Effectively Reducing Risk with Skybox Security Vulnerability

case study
Effectively Reducing Risk with Skybox Security
Vulnerability Management
Banking and Insurance Co-operative
Customer Profile
Company Profile
A banking and insurance co-operative, this organization is
committed to leading the way on ethical, environmental and
community matters. Comprised of a group of businesses that
include insurance, investment and banking services, the
co-operative serves more than 6.5 million customers, and is
headquartered in the United Kingdom.
Financial Services Co-operative
IT Environment
Post-merger, large, complex, multivendor distributed environment with
more than 6,500 servers
Business Objectives
• Gain network visibility
Business Problem and Scope
Fueled by several mergers, the co-operative went through a
period of rapid growth, resulting in a large, complex and multivendor network. With more than 6,500 servers in the network,
the IT security team was facing challenges running vulnerability
scans on their complex network.
Traditional scanners caused unacceptable disruptions to the
network, which impacted critical services. As a result, the IT
security team was unable to scan efficiently and lacked the
coverage and frequency needed for effective vulnerability
assessment. The data that they received from active scanners was
not always accurate, and the team struggled to make clear decisions
on which risks were critical and required their immediate attention.
Customers demanded 24x7 access to their financial data, yet the
organziation needed to ensure the network was secure and
compliant with company requirements. The security team faced a
tough trade-off between the management headaches of vulnerability
scanning, versus potential cyber attacks inflicted by APTs, malware,
cyber criminals, and other sort of threats.
Effective Risk Reduction
They were already using Skybox Security for firewall rule
clean-up and network visibility, and opted to extend their Skybox
deployment to include Risk Control for vulnerability management.
Immediately following implementation, they experienced significant
business and security improvements, including a daily view of the
vulnerabilities that posed the greatest threat to their network.
www.skyboxsecurity.com
• Reduce the vulnerability window of
exposure—the time from vulnerability
assessment to remediation
• Reduce risk
• Find a way to assess vulnerabilities
without the disruption of scanning
Skybox Solution
Skybox Risk Control for
vulnerability management
Results
• For the first time, reduced the time
window for vulnerability awareness
and patching
• Gained network visibility—now
have a daily, accurate view of
vulnerabilities
• Secured resources from management to create a Vulnerability
Management team focused on
reducing risk and optimizing the
vulnerability management process
Effectively Reducing Risk with Skybox Security Vulnerability Management: case study
With these valuable metrics, the IT security team
was able to request additional headcount to create a
vulnerability management team focused on eliminating
attack vectors and reducing risk. The management
team approved the request, and for the first time, the
organization is realizing a measurable reduction in risk.
Since implementing Skybox vulnerability management,
the co-operative has realized a predictable and repeatable ROI along with other valuable benefits:
• Detection of potential network vulnerabilities before
they can damage the network
• Proactive control of the risk management program
• Increased efficiency of vulnerability management
activities
About Skybox Security, Inc.
Skybox Security, Inc., provides the most powerful
risk analytics for cyber security, giving security
management and operations the tools they need to
eliminate attack vectors and safeguard business data
and services. Skybox solutions provide a contextaware view of the network and risks that drives
effective vulnerability and threat management, firewall
management, and continuous compliance monitoring.
Organizations in Financial Services, Government,
Energy, Defense, Retail, and Telecommunications rely
on Skybox Security every day for automated, integrated
security management solutions that lower risk exposure
and optimize security management processes. For
more information visit: www.skyboxsecurity.com.
The Risk Control Remediation Center, featuring a vulnerability remediation dashboard, supports fast resolution to achieve
desired security objectives.
www.skyboxsecurity.com
Headquarters: Skybox Security, Inc.• 2099 Gateway Place, Suite 450 • San Jose, California 95110 USA
Phone: +1 (866) 441 8060 • Phone: +1 408 441 8060 • Fax: +1 408 441 8068
Copyright © 2014 Skybox Security, Inc. All rights reserved. Skybox is a trademarks of Skybox Security, Inc. All other registered or unregistered trademarks are the sole
property of their respective owners. CS_CF_EN_04082014