The cyberoperations team have transformed from a team that worked in a largely reactive manner to a proactive model of working.
How has the new security platform changed the way your team detects, investigates and responds to threats on a day-to-day basis?
The automation features of the new security platform have significantly improved our mean time to detect / respond. It has created enhanced visibility of the cyberthreats facing the university, refined reporting to the executive board and has also highlighted areas of development and ways to elevate the cyber-hygiene of the organisation.
What impact has reducing the number of security alerts had on your IT team’ s ability to focus on more strategic cybersecurity initiatives?
The cyber-operations team have transformed from a team that worked in a largely reactive manner to a proactive model of working. This transition has allowed the resource to be used to develop our maturity against cybersecurity frameworks, improving our processes and utilising our people to add value across the organisation. We now operate on a secure by design mythology for all our IT initiatives and ensure cybersecurity is a critical part of everything we deliver to the organisation.
What were the key drivers behind consolidating multiple endpoint security tools into a single integrated platform?
The university has adopted a minimum effective toolset approach to consolidate the number of security tools we have in operation. This approach provides efficiency in terms of cost, resource commitment and the streamlining of our playbooks to implement a highly automated cybersecurity operation. The efficiencies we have gained support our strategy of providing a 24x7x365 cybersecurity operation service and release valuable internal resources to focus on secure by design Digital Transformation.
How important is executive reporting in helping the university’ s leadership understand cyber-risk and support investment in cybersecurity?
Providing visibility to the university executive board is about raising awareness of the cyberthreats to the sector, fostering a culture that cybersecurity is much wider than an IT problem and demonstrating the value of our investments in adopting cybersecurity frameworks, investing in people and specialised cybersecurity toolsets.
What lessons have you learned from this project that could help other universities looking to strengthen their cyber-resilience?
The lesson I have learned is that the sector can learn a great deal from partners like Palo Alto Networks to develop a culture where we share experiences, adopt a‘ Defend as One’ approach and utilise technology to automate our detection, responses and remediation to the increasing cybersecurity attack surface. I would also recommend the unification of cybersecurity toolsets to adopt a minimum effective toolset and foster a cybersecurity awareness culture across the entire organisation.
We now operate on a secure by design mythology for all our IT initiatives and ensure cybersecurity is a critical part of everything we deliver to the organisation.
WWW. INTELLIGENTCISO. COM 27