Background
Cardiff University supports more than 15,000 users across its student body, academics, professional services and research community. Its international campus also has extensive collaboration with external third parties and must accommodate bring your own device (BYOD) requirements.

The university was facing a cyberattack every ten seconds on average, with phishing and social engineering among the most prevalent methods.
Its extensive end-user environment and reliance on external collaboration also presented challenges around maintaining data integrity and availability. BYOD added another consideration, requiring strong network access control and posture checking to ensure endpoints met cyber security standards for compliance and patching.
Together, these factors created a complex and constantly changing attack surface.
Challenge
Cardiff University was using four separate and overlapping endpoint security tools to protect its environment.
As well as managing threats across a diverse user base, the university needed to identify vulnerable devices, protect sensitive information and respond to a large volume of security alerts.
The existing approach also placed demands on its security team, with staff required to spend time on reactive alert management rather than more strategic security activities.
The university therefore sought to simplify its security infrastructure while improving its ability to identify, investigate and respond to threats at scale.
Solution
The university replaced its four endpoint security tools with a single, connected network and endpoint security platform from Palo Alto Networks.
The new approach uses Palo Alto Networks’ Cortex XDR and Cortex XSOAR alongside its Network Security platform. This is supported by always-on managed detection and response (MDR) services from Unit 42, Palo Alto Networks’ threat intelligence and incident response arm.
The university also worked with Palo Alto Networks Professional Services to accelerate deployment. Within 20 days, Cortex XDR was deployed across 10,000 endpoints.
If you liked this content…
The new environment combines AI-driven analytics and automation with managed detection and response, helping the security team manage threats and reduce manual workload.
The university has also introduced executive-level reporting and security insights from Unit 42 MDR and Cortex XDR. These are regularly presented to its board to demonstrate the work undertaken by the security team and support the case for further investment.
“We hope never to need to use the Unit 42 Incident Response team to recover from a cybersecurity incident or data breach. However, it provides the reassurance that we can bring in experts if required to help us to recover as soon as possible,” said Lee Evans, assistant director of IT infrastructure at Cardiff University.
Results
In the first two months, the new approach resolved more than 99.99 percent of 468,000 security cases.
The university has also reduced the manual workload associated with security operations. Using Cortex XDR and XSOAR alongside Unit 42 MDR has enabled Cardiff to redeploy three members of its team from reactive alert management to more strategic security initiatives.
Key outcomes include:
- More than 99.99 percent of 468,000 security cases resolved in two months
- Four overlapping endpoint security tools replaced with a single connected platform
- Cortex XDR deployed across 10,000 endpoints in 20 days
- Three team members redeployed from reactive alert management to strategic security work
- Executive-ready security reporting and insights provided regularly to the university’s board.
The university says the new approach has increased operational efficiency, secured its IT infrastructure and reduced the risks facing its users.
Next steps
Cardiff University plans to continue extending its deployment of Cortex XDR. Having deployed the technology across 10,000 endpoints in 20 days, it intends to add a further 5,000 endpoints later in 2026.
As part of its 5-year plan, the University will start work on a phased Cortex XSIAM rollout this year.
The university will also continue using Unit 42 MDR and Cortex XDR to provide its board with visibility of its security position and the work undertaken by its security team.








