{"id":47360,"date":"2020-04-24T14:04:02","date_gmt":"2020-04-24T13:04:02","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=47360"},"modified":"2020-05-05T08:26:52","modified_gmt":"2020-05-05T07:26:52","slug":"global-manufacturer-secures-it-and-ot-network-achieves-dramatic-roi-with-forescout","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/04\/24\/global-manufacturer-secures-it-and-ot-network-achieves-dramatic-roi-with-forescout\/","title":{"rendered":"Global Manufacturer Secures IT and OT Network, Achieves Dramatic ROI With Forescout"},"content":{"rendered":"\n<p><strong>Overview<\/strong><br>With a focus on innovation and productivity, Haworth Inc. designs and manufactures adaptable workspaces, including raised floors, movable walls, systems furniture, seating and Workware\u2122 wired and wireless technology devices for real-time collaboration. The Holland, Michigan-based company employs 6,200 people worldwide in 20 production facilities and 55 sales offices. With the recent acquisition of several lifestyle design companies, Haworth needed network access control (NAC) that would permit only authorized devices that meet corporate security standards to access its corporate network.<\/p>\n\n\n\n<p><br>To meet the company\u2019s NAC needs as well as fill other security gaps, such as rogue device detection and containment, Haworth implemented the Forescout platform. With its granular visibility and control, the Forescout solution dramatically improved the security posture of both IT and production environments. Furthermore, integrating it with the company\u2019s firewalls allowed automation of security tasks, freeing up Haworth\u2019s information security team tremendously. The Forescout platform also proved its worth beyond the security realm and is used by other operational areas, including network management.<\/p>\n\n\n\n<p><br><strong>Business Challenge<br><\/strong>\u201cFor these use cases and others, we needed not only greater visibility and control, but also the ability to classify devices, segment networks by device and look for indicators of compromise\u2014all in real time.\u201d Joseph Cardamone, Senior Information Security Analyst and North America Privacy Officer, Haworth<\/p>\n\n\n\n<p><br>Senior Information Security Analyst and North America Privacy Officer Joe Cardamone leads information security strategy at Haworth. As part of a threeperson information security team, Cardamone and his colleagues strive to protect both corporate and production environments throughout Haworth\u2019s global enterprise. The company\u2019s recent acquisition of many autonomously run companies exacerbated the challenge.<br>Devices owned by its new affiliates weren\u2019t the only assets for which the team needed greater visibility and control. For instance, they needed a better, faster way to locate high-risk IoT devices and prevent them from receiving or transmitting any unauthorized communications. They also needed to easily identify and secure its proprietary Workware digital collaboration devices, which constantly move between locations and whose software and hardware are frequently updated.<\/p>\n\n\n\n<p><br><strong>Why Forescout?<br><\/strong>An Easy-to-Deploy, Easy-to-Use \u201cInformation Powerhouse\u201d<br>Cardamone and his team conducted proof of concepts for the Forescout platform and a solution from a vendor that already had a significant presence in the company and the initial backing of Haworth\u2019s network team. Forescout emerged as the clear winner.<br>\u201cThe Forescout platform is an information powerhouse that, unlike our alternative, is quick to deploy and very easy to use,\u201d states Cardamone. \u201cFrom a single pane of glass, I can see across our entire environment with highly granular detail and manage protection with a right click on my mouse. The GUI is very intuitive and the information so clear that even new team members and other departments outside security\u2014including the network team\u2014can use it and benefit from it.\u201d<\/p>\n\n\n\n<p><br><strong>Business Impact<br><\/strong>Rapid Deployment and Time to Value Out of the Box<br>Deployment of the Forescout platform took less than a day. \u201cWe started implementation at lunchtime and when I fired up my computer that evening, 97 percent of our environment had already been discovered and classified,\u201d he recalls. \u201cWithin seven hours we had detailed visibility of our global environment. That\u2019s impressive.\u201d<\/p>\n\n\n\n<p><br><strong>Value of Comprehensive, Granular Visibility Demonstrated from the Beginning<br><\/strong>The accurate visibility provided by the Forescout platform proved its worth immediately upon implementation. \u201cWe thought we had around 7,500 devices on our networks but the Forescout platform discovered more than 12,000 IP addresses,\u201d notes Cardamone. \u201cWe also discovered security gaps we didn\u2019t know about, such as a dozen wireless access points installed in our showrooms. The newfound visibility allowed us to block those devices as well as contact the local administrators to remediate them.\u201d<br>\u201cBut that\u2019s just the tip of the iceberg,\u201d continues Cardamone. \u201cThe amount of information we get back from the Forescout platform is incredible. While many other tools discover the IP addresses of endpoints, it is by far the best solution I have ever used to properly find, identify and control systems. It has been beyond valuable to us.\u201d<br>\u201cOften we can automate action against an endpoint, but when manual intervention is needed, a simple right click is all it takes,\u201d continues Cardamone. \u201cI can also enable Level 1 or 2 staff to take Level 3 actions in a crisis without giving access to privileged functions. The Forescout platform has powerful capabilities right out of the box but is also very customizable. The sky\u2019s the limit on what we can do with it.\u201d<\/p>\n\n\n\n<p><br><strong>Visibility into Device Hygiene of Acquired Companies<br><\/strong>The Forescout platform provided visibility into the acquired companies and the device hygiene level at each. \u201cIf their devices haven\u2019t been patched in a long time, we know it, and can take action\u201d says Cardamone. \u201cThe Forescout platform also checks the patching and antivirus status and operating system of any affiliate device that attempts to connect to the corporate network and blocks those that don\u2019t meet our criteria.\u201d<\/p>\n\n\n\n<p><br><strong>Simpler but More Customizable Network Segmentation<br><\/strong>Using Forescout eyeExtend for Palo Alto Networks\u00ae Next-Generation Firewall, Cardamone quickly integrated the Forescout platform with the company\u2019s firewalls to enable on-the-fly network segmentation based on accurate, real-time, contextual information provided by the Forescout solution. \u201cWith the ForescoutPalo Alto Networks integration, we are no longer limited to segmentation by basic identifiers such as IP or VLAN,\u201d explains Cardamone. \u201cWe have a lot more options than we would have with only 802.1X because we can base the segmentation on a much deeper, richer endpoint profile.\u201d<br>For instance, in Haworth\u2019s manufacturing environment, Cardamone uses the Forescout platform to identify and classify all high-risk IoT devices\u2014primarily those devices that are no longer supported by the manufacturer, such as Windows\u00ae XP or Windows 2000 operating systems. Dynamic network segmentation then automatically blocks these devices from receiving or transmitting any information except under very specific authorized circumstances.<\/p>\n\n\n\n<p><br><strong>Huge, Quantifiable Time Savings from Integration and Automation<br><\/strong>In addition, the Forescout-Palo Alto Networks integration enabled Haworth to automate cumbersome, manual processes. Take Haworth\u2019s Workware technology devices, for example. Present in Haworth headquarters and showrooms around the globe and run on production VLANs, these devices used to be assigned a static IP address that was then allowed to talk to the guest network through the firewall. With 130 of these devices in headquarters alone, constant updates and changes to hardware and software, and physical moves that changed IP addresses, a manual process simply could not keep pace to provide adequate network access control.<br>Today, however, the Forescout platform finds them, classifies them and places them in a dynamic access group linked to a firewall policy that allows IP addresses in that group to talk to the guest network on needed ports and applications. \u201cSo, whether the device is moved to China or Germany, Forescout finds it and the firewall knows what to do,\u201d says Cardamone. \u201cWhat was once an ongoing, almost impossible manual task is now completely automated.\u201d<br>\u201cIf we add up all the time we have saved in our various use cases since installing the Forescout platform and integrating it with our firewall, I estimate savings of about 20 hours each week, or half of a full-time employee,\u201d says Cardamone. \u201cOur small security staff can do more to secure our environment but with less work.\u201d<\/p>\n\n\n\n<p><br><strong>Benefits of Forescout Visibility Extend Beyond Security<br><\/strong>Haworth operations staff also benefits from the Forescout platform. Technology support technicians use it to physically locate devices. Software management uses it to check for noncompliant applications. Even the network team uses it weekly to find information on ports and switches. And new uses are always in the pipeline. For instance, Forescout will play a critical role when the company transitions to a BYOD policy in the future.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>OverviewWith a focus on innovation and productivity, Haworth Inc. designs and manufactures adaptable workspaces, including raised floors, movable walls, systems furniture, seating and Workware\u2122 wired and wireless technology devices for real-time collaboration. The Holland, Michigan-based company employs 6,200 people worldwide in 20 production facilities and 55 sales offices. With the recent acquisition of several lifestyle [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":47361,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[809],"tags":[6050,11638,209,11639,11637,288,5626],"class_list":["post-47360","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-more-news","tag-forescout","tag-haworth","tag-it","tag-joseph-cardamone","tag-manufacturer","tag-network","tag-ot"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/47360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=47360"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/47360\/revisions"}],"predecessor-version":[{"id":47403,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/47360\/revisions\/47403"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/47361"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=47360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=47360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=47360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}