Join the Cyber Forum: Threat Intel on May 12, 2026 to learn how AI is reshaping threat defense.Join the Virtual Cyber Forum: Threat IntelRegister Now
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
Hero Banner
Q2

Q2 Boosts Efficiency and Reduces Attack Volume by 97% with SentinelOne and AWS

“We’re seeing faster queries, better performance, and can store data for longer.”

Lou Senko, Chief Customer Experience Officer, Q2

Download this Customer Success Story

Read how Q2 reduces attack volume by 97% with SentinelOne and AWS
Download as PDF
Back to Our Customers
Table of Contents
Q2

Overview

Q2, a digital banking platform provider serving community and regional financial institutions, found that it needed more scalable and adaptable tools to match its evolving cloud architecture and a rapidly changing threat landscape. Operating with Amazon Web Services (AWS), Q2 chose AWS Partner SentinelOne to modernize and expand its security operations without increasing overhead. After deploying a new security posture that included SentinelOne’s AI-powered platform, the financial technology company saw a 97 percent reduction in malicious sessions with fewer than 2,000 attempts per minute. With improved performance, deeper visibility, and automated protection, Q2 has strengthened its security posture while continuing to deliver trusted digital banking experiences at scale.

Opportunity

Juggling Growth, Trust, and Threats in a High-Stakes Digital Environment

Based in Austin, Texas, Q2 is a mission-driven provider of digital transformation services for financial services, powering online experiences for more than 26 million users and 1,400 banks and credit unions. In addition to serving national banks, Q2 remains committed to its founding goal of supporting communities by helping local banks and credit unions compete with larger institutions through secure, innovative digital services.

These institutions depend on Q2 for performance and reliability, and any disruption, whether from downtime or a security event, could damage reputations and impact local economies. Facilitating more than $3.5 trillion in annual transactions—which is over 10 percent of US GDP—along with managing 41 petabytes of customer data, Q2 must consistently meet exceptional standards for availability, resiliency, and security.

Q2 relied on a legacy endpoint detection and response (EDR) solution that used application whitelisting, which became increasingly difficult to manage across 12,000 servers and hundreds of bespoke customer environments. “We tried re-implementing an EDR solution with another vendor and got everything cleaned up, but within four months we were right back where we started,” said Lou Senko, chief customer experience officer at Q2. “It became a challenge to maintain that solution while also sustaining a strong security posture.” This prompted Q2 to seek a more scalable and intelligent solution that could evolve with emerging threats, reduce operational burden, and support the company’s broader innovation goals, which included automated workflows to assist Q2’s newly formed security operations center (SOC).

Solution

Building a Future-Ready Security Architecture with AI

As Q2 transitioned from co-located data centers to a distributed cloud architecture, it conducted an EDR proof of concept with three different vendors. The company ultimately chose SentinelOne for its artificial intelligence (AI)–powered cybersecurity solutions, ability to scale across diverse workloads, responsive engineering support, and alignment with Q2’s innovation and security roadmap. Because it’s built entirely on AWS, SentinelOne’s suite of solutions integrates deeply with Q2’s Amazon Elastic Compute Cloud (Amazon EC2) instances. It would also further protect the SQL databases that Q2 hosts in Amazon Relational Database Service (Amazon RDS).

To build out its new security approach, Q2 deployed SentinelOne’s Singularity Platform, which provides autonomous, AI-driven threat detection, response, and remediation across endpoints, cloud workloads, and identities to deliver unified cybersecurity protection. This agent-based solution replaced Q2’s previous EDR solution, delivering real-time threat detection and response across Q2’s 13,000 endpoints.

“We deployed agents across everything we could touch, and SentinelOne was a great partner in making that happen,” Senko said. To strengthen incident response, Q2 added Vigilance MDR, which extends the capabilities of the SentinelOne Singularity Platform with 24/7 expert monitoring, threat validation, and response support. This would help Q2’s security teams ensure that unfamiliar threats were triaged and addressed immediately, with the option to escalate issues to SentinelOne’s experts if needed.

Q2 then implemented Purple AI, SentinelOne’s agentic AI security analyst that utilizes generative AI, natural-language queries, intelligent threat guidance, and automated investigation workflows to enhance usability and insight generation. Purple AI is powered by Amazon Bedrock, a fully managed service that allows developers to build and scale generative AI applications using foundation models from leading AI providers through a simple API, without managing infrastructure. Q2 leverages Purple AI to help its SOC analysts surface insights and accelerate critical response and remediation actions, such as isolating. ”Purple AI will give our team an intuitive way to get the answers they need,” Senko said. “It’s built into the platform, making it easier for our analysts to ask questions and uncover findings they might not have thought to look for, without needing to be experts in the underlying data.”

As Q2’s security maturity evolved, the company adopted SentinelOne’s Watchtower Pro, a threat hunting service that augments its internal team with proactive intelligence and analysis—a critical ingredient for protecting banks’ digital interactions. Recognizing the need to unify operational and security data, Q2 migrated its entire data lake into SentinelOne’s Singularity AI SIEM. As a cloud-native, AI-driven security information and event management (SIEM) platform, it ingests and correlates data from Q2’s security stack, consolidating alerting, service level agreement tracking, and operational telemetry into a single platform. This includes logs used for fraud investigations and subpoena responses, which previously required time-consuming backup restores. Now, that data is readily accessible and queryable. Together, these solutions formed a tightly integrated, AI-driven security architecture.

“Purple AI will give our team an intuitive way to get the answers they need.”
- Lou Senko , hief Customer Experience Officer, Q2

Outcome

Stronger Security Thwarts Bad Actors, Reducing Attack Volume by 97%

With a new security stack in place, Q2 has significantly strengthened its security posture while improving operational efficiency across its hybrid cloud environment. The company now protects 7,000 endpoints and 400,000 containers with real-time threat detection, automated response, and AI-driven insights. This allowed the company to enhance team productivity as it scaled up without increasing headcount. Most notably, the company has gone from seeing 70,000 malicious sessions per minute to fewer than 2,000, a 97 percent reduction in attack volume. Credential stuffing attacks have also become less effective. Before using SentinelOne as part of its security stack, attackers would spend about 150 hours attempting to breach Q2’s systems. Now, attackers abandon Q2 as a target much faster—in just 130 minutes, a 1,000 percent reduction from before—due to the strength of the company’s layered defenses.

Denial-of-service (DDoS) attacks have also declined sharply. Two years ago, Q2 experienced 30,000 DDoS events per month, translating to about 37 per hour. Today, that number is down by 95 percent, which has freed up resources and lessened operational noise. “We’re seeing faster queries, better performance, and can store data for longer,” Senko said. “And, we are managing workloads that are thousands of times bigger than they were five years ago.” By consolidating tools, automating response, and enabling deeper visibility, Q2 has improved its security outcomes and positioned itself to scale securely as it continues to innovate in digital banking. This helps the company continue to build trust with customers and improves the productivity and satisfaction of its internal security teams. “Over the years, SentinelOnehas shown that it’s always thinking, ‘What is next? Where should we be going?’ And when my vendor is thinking about the next emerging threat and how to defend against it, I don’t have to,” Senko said.

Location

Global

Industry

Financial Services

Website
www.q2.com
Employees

1,001-5,000

Products & Services Used

Singularity™ Platform

Singularity™ XDR

Singularity™ Hyperautomation

Purple AI

Singularity™ MDR

DFIR

WatchTower Pro

Back to Our Customers

More Success Stories

10x Banking

10x Banking

View Success Story
Credit Saison

Credit Saison

View Success Story
FIMBank

FIMBank

View Success Story
Mississippi Band of Choctaw Indians

Mississippi Band of Choctaw Indians

View Success Story
YKK Americas

YKK Americas

View Success Story
Golden State Warriors

Golden State Warriors

View Success Story
Capital Area Intermediate Unit (CAIU)

Capital Area Intermediate Unit (CAIU)

View Success Story
HiBob

HiBob

View Success Story

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Column 1 Background

Connect with an Expert

Get a Demo
Request Demo
Request Demo
Column 2 Background

Take a SentinelOne Product Tour

Take a Tour
Take a Tour
Take a Tour
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English