ENVIRONMENT

Active Directory

Entra ID, Okta

Homegrown legacy applications
for railways operations

USERS

1,000+ employees

INDUSTRY

Transportation

BASED

Brussels, Belgium

Securing Belgium’s rail freight operations: How Lineas gained control over AD and service account risks

THE SOLUTION:

THE CHALLENGE:

Improved privileged access security and reduced service account exposure

Restricting access and gaining control over AD to prevent operational disruption

  • Enforced MFA protection on RDP access and cleaned up excessive privileged access paths

  • Identified over 60% of inactive service accounts and began cleanup efforts

  • Reduced failed login attempts and lowered domain controllers’ overload

  • Limited ability to enforce a second layer of risk-based MFA protection for privileged access, including RDP

  • Lacked visibility into service account activity and potential misuse across AD

  • Couldn’t monitor or control AD authentication activity across legacy systems

"We had a good SIEM but still lacked the ability to interfere with AD authentication traffic. That’s the capability we needed. You can collect logs all day, but if you can’t act on them in real-time, especially for internal traffic, you’re missing a critical layer of defense."

- Christophe Rome, Cybersecurity Strategy Lead at Lineas

The challenge: Need to secure privileged access and service accounts to protect critical rail operations

Finding the right privileged access security platform

"I’ve known about Silverfort for quite a while. It solves a very specific problem with a unique capability. There’s nothing else I know of that can intercept AD authentication traffic the way Silverfort does."

- Christophe Rome, Cybersecurity Strategy
Lead at Lineas

The solution: Enforcing MFA for privileged access and reducing internal exposure

"Installing Silverfort made us reevaluate everything – accesses we didn’t know existed, failed logins, over-permissioned accounts. We started tidying it all up. The visibility helped us to reduce authentication traffic as a whole, which in turn eased the load on our domain controllers. That wasn’t part of the original goal, but it was a very welcome result."

- Christophe Rome, Cybersecurity Strategy Lead at Lineas

Extending visibility and control over service accounts

"With Silverfort we found more than 60% of our service accounts to be inactive. That gave us the insights we needed to start a proper clean-up, focused on ownership, least privilege, and long-term hygiene."

- Christophe Rome, Cybersecurity Strategy
Lead at Lineas

Looking ahead: Building long-term identity access management with visibility and ownership

"Silverfort gave us the visibility and control we were missing. It’s what allowed us to finally align our tooling with ownership and processes – and that’s where the real progress happened."

- Christophe Rome, Cybersecurity Strategy Lead at Lineas

About Silverfort

Silverfort secures every dimension of identity. We deliver end-to-end identity security that is easy to deploy and won’t disrupt business operations, resulting in better security outcomes with less work. Discover every identity, analyze exposures, and enforce protection inline to stop lateral movement, ransomware, and other identity threats.

About Jarviss

Jarviss an integrator and managed security service provider, delivering expert solutions in cybersecurity and data networking. Founded in 2020, we operate across two countries and three locations, with a dedicated team of 30+ specialists. We focus on select, proven technologies to safeguard our customers’ operations, ensuring security, resilience, and business continuity all with a personal approach.

INDUSTRY

Transportation

ENVIRONMENT

Active Directory

Entra ID, Okta

Homegrown legacy applications for railways operations

BASED

Brussels, Belgium

BASED

Brussels, Belgium

About Silverfort

Silverfort secures every dimension of identity. We deliver end-to-end identity security that is easy to deploy and won’t disrupt business operations, resulting in better security outcomes with less work. Discover every identity, analyze exposures, and enforce protection inline to stop lateral movement, ransomware, and other identity threats.

About Jarviss

Jarviss an integrator and managed security service provider, delivering expert solutions in cybersecurity and data networking. Founded in 2020, we operate across two countries and three locations, with a dedicated team of 30+ specialists. We focus on select, proven technologies to safeguard our customers’ operations, ensuring security, resilience, and business continuity all with a personal approach.

Securing Belgium’s rail freight operations: How Lineas gained control over AD and service account risks

THE CHALLENGE:

THE SOLUTION:

Improved privileged access security and reduced service account exposure

Restricting access and gaining control over AD to prevent operational disruption

  • Enforced MFA protection on RDP access and cleaned up excessive privileged access paths

  • Identified over 60% of inactive service accounts and began cleanup efforts

  • Reduced failed login attempts and lowered domain controllers’ overload

  • Limited ability to enforce a second layer of risk-based MFA protection for privileged access, including RDP

  • Lacked visibility into service account activity and potential misuse across AD

  • Couldn’t monitor or control AD authentication activity across legacy systems

The challenge: Need to secure privileged access and service accounts to protect critical rail operations

"We had a good SIEM but still lacked the ability to interfere with AD authentication traffic. That’s the capability we needed. You can collect logs all day, but if you can’t act on them in real-time, especially for internal traffic, you’re missing a critical layer of defense."

- Christophe Rome, Cybersecurity Strategy Lead at Lineas

Finding the right privileged access security platform

"I’ve known about Silverfort for quite a while. It solves a very specific problem with a unique capability. There’s nothing else I know of that can intercept AD authentication traffic the way Silverfort does."

- Christophe Rome, Cybersecurity Strategy
Lead at Lineas

The solution: Enforcing MFA for privileged access and reducing internal exposure

"Installing Silverfort made us reevaluate everything – accesses we didn’t know existed, failed logins, over-permissioned accounts. We started tidying it all up. The visibility helped us to reduce authentication traffic as a whole, which in turn eased the load on our domain controllers. That wasn’t part of the original goal, but it was a very welcome result."

- Christophe Rome, Cybersecurity Strategy Lead at Lineas

Extending visibility and control over service accounts

"With Silverfort we found more than 60% of our service accounts to be inactive. That gave us the insights we needed to start a proper clean-up, focused on ownership, least privilege, and long-term hygiene."

- Christophe Rome, Cybersecurity Strategy
Lead at Lineas

Looking ahead: Building long-term identity access management with visibility and ownership

"Silverfort gave us the visibility and control we were missing. It’s what allowed us to finally align our tooling with ownership and processes – and that’s where the real progress happened."

- Christophe Rome, Cybersecurity Strategy Lead at Lineas

Fullscreen