Intelligent CISO Issue 14 | Page 53

COVER STORY airport’s infrastructure, IGA is able to protect both the airport’s business and customer data. Since deploying, it has witnessed greater threat hunting and investigative analysis and in-depth visibility in network and endpoints. Ersin Inankul, CIO, Istanbul Grand Airport said: “We have built Istanbul’s airport as the world’s largest airport and with security as a foundation. And we are happy to partner with Cisco to secure this airport.” We asked Inankul further questions about the solution. Why is it important for Istanbul Grand Airport to have an integrated security solution? Integrated solutions are very important for unified visibility, threat intelligence, enrichment and collective response. Within this scope, Cisco integrates security across the network, cloud, Internet, email and endpoints to minimise the complexity of managing security across a distributed organisation and to increase threat visibility into the farthest reaches of the enterprise and global service provider infrastructures. Cisco embeds security throughout the extended network. customer and business data will be protected and secured. Additionally, Cisco AMP Everywhere is easy to deploy. Its flexibility will allow IGA to simply scale its IT infrastructure as the airport and IT team expands throughout its construction phases. Through the integrated architecture, IGA is fully protected – from network, to email, to web, all the way to endpoints. Using AMP Everywhere, IGA will be able to see a threat once and block it everywhere else in their environment, thus decreasing the security administrations workload and time to detect and remediate against threats. Securing the central hub With the full Cisco AMP Everywhere architecture fully deployed in the www.intelligentciso.com | Issue 14 Can you explain how the solution has given you better threat hunting capabilities? Cisco CTR is our primary integrations platform which gives us the capability to reduce the time for detection. Cisco Threat Response automates integrations across select Cisco Security products and accelerates key security operations functions: detection, investigation and remediation. It is a key pillar of the integrated security architecture. The Cisco 2018 Security Capability Benchmark Study indicates that 54% of all cyberattacks result in financial damages of more than US$500,000 including, but not limited to, lost revenue, customers, opportunities and out-of-pocket costs. To prevent such losses, we prefer Cisco to protect our customers’ data. Cisco enables the organisation’s IP network to be used as a sensor to report anomalies on the network and even undertake automatic cybersecurity actions. This means the IP network can be used as a sensor to detect and eliminate security threats. We all know that in the real world there is not a 100% protection system/data but we are confident that we can mitigate 99% of attacks. For the 1%, we focus on end point security solutions, awareness, regulations, network visibility and security solutions. How important is it to IGA to protect the endpoints? Cisco Advanced Malware Protection (AMP) for Endpoints prevents threats at point of entry, then continuously tracks every file it allows into your endpoints. AMP can uncover the most advanced threats – including file-less malware and ransomware, in hours, not days or months. The data is on the endpoints and malware is always active on the endpoints so for us endpoint visibility is very important and using Cisco AMP for Endpoints, which is a hybrid of EPP and EDR solution, gives us the capability to protect endpoints. Why is it so important for IGA to protect the data of its customers and are you confident that this will be protected? Can you explain how the implementation has allowed you to gain visibility and what the benefits of this are? The arena for cybercriminals is increasing. In today’s cyberthreat landscape, every organisation, large or small, is at risk of an attack. Integration with AMP across the board allowed us to gain deep visibility in our endpoints, network, web and email layers. u 53