Making scorching desking safe and accessible on a world scale
The primary rule of interviewing a CISO on the Australian division of Laing O’Rourke is that this: You may’t dig deep into use instances or shoppers.
And this makes excellent sense, as a result of if you’re chargeable for securing vital infrastructure for an AUD $6 billion world development and engineering agency, with initiatives starting from transport to protection, even scant particulars can result in cyberattacks.
Crafting safety for joint ventures, and a really distributed community
Regardless of the excessive stakes, Laing O’Rourke’s safety challenges are distinctly common – particularly post-2020, the place the world noticed an enormous increase within the sophistication and variety of DDoS, VPN, and different web-related assaults. And like peer firms, the corporate wanted to set a agency basis to dam internet-based assaults on distributed infrastructure.
However right here’s the place issues are totally different. Due to enterprise necessities, Laing O’Rourke’s community surroundings is advanced. The corporate typically works on what James Fields, Group Deputy CISO for Laing O’Rourke, calls “mega initiatives,” joint ventures (JVs) with different firms which are – to place it plainly – opponents.
“Being a development enterprise, bodily safety is an actual problem out on challenge websites. Typically, for a few of our larger-scale initiatives, we discover ourselves in collaborative partnerships with our rivals,’” Fields commented. “At one second, they’re our companions in a challenge, and within the subsequent, they might be our opponents for contemporary contracts. By participating in these joint ventures, we’re successfully inviting our competitors into our community.”
So, it’s crucial that Laing O’Rourke delivers safe community entry to employees, shoppers and JV companions in a hot-desking surroundings AND fulfill shoppers demanding adherence to totally different frameworks and certification. The corporate should additionally forestall menace actors — in addition to anybody who may benefit competitively, financially, or in some other method – – from accessing or exfiltrating info from the community.
They usually did it this by including two totally different Cisco options to the stack: Cisco Safe Firewall and Cisco Identification Companies Engine (ISE).
Streamlining safety within the face of pointless, time-consuming duties
Getting backing from management to spend money on the most effective site visitors and menace administration instruments can appear not possible for a lot of groups. Fortunately, Fields has enthusiastic backing from the board.
“My workforce and I are actually keen about cybersecurity, and we’ve got the board’s assist not only for compliance’s sake (not simply performing a tick field train), but in addition for establishing the most effective practices and instilling a cyber-centric mindset all through the enterprise.”
However that doesn’t imply it’s been straightforward constructing that framework.
As a snapshot, earlier than Cisco ISE, Fields says, “Our three way partnership companions and shoppers had a possible danger of unintentionally (or intentionally) accessing our company community resulting from shared workplace area. This prevented enterprise agility, necessitating mounted desks. Consequently, IT needed to incessantly reconfigure ports on challenge websites as employees assignments modified primarily based on challenge phases or collaboration wants.”
Creating these pre-designed workspaces primarily based on whether or not the consumer was from Laing O’Rourke, or a JV took valuable time and vitality that would have been used elsewhere. The Laing O’Rourke workforce wanted clever automation to streamline the method.
Laing O’Rourke already had a number of firewalls in place, but it surely wanted a Cisco Safe Firewall to assist the corporate management community entry, forestall intrusions and exfiltration, filter URLs, and conduct deep packet inspection. In the meantime, Cisco ISE would assist wrangle all these three way partnership gadgets.
For the reason that Laing O’Rourke workforce was already utilizing Cisco switches and was accustomed to how Cisco options work, it made the selection so as to add extra Cisco to the stack all that a lot simpler.
“We, like most enterprises, use Cisco switches at our core and on the edge. So it made sense to speak to Cisco about how they might assist us shield our community.”
Utilizing Cisco Safe Firewall to streamline entry and safeguard the community
Laing O’Rourke wanted bodily safety that would accommodate hybrid employees members and contractors by means of hot-desking (a number of staff utilizing a single bodily workstation) and attaining seamless connectivity and community administration was essential.
To deal with this, Laing O’Rourke turned to Cisco Safe Firewall, permitting the corporate to realize and preserve the confidentiality, integrity, and availability — the coveted CIA triad — of information. By successfully controlling community entry and stopping unauthorized information modifications, Cisco Safe Firewall performed a pivotal position in safeguarding Laing O’Rourke’s community infrastructure.
Key stakeholders, together with Fields, emphasised the significance of Cisco’s wide-ranging menace intelligence. These updates ensured that the firewalls stay present with the newest menace and vulnerability signatures, reinforcing the energy and effectiveness of Laing O’Rourke’s safety measures.
By partnering with Cisco, Laing O’Rourke has enhanced its means to establish and mitigate a variety of threats through the use of superior options of Cisco Safe Firewall, together with intrusion prevention, URL filtering, and deep packet inspection capabilities.
The workforce additionally used Firewall Administration Middle (FMC) dashboards to handle firewalls utilizing a single pane of glass, which was ultra-convenient once they wanted insights on intrusion occasions, potential threats, and geolocation. Due to the proactive safety measures applied by means of Cisco’s Safe Firewall resolution, Laing O’Rourke has skilled a substantial lower in web-related vulnerability assaults.
As soon as the Cisco Firewall was in place for Laing O’Rourke, it was able to do what it’s recognized for: serving to forestall DDOS, malware, VPN, and lots of different assaults.
“With regards to firewalling, we take a twin vendor method. Round 5 years in the past we went out to market to switch our [competitor] firewalls. Given our constructive expertise with Cisco’s networking gear, Cisco FTD’s had been on our procuring record,” Fields stated. “We nonetheless take a twin vendor method and Cisco continues to be serving to safe our edge.”
Including a zero-trust framework with ISE for id
Cisco Safe Firewall has confirmed itself a formidable power to handle site visitors and block threats, with automated updates and frequent assault intel as a sweetener. However ISE has been a revelation for Laing O’Rourke, giving the workforce a agency, assured hand when managing IP telephones, tablets, and laptops – all used to conduct enterprise.
“ISE was an actual sport changer for us. It has reworked the way in which we function on challenge websites, negating the necessity for predefined workspaces primarily based on if the consumer was a Laing O’Rourke employees member, JV companion, consumer, or visitor, whereas concurrently growing safety of our company community”.
With ISE, ports may be configured to dynamically reconfigure a port primarily based on safety posture and gadget possession, allowing entry to the appropriate community segments on the proper time. This consists of entry to the corporate’s company wi-fi (and wired) networks, visitor Wi-Fi, and BYOD – together with operational expertise (OT) networks.
“Whereas ISE takes a little bit of effort to arrange proper, as soon as it up and working, it’s a really secure platform, straightforward to configure and integrates properly with different safety platforms like Firewall Menace Protection (FTD) and cellular gadget administration (MDM) options,” Fields stated.
If he needed to title three issues that make Cisco ISE a strong resolution for Laing O’Rourke, Fields spoke of dynamic profiling that detects gadget sort and applies the appropriate coverage, the MDM integration and compliance verify that makes certain gadgets are up-to-date, and anomalous behaviour detection.
In keeping with Fields, a few years in the past, a pen-tester found a technical hole that completely wanted to be closed. So now when an IP cellphone begins to speak as Home windows site visitors, as an example, ISE catches it with behavioural detection.
“With the dearth of bodily safety on our challenge websites, together with actively inviting our opponents onto our community, looks like a catastrophe ready to occur,” he stated. “Cisco ISE has confirmed to be a useful resolution for segregating entry between our workers and our shoppers and companions, defending us from menace actors and rogue community gadgets.”
Cisco Safe Firewall and ISE save time and cash
Many community and safety execs perceive how painful it may be to safe a community – particularly one which’s distributed. However with a Cisco Safe Firewall in play and ISE to handle BYODs, Laing O’Rourke’s networking workforce has already seen a distinction.
To begin, these Monday morning calls about desk strikes and disrupted community entry are not any extra. Laing O’Rourke is saving minutes, hours, and days, whereas concurrently bolstering community safety: one thing that notoriously…takes time.
The consumer expertise has improved, and the workforce has extra time to give attention to threats. Although Laing O’Rourke makes use of a twin vendor method, Cisco is the go-to for this vital, world firm, with ROI already evident as soon as the corporate’s different firewalls had been changed with Cisco Firewalls.
“The [competitor] firewalls had been considerably dearer and provided no further performance. The substitute [Cisco] really saved us cash,” Fields stated. “What I can say is without doubt one of the few issues that doesn’t maintain me up at evening is our community uptime or network-based safety — due to Cisco Firewall Menace Protection (FTD) and Cisco ISE.”
Need to safe your group’s scorching desking?
Take a look at Cisco Safe Firewall and (ISE) Establish Companies Engine — options Laing O’Rourke utilized to guard their community and other people. Be taught extra about how Cisco has helped different clients obtain Safety Resilience.
We’d love to listen to what you suppose. Ask a Query, Remark Beneath, and Keep Linked with Cisco Safety on social!
Cisco Safety Social Channels
Share: