360° Web Application Security Achieved by IT Services Company with Imperva SecureSphere Virtual Appliances
Technology Category
- Application Infrastructure & Middleware - Event-Driven Application
- Cybersecurity & Privacy - Application Security
Applicable Industries
- Cement
- National Security & Defense
Applicable Functions
- Product Research & Development
Use Cases
- Inventory Management
- Tamper Detection
Services
- Cybersecurity Services
- System Integration
About The Customer
The customer is a Fortune 500 IT services and business software company with over 20,000 employees. They provide data center hosting services for their own financial applications and for third-party web applications. Many of these applications are internet-facing and are regulated by the Sarbanes-Oxley and Gramm-Leach-Bliley Acts. The company has a highly virtualized environment, with web applications, databases, and load balancers all moved to VMware. They also maintain a remote disaster recovery site that mirrors the infrastructure at their primary site.
The Challenge
A Fortune 500 IT services and business software company, with over 20,000 employees, provides data center hosting services for its own financial applications and for third-party web applications. Many of these applications are internet-facing and regulated by the Sarbanes-Oxley and Gramm-Leach-Bliley Acts, requiring the company to protect sensitive data. The company faced challenges in maintaining security due to the dynamic and highly-customized nature of its applications. Continual scanning of applications after every change was burdensome and required significant coordination between application developers and security engineers. The company needed a solution that would not impact release schedules, provide instant vulnerability remediation, and integrate seamlessly into their virtualized environment.
The Solution
The company implemented Imperva SecureSphere virtual appliances, a comprehensive protection solution with granular security policies for their corporate data center and disaster recovery site. The SecureSphere Web Application Firewall was chosen due to its accurate web application protection, easy deployment in a virtualized environment, granular security policies, detailed alerting and reporting, and virtual patching capabilities. The solution was able to stop all application attacks without blocking legitimate traffic. It also provided comprehensive alerts that contained the full HTTP request and clearly identified what part of the request violated security policy. SecureSphere was also able to integrate with the company's existing IBM AppScan and HP Webinspect tools to virtually patch application vulnerabilities, allowing the company to enforce stricter security rules for known vulnerable application elements.
Operational Impact
Quantitative Benefit
Case Study missing?
Start adding your own!
Register with your work email and create a new case study profile for your business.
Related Case Studies.
Case Study
System 800xA at Indian Cement Plants
Chettinad Cement recognized that further efficiencies could be achieved in its cement manufacturing process. It looked to investing in comprehensive operational and control technologies to manage and derive productivity and energy efficiency gains from the assets on Line 2, their second plant in India.
Case Study
Data Capture for Afghanistan Forces
Electronic equipments on the field of Afghanistan provided information on the status of the vehicle and to identify potential threats surrounding it to the British Force. The monitoring and interpretation of this data requires robust and sophisticated digitization for data capture and communication.
Case Study
Digital Transformation of Atlanta Grout & Tile: An IoT Case Study
Atlanta Grout & Tile, a Tile, Stone & Grout restoration company based in Woodstock, Georgia, was facing challenges with its traditional business model. Despite steady growth over the years, the company was falling behind the web revolution and missing out on the opportunity to tap into a new consumer base. They were using independent software from different vendors for each of their department information and workforce management. This resulted in a lot of manual work on excel and the need to export/import data between different systems. This not only increased overhead costs but also slowed down their response to clients. The company also had to prepare numerous reports manually and lacked access to customer trends for effective business decision-making.
Case Study
Major Aerospace Company Automates Asset Management
The O&M division of an aerospace and global security company was using spreadsheets to manually track more than 3,000 assets assigned to students and staff. Maintaining audit trails for this high volume of equipment became increasingly time-consuming and challenging. The chore involved knowing precisely what equipment was on hand, what had been issued, its location and the name of the custodial owner of each item. Every aspect of this task was carried owner of each item. Every aspect of this task was carried out by individuals with spreadsheets. Manually documenting the full lifecycle of each asset added to the burden. This included tracking maintenance requirements and records, incidents and damages, repairs, calibrations, depreciation, and end-of-life data.
Case Study
Revolutionizing Construction Equipment Rental: A Case Study on ProsRent and ENO8
ProsRent, a startup that won the 'Best Financial Opportunity' and 'Best Pitch' at CodeLaunch 2016, aimed to revolutionize the way construction professionals source and rent heavy equipment. In the construction industry, project managers and contractors typically rent heavy equipment from supply companies. However, predicting inventory can be challenging, and finding the required equipment at the right time and place can be a hassle. If the preferred vendor doesn't have the required equipment, it results in wasted time and money in searching for it, often leading to higher costs due to non-preferred rates and increased delivery costs if the vendor is located far from the job site. Suppliers, on the other hand, desired access to a wider base of trusted renters that they didn't have to vet themselves and wanted to offer dynamic rental pricing based on demand and availability in their market. ProsRent's challenge was to produce a minimum viable product that was fast and first to market but also strong enough to engender loyalty and repeat business from the target market.