MXDR for Google Cloud

www.mergeworld.com
The Challenge
A hard deadline and a fragmented estate
The requirements went well past a like-for-like replacement:
- Unified visibility across more than fifteen log sources spread over two clouds
- Compliance-grade evidence that would stand up to HITRUST and SOC 2 requirements
- A partner, not a vendor — someone to advance the security program, not just operate a new tool
- No gap in coverage during the cutover
Roze San Nicolas on $500k cost savings at MERGE
Roze San Nicolas, Director of TechOps, Information Security at MERGE, with Jeremy Hehl, Chief Evangelist at Foresite. Recorded at Google Cloud Next.
The Solution
Prove it first, then migrate
Foresite structured the work in phases so MERGE could see value before committing to a full platform move.
- Assess
A Google Workspace and Google Cloud security assessment established the baseline: what was covered, what was not, and where the blind spots sat. - Prove
A scoped proof of concept validated Google SecOps against MERGE's real telemetry and real detection requirements, before any contract decision. - Migrate
A full migration to Google SecOps, delivered under Foresite's Catalyst Citadel MXDR service. Foresite handled parser development, telemetry integration through BindPlane, and detection engineering across the log estate. - Extend
Security Command Center Enterprise centralized cloud security posture management across both clouds. Google Threat Intelligence enriched detections. Managed vulnerability management and offensive security testing carried the program past SIEM into continuous security operations.
|
Practitioner-governed, human in the loop
Autonomous investigation runs at machine speed. Named Foresite practitioners validate every high-impact action before execution. Agentic never means uncontrolled. |
“We have a full-time SOC that is triaging alerts, doing all the detections and responding and escalations when needed, for governance, risk and compliance and maturing our security program.
And that's the real ROI for us, because then we're really able to focus on providing that whole human value to our clients.”
The Outcome
One platform, one team, across two clouds
MERGE now runs a single security operations platform across its entire multi-cloud footprint, operated by Foresite.
- Unified visibility. Telemetry from across Azure and Google Cloud lands in one platform, giving the team a view they did not previously have.
- Compliance evidence in one place. SCCE centralizes posture and audit evidence in support of MERGE's HITRUST certification goals.
- Operational weight lifted. Foresite's managed service runs detection and response, so MERGE's team is accountable for direction rather than console time.
- The scope kept growing. What began as a SIEM migration is now a multi-year program spanning detection and response, cloud posture, vulnerability management, and penetration testing.
Where strategy, creative, and technology meet
MERGE is a marketing and technology agency that unites strategy, creative, and technology to deliver performance for clients across healthcare, financial services, and consumer brands.
Modernizing off a legacy SIEM?
Foresite migrates enterprises off Splunk, Sentinel, and QRadar onto Google SecOps, then runs it as a managed outcome with named practitioners in the loop.
Ready to Accelerate Your Google SecOps Deployment?
In this conversation, Joe McGee (Security Operations Manager at Copado) and Jeremy Hehl (VP of Business Development at Foresite) discuss how they partnered to operationalize security across Copado’s DevOps pipelines and containerized workloads.
Using Google SecOps, Security Command Center Enterprise, and Gemini AI—delivered through Foresite’s Catalyst Bridge platform—Copado achieved real-time detection, full-stack visibility, and a transparent, scalable security model without compromising customer trust.
