Kyocera Cyber brings hyper-automation to Reading-based SOC through partnership with Torq
In the UK, people mainly associate Kyocera with print devices, but over the last two and a half years it has been quietly building a specialist cybersecurity business which it is now officially launching in the UK.
Operating from its headquarters in Reading, Kyocera Cyber adds an eighth specialism to Kyocera UK’s portfolio, alongside the company’s existing offerings in production print, document solutions, content services, Kyodo consulting, managed services, collaboration and infrastructure.
Kyocera Cyber unifies new and existing Kyocera security services under what Kyocera describes as a ‘startup cybersecurity brand providing global protection services to SMEs’, focused mainly, but not exclusively, on existing Kyocera UK customers at the upper end of the SME spectrum.
Through partnerships with cybersecurity leaders like Microsoft, Fortinet, Mimecast, KnowBe4 and Crowdstrike and start-ups like Torq, it offers all the services you would expect from an MSSP, including managed endpoint detection and response (MDR), managed phishing defence and simulation, incident response, managed backup, disaster recovery and business continuity, delivered by a UK-based next-generation managed security operations centre (M-SOC) with 24/7 global coverage. This SOC, and its ability to provide rapid, bespoke protection through Torq’s AI-powered hyper-automation platform for security operations teams, is to a great extent what stops Kyocera Cyber from being just another me-too cybersecurity brand, which Chief Information & Strategy Officer Andrew Smith says was a key consideration when developing the business.
“There are so many different cybersecurity companies out there. They all have more or less the same menu cards – we do instant response, we do SOC, we do MEDR, we do all these different services. We wanted to take that innovation but be different and deliver different services and value to our customers,” he said.
In doing so, Smith has tried to balance the heft of being part of a £10 billion global corporation, which he admits has been beneficial in building partnerships, providing global coverage and securing investment for technology and staff, with the agility, energy, innovation and specialism of a start-up or a boutique-style business, because his research shows that customers want to work with cybersecurity specialists, not general IT providers and MSPs that have failed to provide the bespoke protection businesses need.
To this end, Smith has prioritised innovation and customer relevancy.
“What we’re trying to do is focus on the customer and being relevant, because we recognise that if we want to succeed in this globally, we need to offer something slightly different to the marketplace,” he said.
“Our customers want diverse choice, they want a reputable brand, they want to speak to experts, but increasingly they are saying make that advice relevant to us. One of our customers, a global manufacturer and one of the biggest coffee brands serving High Street outlets in the UK, said to us: ‘We’ve had three different cyber security companies come in. They all tell us that our software is out of date. They all tell us that we need to do this, we need to buy this software, we need to buy this tool, but none of them understands how our factories work and how our business operates’. That’s the difference we can provide. People want relevant advice. They don’t want one- size-fits-all ICT security or cybersecurity packages.”
AI & hyper-automation
Through Kyocera’s existing customer relationships, Kyocera Cyber clearly has a large group of businesses to go after and a built-in advantage when it comes to understanding their businesses, something it is doubling down on by putting AI and hyper-automation at the core of its offering.
“When we started to build Kyocera Cyber two and a half years ago, there was one thing Japan pushed really hard on which was for us to integrate AI into our operations from the start and to have hyper- automation at our core. Hyper- automation isn’t only about our operations; it’s about the customer side, too. That’s where we think the customer demand is and where we believe we can be a bit different in the marketplace.”
One of the benefits of the Torq Hyperautomation Platform used by Kyocera’s SOC is its ability to automate alert handling and SOC responses at machine speed, which massively reduces threat detection and remediation times and helps address the tech sprawl and alert fatigue experienced by in-house and outsourced SOCs alike (see survey findings on page 28).
Speaking at the launch of Kyocera Cyber, Usman Gulfaraz, Torq VP of Sales EMEA, pointed out that the net effect of new cybersecurity tools introduced in recent years – EDR, threat intel, SIEM and SOAR – has been bloated cybersecurity operations that still involve significant manual work and time-consuming customisation and integrations.
“The reality is that through this amalgamation of technology, we are a lot farther away from an operationally efficient organisation than ever,” he said.
“This is where Torq comes in and says ‘You have all the data. You’ve got your SIEM, you’ve got your EDR tools, you’ve got the information readily available, you’ve got a SOC operation. What if we, in the spirit of no code-low code, were able to leverage the AI capacity that we have and the computational power that is available to all of us today to hyper-automate to the point where you are no longer dependent on manual, lethargic, legacy issues and can create in five minutes an automation that would once have involved months and months of customisation?
And what if we could do that with no code-low code so that someone in marketing could build a workflow or use case with even more structure and framework and reliability and future proofing than your best analyst? What if you’re able to leverage that hyper- automation and run a full SOC case management end to end for any issue that comes in, from understanding what it is in real time to actual remediation? This is what Torq does. And that’s why we’ve been growing like wildfire.”
Gulfaraz suggests that the priority now is not more visibility but the speed at which you are able to detect something and how quickly you can respond to it, irrespective of the technology stack that you have.
“You can have a dependency on Crowdstrike. You can have a dependency on Sentinel One. You can have a dependency on anything, but if it’s not talking to your organisation and the people that are able to take action, it really doesn’t mean anything,” he said.
Personalisation at speed
Gulfaraz adds that as well as resolving problems much more quickly, Torq expands the relationship an MSSP can have with customers by enabling them to suggest ideas that can be rolled out in a matter of minutes, making them much more of a strategic partner.
As an example of what this might mean in practice, Smith cites the efficiencies Kyocera itself has brought to the management of alerts caused when a member of staff travels abroad with a company smartphone, tablet and/or laptop and neglects to register that they will be logging on from a different region.
“When that person logs on in Germany, the SOC is flooded with alerts because their mobile phone, their laptop, their watch are all logging in. Someone consolidates those alerts, has a look on the HR system, but there’s no record of them being abroad because they didn’t register to travel. The next step is to see whether the telemetry on their device reveals where the device is. We’re 20 minutes in now. Next, you’ll have to message the person to find out where they are and, after they’ve apologised for not registering, clear all those alerts down. Or maybe not. If it turns out they are travelling but not in Germany, you’ll have to revoke all their sessions, change their passwords, reset their MFA,” he explained.
“When we started to look at this scenario, it was obvious that every company does things slightly differently. If you run a SOC or provide that service to customers, you want a one size fits all otherwise your costs explode, but you can’t fit into every business process. What Torq enables us to do in just 5-10 minutes is build that workflow utilising AI and offer that personalised approach to the customer. Instantly, our AI agent within our SOC is communicating with the individual concerned, finding out where they are and either closing down all of the alerts or revoking all of their sessions, disabling their account and getting a highly skilled SOC agent to analyse what’s going on.
“We started out with that proof of concept with Torq and built that workflow, integrated into our Azure AD, our HR system and our SOC within 15 minutes. We believe that ability to tailor our service to our customers’ needs is a differentiator.”
Smith added: “Partnering with Kyocera Cyber means customers can choose what works best for them, whether that means fully outsourcing to our M-SOC or adopting a blend of managed security services to extend their coverage. Joining forces with Torq is key to this, as their platform helps ensure our proprietary architecture is best-equipped to offer peace of mind to customers. We look forward to seeing the new brand grow, alongside our collaboration with Torq.”


Be First to Comment