Un leader nel Magic Quadrant™ Gartner® 2025 per la Protezione di Endpoints. Cinque anni di fila.Leader nel Magic Quadrant™ di Gartner®Leggi il report
La tua azienda è stata compromessa?Blog
IniziareContattaci
Header Navigation - IT
  • Piattaforma
    Panoramica della piattaforma
    • Singularity Platform
      Benvenuti nella Sicurezza Aziendale Integrata
    • Portfolio di Sicurezza AI
      Leader nelle Soluzioni di Sicurezza basate su AI
    • Come funziona
      La Differenza di Singularity XDR
    • Marketplace di Singularity
      Integrazioni con un solo clic per sbloccare la potenza di XDR
    • Prezzi e Pacchetti
      Confronti e indicazioni in sintesi
    Data & AI
    • Purple AI
      Accelerare la SecOps con l'IA generativa
    • Singularity Hyperautomation
      Automatizzare facilmente i processi di sicurezza
    • AI-SIEM
      Il SIEM AI per il SOC autonomo
    • Singularity Data Lake
      Alimentato dall'IA, unificato dal lago di dati
    • Singularity Data Lake for Log Analytics
      Ingestione dei dati da ambienti on-premise, cloud o ibridi senza soluzione di continuità
    Endpoint Security
    • Singularity Endpoint
      Prevenzione, rilevamento e risposta autonoma
    • Singularity XDR
      Protezione, rilevamento e risposta nativa e aperta
    • Singularity RemoteOps Forensics
      Orchestrare l'analisi forense su larga scala
    • Singularity Threat Intelligence
      Intelligence avversaria completa
    • Singularity Vulnerability Management
      Scoperta di risorse illecite
    • Singularity Identity
      Rilevamento e risposta alle minacce per l'identità
    Cloud Security
    • Singularity Cloud Security
      Bloccare gli attacchi con una CNAPP basata sull'IA
    • Singularity Cloud Native Security
      Proteggere il cloud e le risorse di sviluppo
    • Singularity Cloud Workload Security
      Piattaforma di protezione del carico di lavoro del cloud in tempo reale
    • Singularity Cloud Data Security
      Rilevamento delle minacce potenziato dall'intelligenza artificiale
    • Singularity Cloud Security Posture Management
      Rilevare e correggere le configurazioni errate del cloud
    Protezione dell’IA
    • Prompt Security
      Proteggere gli strumenti di IA in tutta l’azienda
  • Perché SentinelOne?
    Perché SentinelOne?
    • Perché SentinelOne?
      Cybersecurity per il futuro
    • I nostri Clienti
      Scelta dalle aziende leader nel mondo
    • Riconoscimenti dal mercato
      Testato e comprovato dagli esperti
    • Chi siamo
      Il leader del settore nella sicurezza informatica autonoma
    SentinelOne a confronto
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Settori Verticali
    • Energia
    • Governo Federale
    • Servizi Finanziari
    • Sanitario
    • Scuola Superiore
    • Istruzione Primaria e Secondaria
    • Manifatturiero
    • Retail
    • Settore pubblico statale e locale
  • Servizi
    Managed Services
    • Panoramica dei Managed Services
      Wayfinder Threat Detection & Response
    • Threat Hunting
      Competenza di livello mondiale e Threat Intelligence.
    • Managed Detection & Response
      MDR esperto 24/7/365 per tutto il tuo ambiente.
    • Incident Readiness & Response
      DFIR, preparazione alle violazioni & valutazioni di compromissione.
    Supporto, implementazione e igiene
    • Gestione tecnica dei clienti
      Customer Success con un servizio personalizzato
    • SentinelOne GO
      Consulenza per l'onboarding e l'implementazione
    • SentinelOne University
      Formazione live e on-demand
    • Panoramica dei Servizi
      Soluzioni complete per operazioni di sicurezza senza interruzioni
    • SentinelOne Community
      Community Login
  • Partner
    La Nostra Rete
    • Partner MSSP
      Successo più veloce con SentinelOne
    • Marketplace di Singularity
      Amplia la potenza della tecnologia SentinelOne
    • Partner specializzati nel Cyber Risk
      Ingaggiare i team per gestire le risposte agli incidenti
    • Alleanze Tecnologiche
      Soluzione aziendale integrata su larga scala
    • SentinelOne per AWS
      Ospitato nelle regioni AWS di tutto il mondo
    • Partner di canale
      Offriamo le soluzioni giuste, insieme
    Per saperne di più sul Programma→
  • Risorse
    Centro Risorse
    • Schede tecniche
    • eBook
    • Video
    • Whitepaper
    • Events
    Accedi a tutte le risorse→
    Blog
    • Riflettori puntati sulle funzionalità
    • Per CISO/CIO
    • Direttamente dalla prima linea
    • Identità
    • Cloud
    • macOS
    • Blog di SentinelOne
    Blog→
    Risorse Tecniche
    • SentinelLABS
    • Glossario del Ransomware
    • Cybersecurity 101
  • Chi siamo
    Informazioni su SentinelOne
    • Informazioni su SentinelOne
      Il leader di mercato nella sicurezza cyber
    • SentinelLABS
      Ricerche sulle minacce per il moderno Threat Hunter
    • Carriere
      Opportunità di lavoro
    • Stampa e notizie
      Annunci dell’azienda
    • Blog
      Tutto sulle minacce alla cyber security, le ultime notizie e molto altro
    • FAQ
      Ottieni risposte alle domande più frequenti
    • DataSet
      La Piattaforma dal vivo
    • S Foundation
      Garantire un futuro più sicuro per tutti
    • S Ventures
      Investire nella sicurezza e nei dati di prossima generazione
IniziareContattaci
Hero Banner
Q2

Q2 Boosts Efficiency and Reduces Attack Volume by 97% with SentinelOne and AWS

“We’re seeing faster queries, better performance, and can store data for longer.”

Lou Senko, Chief Customer Experience Officer, Q2

Download this Customer Success Story

Read how Q2 reduces attack volume by 97% with SentinelOne and AWS
Download as PDF
Back to Our Customers
Indice dei contenuti
Q2

Overview

Q2, a digital banking platform provider serving community and regional financial institutions, found that it needed more scalable and adaptable tools to match its evolving cloud architecture and a rapidly changing threat landscape. Operating with Amazon Web Services (AWS), Q2 chose AWS Partner SentinelOne to modernize and expand its security operations without increasing overhead. After deploying a new security posture that included SentinelOne’s AI-powered platform, the financial technology company saw a 97 percent reduction in malicious sessions with fewer than 2,000 attempts per minute. With improved performance, deeper visibility, and automated protection, Q2 has strengthened its security posture while continuing to deliver trusted digital banking experiences at scale.

Opportunity

Juggling Growth, Trust, and Threats in a High-Stakes Digital Environment

Based in Austin, Texas, Q2 is a mission-driven provider of digital transformation services for financial services, powering online experiences for more than 26 million users and 1,400 banks and credit unions. In addition to serving national banks, Q2 remains committed to its founding goal of supporting communities by helping local banks and credit unions compete with larger institutions through secure, innovative digital services.

These institutions depend on Q2 for performance and reliability, and any disruption, whether from downtime or a security event, could damage reputations and impact local economies. Facilitating more than $3.5 trillion in annual transactions—which is over 10 percent of US GDP—along with managing 41 petabytes of customer data, Q2 must consistently meet exceptional standards for availability, resiliency, and security.

Q2 relied on a legacy endpoint detection and response (EDR) solution that used application whitelisting, which became increasingly difficult to manage across 12,000 servers and hundreds of bespoke customer environments. “We tried re-implementing an EDR solution with another vendor and got everything cleaned up, but within four months we were right back where we started,” said Lou Senko, chief customer experience officer at Q2. “It became a challenge to maintain that solution while also sustaining a strong security posture.” This prompted Q2 to seek a more scalable and intelligent solution that could evolve with emerging threats, reduce operational burden, and support the company’s broader innovation goals, which included automated workflows to assist Q2’s newly formed security operations center (SOC).

Solution

Building a Future-Ready Security Architecture with AI

As Q2 transitioned from co-located data centers to a distributed cloud architecture, it conducted an EDR proof of concept with three different vendors. The company ultimately chose SentinelOne for its artificial intelligence (AI)–powered cybersecurity solutions, ability to scale across diverse workloads, responsive engineering support, and alignment with Q2’s innovation and security roadmap. Because it’s built entirely on AWS, SentinelOne’s suite of solutions integrates deeply with Q2’s Amazon Elastic Compute Cloud (Amazon EC2) instances. It would also further protect the SQL databases that Q2 hosts in Amazon Relational Database Service (Amazon RDS).

To build out its new security approach, Q2 deployed SentinelOne’s Singularity Platform, which provides autonomous, AI-driven threat detection, response, and remediation across endpoints, cloud workloads, and identities to deliver unified cybersecurity protection. This agent-based solution replaced Q2’s previous EDR solution, delivering real-time threat detection and response across Q2’s 13,000 endpoints.

“We deployed agents across everything we could touch, and SentinelOne was a great partner in making that happen,” Senko said. To strengthen incident response, Q2 added Vigilance MDR, which extends the capabilities of the SentinelOne Singularity Platform with 24/7 expert monitoring, threat validation, and response support. This would help Q2’s security teams ensure that unfamiliar threats were triaged and addressed immediately, with the option to escalate issues to SentinelOne’s experts if needed.

Q2 then implemented Purple AI, SentinelOne’s agentic AI security analyst that utilizes generative AI, natural-language queries, intelligent threat guidance, and automated investigation workflows to enhance usability and insight generation. Purple AI is powered by Amazon Bedrock, a fully managed service that allows developers to build and scale generative AI applications using foundation models from leading AI providers through a simple API, without managing infrastructure. Q2 leverages Purple AI to help its SOC analysts surface insights and accelerate critical response and remediation actions, such as isolating. ”Purple AI will give our team an intuitive way to get the answers they need,” Senko said. “It’s built into the platform, making it easier for our analysts to ask questions and uncover findings they might not have thought to look for, without needing to be experts in the underlying data.”

As Q2’s security maturity evolved, the company adopted SentinelOne’s Watchtower Pro, a threat hunting service that augments its internal team with proactive intelligence and analysis—a critical ingredient for protecting banks’ digital interactions. Recognizing the need to unify operational and security data, Q2 migrated its entire data lake into SentinelOne’s Singularity AI SIEM. As a cloud-native, AI-driven security information and event management (SIEM) platform, it ingests and correlates data from Q2’s security stack, consolidating alerting, service level agreement tracking, and operational telemetry into a single platform. This includes logs used for fraud investigations and subpoena responses, which previously required time-consuming backup restores. Now, that data is readily accessible and queryable. Together, these solutions formed a tightly integrated, AI-driven security architecture.

“Purple AI will give our team an intuitive way to get the answers they need.”
- Lou Senko , hief Customer Experience Officer, Q2

Outcome

Stronger Security Thwarts Bad Actors, Reducing Attack Volume by 97%

With a new security stack in place, Q2 has significantly strengthened its security posture while improving operational efficiency across its hybrid cloud environment. The company now protects 7,000 endpoints and 400,000 containers with real-time threat detection, automated response, and AI-driven insights. This allowed the company to enhance team productivity as it scaled up without increasing headcount. Most notably, the company has gone from seeing 70,000 malicious sessions per minute to fewer than 2,000, a 97 percent reduction in attack volume. Credential stuffing attacks have also become less effective. Before using SentinelOne as part of its security stack, attackers would spend about 150 hours attempting to breach Q2’s systems. Now, attackers abandon Q2 as a target much faster—in just 130 minutes, a 1,000 percent reduction from before—due to the strength of the company’s layered defenses.

Denial-of-service (DDoS) attacks have also declined sharply. Two years ago, Q2 experienced 30,000 DDoS events per month, translating to about 37 per hour. Today, that number is down by 95 percent, which has freed up resources and lessened operational noise. “We’re seeing faster queries, better performance, and can store data for longer,” Senko said. “And, we are managing workloads that are thousands of times bigger than they were five years ago.” By consolidating tools, automating response, and enabling deeper visibility, Q2 has improved its security outcomes and positioned itself to scale securely as it continues to innovate in digital banking. This helps the company continue to build trust with customers and improves the productivity and satisfaction of its internal security teams. “Over the years, SentinelOnehas shown that it’s always thinking, ‘What is next? Where should we be going?’ And when my vendor is thinking about the next emerging threat and how to defend against it, I don’t have to,” Senko said.

Location

Global

Industry

Financial Services

Website
www.q2.com
Employees

1,001-5,000

Products & Services Used

Singularity™ Platform

Singularity™ XDR

Singularity™ Hyperautomation

Purple AI

Singularity™ MDR

DFIR

WatchTower Pro

Back to Our Customers

More Success Stories

10x Banking

10x Banking

View Success Story
Credit Saison

Credit Saison

View Success Story
FIMBank

FIMBank

View Success Story

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Column 1 Background

Connect with an Expert

Get a Demo
Request Demo
Request Demo
Column 2 Background

Take a SentinelOne Product Tour

Take a Tour
Take a Tour
Take a Tour
  • Iniziare
  • Richiedi una demo
  • Presentazione del prodotto
  • Perché SentinelOne
  • Prezzi e Pacchetti
  • Contattaci
  • Contattaci
  • Supporto
  • SentinelOne Status
  • Lingua
  • Italiano
  • Piattaforma
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Servizi
  • Wayfinder TDR
  • SentinelOne GO
  • Gestione tecnica dei clienti
  • Servizi di Supporto
  • Settori Verticali
  • Energia
  • Governo Federale
  • Servizi Finanziari
  • Sanitario
  • Scuola Superiore
  • Istruzione Primaria e Secondaria
  • Manifatturiero
  • Retail
  • Settore pubblico statale e locale
  • Cybersecurity for SMB
  • Risorse
  • Blog
  • Labs
  • Video
  • Presentazione del prodotto
  • Events
  • Cybersecurity 101
  • eBooks
  • Stampa
  • Pers
  • Notizie
  • Glossario del Ransomware
  • Azienda
  • Chi siamo
  • I nostri clienti
  • Opportunità di Lavoro
  • Partner
  • Legale e conformità
  • Sicurezza e conformità
  • S Foundation
  • S Ventures

©2026 SentinelOne, Tutti i diritti riservati.

Informativa sulla privacy Condizioni di utilizzo