Customer Story

Fortune 500 Distribution Company

A Fortune 500 automotive and industrial distributor transformed its global cloud security operations by migrating from a managed Splunk service to Google Security Operations (Google SecOps) with RKON.

This migration delivered a unified, AI-driven SOC that improved visibility, reduced costs, and empowered internal teams with direct control across a complex multi-cloud environment.

 

Customer Story - Fortune 500 Automotive Distributor

Client:

Global industrial and automotive replacement parts distributor

Company Size:

10,000+ stores and fulfillment centers across 17 countries

63,000 employees

Industry:

Automotive & Industrial Distribution

Project Type

Modernized Security Operations (SIEM/SOAR)

Two Coworkers Informal Meeting Laptop

The Challenge

Migrate from a managed Splunk SIEM to an in-house, cloud-native Google Security Operations (SIEM + SOAR) environment. Design, deploy, and train SOC teams for improved detection, visibility, and compliance.

As a global enterprise with a complex IT footprint (including on-premises systems, supply chain platforms, and multi-cloud deployments across GCP, AWS, and Azure), the customer needed a unified, scalable approach to cloud security.

Previously, the company relied on a managed security provider using Splunk, which initially offered baseline visibility. However, as operations and cloud adoption accelerated, the model became inefficient and costly. The security team faced rising ingestion fees, slow response times, and limited flexibility to adapt.

Key challenges:

  • Escalating SIEM and MSSP costs tied to ingestion and service fees
  • Fragmented visibility across retail, distribution, and corporate networks
  • Limited automation and tuning capabilities for detections
  • Compliance and data custody concerns with third-party log management
  • Lack of integrated ticketing and workflow automation

With increasing data volumes, multi-cloud complexity, and strict compliance demands, the company needed a more agile, cloud-native security operations center (SOC).

Our Solution

Migrating to
Google Security Operations

The customer engaged RKON, a trusted Google Cloud Security Consulting Partner, to lead the migration through Partner Service Funds, allowing the project to proceed at no cost to the customer.

RKON designed and deployed a dedicated Google Security Operations tenant (SIEM + SOAR), giving the customer direct control, centralized visibility, and AI-driven automation across its global environment.
home-cards-icon-2

Conducted Architecture Assessment

Across on-premises and multi-cloud environments

 

home-cards-icon-2

Deployed and configured the Google Security Operations tenant

Designed IAM roles and RBAC policies

For least privilege and separation of duties

 

 

home-cards-icon-2

Integrated BindPlane

For enterprise-wide log aggregation

home-cards-icon-2

Ingested and Normalized Logs

From servers, firewalls, SaaS platforms, and multi-cloud systems

home-cards-icon-2

Converted Splunk Detection Rules to YARA-L

And rebuilt dashboards in Google SecOps

home-cards-icon-2

Created end-to-end documentation

Migration diagrams & SOC training materials

home-cards-icon-2

Implementation & Migration

RKON partnered with the customer’s corporate IT and cyber defense teams to design, deploy, and validate the new Google SecOps environment.

Migration milestones: 

  • Led discovery and design workshops to capture business and technical requirements

  • Coordinated cross-functional teams and vendors using detailed project plans, RAID logs, and risk registers

  • Normalized and centralized thousands of log sources into Google Security Operations

  • Developed SOAR playbooks to automate response actions and streamline SOC workflows

  • Validated IAM, monitoring, and compliance requirements for PCI and GDPR readiness

  • Delivered detailed documentation and training to ensure long-term SOC independence

This structured approach ensured a seamless transition, reduced operational risk, and accelerated global delivery.

"Owning our Google SecOps tenant gives us predictable costs and the flexibility to adapt quickly as our business grows. The transition has made our security operations more efficient and aligned with the needs of a global enterprise."
Chief Information Security Officer

The Outcome

Complete Migration from Splunk

Full normalization of retail, distribution, and cloud logs within Google SecOps

 

AI-powered threat detection

Analysts use Google Gemini AI for natural language queries and detection building

Faster Response Times

Incident resolution accelerated from days to hours via automated SOAR playbooks

Cost predictability

Eliminated variable ingestion costs with flat, scalable billing

Unified Visibility

Centralized SIEM/SOAR visibility across multi-cloud and on-prem systems


Enhanced compliance

Simplified PCI and GDPR audit readiness with improved data custody

By migrating from a managed Splunk-based service to Google Security Operations, the company gained complete control of its SOC, reduced operational costs, and improved agility across its global footprint.

Key achievements:

  • Delivered a cloud-native, AI-driven SIEM/SOAR platform

  • Improved compliance, cost predictability, and response time

  • Enabled full SOC ownership and independence

  • Accelerated security transformation through Google’s Partner Service Funds

With RKON’s delivery expertise and Google Cloud’s modern SecOps platform, this global distributor established a scalable, future-ready foundation for cloud security across its enterprise.

“Partnering with RKON and Google Cloud allowed us to move quickly and build a stronger foundation for our security operations.”

- Global Senior Director for Cyber Defense

More Resources

View All