Making sizzling desking safe and accessible on a worldwide scale
The primary rule of interviewing a CISO on the Australian division of Laing O’Rourke is that this: You may’t dig deep into use instances or purchasers.
And this makes good sense, as a result of while you’re answerable for securing important infrastructure for an AUD $6 billion international development and engineering agency, with tasks starting from transport to protection, even scant particulars can result in cyberattacks.
Crafting safety for joint ventures, and a really distributed community
Regardless of the excessive stakes, Laing O’Rourke’s safety challenges are distinctly common – particularly post-2020, the place the world noticed an enormous increase within the sophistication and variety of DDoS, VPN, and different web-related assaults. And like peer corporations, the corporate wanted to set a agency basis to dam internet-based assaults on distributed infrastructure.
However right here’s the place issues are completely different. Due to enterprise necessities, Laing O’Rourke’s community surroundings is complicated. The corporate typically works on what James Fields, Group Deputy CISO for Laing O’Rourke, calls “mega tasks,” joint ventures (JVs) with different corporations which are – to place it plainly – opponents.
“Being a development enterprise, bodily safety is an actual problem out on challenge websites. Typically, for a few of our larger-scale tasks, we discover ourselves in collaborative partnerships with our rivals,’” Fields commented. “At one second, they’re our companions in a challenge, and within the subsequent, they could possibly be our opponents for contemporary contracts. By participating in these joint ventures, we’re successfully inviting our competitors into our community.”
So, it’s crucial that Laing O’Rourke delivers safe community entry to employees, purchasers and JV companions in a hot-desking surroundings AND fulfill purchasers demanding adherence to completely different frameworks and certification. The corporate should additionally stop menace actors — in addition to anybody who may benefit competitively, financially, or in another manner – – from accessing or exfiltrating data from the community.
And so they did it this by including two completely different Cisco options to the stack: Cisco Safe Firewall and Cisco Identification Providers Engine (ISE).
Streamlining safety within the face of pointless, time-consuming duties
Getting backing from management to spend money on one of the best visitors and menace administration instruments can appear not possible for a lot of groups. Fortunately, Fields has enthusiastic backing from the board.
“My workforce and I are really captivated with cybersecurity, and we have now the board’s help not only for compliance’s sake (not simply performing a tick field train), but additionally for establishing one of the best practices and instilling a cyber-centric mindset all through the enterprise.”
However that doesn’t imply it’s been simple constructing that framework.
As a snapshot, earlier than Cisco ISE, Fields says, “Our three way partnership companions and purchasers had a possible threat of unintentionally (or intentionally) accessing our company community on account of shared workplace house. This prevented enterprise agility, necessitating fastened desks. Consequently, IT needed to often reconfigure ports on challenge websites as employees assignments modified based mostly on challenge phases or collaboration wants.”
Creating these pre-designed workspaces based mostly on whether or not the person was from Laing O’Rourke, or a JV took valuable time and vitality that would have been used elsewhere. The Laing O’Rourke workforce wanted clever automation to streamline the method.
Laing O’Rourke already had a number of firewalls in place, however it wanted a Cisco Safe Firewall to assist the corporate management community entry, stop intrusions and exfiltration, filter URLs, and conduct deep packet inspection. In the meantime, Cisco ISE would assist wrangle all these three way partnership units.
For the reason that Laing O’Rourke workforce was already utilizing Cisco switches and was aware of how Cisco options work, it made the selection so as to add extra Cisco to the stack all that a lot simpler.
“We, like most enterprises, use Cisco switches at our core and on the edge. So it made sense to speak to Cisco about how they may assist us shield our community.”
Utilizing Cisco Safe Firewall to streamline entry and safeguard the community
Laing O’Rourke wanted bodily safety that would accommodate hybrid employees members and contractors via hot-desking (a number of employees utilizing a single bodily workstation) and attaining seamless connectivity and community administration was essential.
To handle this, Laing O’Rourke turned to Cisco Safe Firewall, permitting the corporate to attain and preserve the confidentiality, integrity, and availability — the coveted CIA triad — of information. By successfully controlling community entry and stopping unauthorized information adjustments, Cisco Safe Firewall performed a pivotal position in safeguarding Laing O’Rourke’s community infrastructure.
Key stakeholders, together with Fields, emphasised the significance of Cisco’s wide-ranging menace intelligence. These updates ensured that the firewalls stay present with the most recent menace and vulnerability signatures, reinforcing the energy and effectiveness of Laing O’Rourke’s safety measures.
By partnering with Cisco, Laing O’Rourke has enhanced its skill to establish and mitigate a variety of threats through the use of superior options of Cisco Safe Firewall, together with intrusion prevention, URL filtering, and deep packet inspection capabilities.
The workforce additionally used Firewall Administration Middle (FMC) dashboards to handle firewalls utilizing a single pane of glass, which was ultra-convenient after they wanted insights on intrusion occasions, potential threats, and geolocation. Due to the proactive safety measures applied via Cisco’s Safe Firewall answer, Laing O’Rourke has skilled a substantial lower in web-related vulnerability assaults.
As soon as the Cisco Firewall was in place for Laing O’Rourke, it was able to do what it’s identified for: serving to stop DDOS, malware, VPN, and plenty of different assaults.
“In terms of firewalling, we take a twin vendor method. Round 5 years in the past we went out to market to switch our [competitor] firewalls. Given our constructive expertise with Cisco’s networking tools, Cisco FTD’s had been on our buying record,” Fields mentioned. “We nonetheless take a twin vendor method and Cisco remains to be serving to safe our edge.”
Including a zero-trust framework with ISE for identification
Cisco Safe Firewall has confirmed itself a formidable pressure to handle visitors and block threats, with automated updates and frequent assault intel as a sweetener. However ISE has been a revelation for Laing O’Rourke, giving the workforce a agency, assured hand when managing IP telephones, tablets, and laptops – all used to conduct enterprise.
“ISE was an actual sport changer for us. It has remodeled the best way we function on challenge websites, negating the necessity for predefined workspaces based mostly on if the person was a Laing O’Rourke employees member, JV accomplice, shopper, or visitor, whereas concurrently rising safety of our company community”.
With ISE, ports could be configured to dynamically reconfigure a port based mostly on safety posture and gadget possession, allowing entry to the correct community segments on the proper time. This consists of entry to the corporate’s company wi-fi (and wired) networks, visitor Wi-Fi, and BYOD – together with operational know-how (OT) networks.
“Whereas ISE takes a little bit of effort to arrange proper, as soon as it up and operating, it’s a really steady platform, simple to configure and integrates properly with different safety platforms like Firewall Menace Protection (FTD) and cellular gadget administration (MDM) options,” Fields mentioned.
If he needed to identify three issues that make Cisco ISE a strong answer for Laing O’Rourke, Fields spoke of dynamic profiling that detects gadget sort and applies the correct coverage, the MDM integration and compliance examine that makes positive units are up-to-date, and anomalous behaviour detection.
Based on Fields, a few years in the past, a pen-tester found a technical hole that completely wanted to be closed. So now when an IP cellphone begins to speak as Home windows visitors, for example, ISE catches it with behavioural detection.
“With the dearth of bodily safety on our challenge websites, together with actively inviting our opponents onto our community, looks like a catastrophe ready to occur,” he mentioned. “Cisco ISE has confirmed to be a useful answer for segregating entry between our workers and our purchasers and companions, defending us from menace actors and rogue community units.”
Cisco Safe Firewall and ISE save time and money
Many community and safety execs perceive how painful it may be to safe a community – particularly one which’s distributed. However with a Cisco Safe Firewall in play and ISE to handle BYODs, Laing O’Rourke’s networking workforce has already seen a distinction.
To start out, these Monday morning calls about desk strikes and disrupted community entry aren’t any extra. Laing O’Rourke is saving minutes, hours, and days, whereas concurrently bolstering community safety: one thing that notoriously…takes time.
The person expertise has improved, and the workforce has extra time to give attention to threats. Although Laing O’Rourke makes use of a twin vendor method, Cisco is the go-to for this important, international firm, with ROI already evident as soon as the corporate’s different firewalls had been changed with Cisco Firewalls.
“The [competitor] firewalls had been considerably costlier and supplied no further performance. The substitute [Cisco] really saved us cash,” Fields mentioned. “What I can say is among the few issues that doesn’t preserve me up at night time is our community uptime or network-based safety — because of Cisco Firewall Menace Protection (FTD) and Cisco ISE.”
Wish to safe your group’s sizzling desking?
Try Cisco Safe Firewall and (ISE) Establish Providers Engine — options Laing O’Rourke utilized to guard their community and folks. Study extra about how Cisco has helped different clients obtain Safety Resilience.
We’d love to listen to what you assume. Ask a Query, Remark Under, and Keep Related with Cisco Safety on social!
Cisco Safety Social Channels
Share: