COVER story
Do you have a cloud-first strategy?
Yes, and we work with all the major cloud partners and have various areas from which data is ingested. Cloud is one of them. We also have multiple EDR solutions, numerous applications and extensive integrations with customers and partners.
The objective is to ensure that we can support the hybrid and distributed model we operate. We are present across 60 markets with warehouses and factories. We also work with large global enterprises, so we have a very complex ecosystem.
One of our key objectives is to simplify that complexity while integrating Cortex into the environment.
The implementation was completed in four months. How did you manage to achieve this without disrupting day-to-day business operations?
One of the advantages of working with the right partners is the expertise they bring to the table. I think we were fortunate this time around. We had Palo Alto Networks’ professional services team closely engaged throughout the project.
From an organisational perspective, cybersecurity was approached with a great deal of seriousness, so we mobilised both our internal team and the Palo Alto Networks team to deliver the project.
I told the team that this was probably one of the most unique implementations I have undertaken in my entire career. We implemented the solution almost exactly as we had initially planned.
Beyond the usual metrics such as MTTD and MTTR, have you seen improvements in any other areas?
For me, one of the key objectives was automation. That is an important metric for us. As I said, we have automated almost 70 % of the manual activities we used to perform in the past.
We initially had plans to augment the current workforce. However, I think we have now avoided the need to hire at least three additional SOC specialists.
In terms of efficiency, if you speak to the existing SOC team, you can easily see that probably 50 % of their time has now been freed up. We want them to focus on activities that actually bring value to the business rather than simply aggregating data, connecting the dots and trying to make sense of the silos we previously had.
Typically, in an enterprise of your scale, alert fatigue and fragmented security tools are major challenges. Has this implementation helped you address these issues?
Yes, it has. If you look at false positives, for example, we previously had a very distributed ecosystem with numerous points of data ingestion. It was up to us to aggregate all that data and bring the alerts together.
We had multiple scripts and databases in place to connect everything. In many cases, we were dealing with false positives and spending significant time and effort investigating alerts that did not necessarily represent genuine threats.
As you mentioned, you have a very complex supply chain ecosystem. How are you addressing third-party risk across this environment?
This is something we are currently discussing as well. There are two key areas we are looking at. One is Cortex AgentiX and the other is Zero Trust for partners, customers and other third parties. We are also looking at the Zero Trust and SaaS capabilities they offer. I think these provide a very important value proposition for us.
But again, we want to leverage the capabilities of AI. First, we want to integrate all this data and make sense of it. Second, we want to prioritise the areas we should be focusing on. The next step is to automate some of those activities, whether the risk originates from a customer, supplier, partner or vendor.
How do you see your SOC evolving over the next couple of years?
First, we definitely want to stay as lean as possible. We want to ensure that cost, whether from IT or security, enables the business rather than becoming an overhead. We see security as an enabler of growth.
Second, we do not want to introduce unnecessary constraints into the ecosystem. We want our teams to continue operating effectively while, obviously, bringing trust into the environment.
For us, this is just the foundation. We now need to build on top of it with Zero Trust, Cortex AgentiX and many of the other capabilities we plan to explore.
We want to ensure that cost, whether from IT or security, enables the business rather than becoming an overhead.
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 17