1Appreciates Rachel listening, contrasting with calls that go into a black hole. · support experience
- Rachel TorresAegisCloud12:07turn 70ASR 88%
I hear you, and I want to make sure that doesn't happen here — I'll keep you posted on what traction these get with the product team, even if the answer is not yet, I'll tell you.
- Sandra KeatingCustomer12:21turn 71ASR 94%
That's all I ask — okay I've got a hard stop in about two minutes so let's call it there.
- Rachel TorresAegisCloud12:28turn 72ASR 89%
Sounds good — thanks Sandra, I'll have everything in your inbox by end of week.
- Sandra KeatingCustomer12:34turn 73ASR 97%
Great, talk soon.