How we support DAW’s transition to Microsoft Security and a Managed SOC.
From fragmented security solutions to a centralized, efficient IT security architecture with Microsoft Sentinel and Defender.

The challenge
Three SOCs, multiple service providers, a wide range of tools: DAW’s security landscape had grown over the years, and became fragmented along the way. Server logs, endpoints, EDR, alerting, and escalation ran through different solutions and partners – not a sustainable foundation for a company with high security standards.
On top of that, a central solution was approaching end of life. DAW had to act, and used the opportunity to rebuild its IT security from the ground up.
“Security is taken very seriously at DAW. Early detection of attacks and anomalies is essential for us. The new security strategy also needed to reduce the complexity of our previous solution.”
Alexander Sfetcu, CISO, DAW
At the same time, the IT landscape of the DAW Group is anything but simple: 23 locations across Europe, hybrid infrastructures, processes shaped by years of growth. What was needed wasn’t an isolated fix, but a strategic security approach equal to these challenges.
The solution
Before the overhaul of its IT security really got underway, DAW made a strategic decision: Microsoft would play a significantly bigger role going forward as the central technology stack, including in security. Through Microsoft, water came into the conversation as a recommended partner.
“Even in the first conversations, we noticed that water doesn’t just offer an off-the-shelf solution. Instead, all our challenges were approached with a clear concept, solid preparation, and a lot of structure.”
Alexander Sfetcu, CISO, DAW
Together, the scope of the migration project was defined and broken down into several work streams. Three major building blocks were at the center: XDR and endpoint security with the Microsoft Defender family, log forwarding and log analysis with Microsoft Sentinel, and water’s Managed SOC, providing 24/7 monitoring.
This involved more than technical implementation. It also meant consulting, conceptual design, and integration with internal processes. Playbooks, escalation paths, and alerting processes were developed further together. Connecting existing crisis management tools was also part of the project.
Importantly, this isn’t a one-off rollout but an ongoing improvement process. Step by step, old structures are being replaced, log sources connected, processes refined, and new use cases built out.

The benefits
Instead of switching between multiple portals, service providers, and areas of responsibility, water’s security solution now provides a central view of security-relevant events. For DAW, that means more oversight, clearer processes, and higher quality incident handling.
“It makes a difference whether I have to switch between three or four portals, or have one central source. With water, our IT security became more efficient, clearer, and better organized.”
Alexander Sfetcu, CISO, DAW
The role of the SOC has changed too. For previous service providers, an incident often ended right after the alert. The rest was left to DAW’s team.
“Before, an anomaly was identified, a ticket was created, and then it was up to us to interpret it. water goes much deeper into the analysis, knows our technical environment better, and can assess incidents directly in the context of our infrastructure. That takes a huge load off our internal team.”
Alexander Sfetcu, CISO, DAW
With water, DAW found a partner who supports the Microsoft Security migration not just technically, but conceptually too. The result: less fragmentation, more efficiency, and a security landscape being aligned step by step toward a central, scalable Microsoft stack.

