0% found this document useful (0 votes)
41 views9 pages

Skybox Partner Training - Personas

Uploaded by

Prashant Biswas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
41 views9 pages

Skybox Partner Training - Personas

Uploaded by

Prashant Biswas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Skybox Training

Use Cases and


Personas

September, 2021

© 2021 Skybox Security, Inc. 1


Skybox Training – Use Cases
This training course explores specific use cases and personas for all
Skybox solutions.

© 2021 Skybox Security, Inc. 2


Use Case 1 – Managing Complexity through
Automation of Processes
Persona: Director of Network and System Services

Customer: A global leader (Fortune 500) in business and technology services, providing information technology, consulting and
business processing outsourcing to a worldwide customer base. Its global network is comprised of 50 delivery centers and nearly
a quarter of a million employees.

The Problem: After exponential growth of the company, IT was relying heavily on manual processes within their security
program; but supporting a fast–growing company with dozens of global sites and a large employee base put huge strains on
limited IT resources.

Specifics:
• IT services was receiving 300 firewall rule requests a day, unachievable
• Needed new technology, automation and analytics to bring them up to speed
• Maintaining their own compliance with ISO 27001 and ISM was paramount as well as customer compliance requirements
• Managed complex network architecture including 800 firewalls, 500 routers and thousands of switches
• IPS signatures, countless other compensating security controls, maintaining security and compliance of all these devices was
becoming impossible for the IT security teams

Results after implementing Skybox:


• Comprehensive network model with simulation and security analytic capabilities.
• Intelligently automated compliance monitoring and reporting
• Detailed visibility to compliance at the device level
• 90 percent increase in efficiency by shifting to automated processes.

© 2021 Skybox Security, Inc. 3


Use Case 2 – Firewall Assurance, Change
Management and Tracking of all Firewalls
Persona: CISO
Customer: Large, global manufacturer of quality skin care, makeup, fragrance and hair care products. Design, build, migration
and Operation of Firewall Assurance and Change Manager with 170 + firewalls
The Problem: Customer needed to change their current process in order to manage over 170 firewalls by a variety of vendors
like Palo Alto Networks, Cisco, etc. They currently have difficulty managing policies and compliance.
Specifics:
• Client needed a new firewall assurance process for their 170 + firewalls
• Configuration and Policy Compliance along with Rule Usage Analysis (RUA) as part of Daily Operations
• PCI compliance – required a solution for scanning and analyzation of firewall posture
• Required Change Simulation for all firewalls and needed to correctly identify vulnerabilities and Policy violations
• Ability to do change tracking on an ongoing basis
Results after implementing Skybox:
• Automatic importation of firewall configurations by Skybox Collector per customer-defined schedule across all geos
• Centralized Management of all firewalls and policies
• Redundant and unused firewall rules and objects were located
• Discovery of access policy violations and root cause analysis
• Reports with all Compliance Metrics, Optimization and Clean up
• Change Simulation and Auto Technical Analysis with Implementation

© 2021 Skybox Security, Inc. 4


Use Case 3 – Preserving Revenue and Customer Trust
by Drastically Reducing Security Vulnerabilities
Persona: Security Operations

Customer: World’s largest online bank, based in the UK, provides banking services to over 3.6 million customers. Ensuring that
transactions are fully secure is vital to maintaining trust and confidence with their customer base.

The Problem: The bank was vulnerable not only to a wide host of external threats—vulnerabilities, Trojans and worms, hackers
and “zombie” machines—but also to internal security breaches, both malicious and accidental. If a security breach were to occur,
the damage would have been devastating. In addition to the costs associated with business interruption, reconfiguring damaged
machines and funds lost to theft, any security breach could mean lost trust between the bank and its customers.

Specifics:
• The customer was concerned about the strength of its network security and vulnerability management processes.
• In addition, the bank lacked automated compliance reporting.
• The organization was subject to strict compliance requirements and regular audits. Without automation, the IT security team
couldn’t possibly keep up with security and compliance needs.
• As a UK-based company, our customer was subject to intense compliance scrutiny under the U.K.

Expected Results:
• Total network visibility to identify threats and compliance issues
• Prioritized threats and clear, simple remediation plans
• Continuous compliance with the Data Protection Act
• Automated weekly reporting with daily updates

© 2021 Skybox Security, Inc. 5


Use Case 4 – Enhanced Visibility into Assets and
Configuration Changes
Persona: Compliance Team and Security Managers
Customer Profile - Finnish multinational telecommunications, information technology and consumer electronics company, with
about 100k employees, annual revenue of over $20B

The Problem – Extreme network complexities with thousands of application interdependencies created a huge challenge for the
credit union. The constant network changes along with software vulnerabilities overwhelmed the company.

Specifics:
• Difficulty with identifying, addressing and remediating threats before critical applications and data was compromised
• Lack of visibility across their network and into the value of their business assets
• Basing remediation plans on vague vendor-provided risk labels, such as low, medium and high
• Administrators wasting countless hours rushing to implement patches for minor risks
• No automation of firewall change management workflows causing poor communication and efficiency across security teams

Expected Results:
• Significantly reduced vulnerability exposure window
• Harnessed total visibility to analyze access paths and connectivity for improved security—even during changes
• Automated vulnerability management processes, prioritizing risk and remediation in context
• Simulated attacks to identify access paths and vulnerabilities
• Ensured continuous compliance and implemented a Security Risk Management (SRM) program

© 2021 Skybox Security, Inc. 6


Use Case – 5 Managing the Environment and
Compliance Across Geographical Locations
Persona: IT Security Team
Customer Profile Our customer is a leader in the payroll and human resources management industry. Employing more than
30,000 people, the organization operates worldwide, with major service areas in the Americas, Europe and Asia Pacific
The Problem Statement – In Europe, the organization operates two data centers to support corporate telecommunications and
two data centers dedicated to servers and application hosting. Their European network is large and complex, containing more
than 1,200 pieces of equipment, including Cisco and Check Point firewalls with 40,000 active rules along with 1,000 switches,
routers, load balancers and security appliances. While not specifically subject to government regulations, the organization was
proactively implementing the best practices associated with CIS, PCI and SAS70 as part of their security processes and as a basis
for their internal rule compliance. Following these guidelines contributed to certification like Sarbanes Oxley. Prior to
implementing Skybox® , firewall management was decentralized and entirely manual. Rules were evaluated by team members at
different locations and remediation decisions were based on personal experience and knowledge. Each decision was handled at
the local department level using a manual process. Each business unit had its own applications hosted at the primary European
data center, where internal policy required that the center maintain network segregation. However, there was no easy way for the
IT security team to maintain segmentation or manage each business unit independently
Expected Results:

• Increased productivity 20 percent by automating security management and compliance

• Achieved continuous compliance with regulatory, industry and internal security policies

• Automated reporting for auditors and senior management

• Centralized firewall management and network security

© 2021 Skybox Security, Inc. 7


Summary Scorecard
To be eligible for rewards, user must submit these benefits statements
as part of the claim form.
In this section, you are asked to submit 6 benefit statements summarizing how Skybox Security
helps customers to solve difficult problems around security, change management, compliance,
and visibility. (Ex: Skybox Security provides deep visibility into network assets that may be a
vulnerability threat)

1.

2.

3.

4.

5.

6.

© 2021 Skybox Security, Inc. 8


THANK YOU
[Link]

© 2021 Skybox Security, Inc. 9

You might also like