List of IBM Security QRadar SIEM Customers
Armonk, NY, 10504,
United States
Since 2010, our global team of researchers has been studying IBM Security QRadar SIEM customers around the world, aggregating massive amounts of data points that form the basis of our forecast assumptions and perhaps the rise and fall of certain vendors and their products on a quarterly basis.
Each quarter our research team identifies companies that have purchased IBM Security QRadar SIEM for Security Information and Event Management (SIEM) from public (Press Releases, Customer References, Testimonials, Case Studies and Success Stories) and proprietary sources, including the customer size, industry, location, implementation status, partner involvement, LOB Key Stakeholders and related IT decision-makers contact details.
Companies using IBM Security QRadar SIEM for Security Information and Event Management (SIEM) include: Occidental Petroleum Corporation, a United States based Oil, Gas and Chemicals organisation with 11973 employees and revenues of $36.63 billion, Scotiabank, a Canada based Banking and Financial Services organisation with 86746 employees and revenues of $24.55 billion, Metropolitan Transportation Authority (MTA), a United States based Transportation organisation with 70000 employees and revenues of $21.30 billion, Ford Motor Company, a United States based Automotive organisation with 175000 employees and revenues of $18.73 billion, RWJBarnabas Health, a United States based Healthcare organisation with 45000 employees and revenues of $11.00 billion and many others.
Contact us if you need a completed and verified list of companies using IBM Security QRadar SIEM, including the breakdown by industry (21 Verticals), Geography (Region, Country, State, City), Company Size (Revenue, Employees, Asset) and related IT Decision Makers, Key Stakeholders, business and technology executives responsible for the software purchases.
The IBM Security QRadar SIEM customer wins are being incorporated in our Enterprise Applications Buyer Insight and Technographics Customer Database which has over 100 data fields that detail company usage of software systems and their digital transformation initiatives. Apps Run The World wants to become your No. 1 technographic data source!
Apply Filters For Customers
| Logo | Customer | Industry | Empl. | Revenue | Country | Vendor | Application | Category | When | SI | Insight |
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
Askari Bank | Banking and Financial Services | 7881 | $1.0B | Pakistan | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2019 | Software Productivity Strategists |
In 2019, Askari Bank implemented IBM Security QRadar SIEM together with QRadar SOAR and UBA to establish a 24/7 security operations center and automate incident response playbooks. The deployment targeted compliance with Pakistan's Cyber Security Policy and centralized security monitoring under the Security Information and Event Management (SIEM) category.
The implementation configured IBM Security QRadar SIEM for high volume event ingestion and correlation, QRadar UBA for anomalous user behavior detection, and QRadar SOAR to operationalize automated playbooks and runbooks. Standard SIEM capabilities such as normalization, correlation rules, threat scoring and automated response workflows were instrumented to improve event prioritization and reduce manual triage.
Software Productivity Strategists served as the systems integrator supporting deployment and operational enablement, aligning SIEM workflows with the bank's 24/7 SOC operating model. The deployment centralized telemetry from across the bank's environment into the QRadar platform, feeding SOC analyst dashboards, automated playbooks and UBA alerts.
Governance changes included formalized SOC processes, playbook ownership and incident escalation paths to meet regulatory requirements. The Pakistan banking deployment reduced daily security incidents from approximately 700 to under 20 and cut average remediation time from around 30 minutes to about 5 minutes through automation and improved event prioritization.
|
|
|
California State Polytechnic University-Pomona | Education | 2675 | $454M | United States | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2022 | n/a |
In 2022, California State Polytechnic University-Pomona deployed IBM Security QRadar SIEM as its Security Information and Event Management (SIEM) solution to centralize campus security monitoring across a heterogeneous IT environment. The implementation targeted U.S. higher education operational needs, consolidating telemetry and security events into a single platform for campus security teams.
The deployment of IBM Security QRadar SIEM centralized log collection, normalization, correlation, and alerting across network, wireless, and campus services. Configurations emphasized ingestion from a broad device estate, and the environment consolidated logs from approximately 84,000 devices, enabling consolidated event indexing and correlation across disparate data sources.
Operationally the platform supports production SOC activities and is integrated into student cybersecurity training workflows, providing a shared operational instance for both incident detection and educational use. The security team implemented alert triage and investigation workflows, and the deployment reduced daily alert noise to roughly 20 to 40 items per day for focused investigation.
Governance and rollout followed a campus-wide monitoring model, with the central security operations capability used to standardize event handling and investigative processes across sites and services. IBM Security QRadar SIEM provides the campus with a unified Security Information and Event Management (SIEM) foundation for SOC operations and hands-on cybersecurity education.
|
|
|
ESAF Small Finance Bank | Banking and Financial Services | 8336 | $267M | India | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2020 | n/a |
In 2020, ESAF Small Finance Bank implemented IBM Security QRadar SIEM as its Security Information and Event Management (SIEM) solution to centralize event collection and real-time monitoring across the bank's security operations. The IBM Security QRadar SIEM deployment was positioned to support continuous threat detection and incident management within the bank's SOC and core security teams, establishing a centralized analytics layer for log aggregation and correlation.
Configuration focused on standard SIEM functional modules, including log ingestion and normalization, correlation rules and offense generation, security analytics and anomaly detection, searchable indexed event storage, and dashboarding for SOC use. The implementation of IBM Security QRadar SIEM included rule tuning and playbook alignment to support automated alert triage and investigator workflows, with retention and audit capabilities configured to meet banking regulatory and operational needs.
Integrations were explicitly instrumented with external threat intelligence and XDR telemetry, the bank ingesting feeds from Cyble and FortiRecon for dark web and threat intelligence enrichment and consuming endpoint telemetry from TrendMicro XDR to extend detection and response across endpoints. Operational coverage included staffed 24/7 monitoring by SOC analysts, with real-time event analysis and coordinated incident escalation to response teams as captured in operational notes from March 2024 to May 2025.
Governance and workflow changes accompanied the rollout, with SOC process definitions, incident handoff procedures, and stakeholder communication protocols formalized to ensure effective information sharing between analysts, the SOC manager, and vendors. The implementation supported advanced threat detection, incident response, and security analytics via IBM Security QRadar SIEM integrated with the bank's threat intelligence and XDR tooling to enhance security posture and mitigate risks as reported by internal security staff.
|
|
|
Ford Motor Company | Automotive | 175000 | $18.7B | United States | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2013 | n/a |
In 2013, Ford Motor Company deployed IBM Security QRadar SIEM as a core element of its Security Information and Event Management (SIEM) program to support a global Enterprise Security Operations Center. The deployment was positioned to centralize log collection, event correlation, and incident detection use cases across enterprise IT and manufacturing estates while aligning with formal SOC planning and engineering activities.
IBM Security QRadar SIEM was configured to provide standard SIEM capabilities including scalable log management, real time event correlation, customizable detection rules, and alerting workflows. The implementation incorporated threat intelligence and security analytics capabilities documented in Ford’s security engineering work, and was used to operationalize vulnerability and threat management, SOC incident detection and response playbooks, and security metrics and scorecards.
The QRadar implementation integrated telemetry from on-premises network and endpoint sensors and from cloud platforms as explicitly documented, including AWS and Microsoft Azure. The program tied QRadar visibility into Cisco Umbrella, Microsoft 365, applications running on the Pivotal Cloud Foundry platform, and upstream network aggregation via Gigamon GigaVue, and it was deployed alongside firewalls and IDS/IPS technology from Cisco and Palo Alto as part of an orchestrated security stack.
Operational scope covered global Enterprise SOC responsibilities, joint ventures, supplier parks, and BYOD-environments, with cross functional collaboration across IT, Manufacturing, and Connected Vehicle teams. Governance and compliance workstreams referenced ISO 27001 based policy, Sarbanes-Oxley 404, GDPR, China Cybersecurity Law, and the India IT Act, and the SIEM was used to support policy enforcement, incident response procedures, and enterprise security reporting.
Outcomes described in the implementation notes include establishing the Enterprise Security Operations Center and extending visibility into cloud and enterprise applications through IBM Security QRadar SIEM, and integrating security metrics and scorecards into the IT dashboard. The QRadar deployment formed an anchoring capability for threat monitoring, detection, and coordinated response across Ford’s global security operations.
|
|
|
Inspira Enterprise | Professional Services | 1500 | $200M | India | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2022 | n/a |
In 2022, Inspira Enterprise implemented IBM Security QRadar SIEM to centralize Security Information and Event Management (SIEM) capabilities for its Security Operations Center. The deployment was adopted into SOC workflows used by Security Analysts from June 2022 onward, operating out of Maharashtra, India, and intended to support incident detection, triage, and containment across the firm.
The IBM Security QRadar SIEM implementation focuses on core SIEM functions including correlation rule development, detection use case configuration, log parsers, and dashboarding for visibility. Complementary capabilities were instrumented for UEBA style analytics, network behavior anomaly detection NBAD, and packet capture PCAP analysis to support hypothesis-driven threat hunting and deep log investigation.
Operational integrations and telemetry consolidation were prominent in the build, with QRadar correlated alongside RSA NetWitness and Splunk as part of deep log analysis workflows. Threat intelligence and IOC enrichment flows were connected to a TIP, OSINT and feeds including iZOOlogic, Zscaler, and Deception platforms, enabling analysts to map adversary activity to MITRE ATT&CK techniques and to enrich alerts with IPs, hashes, and domains from multiple sources.
Governance and operationalization centered on SOC process formalization, with creation of SOPs, incident handling documents and playbooks to standardize triage, containment and remediation. The program included escalation guidance for L1 analysts, documented shift management practices used in absence of a SOC lead, weekly and monthly SOC performance reporting for KPI tracking, and root cause analysis processes for recurring incidents.
|
|
|
|
Professional Services | 16000 | $2.2B | United States | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2022 | n/a |
|
|
|
|
Transportation | 70000 | $21.3B | United States | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2019 | n/a |
|
|
|
|
Oil, Gas and Chemicals | 11973 | $36.6B | United States | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2021 | n/a |
|
|
|
|
Healthcare | 45000 | $11.0B | United States | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2019 | n/a |
|
|
|
|
Banking and Financial Services | 86746 | $24.5B | Canada | IBM | IBM Security QRadar SIEM | Security Information and Event Management (SIEM) | 2022 | n/a |
|
Buyer Intent: Companies Evaluating IBM Security QRadar SIEM
- Greenly, a France based Professional Services organization with 205 Employees
- Socbyte, a Pakistan based Professional Services company with 75 Employees
- Samaritan Health Services, a United States based Healthcare organization with 6000 Employees
Discover Software Buyers actively Evaluating Enterprise Applications
| Logo | Company | Industry | Employees | Revenue | Country | Evaluated |
|---|---|---|---|---|---|---|
| Greenly | Professional Services | 205 | $39M | France | 2026-07-17 | |
| Socbyte | Professional Services | 75 | $8M | Pakistan | 2026-05-25 | |
| Samaritan Health Services | Healthcare | 6000 | $1.7B | United States | 2026-05-24 | |
| Media | 320 | $66M | United Kingdom | 2026-04-19 | ||
| Insurance | 34000 | $48.8B | United States | 2024-12-16 | ||
| Professional Services | 100 | $10M | Uruguay | 2024-12-05 | ||
| Professional Services | 150 | $31M | Israel | 2024-06-03 |