How A Leading Museum Automated Its Security Operations with Torq

Contents

Get a Personalized Demo

See how Torq harnesses AI in your SOC to investigate, prioritize, and respond to threats faster.

Request a Demo

The organization at the center of this story is one of the most visited cultural institutions in the world, dedicated to preserving history and educating the public.

Protecting that mission — and the digital infrastructure behind it — falls to a lean security team responsible for everything: SSO integrations, email, endpoints, servers, applications, websites, and micro-segmentation across the entire organization.

It’s a wide surface for any security team to cover. It’s an even wider one when your institution’s global profile and cultural significance make you a target. Geopolitical tensions have driven an increase in cyberattacks against the institution, demanding a security posture well beyond what the team could deliver manually.

This is the story of how that team went from fully manual operations to automated threat blocking, identity lifecycle management, and endpoint response.

When Every Security Action Depends on a Human, Nothing Moves Fast Enough

Before The Torq AI SOC Platform, the security team’s day-to-day was what you’d expect from an operation running without automation: reviewing logs by hand, writing custom scripts, pulling reports, working through spreadsheets. Every step required someone to touch it.

That meant threat response moved at human speed. A device querying a malicious URL would get flagged, but by the time an analyst reviewed it, confirmed it, and took action, a week had passed. A week of known, unresolved exposure.

The team initially looked at Torq for security playbooks to automate detection and response workflows that consume analyst time. Two things made it the right fit: it was faster to build in than native tooling, and the whole team could use it without specialized coding skills. For a security operation where everyone covers everything, that accessibility was a requirement.

Migrating to Okta: The Problem Torq Solved in Hours

The museum undertook a major overhaul of its identity infrastructure, migrating from Active Directory–sourced accounts to Okta as the primary identity provider. It’s the kind of migration that touches every user, every application, and every access workflow in the organization.

The problems surfaced almost immediately. When users didn’t respond to Okta’s verification prompts within the predefined time window, their accounts were automatically flagged, and email access was locked. For a museum with staff across departments — curators, educators, researchers, operations — lockouts stalled work, frustrated employees, and generated a cascading queue of support requests.

The obvious fix was to build an automated workflow in Okta itself. But Okta Workflows is its own ecosystem, time-intensive to implement, and creates a knowledge gap for the team. Torq offered a faster path. Through a straightforward API call, the team built a workflow that automatically detects locked-out users and clears the flags, allowing accounts to be onboarded without manual intervention.

That migration fix opened a bigger door. The team discovered that Torq could do things with Okta data that the native dashboard couldn’t. They started pulling error logs through Torq and running analysis to surface root causes, not just the symptoms the dashboard displayed. What started as a migration fix became an ongoing operational layer on top of their identity infrastructure, giving the team better visibility into their identity environment than the identity provider itself.

Security Automation That Grew into Something Bigger

The team started with security automation and quickly found that Torq’s platform could absorb manual work across security and IT operations alike. What began as a handful of security playbooks has grown into a library of automated workflows spanning threat response, identity management, endpoint security, and infrastructure monitoring.

Automated Threat Blocking

The team’s very first workflow is still one of the most impactful. The museum’s network monitoring tool continuously watches for suspicious outbound connections. When a device is flagged for querying a potentially malicious URL, Torq automatically sends the indicator to VirusTotal for cross-referencing against dozens of antivirus engines. More than four positive hits? Blocked immediately, without a human in the middle.

Before Torq, an analyst had to review the flag, look up the URL, make a judgment call, and take action. Now it runs in seconds.

Endpoint Enrichment and Response

When SentinelOne detects a suspicious event on an endpoint, the alert triggers a Torq micro-playbook that automatically enriches the event. Torq pulls the relevant indicators — hashes, IPs, domains — and queries them against VirusTotal and other threat intelligence sources. Based on the results, the playbook either documents the event as benign or executes a blocking action, without requiring an analyst to manually copy indicators between tools.

Baseline Scanning and Configuration Monitoring

Tools get deployed with specific security baselines: hardened configurations, required settings, expected states. Over time, those baselines drift. A setting gets changed during troubleshooting and is never reverted. An update overwrites a configuration. A new deployment doesn’t match the standard.

The team uses Torq to scan their tool stack and flag discrepancies against defined baselines. Instead of manually auditing on a schedule — or discovering drift after an incident — Torq surfaces gaps proactively.

Automatic Reboot for Critical Updates 

Patching is one of the most basic security hygiene practices and one of the easiest to let slip. A critical update lands, but the reboot requires coordination: confirm the asset is clear, schedule a window, and follow up. For a lean team, that coordination competes with every other task on the list.

The team built a Torq workflow that monitors for assets with pending critical updates and triggers an automatic nightly reboot. Patches are applied on schedule, every time, without manual follow-up.

Stale Asset and Duplicate Cleanup 

Every tech stack accumulates clutter. Devices get decommissioned but never removed. Endpoints are reimaged, creating duplicates. Orphaned records pile up. Each one is a blind spot — an asset that shows as managed when it isn’t, or a duplicate that skews reporting and wastes license seats.

Torq continuously scans the team’s tech stack, identifies stale or duplicate assets, and cleans them up. What used to be a periodic manual audit is now a continuous hygiene function.

Automatic Re-Enablement of Disabled Agents 

A disabled security agent is an unmonitored endpoint. The disable might be intentional (for troubleshooting), accidental (due to a bad update), or the first sign of compromise. The longer it stays disabled, the bigger the gap.

Torq monitors disabled agents and automatically re-enables them. The team is notified immediately — if the disable was legitimate, they know. If it wasn’t, the gap would be closed before it could be exploited.

The Impact

  • Threat response moved from days to seconds. Malicious activity that used to sit in a queue waiting for human action is now caught and blocked the moment it’s confirmed.
  • Routine bottlenecks disappeared. Okta onboarding issues that required tickets, callbacks, and meetings are resolved automatically. Endpoint events that waited for manual enrichment are handled in the background. The team focuses on work that requires human judgment, not work that was waiting for someone to get to it.
  • Security hygiene runs continuously. Critical updates are applied overnight. Stale assets are cleaned up. Disabled agents are re-enabled. The team doesn’t have to remember to do these things; they just happen.
  • The platform expanded beyond security. The team came to Torq for SOC automation. The fact that it’s now embedded across multiple operations says something about how much manual work was hiding in plain sight across the organization.

“Using Torq, we have the ability to retrieve data from multiple applications and mirror human action in an automated way. That saves time, and where we really need to save time is on the action side. Instead of waiting a week to block a bad IP address, Torq lets us do it almost instantaneously. It’s a major risk reduction.” – Michael Trofi, CISO

Defending History Requires Modern Defense

The museum exists to preserve history and make sure the world never forgets. That mission draws millions of visitors, powers a global digital presence, and makes the institution a target.

The security team didn’t automate because it checked a box. They automated because the mission was too important to protect at human speed. The automation this team built is the foundation the AI SOC is built on: the shift from human-speed operations to machine-speed defense. The threats keep evolving, and so does the team.

This major museum’s team is proof of what the data shows: lean SOCs that deploy the right automation get ahead. See how 450 security leaders are thinking about AI, automation, and the future of security operations.

SEE TORQ IN ACTION

Ready to automate everything?

“Torq takes the vision that’s in your head and actually puts it on paper and into practice.”

Corey Kaemming, Senior Director of InfoSec

“Torq offers unprecedented protection and drives extraordinary efficiency for RSM and our customers.”

Todd Willoughby, Director

Compuquip logo in white

“Torq saves hundreds of hours a month on analysis. Alert fatigue is a thing of the past.”

Phillip Tarrant, SOC Technical Manager

Fiverr logo in black

“The only limit Torq has is people’s imaginations.”

Gai Hanochi, VP Business Technologies

Carvana logo in black

“Torq Agentic AI now handles 100% of Carvana’s Tier-1 security alerts.”

Dina Mathers, CISO

Riskified logo in white

“Torq has transformed efficiency for all five of my security teams and enabled them to focus on much more high-value strategic work.”

Yossi Yeshua, CISO