Story Poster

Success Story

Rapidly Reducing Risk for Key Public Services

Stirling Council Cuts Total Number of Vulnerabilities by 81% with Qualys

Summary

In the UK, cybercriminals are targeting education institutions more than any other sector. To enhance its security posture and ensure compliance with nationwide cyber regulations, Stirling Council in Scotland uses the Qualys Enterprise TruRisk™ Platform to help it protect thousands of IT assets across schools and council buildings.

Outcomes

vulnerabilities patched in just seven months

reduction in the total number of vulnerabilities across Stirling Council

Business Background

At Stirling Council, the Information and Communication Technology (ICT) team is primarily tasked with protecting critical public services against evolving digital threats. This involves securing all IT infrastructure used throughout the council, including schools and administrative facilities. Maintaining robust information security measures is vital for two key reasons: to ensure the council’s operational resilience and to meet the strict compliance requirements for accessing the UK government’s secure Public Services Network (PSN).

Business Challenges

Ensure reliable delivery of public services for thousands of residents

Achieve and maintain compliance with PSN requirements

Increase visibility of a large inventory of software and hardware, including servers, laptops, and workstations deployed at multiple sites

Enable remote patching of devices without requiring the central ICT team to visit each site

Accelerate normal patching cycles and respond faster to zero-day threats

Build a stronger information security posture within lean public-sector budgets

Quote Icon

In the last 12 months, education institutions in the UK were more likely to experience a breach or attack than any other sector. Stirling Council is responsible for thousands of IT assets across locations such as council offices and schools, which is one the key reasons we’ve partnered with Qualys to help reduce our cybersecurity risk.”

Murat DilekICT Manager, Stirling Council

The Solution

To enhance its approach to vulnerability management, Stirling Council replaced multiple scanning and patching tools with streamlined and integrated solutions from Qualys. By harnessing the power of the Qualys platform, specifically Qualys VMDR with TruRisk and Qualys TruRisk Eliminate™, the organization can now detect, prioritize, and remediate vulnerabilities from a single point of control.

Qualys Shield
Murat Dilek, ICT Manager at Stirling Council. “Based on my positive experience using Qualys at another Scottish council, I was confident their solutions would help us achieve PSN compliance and better protect schools in Stirling.” Working closely with the ICT team, experts from Qualys helped Stirling Council deploy lightweight Qualys Cloud Agents on all endpoints and configure the new solutions.

“The deployment process went very smoothly,” says Dilek. “One of the big factors behind our success was sitting down with our Qualys Technical Account Manager at the very start of the project. Qualys helped us push agents out to our endpoints, adopt a risk-based approach to prioritization based on Qualys TruRisk, and train and onboard our team.” Stirling Council covers an area of approximately 840 square miles, and some of its schools are located a two-hour drive from the council’s head office.

With Qualys, Stirling Council eliminates the need for time-consuming travel to local sites and reduces manual work for IT technicians based at its schools.

“Using Qualys TruRisk Eliminate, we’ve automated repetitive tasks such as deleting old user profiles from shared Windows workstations,” says Dilek. “We’ve also given IT technicians access to Qualys dashboards for their schools—replacing outdated spreadsheets with real-time insights.”
Quote Icon

One of the big factors behind our success was sitting down with our Qualys Technical Account Manager at the very start of the project. Qualys helped us push agents out to our endpoints, adopt a risk-based approach to prioritization based on Qualys TruRisk, and train and onboard our team.

Murat DilekICT Manager, Stirling Council

Qualys Difference

Combines timely vulnerability insights and automated patching capabilities into a single pane of glass

Delivers a fast deployment and user onboarding process, backed by industry best practices for remediation and patching

Provides a clear, risk-based view of vulnerabilities across thousands of IT assets

Highlights PSN compliance gaps, helping Stirling Council to target remediation work effectively

Covers patching for all core business and education apps, including third-party web browsers and archiving software

Streamlines, automates patching for remote assets, removing the need for ICT team members to perform the work in person

Hear from our customers

Start your 30-day free trial