Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Sangfor: How UMS Strengthened Cybersecurity with MDR

Sangfor
07/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


systems every day to learn, teach, conduct research, and stay connected. Behind these systems is a team responsible not only for keeping learning services available, but also for keeping the university's digital environment secure. At Universiti Malaysia Saba, one of our biggest challenges is balancing openness with cybersecurity. As a university, we encourage collaborations, accessibility, and knowledge sharing. Students, researchers, and external communities interact with our system every day, but this openness also naturally increases our cybersecurity exposure. So the challenge is finding the right balance between protecting students' records, staff information, and sensitive research data, and how we can keep our digital environment accessible at all times. This also means ensuring our cybersecurity controls align with Malaysia's cybersecurity and data-protecting expectations. And this is including the Cybersecurity Act 2024 and also PDPA. From a technology evaluation perspective, our focus was not simply to purchase more cybersecurity products, but to enhance our operational capabilities. We already have several security systems in place, including firewalls, endpoint protection, and network monitoring. These systems generate a lot of alerts and security information, but the question is how we can understand what really matters and quickly take action on that information and more effectively. This led us to consider MDR, a more practical model that could strengthen our security operations without investigating in full 24x7 SoC, including advanced platforms and up to five additional antenna hires. That would be a major commitment and cost for the university. We looked at several MDR services from leading vendors and local MSSP. In the end, SEM4Athena MDR stood out because it provides the right fit for our requirements. Overall, SEM4Athena MDR gives us the right balance of capability, support, deployment speed, and value for the investment. Before implementing SEM4Athena MDR, our security operations were heavily manual and lack consistency. We had around 90 IT offices and technicians, but only three dedicated to cybersecurity. During peak operational periods, our environment could generate around 1,000 logs per hour. With a small cybersecurity team, it was not possible to review everything manually. For real threats, our team had to manually collect and correlate logs from multiple systems to understand what happened. Depending on the case, investigation could take weeks and in some cases up to one month. Before, we had a clear picture of what happened. After implementing SEM4Athena MDR, the biggest improvement is that our team no longer had to start from raw alerts. The MDR team analyzed all the security events. First, and only escalated verified threats or incidents to us. This reduced noise and freed up our team to focus on higher value works. 24x7 monitoring is also important for us. Previously, we did not have enough resources to monitor continuously outside office hours, during weekends, or on holidays. With SEM4Athena MDR, we now have consistent monitoring, containment support, and escalation through instant messaging or phone calls. So we know what is happening and can decide the next step even when we are not in the office. One of the best outcomes of adopting SEM4Athena MDR is that we now have fewer emergency cybersecurity escalations and management meetings. For me personally, no news means good news. It gives us greater confidence that the university environment is being monitored continuously and not proactively. Cybersecurity investment is not only about financial ROI. It is also about protecting operational continuity, institutional reputation, and ensuring the university can continue serving students and researchers securely. By working together with SEM4Athena MDR, we were able to strengthen our cybersecurity readiness much faster. For University Malaysia Sabah, cybersecurity is not a one-time project. It is a continuous journey of strengthening resilience, improving visibility, and protecting the future of digital education.

TL;DR

  • UMS serves over 19,200 students and 3,600 staff daily, creating broad cybersecurity exposure that a team of just three dedicated security staff could not adequately manage manually.
  • Generating around 1,000 logs per hour at peak, UMS faced investigation timelines of weeks or even a month per incident before adopting a managed detection and response model.
  • Sangfor Athena MDR was selected over competing MDR providers and local MSSPs for its balance of capability, support, deployment speed, and overall value for the university's investment.
  • Post-deployment, UMS benefits from 24/7 threat monitoring, pre-validated escalations, and fewer emergency cybersecurity management meetings — with the team freed to focus on higher-value work.

Summary

Universiti Malaysia Sabah (UMS), a Malaysian public university serving more than 19,200 students and 3,600 staff, faced a fundamental tension common to higher education institutions: maintaining an open, collaborative digital environment while meeting increasingly stringent cybersecurity obligations. With compliance requirements including Malaysia's Cybersecurity Act 2024 and the Personal Data Protection Act (PDPA), UMS needed to move beyond its existing stack of firewalls, endpoint protection, and network monitoring tools — all of which were generating roughly 1,000 logs per hour during peak periods. With only three staff dedicated to cybersecurity out of a 90-person IT function, manual investigation of incidents could take weeks or even a month to complete. Rather than invest in a full 24/7 in-house Security Operations Center — which would have required advanced platforms and up to five additional hires — UMS evaluated several MDR providers before selecting Sangfor Athena MDR for its balance of capability, deployment speed, and cost-effectiveness. Post-deployment, the UMS cybersecurity team no longer starts from raw alerts; the Athena MDR team pre-validates and escalates only confirmed threats. Continuous monitoring now extends through weekends and holidays via instant messaging and phone escalation. The result is fewer emergency management escalations, greater operational confidence, and a faster path to cybersecurity maturity — without the overhead of building an internal SOC from scratch.

Chapters

0:00 - UMS Digital Environment Overview
0:28 - Balancing Openness and Security
1:29 - Technology Evaluation Approach
2:43 - Pre-MDR Security Challenges
3:28 - Outcomes After Athena MDR Deployment
4:44 - Cybersecurity as a Continuous Journey

Key Quotes

0:28 "At Universiti Malaysia Saba, one of our biggest challenges is balancing openness with cybersecurity."
2:00 "This led us to consider MDR, a more practical model that could strengthen our security operations without investigating in full 24x7 SoC, including advanced platforms and up to five additional antenna hires."
3:18 "Depending on the case, investigation could take weeks and in some cases up to one month."
4:30 "For me personally, no news means good news."
4:44 "Cybersecurity investment is not only about financial ROI. It is also about protecting operational continuity, institutional reputation, and ensuring the university can continue serving students and researchers securely."

FAQ

Why did UMS choose an MDR service instead of building its own Security Operations Center?

UMS determined that standing up a full 24/7 in-house SOC would require significant investment in advanced platforms and up to five additional security hires — a major financial and operational commitment. MDR offered equivalent monitoring and response capability at a fraction of the cost and complexity, making it the more practical choice for a university environment.

What specific improvements did UMS see after deploying Sangfor Athena MDR?

UMS eliminated the need to manually triage raw alerts, reduced investigation timelines from weeks to near-real-time, gained continuous 24/7 monitoring coverage including weekends and holidays, and experienced fewer emergency cybersecurity escalations to senior management. The team was freed to focus on higher-value security work rather than log correlation.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • Managed Security
  • Customer Story
  • Compliance & Governance
  • Getting Started
  • Managed Detection and Response
  • Higher Education Cybersecurity
  • Security Operations Center Alternatives
  • Alert Triage and Noise Reduction
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Sangfor: How UMS Strengthened Cybersecurity with MDR

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version