Intrado deploys AI-driven cybersecurity to safeguard critical infrastructure

SUMMARY

Intrado Life & Safety is the largest provider of emergency communication services in the United States touching approximately 90% of all 911 calls daily and over 15 billion calls since its inception 50 years ago. Dedicated to saving lives and protecting communities, the company’s innovative technology helps first responders deliver quick, effective assistance when and where it’s needed most.

As a guardian of critical national infrastructure, Intrado is a primary target for sophisticated nation-state cyberattacks. The threats have grown more complex as adversaries weaponize AI to launch threats at unprecedented speed and scale. This challenge was compounded by years of accumulated tool silos and the alert fatigue that came with them. By unifying its products and services under an AI-driven enterprise framework, Intrado completely reinvented its SOC, collapsing incident resolution times from hours to one minute.

RESULTS

1 minute

median time to resolution, down from 10+ hours

99.8%

automated case closure rate, up from zero

12 FTEs

redeployed to strategic tasks due to 24/7 SOC management by Unit 42
CHALLENGES

Securing high-stakes public safety networks.

As Chief Strategy Officer Brian Davenport frames it, “People dialing 911 are probably having the worst day of their life. Making sure that that call always goes through can’t be compromised.” To guarantee seamless operations, his team had to overcome several challenges:

  • Critical infrastructure requirements: A secure platform was needed to ensure uninterrupted access to 911 services and meet compliance standards.
  • Increasing attack and alert volume: Intrado’s small team was unable to respond quickly enough to the escalating velocity of advanced nation-state attacks targeting public safety.
  • Siloed technology: Products had been deployed in silos for many years, limiting the real-time visibility necessary for responding to modern, AI-powered threats immediately.
SOLUTIONS

Breaking down SOC silos.

To eliminate operational friction, Intrado replaced an assortment of security tools—including SIEM, EDR, and SOAR—with Cortex XSIAM. At the heart of the company’s modernized SOC, this centralized command center unifies nearly 700 GB of data from 170 sources across endpoints, network, and cloud environments. The platform’s embedded AI automatically correlates disparate data points, from user workstations to servers and web traffic, into singular, actionable incidents, instantly revealing the root cause and cutting through alert fatigue.

Leveraging global threat intelligence, Cortex XSIAM pushes dynamic, real-time protection updates across the network, automatically shielding critical routing fabrics and enabling a lean security team to neutralize sophisticated nation-state threats within seconds. As threats evolve, Cortex AgentiX will equip Intrado with advanced agentic AI capabilities, effectively fighting AI with AI to block machine-speed attacks with automated defenses.

  • From manual daily triage to proactive security engineering

    So Intrado could achieve an around-the-clock defensive posture without building an expensive internal 24/7 capability, the company integrated Unit 42 Managed Detection and Response to directly support its Cortex environment. Today, Unit 42 acts as an extension of Intrado’s security team, combining AI-driven operations, proactive threat hunting, expert-led investigations, and response to help protect critical infrastructure. By offloading high-volume alert analysis and response activities to Unit 42, Intrado transformed its security operations from reactive maintenance to proactive innovation.

  • A SOC custom-built for critical infrastructure

    To support its dual attack surface of legacy landline and next-generation IP networks, Intrado plans to upgrade from Unit 42 MDR to Managed XSIAM. The move adds dedicated Unit 42 SOC engineers to codevelop custom detections, threat-hunting queries, automation playbooks, and security controls tailored to its unique public safety environment. MSIAM also extends visibility across native and third-party EDR environments and includes a built-in 250-hour Breach Response Guarantee, providing access to Unit 42 incident response experts if a major incident occurs. The enhanced customization ensures highly sensitive 911 call data remains protected within Intrado’s own tenant while supporting strict FCC requirements.

“Unit 42 Managed XSIAM will create custom searches, activities, and playbooks for our particular environment, so my small team doesn’t have to worry about how to do it all.”

— Charles Gifford

CISO, Intrado

  • On-call experts for IR and ongoing readiness

    "The Unit 42 Retainer gives us the ability to have IR teams that are on the bleeding edge of our technology—and who understand the latest adversarial attacks—supporting us when we do have an incident," explains Gifford. Throughout the year, Intrado actively leverages its retainer credits to conduct threat modeling against nation-state tactics, perform deep-dive digital forensics to validate data protection mechanisms, and run simulated tabletop exercises that proactively test and improve daily operational processes.

  • Defending the development pipeline

    Intrado relies on cloud-native environments to deliver critical public safety infrastructure at scale. To strengthen the security of these environments, Intrado upgraded from Prisma® Cloud to Cortex Cloud to unify application security, cloud posture security, and runtime protection on a single platform. By eliminating silos between SecOps, cloud, and development teams, Cortex Cloud gives Intrado a shared understanding of risk across the organization, enabling teams to identify risks earlier and accelerate threat detection and response. Additionally, security engineers are now able to proactively address configuration issues across the development pipeline, credential exposures, and compliance violations before they impact production environments.

  • Bridging the gap between legacy and next-gen networks

    To manage the high-stakes transition from legacy 1970s copper infrastructure to modern Next Generation 911 (NG911) IP-based frameworks, Intrado is pursuing an even greater rollout of its Next-Generation Hardware Firewalls. Davenport notes, “Moving to a modern, public-safety-grade IP network will enable tremendous enhancements in the services we provide to the citizens of this country.” Having trusted these firewalls for many years, the Intrado team treats them as critical pillars of its next-gen infrastructure, confident it can rely on them daily to protect the environment and maintain total operational uptime.

    While Intrado maintains separate networks for emergency services and enterprise clients, these firewalls secure the data center perimeters and shield the private pathways routing emergency calls—all from a single console. Operating across legacy and next-gen systems simultaneously, the firewalls deploy Cloud-Delivered Security Services to block threats instantly. This provides real-time visibility into the global threat landscape (such as active exploits emerging in Europe) and automatically applies those insights to safeguard the US 911 environment. Armed with Advanced Threat Prevention and Advanced WildFire, Intrado can seamlessly defend against unknown command-and-control (C2) activities and evasive malware.



Future-proofing emergency response.

Having proven the operational value of an integrated, automated defense platform alongside Unit 42 experts managing an elite 24/7 SOC, Intrado views Palo Alto Networks® as a strategic partner and foundational component of its future readiness. From a leadership perspective, Gifford notes that platformization has provided predictability and stability in costs while successfully moving his small team out of firefighting mode and empowering it to focus on strategic projects that drive innovation. In fact, he says, “It has enabled me as the CISO to breathe a little easier and sleep a little better knowing that I have an amazing team and partner monitoring my environment 24/7/365.” Continuous collaboration will ensure that, as the public safety sector faces shifting, AI-driven risks, Intrado remains equipped with its own AI-driven SOC to guarantee that lifesaving communications remain uninterrupted.

“Our partnership with Palo Alto Networks is mutual. We’re responsible for critical infrastructure across our country, and Palo Alto Networks brings the cutting-edge technology and people that support that.”

— Charles Gifford

CISO, Intrado

Get in touch
Find out how Palo Alto Networks can help defend your organization at AI speed.