Cut threat detection and response times (MTTD/MTTR) by 15% with Google SecOps and Gemini
Accelerated weekly detection rule creation by 300% and raised the detection true-positive rate by 10% by applying the Mandiant detection engineering framework
Increased MITRE ATT&CK coverage by 10%, deliberately closing detection gaps across relevant techniques on Google SecOps
Zero SLA breaches on Google Cloud and Cloud Monitoring
AGIT scales its enterprise Managed SOC in Indonesia using Google SecOps, Gemini, and Mandiant to drive 15% faster response times.
Many enterprises rely on PT Astra Graphia IT (AGIT), based in Indonesia, to keep their digital infrastructure safe. Operating as the IT services pillar of the Astra International Tbk Group, AGIT acts as a one-stop digital service provider and managed security services provider (MSSP). But as client log volumes grew rapidly, AGIT’s legacy on-premises SIEM began to stall.
The team ran into the limitations of a legacy platform that wasn’t built for the scale and advancements AGIT needed. During complex investigations, analysts spent valuable time working around the platform's data-processing constraints instead of analyzing threats, putting strict Service Level Agreements (SLAs) under pressure.
AGIT needed to scale its Security Operations Center (SOC) without taking on physical hardware overhead. The team decided to move its security operations to Google Cloud. A decisive factor was local data residency: Google Cloud established a local Google SecOps tenant in Indonesia, allowing AGIT’s enterprise clients to meet strict domestic compliance laws. Supported by expert consulting from Mandiant, AGIT built a cloud-native, 24/7 defense operation designed to scale seamlessly with client growth.
Google SecOps in the Indonesia region ensures our customer data remains in-country to satisfy strict regulatory compliance. Beyond cloud scalability, partnering with Google Cloud and Mandiant gives our clients total confidence in our cybersecurity maturity.
Olive Kusumbara
Head of Cybersecurity Services, PT. Astra Graphia Information Technology (AGIT)
Together, these capabilities provided AGIT with the next-generation platform it required to meet its scalability and availability needs, support its core cybersecurity operations, and prepare for increasingly complex cyberattacks.

AGIT partnered with Mandiant across five core areas to elevate its operational maturity: cyber defense assessments, playbook creation, SOC procedure uplifts, purple team exercises, and detection engineering. Underpinning this, AGIT's platform runs on tightly controlled access, enforced through Identity and Access Management (IAM) and Workforce Identity Federation (WIF), with backend integrations built on Compute Engine and Cloud Run.
Using Gemini as an operational helper allows our analysts to skip writing incident drafts from scratch and focus on rapid verification. Coupled with our new CI/CD pipeline, we can continuously push high-quality detections at scale.
Renaldy
Lead Detection and SOC Engineering Platform, AGIT
At the same time, AGIT brought Gemini into the SOC as an intelligent assistant for analysts. Instead of opening support tickets and waiting days for custom log parsers, AGIT engineers now use Gemini to write parser code directly when onboarding new client devices. During live investigations, Gemini builds threat correlation summaries and drafts initial incident reports automatically, so analysts can verify findings immediately rather than writing summaries from scratch, accelerating response without compromising accuracy.
AGIT built custom ticketing tools integrated with Cloud Monitoring and Cloud Logging to track telemetry across hybrid on-premise and multi-project cloud environments, with log staging handled through Cloud Storage.
This gives AGIT fast, reliable visibility into the entire ingestion pipeline, so the team always knows its monitoring coverage is complete and flowing as expected.
The clearest shift came in detection engineering, where scattered, ad-hoc version control gave way to a structured CI/CD pipeline that automates the build, testing, and deployment of over 100 detections, each mapped directly to the MITRE ATT&CK framework. Every rule is version-controlled and validated before release, so new coverage reaches production faster and more reliably than our old manual process, and a faulty detection can be safely rolled back rather than hot-fixed in production.

The shift to Google Cloud and Mandiant delivered concrete gains across AGIT’s security operations. Automated triage and Gemini-assisted workflows cut mean time to detect and respond (MTTD/MTTR) by roughly 15%, helping contain threats faster during active incidents. Detection rule development accelerated by 3x, while rule tuning lifted true-positive accuracy by 10%—significantly cutting down noise and alert fatigue for analysts.
Operationally, AGIT maintained zero SLA breaches while achieving formal SOC 2 certification. That audited baseline gives AGIT a clear advantage when navigating complex due diligence checks with enterprise risk committees in Indonesia.
With hardware maintenance removed from their daily workloads, AGIT’s security engineers now spend their shifts on proactive threat hunting and improving platform capabilities. Looking ahead, AGIT plans to deepen its Google Cloud integrations and explore AI-centric agentic solutions to combat increasingly complex cyber threats.
Achieving SOC 2 attestation and backing our SOC with Google Cloud and Mandiant gives us a complete value proposition. It streamlines enterprise due diligence and provides our clients with bulletproof operational trust.
Olive Kusumbara
Head of Cybersecurity Services, AGIT
PT Astra Graphia IT (AGIT), a subsidiary of PT Astra International Tbk Group, is a leading Indonesian Digital Services Provider delivering one-stop ICT, cloud, and managed security solutions.
Industries: Technology, Software and Internet
Location: Indonesia
Products: Google SecOps, Gemini, Cloud Logging, Cloud Monitoring, Cloud Storage, Compute Engine, Cloud Run, Identity and Access Management (IAM), Workforce Identity Federation (WIF)