Customer Case Study · Security Operations
From an underperforming provider
to an in-house SOC — in four weeks
How Small Robot helped a national retailer replace an underperforming incumbent security provider with its own Splunk-based detection and response capability — reaching parity with the outgoing service in two days.
Client name, logo and incumbent provider identity withheld at the customer's request(name withheld)
The starting point
A national retailer, an underperforming security provider, and a decision to bring it in-house.
The client is a national retailer with the scale, brand exposure and customer data holdings that make it a genuine target — the kind of business where a security incident is a headline, not just an internal issue. Security monitoring and response had been outsourced to a third-party provider, the model many retailers of this size start with.
That incumbent provider was not performing to the standard the business needed. Rather than switch to another external provider and risk the same outcome, the client made a different call: build the capability internally, on a platform it would own and control. That decision — not a security incident — is what set the engagement in motion.
The challenge
Replace an external provider without a gap in coverage, and do it on a platform the client would run itself.
An underperforming incumbent
The existing third-party security provider was not delivering the coverage or responsiveness the business expected — the trigger for the client's decision to stop outsourcing the function altogether.
No coverage gap allowed
Moving from an external provider to an in-house capability had to happen without a period of reduced protection. The new capability needed to match — not eventually approach — what the incumbent was meant to be providing, and do it fast.
Why the timeline mattered
Every day running two security models at once — winding down a provider while a new capability comes online — is a day of ambiguity about who is actually watching the environment. The brief was not just "build an in-house SOC." It was "build one fast enough that the gap is never real."
What Small Robot did
Platform, detection and response — built and owned in-house from day one.
- Deployed Splunk Enterprise Security. The platform was configured for the client's own environment, not carried over from the incumbent's tooling.
- Developed detection analytics. Built the detection content the retailer's environment needed, engineered to reach and exceed what the incumbent was covering.
- Developed response playbooks. Documented the response steps for each detection, so response no longer depended on an external provider's own runbooks.
- Implemented the playbooks in Splunk SOAR. Converted those documented steps into orchestrated, repeatable automation the client's own team could execute.
Four weeks, three phases
Enterprise Security and detections first, then playbooks, then automation.
The results
Parity with the outgoing provider in days, full capability in weeks.
| Area | Before | After |
|---|---|---|
| Security coverage | Outsourced to a third-party provider not meeting expectations | Matched incumbent coverage within two days; now exceeded via purpose-built detections |
| Detection capability | Dependent on the incumbent's own detection content | Splunk Enterprise Security deployed with detections built for this environment specifically |
| Response capability | Response processes owned and run by the external provider | Documented playbooks implemented as automation in Splunk SOAR, owned by the client |
| Ownership & control | Security operations sat with a third party | Security operations brought fully in-house, on a platform the client controls |
A note on the two-day figure
The client confirmed parity with the incumbent's detection coverage was reached within two days.
In their words
“Your team work fast and we love the result. Thank you for the collaboration and knowledge transfer to get us up to speed quickly.”
Where things stand today
The client's own team now runs Splunk Enterprise Security and Splunk SOAR, using the detections and playbooks built during the engagement. Security operations sit fully in-house, on a platform the business controls end to end — the outcome the original decision to insource was aiming for.