Rate Companies (formerly Guaranteed Rate) is the second-largest retail mortgage lender in the U.S. With billions of sensitive transactions flowing through its systems daily, the company is a prime target for cybercriminals.
“Because of the nature of our business, we face some of the most advanced and persistent cyber threats out there,” said Katherine Mowen, SVP of Information Security at Rate Companies. “We saw many of our competitors getting breached, so we needed to ensure it didn’t happen to us.”
For Rate Companies, it wasn’t just about protecting one or two areas of the business. The company needed a comprehensive cybersecurity strategy that could safeguard its entire digital ecosystem from endpoint to cloud. With this in mind, Rate Companies turned to CrowdStrike, gaining both unified protection and flexible deployments with CrowdStrike Falcon® Flex.
Building a Cybersecurity Foundation with CrowdStrike
In 2018, Rate Companies took a critical step in fortifying its defenses by deploying the AI-native CrowdStrike Falcon® cybersecurity platform, starting with CrowdStrike Falcon® Insight XDR for endpoint detection and response (EDR). With its endpoints under constant threat from sophisticated malware, ransomware and phishing attacks, the lender needed a platform that could detect and respond to these threats in real time.
“We chose the Falcon platform because it gave us better visibility into our environment and allowed us to detect and mitigate threats faster than anything we’d seen before,” said Mowen.
As the threat landscape evolved, so did Rate Companies’ security strategy. Recognizing the need for a new level-one SOC, it deployed CrowdStrike Falcon® Complete Next-Gen MDR. Today, the Falcon Complete team acts as a seamless extension of Rate Companies’ security team, delivering 24/7 expert monitoring, proactive threat hunting, integrated threat intelligence and full-cycle remediation delivered by CrowdStrike experts.
“Our previous MDR had a lot of false positives, which wears on people. Nobody likes to get woken up at night with a false alarm,” explained Mowen. “But when CrowdStrike calls, we know it’s real. The quality of their alerts actually helps us retain security staff.”
In addition, Rate Companies deployed CrowdStrike Falcon® Identity Protection to counter the growing number of identity-based attacks, especially as remote work became more prevalent during the pandemic. Falcon Identity Protection, which runs on the lightweight Falcon agent, enabled Rate Companies to secure user credentials and prevent identity compromise — a key vulnerability as attackers increasingly target users rather than infrastructure.
“Identity-based attacks are a huge concern, especially with our large contingency of remote lending officers,” said Mowen. “Falcon Identity Protection has given us the visibility and control we need to defend against these types of threats.”
Protecting Critical Workloads with Falcon Cloud Security
As a financial services provider, Rate Companies’ business needs fluctuate with the market, including the size of its workforce, which exploded from 6,000 to 15,000 people in 2020. Rate Companies has also acquired multiple companies in recent years, which means new users and cloud environments to protect. Both of these dynamics create the need for cloud security that easily scales with the business.
“Our business is subject to big swings, so managing the security of a workforce that grows or shrinks in response to market conditions is a huge challenge for us,” explained Mowen. “We needed a cloud security solution that could scale with us without adding complexity.”
This is where CrowdStrike Falcon® Cloud Security proves invaluable. As Rate Companies evolves, Falcon Cloud Security allows it to seamlessly scale its protection, providing real-time visibility and threat detection across its cloud infrastructure — regardless of the number of employees or the amount of data being processed.
Falcon Cloud Security integrated seamlessly with the existing CrowdStrike deployment, offering real-time visibility across all of Rate Companies’ cloud assets from the single Falcon sensor. It also provides automated detection of misconfigurations, vulnerabilities and unauthorized access, giving Mowen’s team the confidence to expand its cloud initiatives without increasing risk.
“The ability to secure our cloud environments with the same platform we use for endpoint and identity protection was a major benefit for us,” Mowen explained. “With the Falcon platform, we can manage and protect multiple attack surfaces through one console.”
Consolidating with Falcon Flex
As Rate Companies added more and more CrowdStrike protection over the years, the value of consolidating its cybersecurity tools onto a single platform became clear. Using Falcon Flex, Rate Companies chose the easiest way to adopt the CrowdStrike portfolio and scale its user licenses without the hassle of renegotiating contracts.
One of the most impactful additions was CrowdStrike® Falcon LogScale™, a log management solution that enables Rate Companies to gather and analyze log data in real time. The company has also started ingesting security telemetry into the Falcon platform using CrowdStrike Falcon® Next-Gen SIEM. The seamless integration of these solutions with the Falcon platform means Rate Companies can easily correlate log data with other security telemetry to detect and respond to incidents faster than ever before.
“The SIEM we were using before was expensive, clunky and hard to integrate with the rest of our security tools. Falcon LogScale, on the other hand, has a much lower total cost of ownership, is far easier to integrate into our workflows and offers a better user experience.”
Through Falcon Flex, Rate Companies also deployed CrowdStrike Falcon® Data Protection, securing its most sensitive financial data from insider threats, unauthorized access and accidental leaks. As with other Falcon platform modules, Rate Companies was able to quickly and easily enable Falcon Data Protection using the lightweight Falcon agent.
The ability to easily scale its security capabilities through Falcon Flex has been key to Rate Companies’ success in staying ahead of emerging threats.
“The flexibility of Falcon Flex allows us to easily scale our security as our needs change,” Mowen explained. “With CrowdStrike, we’re consolidating our cybersecurity tools into one cohesive system, making everything from management to incident response far more efficient.”
“CrowdStrike Everywhere”
As Rate Companies looks toward the future, it’s committed to staying ahead of cyber threats by leveraging CrowdStrike’s full capabilities. With its motto of “CrowdStrike Everywhere,” the mortgage lender has built a robust, scalable cybersecurity strategy that protects its endpoint, cloud and identity attack surfaces from a growing array of sophisticated threats.
“CrowdStrike is the cornerstone of our cybersecurity strategy,” concluded Mowen. “They give us the flexibility, visibility and speed we need to stay ahead of attackers.”