Skip to main content

Making sizzling desking safe and accessible on a world scale

The primary rule of interviewing a CISO on the Australian division of Laing O’Rourke is that this: You’ll be able to’t dig deep into use instances or shoppers.

And this makes excellent sense, as a result of once you’re liable for securing crucial infrastructure for an AUD $6 billion world development and engineering agency, with tasks starting from transport to protection, even scant particulars can result in cyberattacks.

Crafting safety for joint ventures, and a really distributed community

Regardless of the excessive stakes, Laing O’Rourke’s safety challenges are distinctly common – particularly post-2020, the place the world noticed an enormous enhance within the sophistication and variety of DDoS, VPN, and different web-related assaults. And like peer corporations, the corporate wanted to set a agency basis to dam internet-based assaults on distributed infrastructure.

However right here’s the place issues are completely different. Because of enterprise necessities, Laing O’Rourke’s community surroundings is advanced. The corporate usually works on what James Fields, Group Deputy CISO for Laing O’Rourke, calls “mega tasks,” joint ventures (JVs) with different corporations which are – to place it plainly – rivals.

“Being a development enterprise, bodily safety is an actual problem out on challenge websites. Typically, for a few of our larger-scale tasks, we discover ourselves in collaborative partnerships with our rivals,’” Fields commented. “At one second, they’re our companions in a challenge, and within the subsequent, they may very well be our rivals for recent contracts. By participating in these joint ventures, we’re successfully inviting our competitors into our community.”

So, it’s crucial that Laing O’Rourke delivers safe community entry to workers, shoppers and JV companions in a hot-desking surroundings AND fulfill shoppers demanding adherence to completely different frameworks and certification. The corporate should additionally forestall risk actors — in addition to anybody who may benefit competitively, financially, or in some other means – – from accessing or exfiltrating info from the community.

And so they did it this by including two completely different Cisco options to the stack: Cisco Safe Firewall and Cisco Identification Providers Engine (ISE).

Streamlining safety within the face of pointless, time-consuming duties

Getting backing from management to put money into the most effective site visitors and risk administration instruments can appear unattainable for a lot of groups. Fortunately, Fields has enthusiastic backing from the board.

“My group and I are actually enthusiastic about cybersecurity, and we’ve the board’s help not only for compliance’s sake (not simply performing a tick field train), but additionally for establishing the most effective practices and instilling a cyber-centric mindset all through the enterprise.”

However that doesn’t imply it’s been simple constructing that framework.

As a snapshot, earlier than Cisco ISE, Fields says, “Our three way partnership companions and shoppers had a possible threat of unintentionally (or intentionally) accessing our company community because of shared workplace house. This prevented enterprise agility, necessitating fastened desks. Consequently, IT needed to continuously reconfigure ports on challenge websites as workers assignments modified primarily based on challenge phases or collaboration wants.”

Creating these pre-designed workspaces primarily based on whether or not the person was from Laing O’Rourke, or a JV took valuable time and vitality that would have been used elsewhere. The Laing O’Rourke group wanted clever automation to streamline the method.

Laing O’Rourke already had a number of firewalls in place, however it wanted a Cisco Safe Firewall to assist the corporate management community entry, forestall intrusions and exfiltration, filter URLs, and conduct deep packet inspection. In the meantime, Cisco ISE would assist wrangle all these three way partnership gadgets.

Because the Laing O’Rourke group was already utilizing Cisco switches and was acquainted with how Cisco options work, it made the selection so as to add extra Cisco to the stack all that a lot simpler.

“We, like most enterprises, use Cisco switches at our core and on the edge. So it made sense to speak to Cisco about how they may assist us shield our community.”

Utilizing Cisco Safe Firewall to streamline entry and safeguard the community

Laing O’Rourke wanted bodily safety that would accommodate hybrid workers members and contractors via hot-desking (a number of employees utilizing a single bodily workstation) and reaching seamless connectivity and community administration was essential.

To deal with this, Laing O’Rourke turned to Cisco Safe Firewall, permitting the corporate to realize and preserve the confidentiality, integrity, and availability — the coveted CIA triad — of information. By successfully controlling community entry and stopping unauthorized information adjustments, Cisco Safe Firewall performed a pivotal position in safeguarding Laing O’Rourke’s community infrastructure.

Key stakeholders, together with Fields, emphasised the significance of Cisco’s wide-ranging risk intelligence. These updates ensured that the firewalls stay present with the most recent risk and vulnerability signatures, reinforcing the power and effectiveness of Laing O’Rourke’s safety measures.

By partnering with Cisco, Laing O’Rourke has enhanced its means to establish and mitigate a variety of threats through the use of superior options of Cisco Safe Firewall, together with intrusion prevention, URL filtering, and deep packet inspection capabilities.

The group additionally used Firewall Administration Heart (FMC) dashboards to handle firewalls utilizing a single pane of glass, which was ultra-convenient after they wanted insights on intrusion occasions, potential threats, and geolocation. Because of the proactive safety measures applied via Cisco’s Safe Firewall resolution, Laing O’Rourke has skilled a substantial lower in web-related vulnerability assaults.

As soon as the Cisco Firewall was in place for Laing O’Rourke, it was able to do what it’s identified for: serving to forestall DDOS, malware, VPN, and lots of different assaults.

“In relation to firewalling, we take a twin vendor method. Round 5 years in the past we went out to market to exchange our [competitor] firewalls. Given our constructive expertise with Cisco’s networking tools, Cisco FTD’s had been on our buying record,” Fields stated. “We nonetheless take a twin vendor method and Cisco continues to be serving to safe our edge.”

Including a zero-trust framework with ISE for id

Cisco Safe Firewall has confirmed itself a formidable power to handle site visitors and block threats, with computerized updates and frequent assault intel as a sweetener. However ISE has been a revelation for Laing O’Rourke, giving the group a agency, assured hand when managing IP telephones, tablets, and laptops – all used to conduct enterprise.

“ISE was an actual sport changer for us. It has remodeled the way in which we function on challenge websites, negating the necessity for predefined workspaces primarily based on if the person was a Laing O’Rourke workers member, JV companion, shopper, or visitor, whereas concurrently growing safety of our company community”.

With ISE, ports may be configured to dynamically reconfigure a port primarily based on safety posture and gadget possession, allowing entry to the correct community segments on the proper time. This consists of entry to the corporate’s company wi-fi (and wired) networks, visitor Wi-Fi, and BYOD – together with operational know-how (OT) networks.

“Whereas ISE takes a little bit of effort to arrange proper, as soon as it up and working, it’s a really steady platform, simple to configure and integrates properly with different safety platforms like Firewall Menace Protection (FTD) and cell gadget administration (MDM) options,” Fields stated.

If he needed to title three issues that make Cisco ISE a stable resolution for Laing O’Rourke, Fields spoke of dynamic profiling that detects gadget sort and applies the correct coverage, the MDM integration and compliance verify that makes certain gadgets are up-to-date, and anomalous behaviour detection.

In response to Fields, a few years in the past, a pen-tester found a technical hole that completely wanted to be closed. So now when an IP telephone begins to speak as Home windows site visitors, as an illustration, ISE catches it with behavioural detection.

“With the shortage of bodily safety on our challenge websites, together with actively inviting our rivals onto our community, looks as if a catastrophe ready to occur,” he stated. “Cisco ISE has confirmed to be a useful resolution for segregating entry between our workers and our shoppers and companions, defending us from risk actors and rogue community gadgets.”

Cisco Safe Firewall and ISE save time and money

Many community and safety execs perceive how painful it may be to safe a community – particularly one which’s distributed. However with a Cisco Safe Firewall in play and ISE to handle BYODs, Laing O’Rourke’s networking group has already seen a distinction.

To start out, these Monday morning calls about desk strikes and disrupted community entry are not any extra. Laing O’Rourke is saving minutes, hours, and days, whereas concurrently bolstering community safety:  one thing that notoriously…takes time.

The person expertise has improved, and the group has extra time to deal with threats. Although Laing O’Rourke makes use of a twin vendor method, Cisco is the go-to for this crucial, world firm, with ROI already evident as soon as the corporate’s different firewalls had been changed with Cisco Firewalls.

“The [competitor] firewalls had been considerably dearer and provided no further performance. The alternative [Cisco] truly saved us cash,” Fields stated. “What I can say is likely one of the few issues that doesn’t preserve me up at night time is our community uptime or network-based safety — due to Cisco Firewall Menace Protection (FTD) and Cisco ISE.”

Need to safe your group’s sizzling desking?

Take a look at Cisco Safe Firewall and (ISE) Determine Providers Engine — options Laing O’Rourke utilized to guard their community and other people. Be taught extra about how Cisco has helped different clients obtain Safety Resilience.


We’d love to listen to what you assume. Ask a Query, Remark Under, and Keep Related with Cisco Safety on social!

Cisco Safety Social Channels

Instagram
Fb
Twitter
LinkedIn

Share:




Supply hyperlink

Hector Antonio Guzman German

Graduado de Doctor en medicina en la universidad Autónoma de Santo Domingo en el año 2004. Luego emigró a la República Federal de Alemania, dónde se ha formado en medicina interna, cardiologia, Emergenciologia, medicina de buceo y cuidados intensivos.

Leave a Reply