Couldn’t make Fal.Con? Get in on Fal.Con Digital. Learn more
Customer Story

EFG Holding Strengthens Cyber Resilience Across the Middle East with CrowdStrike

EFG Holding operates in one of the world’s most dynamic financial markets — and one of its most complex threat environments.

As the largest investment bank in the Middle East and Egypt, EFG Holding provides brokerage, research, lending, factoring, and leasing services across several regional markets. The company plays an important role in helping people and businesses access financial services and protect the value of their money.

For EFG Holding, cyber risk is shaped by evolving threats, sensitive customer information, and the need to protect critical business operations across multiple markets. But for Osama M. Hijji, CISO at EFG Holding, the company’s biggest security challenge is complexity.

“We operate across multiple domains and lines of business, and the rapid pace of technology adoption is exposing us to new kinds of threats,” he said.

As EFG Holding modernized its business, its security strategy needed to evolve with it. The company needed to reduce operational complexity, improve detection and response, and protect innovation without slowing down the business. That’s when it turned to CrowdStrike.

Consolidating Security Without Compromising Protection

When Hijji joined EFG Holding, one of his first responsibilities was to evaluate the company’s security technology stack and determine whether it could support the organization’s future. EFG Holding was already using CrowdStrike for endpoint security. As part of his review, Hijji assessed whether CrowdStrike provided the right platform for the company’s long-term strategy.

“CrowdStrike was not one of the technologies I thought we needed to replace,” Hijji said. “It was the opposite. It was the technology we wanted to build on.”

Before standardizing on CrowdStrike, EFG Holding relied on multiple security tools across its environment. In some cases, endpoints were running several agents to provide basic protection. This created operational friction, consumed system resources, and interfered with work.

“You cannot have a computer using 30% of its CPU just to power security agents,” Hijji said. “We had developers who couldn’t compile code because a security tool was interrupting legitimate work.”

With the CrowdStrike Falcon® platform, EFG Holding consolidated critical capabilities into a single lightweight sensor. This reduced the need for multiple tools while improving protection.

“We eliminated a lot of complexity,” Hijji said. “We freed memory, CPU, and disk space for the business. And we improved security at the same time.”

Stronger Detection in the Real World

EFG Holding took a measured approach to validating CrowdStrike. Rather than immediately replacing its existing tools, the company ran CrowdStrike in parallel with two legacy endpoint security solutions for 18 months. This side-by-side evaluation gave the team a clear view of CrowdStrike’s detection capabilities.

“We started seeing detections in the Falcon platform that the other two vendors were missing,” Hijji said.

The distinction mattered. False positives can waste time, but missed detections create far greater risk, according to Hijji. “You cannot protect yourself from threats you don’t detect,” he said. “It is as simple as that.”

Once the team saw CrowdStrike detect malicious activity the legacy tools missed, the path forward became clear: remove redundant agents and make the Falcon platform the core security platform.

“As we removed the other agents, we maintained stronger detection and response while reducing complexity, resource utilization, and false positives,” Hijji said.

Continuous Visibility Into Exposure

As EFG Holding expanded its use of the Falcon platform, exposure management became a critical capability.

Historically, vulnerability management depended on network-based scanning. For EFG Holding, that approach was time-consuming, disruptive, and incomplete. Scans often needed to run late at night or on weekends to avoid interfering with business activity, and they still didn’t provide the full visibility the security team needed.

With CrowdStrike Falcon® Exposure Management, EFG Holding gained a more complete and continuous view of vulnerabilities across endpoints, network assets, and its external attack surface.

“Now we have visibility across three vectors: endpoint, network, and web,” Hijji said. “What used to take six to eight hours is now available continuously in one place.”

That shift gives EFG Holding more timely insight into risk and helps the team prioritize action with greater confidence. “This is not a monthly scan,” Hijji said. “We have this information all the time. The moment something changes, we can see the vulnerability.”

Securing Cloud Modernization

As EFG Holding delivers services across multiple countries, cloud technologies have become essential to reliable and scalable operations. The company’s direct market access solution runs through the cloud, and EFG Holding is moving from traditional monolithic applications toward containerized applications and microservices.

This modernization required a strong cloud security foundation, which EFG Holding found in CrowdStrike Falcon® Cloud Security.

“Before we could move into the cloud, we had to secure our position there,” Hijji noted.

For EFG Holding, securing cloud environments includes understanding posture, protecting containers, and supporting modern application architectures. That capability is especially important in financial markets, where data sovereignty and cloud security are closely scrutinized.

“We couldn’t go live without the proper security for containers,” Hijji said. “Falcon Cloud Security helped us enable the business.”

Building a Platform for Secure Innovation

For Hijji, CrowdStrike’s highest value comes from the Falcon platform’s ability to help EFG Holding reduce complexity, strengthen protection, and prepare for what comes next.

By consolidating on CrowdStrike, EFG Holding has strengthened its ability to protect critical financial services while supporting growth across the Middle East. As the company continues to modernize, the Falcon platform helps extend protection across the areas that matter most to the business — from endpoint and exposure management to identity, cloud, and AI.

“Consolidating with CrowdStrike has reduced waste across our IT infrastructure and expanded protection for the business,” Hijji concluded. “We can now protect identities, secure the cloud, and prepare for AI. Without that secure foundation, the business couldn’t move forward.”

Challenges

  • Reduce security complexity across a diverse financial services business
  • Improve threat detection while eliminating endpoint sprawl
  • Secure cloud modernization and continuous vulnerability visibility

Results

  • Reduced endpoint complexity by consolidating multiple security tools into the unified Falcon platform
  • Cut vulnerability assessment time from 6-8 hours to continuous visibility
  • Enabled secure cloud modernization for containerized applications and microservices

CrowdStrike Solutions

  • Falcon Insight XDR for extended detection and response
  • Falcon Exposure Management
  • Falcon Cloud Security
  • Falcon Next-Gen SIEM
Contact Sales Schedule a demo