Site Search

CrowdStrike

CrowdStrike

How does everyone manage their daily CrowdStrike operations? – Reflecting on daily decisions and how to communicate with upper management from the field – [Falcom Meetup Vol.3 Event Report]

Introduction

Hello everyone. Macnica operates "Falcomi," a community for users of CrowdStrike Falcon.

On July 31, 2026, we held the CrowdStrike user event "Falcom Meetup Vol.3". The theme of this event was "How do you all handle daily CrowdStrike operations? – Thinking about daily decisions and how to communicate them to upper management from the realities of the field."

From responding to alerts and improving operations to communicating with management and even utilizing AI, security professionals exchanged opinions through case study sessions and table talks on the themes they face in their daily work. At this Meetup, participants shared the ingenuity they have accumulated in their respective fields, as well as the challenges they face that do not have easy answers. This article will introduce the events of the day and the themes that emerged from the dialogue among the participants.

Program

  • User Case Study Sharing Session
    ① SOMPO Holdings Co., Ltd.
    ② BookLive
    ③ TOTO
  • Table discussion
  • Social gathering

Learning from the realities of CrowdStrike operation at three companies.

Three companies—SOMPO Holdings, BookLive, and TOTO—presented at this case study session.
Even when using the same CrowdStrike, the challenges and approaches to addressing them vary depending on the organization's environment and operational structure.
Through the case studies of the three companies, different perspectives on daily operations were shared.

SOMPO Holdings: Between alerts and management decisions

SOMPO Holdings presented how they utilize CrowdStrike's detection information to inform their business decisions.
This initiative involves not simply relaying detected alerts, but combining them with asset registers and information on the impact on the business, transforming them into a format that is easier for management to understand and make decisions about.
In addition, examples of AI-powered report generation and decision support applications were shared.
How do we present information obtained from the field of security to senior management? This session focused on "How to present information to upper management," which was also the theme of this Meetup.

BookLive: To what extent should we entrust Falcon Complete to you?

BookLive presented a case study showcasing their use of Falcon Complete.
Through sharing actual operational experiences and incident response anecdotes, participants shared strategies for efficiently maintaining operations even with a small team.
Among the questions raised were, "To what extent should we delegate responsibilities?" and "What should our company keep track of?"
The discussion touched upon the challenges that arise from using Falcon Complete, and how to integrate the service into a company's operations.

TOTO: Security operations and ITDR utilization in a global environment

TOTO presented their security operations in a global environment and case studies of ITDR utilization.
In addition to the operational structure including overseas locations, initiatives combining multiple modules were shared, such as asset management and vulnerability management utilizing Discover and Spotlight, and protection of the authentication infrastructure through ITDR.
Various perspectives were presented as examples of expanding the scope of CrowdStrike's use while simultaneously enhancing its operational sophistication.

It doesn't end with just listening. Table talks where users talk to each other.

In the second half, we split into smaller groups and discussed the following three themes.

  • Reporting and communication with higher management
  • Operational design and improvement
  • What are your next goals or modules you'd like to use in CrowdStrike?

At each table, participants shared their approaches and perspectives on daily operational challenges, incident response, and methods of communicating with management.
Furthermore, the discussion expanded to topics that will further enhance future operations, such as Falcon Complete, NG-SIEM, ITDR, Spotlight, Discover, and Charlotte AI.
At one table, users shared operational tips and concerns that could only be discussed amongst themselves, and the conversation became so lively that it felt like there wasn't enough time.
Beyond simply learning about product features and implementation examples, a crucial element of Falcom Meetup is providing an opportunity for users involved in daily operations to communicate from the same perspective. This time for information exchange is also an important part of the event.

It doesn't end with just listening. Table talks where users talk to each other.
It doesn't end with just listening. Table talks where users talk to each other.

What were the concerns of the operations managers that emerged this time?

Participant surveys and table discussions revealed themes that many user companies are interested in.

AI utilization and Charlotte Online AI

As the use of generative AI and AI agents progresses,

  • How to use AI safely
  • What can you do with Charlotte AI?
  • How to utilize AI in SOC operations

This demonstrated a high level of interest in these topics.
The focus is not on introducing AI itself, but rather on how to utilize it in daily security operations.

Operational efficiency improvements and utilization of NG-SIEM

Many challenges were raised, such as "Should we implement SIEM?", "How can we reduce the operational burden?", and "How can we make the SOC more efficient?".
In particular, NG-SIEM and Complete for NG-SIEM were discussed in multiple tables.
How can we increase efficiency while keeping the workload down as we continue operations?
This appears to be a common problem for many companies.

ITDR, asset management, vulnerability management

There was also interest in countermeasures against attacks targeting authentication infrastructure, as well as asset visibility and vulnerability management using Discover and Spotlight.
Security operations are not limited to endpoints.
How should we define the scope of what needs to be protected, including IDs and asset management?
The results suggest that interest among fund managers is spreading.

There isn't just one right way to implement it.

What I realized again through this Meetup is that "there isn't just one right way to manage investments."
The challenges faced and the methods chosen will vary depending on the size and structure of the organization, as well as the characteristics of the business.
On the other hand, there were many problems that I could relate to because we were all CrowdStrike users, as well as many helpful tips that I could use as reference.
If you only consider things from your own company's perspective, you may find that your options become narrower without you realizing it.
By learning about other companies' approaches and actual practices, we can gain an opportunity to review our own company's operations.
That's the value of users coming together and talking to each other.
Instead of searching for a single correct answer, we should find solutions that are appropriate for each specific environment.
Therefore, I believe that the ability to bring together experiences and concerns is a unique appeal of the Falcom Meetup.

What is Falcomi?

Falcomi is a community exclusively for companies that have implemented CrowdStrike Falcon.
This platform was created exclusively for companies using Falcon through Macnica, providing a space for users to exchange information and share operational know-how, enabling them to utilize Falcon more efficiently and effectively.

You can easily ask questions about things you'd like to know.

"How are other companies handling this setting?"
"How do you deal with alerts like this?"
Some questions that arise during daily operations cannot be answered by product documentation alone. Falcom provides a platform where users can share these questions with each other and pool their knowledge.

A wide variety of community-exclusive events are available.

In addition to Meetups like this one, we regularly organize study sessions and seminars for community members, such as "FalconTech," a CTF-style event where participants learn how to use Falcon.
In addition to listening to case studies, we provide opportunities for users to talk with each other and learn practically.

Content for users immediately after implementation is also available.

Immediately after installing Falcon, you may encounter difficulties with the setup process. FalconCom provides videos and documentation to help resolve common setup questions that users often encounter after installation.
This community is also available to users who are just starting to use the service.

The greatest appeal of Falcomi is that it allows user companies to exchange real-world operational knowledge and tips with each other. You'll find colleagues you can immediately consult with about any questions you have, and opportunities for in-depth learning at events. If you're interested in using Falcon more or learning about other companies' cases, why not join Falcomi?

Click here for details and registration for Falcomi.

*Limited to CrowdStrike user companies and companies purchasing through Macnica.
*If you are not sure whether you purchased from Macnica, please apply first (^^)/

Inquiry/Document request

In charge of Macnica CrowdStrike Co., Ltd.

Weekdays: 9:00-17:00