COMPANY PROFILE
SBFE: The Trusted Source for U.S. Small Business Credit Data
The Small Business Financial Exchange (SBFE) is an industry trade association formed in 2001. Over 140 U.S. small business lenders are members. SBFE's mission is to be the trusted source for small business data, delivering solutions and data-driven insights that drive access to capital and the growth of small businesses.
SBFE operates as a central repository for aggregating credit payment performance data , a closed, "give to get" exchange that provides data received from member lenders to major credit reporting bureaus for inclusion in risk management products. The sensitivity of that data and the trust of over 140 member institutions set the bar for what security must deliver: coverage that is continuous, auditable, and never dependent on manual effort.
CHALLENGES
The Problem: Growing Infrastructure, Rising Complexity, and Security That Could Not Keep Pace
SBFE's security posture was constrained by the limits of a conventional model , a legacy SIEM paired with manual SOC workflows , that could not scale alongside an expanding, data-sensitive environment.
A Legacy SIEM and Manual SOC That Could Not Scale
SBFE operated a conventional security model , a legacy SIEM for log collection and detection, paired with manual SOC workflows for triage, investigation, and response. As the infrastructure grew across cloud, identity, endpoints, and SaaS, the gap between alert volume and available analyst capacity widened. Maintaining detection logic, managing escalations, and tracking investigation status required continuous human effort that compounded with every new environment addition.
No Consolidated Detection Posture or Coverage Visibility
Without a unified view of what was being detected and where critical assets sat relative to known attack techniques, understanding coverage gaps required manual effort the team could not consistently sustain. As new assets were added to the environment, default monitoring coverage was not guaranteed , posture had to be actively tracked rather than built in.
Security Operations That Needed to Scale Without Proportional Headcount
With over 140 member institutions depending on SBFE data, the security function carried obligations that demanded scale. Manual triage, fragmented workflows, and coverage dependent on shift schedules created an operating model that could not sustainably match the pace of a growing threat environment.
Compliance Posture That Depended on Manual Assembly
Maintaining a structured, continuous audit record for a data-intensive environment required manual effort that competed directly with active security operations. Every compliance review demanded time the team needed to spend elsewhere. A built-in, continuous compliance trail , not one assembled after the fact , was a clear operational requirement.
TRANSFORMATION
From a Legacy SIEM and Manual SOC to One Integrated Agentic Platform
BEFORE TRENCH
- Legacy SIEM combined with a manual SOC model: detection, investigation, and response managed across separate tools and workflows with significant human overhead
- No consolidated view of detection posture or MITRE ATT&CK coverage , understanding coverage required ongoing manual effort
- Detection rules and investigation configurations required continuous manual upkeep as the environment scaled
- Alert volume and investigation workload grew faster than the team could absorb , every triage cycle required analyst time
- Security workflows lived outside the team's primary collaboration environment, creating context-switching overhead
- Escalation workflows lacked structured context , teams received notifications without severity, scope, or recommended next steps
- Producing a structured audit record required significant manual effort drawn from active security operations
AFTER TRENCH
- One integrated agentic platform combining SIEM and SOC: detection, investigation, hunting, and response running continuously on the Trench Agentic SIEM
- Critical asset coverage established in weeks , full MITRE ATT&CK posture visible and continuously updated
- Detection rules authored and deployed automatically from live threat intel through Intent Graph , no manual configuration, no tuning cycles
- Every alert auto-investigated 24x7 , each escalation arrives with full context: what happened, blast radius, and recommended next action in under 10 minutes
- 100% headless SecOps , all findings, investigations, and response actions surface inside the team's collaboration tools with full context
- Every escalation arrives with full context of what happened and what needs to be done in under 10 minutes
- Every detection, investigation, and closure timestamped with a full audit trail , compliance posture is continuous and built in
ADOPTION STORY
SBFE Built an Actionable SOC: Powered by the Trench Agentic SIEM
One Platform Replacing a Legacy SIEM and Manual SOC
SBFE replaced its legacy SIEM and the manual SOC workflows it required with Trench's security-first, data lake-centric Agentic SIEM , one integrated platform where detection, investigation, threat hunting, and response run continuously, without separate tooling or human orchestration between them. Every log source across endpoints, identity, cloud, network, and SaaS now flows into a unified data layer. What previously required a SIEM for ingestion, a separate workflow for triage, and analyst time for every investigation is now a single, continuously operating agentic system.
Detection Posture Rebuilt Around Intent Graph and MITRE Coverage
Trench's Intent Graph became the foundation of SBFE's new detection posture , reasoning about the behavioral purpose behind every signal, not just the individual event. Rather than evaluating alerts in isolation, Intent Graph reasons across relationships, sequences, and context to identify what is genuinely suspicious versus expected activity. MITRE ATT&CK-aligned detection rules now deploy automatically from live threat intel, with critical asset coverage established in weeks and every new asset onboarded with its default detection workflow enabled from day one.
Automated Investigation: Every Escalation Arrives With Context
Every alert now enters an automated investigation loop , context gathered, timeline built, blast radius scoped, case closed. Every escalation that reaches a human arrives with the complete picture: what happened, the scope of impact, and a clear recommended action, in under 10 minutes. Response and remediation cycles that previously required significant analyst time now close before the next shift starts.
Headless SecOps: Security That Comes to the Team
For a team where security operations needed to scale without proportional headcount, the headless model was the right architectural fit. Security findings, investigation outcomes, and escalations surface directly inside the collaboration layer the team already uses , no console login, no context switching, no separate tool to monitor. Security became something that came to the team, fully reasoned and ready to act on.
The compliance posture changed fundamentally. Every detection, every investigation, every closure is timestamped with a full audit trail , built continuously as Trench operates, not assembled under pressure. The result is a compliance record that is always current, always complete, and available on demand.
Autonomous Threat Hunting Across the Full Attack Surface
Trench's autonomous threat hunting agents run continuously across SBFE's environment , proactively surfacing threats that evade rule-based detection. Behavioral anomalies, lateral movement indicators, and insider risk signals that no static rule set can anticipate are identified and surfaced before they become incidents. For an organization where data integrity underpins the trust of over 140 member institutions, proactive coverage across the full attack surface is not optional.