Skip to main content
40d 23:53:10Fal.Con 2026 — our biggest reveals of the year.See the announcements
← Case studies
Customer story
Practising Law Institute

Closing the visibility gap: how Practising Law Institute modernized security operations with Falcon Next-Gen SIEM

A 90-year-old nonprofit serving the legal profession replaced an MDR service that could not see its full environment with a centralized CrowdStrike Falcon® Next-Gen SIEM, implemented by Vijilan.

Industry
Legal & Professional Education (Nonprofit)
Headquarters
New York, NY
Founded
1933, chartered by the Regents of the University of the State of New York
CrowdStrike solutions
Falcon Complete, Falcon Next-Gen SIEM, Falcon Exposure Management, Falcon Identity Protection
Implementation partner
Vijilan
"The platform provides a centralized security operations experience, bringing together endpoint, cloud, identity, and infrastructure telemetry into a single solution, enabling more comprehensive detection, investigation, and response capabilities across our environment."
Liang Chen, Director, Network Operations, Practising Law Institute
What changed for PLI
Telemetry that lived in separate systems now lands in one view.
Endpoint
Network
Cloud
Identity
One centralized view
CrowdStrike Falcon Next-Gen SIEM

Detection, investigation, and response across the whole environment, in one place. Falcon Complete keeps running PLI's 24/7 MDR alongside it.

01

The challenge

Practising Law Institute has trained the legal profession since 1933. Its security team protects the systems behind that mission, and its previous MDR provider had become the weak point: the service could not ingest and correlate telemetry from key sources, including PLI's web application firewall. Critical activity lived outside the provider's view, and the team was left with a visibility gap it could not close from inside the tool.

PLI decided not to renew. It ran a formal RFP across multiple MDR providers, and CrowdStrike won on the strength of its endpoint protection and CrowdStrike Falcon® Next-Gen SIEM, the piece that would finally bring PLI's scattered telemetry into one place.

02

The deployment

CrowdStrike recommended and assigned Vijilan as the implementation partner for the Falcon Next-Gen SIEM build-out. The timeline was tight and PLI's team was new to the platform, so structure mattered: Vijilan's Eder Fonseca ran the engagement on a weekly cadence with clear action items and low overhead for PLI's staff.

The scope stayed clean throughout. Falcon Complete, CrowdStrike's own managed detection and response service, continued to own PLI's 24/7 monitoring and response. Vijilan's job was professional services: stand up the SIEM, connect the data sources, tune the detections, and transfer the knowledge so PLI's team could run the platform themselves.

"His flexibility with scheduling and willingness to accommodate our needs made him feel like an extension of our internal team rather than an external consultant."
Liang Chen · on Vijilan's Eder Fonseca

By the end of implementation and knowledge transfer, PLI estimated the environment was roughly 80% tuned to its needs. That estimate held up under independent review: PLI later hired a Lead Security Engineer who examined the deployment and found only minor tuning left, mainly log ingestion optimization and a handful of detection rules.

"Smooth, efficient, and exceeded our expectations."
Liang Chen · on the overall deployment
03

The impact

Falcon Next-Gen SIEM now runs alongside Falcon Complete. Endpoint, network, cloud, and identity telemetry that used to live in separate systems flows into one centralized view. Ad-hoc investigations that once meant pulling data from multiple tools happen in one place.

The team uses dashboards to track AI application usage, data source coverage, log volume, and telemetry trends. And the platform has grown with them: PLI has since added Falcon Exposure Management and Falcon Identity Protection on top of Falcon Complete's endpoint protection.

The dashboards PLI's team runs today
AI application usage
Data source coverage
Log volume
Telemetry trends
"Having those capabilities integrated into a single platform has simplified operations, improved our security posture, and allowed us to focus on strategic initiatives rather than day-to-day monitoring and management."
Liang Chen, Director, Network Operations, Practising Law Institute
Securing the AI revolution

The platform PLI standardized on is now securing AI itself.

PLI already watches AI application usage from its Falcon Next-Gen SIEM dashboards. CrowdStrike is going much further: in December 2025 it made CrowdStrike Falcon® AI Detection and Response (AIDR) generally available, extending the same Falcon platform to the fastest-growing attack surface in the AI era, the prompt and agent interaction layer.

Prompt and agent protection

Falcon AIDR stops prompt injection, jailbreaks, and unsafe content in real time, and contains malicious agent actions before they spread.

Sensitive data stays inside

Credentials and regulated data are detected and blocked before they reach models, agents, or external AI systems.

Same platform, new attack surface

AI security lands in the Falcon platform PLI already standardized on: one console, one data layer, no new tool sprawl.

Falcon AIDR is CrowdStrike platform capability and is not part of the PLI deployment described above. Standardizing on Falcon today is what makes adding it later a console update instead of another migration.

See what Vijilan is unveiling at Fal.Con 2026
04

Who this is for

Asked what kind of organization should consider the same move, PLI's answer was direct: teams that need comprehensive security coverage without the overhead of managing many separate tools or building a large in-house staff. If that describes your organization, start with how we work with security leaders.

Take this story with you

Get the two-page PDF version, formatted for sharing with your team. Work email required.

We use your email to send Vijilan resources. No spam, unsubscribe anytime.

CrowdStrike®, Falcon®, Falcon Complete®, Falcon Next-Gen SIEM, Falcon Exposure Management, and Falcon Identity Protection are trademarks of CrowdStrike, Inc. This story reflects Practising Law Institute's experience and is published with their review and approval. Vijilan is a CrowdStrike Powered Service Provider (CPSP) and authorized reseller. NextDefend™ is a trademark of Vijilan Security.

NextDefend™ · managed Falcon Next-Gen SIEM

Already running Falcon Complete and want the same visibility?
This engagement is a product.

What PLI bought as a professional services engagement is what NextDefend delivers as a service: Falcon Next-Gen SIEM implementation, onboarding, and tuning that complements Falcon Complete where it is present. Vijilan is a CrowdStrike Powered Service Provider (CPSP) with 50+ Falcon Next-Gen SIEM environments stood up.