Cloud-native services and software company seeks best combination of cloud security tools, tactics and techniques
As an e-commerce fulfillment and inventory management company with no physical office space – all its employees work remotely – this company has warehouse fulfillment operations in several locations around the globe.
Its IT operation is also fully remote and distributed, and runs on AWS. According to the Chief Information & Intelligence Officer: “With all our personnel remote, a threat actor can literally be anywhere, pretending to be from our company. Securing an enterprise like ours is a unique proposition because none of the rules work, and most tools aren’t a good fit. Our goal is to find the best combination of security tools, tactics and techniques while not overlapping too much in the service provider landscape.”
Creating and maintaining zero trust
“My team manages data loss prevention, cyber security and IT – and most of our AWS infrastructure,” explains the company's CIO. “We're a smaller team trying to do our best; efficiency is critical.” The organization has a yin-yang of cloud environments to secure: their production environment, used by customers, and their internal, cloud-native distributed environments, used by employees.
The order fulfillment company sought to create and maintain a stateless zero-trust environment in which they assumed trust but verified minimum access and least privilege at all levels. According to the CIO, they use CSP-native identity services which creates a complicated mesh architecture of trust. He shares that their greatest challenge was getting control over their identity services, including credentials as their cloud security process needed to be identity first.
The right solution at the right time
“Someone reached out, explaining that Tenable Cloud Security is an identity-first cloud security platform,” shares the CIO. “Already in the discovery call we saw that it was the right solution, and the right people, at the right time – incredible serendipity. The platform aligns perfectly with our zero-trust approach.”
Without engaging the Tenable One Security team, the order fulfillment company did a proof of concept. “Doing the PoC on our own speaks to the clarity of the Tenable UX and documentation,” he says.
Onboarding and usage
Tenable Cloud Security was one of the first third-party tools the team onboarded. They quickly saw that it was a good fit. “I integrated the Tenable platform in our entire cloud environment in two hours – some solutions take 12-24 hours – and the data began flowing almost immediately,” explains the company’s Security Operations Engineer. “We could see everything – it was amazing, and validated that we’d done the integration correctly.”
“The Tenable Cloud Security platform is easy, clear and intuitive, and the guidance is accurate. I've yet to get information in Tenable that doesn’t apply – and that moves us forward,” she added.
“Tenable Cloud Security has enabled us to get 80%-90% of the way to implementing zero trust for IAM,” says the CIO. “We now have clarity about who everyone is, who or what needs access and what they have access to, so can now focus on hardening our architecture. If we remediate something, Tenable pops up to let us know where and why.”
“I integrated Tenable Cloud Security in our entire cloud environment in two hours. We could see everything – it was amazing, and validated that we’d done the integration correctly.”
-Security Operations Engineer
Striving for compliance
The order fulfillment company strives for the highest levels of compliance and is using Tenable to meet their compliance certification goals.
“Tenable Cloud Security was instrumental in completing our ISO/IEC 27001:2013 and SOC2 type 2 certifications and is key as we work on the AWS Well-Architected Framework and its benchmarks,” explains the Security Operations Engineer. “We are tracking and spotting gaps quickly, and trending upward every month, which is very encouraging.” Tenable reports are helping the company communicate with auditors.
Prioritization and remediation
A primary focus for the company has been removing critical risks and keeping their zero-trust strategy on point.
“Tenable has enabled us to focus where needed rather than face a mountain of findings we don’t have the breadth to tackle,” shares the Security Operations Engineer.
Their security team handles Tenable Cloud Security findings that involve architecture or least privilege, such as reining in public access. When a finding involves a code fix, the security team uses the platform's Jira integration to pass it to the developers for addressing in the relevant sprint based on Tenable's prioritization.
“Tenable Cloud Security remediation workflows are easy to follow and really help us with least privilege,” she added. “The Tenable platform shows if a user or programmatic access hasn't touched a resource in 90 days and provides a JSON script that eliminates the excessive privileges almost immediately. As our environment grows and tracking access risk becomes more complex, I know the Tenable recommendations on my dashboard won’t need second-guessing.”
ROI and other benefits
The company cites savings, expertise and collaboration among the benefits of their use of the Tenable Cloud Security platform.
"Like fire insurance."
“Our ability with Tenable to escalate and resolve residual access risks correctly, and give evidence that we have, links directly back to the business,” says the CIO. “We’re too young to survive the cost of a data breach; Tenable Cloud Security is like fire insurance, helping prevent the impact upon a data breach.”
Reduced headcount need, lower-cost skills
Instead of three security engineers, with Tenable, the company manages with one. “When we do add headcount this year it will be at reduced technical requirements so at a lower cost and easier to source. And the platform is so well-designed you can use it to close skill gaps and bring more people into the cloud security community,” the CIO explains.
Actionable insights
According to the Security Operations Engineer, Tenable Cloud Security offers innovative ways to fix things. “Its remediation guidance actually teaches you how to use the cloud,” she says.
The CIO adds that “Tenable’s correlated insights is unique, showing how all problems connect to your architecture and configuration state – and reveals all exploits of a compromised resource.” 24/7 partnership.
The Tenable developers and customer success team are always ready to jump on a call. The Security Operations Engineer says she can message with them almost any time and get anything fixed. “Having such a close relationship and getting rapid feedback is huge for us," she shares.
Everyone on board for cloud security
“I go into executive meetings, point at the Tenable Cloud Security dashboard, and everyone gets it,” says the CIO. “It’s a window into cloud complexity that conveys the technical perspective and at the same time easily communicates on cloud security posture – you don’t need industry expertise to understand what's going on.”
Cost-effective efficiency
According to the CIO, “Many cloud security tools push real time monitoring – in reality, for most organizations, it’s hard to do and an expensive lift. Tenable has managed to make something just as effective, at a more reasonable cost and much more robust value proposition. The platform is amazing, enabling us to make intense progress on our zero-trust strategy and has increased productivity for our highly capable teams.”