{"id":12551,"date":"2022-03-07T13:59:56","date_gmt":"2022-03-07T13:59:56","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=12551"},"modified":"2022-03-16T11:41:18","modified_gmt":"2022-03-16T11:41:18","slug":"city-of-phoenix-deploys-endpoint-security-and-services-from-crowdstrike","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2022\/03\/07\/city-of-phoenix-deploys-endpoint-security-and-services-from-crowdstrike\/","title":{"rendered":"City of Phoenix deploys endpoint security and services from CrowdStrike"},"content":{"rendered":"\n<p><strong><em>The City of Phoenix in Arizona has deployed endpoint security and services from CrowdStrike including EDR, next-generation antivirus protection, IT hygiene and vulnerability management to protect diverse infrastructure.&nbsp;<\/em><\/strong><\/p>\n\n\n\n<p>When Shannon Lawson, CISO at the City of Phoenix, told senior city managers about the costs associated with ransomware attacks on Atlanta and Baltimore, it was the kickstart they needed to support a comprehensive review of the city\u2019s security posture.<\/p>\n\n\n\n<p>The City of Phoenix is the municipal government for Phoenix, the fifth largest city in the US. It provides about 1,600,000 citizens with a wide range of public services including water, police, fire and housing, and employs 13,000 staff across diverse and often autonomous operational units.<\/p>\n\n\n\n<p>The city\u2019s existing security infrastructure consisted of a mix of individual, mostly on-premises legacy components.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2022\/03\/Shannon-Lawson.jpg\" alt=\"\" class=\"wp-image-12552\" width=\"265\" height=\"265\" srcset=\"https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2022\/03\/Shannon-Lawson.jpg 500w, https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2022\/03\/Shannon-Lawson-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2022\/03\/Shannon-Lawson-150x150.jpg 150w\" sizes=\"auto, (max-width: 265px) 100vw, 265px\" \/><figcaption><strong>Shannon Lawson, CISO at the City of Phoenix<\/strong><\/figcaption><\/figure><\/div>\n\n\n\n<p>\u201cWhen evaluating the maturity of any new environment, I first look at web, email and password exposures, and especially how endpoints are being protected,\u201d shared the CISO. \u201cI needed to determine if we had all the right pieces in place.\u201d<\/p>\n\n\n\n<p>Focusing on validating the city\u2019s choice of endpoint protection, Lawson carried out a detailed review and comparisons across the endpoint detection and response (EDR) market.<\/p>\n\n\n\n<p>\u201cI compared leading offerings with our incumbent endpoint protection product &#8211; using criteria that included ease of deployment, scope of supported systems, CPU power consumption, the overhead imposed on the endpoint, and how well both common and previously unseen threats were handled &#8211; and decided that we should do more in-depth testing of CrowdStrike,\u201d he said.<\/p>\n\n\n\n<p><strong>Running a trial<\/strong><\/p>\n\n\n\n<p>Lawson conferred with several other public sector organizations that had deployed CrowdStrike. However, it was not until the city ran a trial that the real power of the CrowdStrike Falcon platform and Falcon Complete managed detection and response (MDR) service became apparent.<\/p>\n\n\n\n<p>Lawson likened his initial experience of evaluating CrowdStrike to the movie Aliens when the crew scans the spaceship and watches, mesmerized, as the alien gets closer and closer.<\/p>\n\n\n\n<p>\u201cWe set up CrowdStrike to monitor our environment and witnessed the launch of a keyboard attack targeting our externally-facing PeopleSoft servers,\u201d explained Lawson. \u201cCrowdStrike immediately detected the threat attempt and before anything malicious could occur, we were able to shut down the servers. The CrowdStrike team then calmly walked us through the resolution process and helped ensure that the servers couldn\u2019t be compromised in this way again.<\/p>\n\n\n\n<p>\u201cBam! Right off the bat, CrowdStrike delivered and then some. Choosing CrowdStrike was a no-brainer for us all,\u201d Lawson said. \u201cEveryone was sold.\u201d<\/p>\n\n\n\n<p><strong>Rapid deployment, rapid returns<\/strong><\/p>\n\n\n\n<p>The city deployed a broad selection of CrowdStrike products, using the Falcon platform to deliver widespread capabilities, including EDR, next-generation antivirus protection, IT hygiene and vulnerability management. To offset the industry-wide shortage of security expertise, especially in the public sector, Lawson implemented CrowdStrike Falcon Complete MDR and purchased a CrowdStrike Incident Response Retainer.<\/p>\n\n\n\n<p>Starting with the pervasive Information Technology services (ITS) group, CrowdStrike was rolled out across the city\u2019s environment and immediately onboarded, in less than 24 hours, by the Falcon Complete team.<\/p>\n\n\n\n<p>\u201cWe were operational right off the bat,\u201d Lawson said. \u201cSome vendors make products that are unnecessarily complicated and need a PhD to understand. Falcon is not one of these. Ramp-up time is minimal for something this sophisticated. It has a very intuitive interface that accelerates analysis and the amount of information it gives us is unreal. Really, it\u2019s that good!\u201d<\/p>\n\n\n\n<p>To maintain continuous protection, CrowdStrike was implemented on endpoints prior to the city\u2019s legacy security application being uninstalled. In some instances, a third, well-known endpoint security tool also had been running in parallel on the same device.<\/p>\n\n\n\n<p>\u201cWe had the perfect trifecta on some of these systems to do a meaningful three-way comparison,\u201d Lawson said.<\/p>\n\n\n\n<p><strong>Flexibility<\/strong><\/p>\n\n\n\n<p>Close collaboration and operating as a single team with the Falcon Complete MDR team has been another appealing aspect of the CrowdStrike solution.<\/p>\n\n\n\n<p>\u201cCrowdStrike is there for us 24 by 7 by 365 and gives more flexibility for my team to take time off as the company really has our back. It\u2019s like having a secondary SOC and indeed, many times functions as our primary operations center for endpoints,\u201d said Lawson.<\/p>\n\n\n\n<p>Through the city\u2019s Falcon Complete contract, Lawson has access to a large pool of highly trained security experts and continuous human threat hunting via Falcon OverWatch, something that would be impossible for most public or private entities to achieve on their own.<\/p>\n\n\n\n<p>The CrowdStrike Incident Response Retainer also has proven invaluable.<\/p>\n\n\n\n<p>\u201cWe\u2019ve had the retainer in place since 2019. When the SolarWinds attack hit in late 2020, the first thing we did was to call the CrowdStrike Incident Response Team. Because we already had the contract in place, they were immediately able to assist in determining if we\u2019d been compromised. Knowing that most of the world\u2019s CISOs and CSOs were scrambling to get help from their security vendors, it was just great to get priority treatment,\u201d said Lawson.<\/p>\n\n\n\n<p>Another way CrowdStrike helped the city secure itself &#8211; and accommodate the sometimes convoluted public procurement processes &#8211; was agreeing to a flexible purchasing schedule aligned with the city\u2019s budgeting calendar.<\/p>\n\n\n\n<p>The CrowdStrike solution also demonstrated its merits during the outbreak of COVID-19.<\/p>\n\n\n\n<p>\u201cWe instantly had people working all over the place, but because CrowdStrike only needs an Internet connection to function, we were able to continue operating securely, even in the midst of the pandemic. We couldn\u2019t do that with a lot of our other tools,\u201d said Lawson.<\/p>\n\n\n\n<p><strong>Customer relationships<\/strong><\/p>\n\n\n\n<p>Lawson noted that some vendors focus too much on the bottom line rather than customer relationships, but not so with CrowdStrike.<\/p>\n\n\n\n<p>\u201cI am a CISO for a very large city and have a lot to focus on. But CrowdStrike has been one of those vendors that really is a true partner,\u201d he explained.<\/p>\n\n\n\n<p>\u201cWe have never been pressured, in any way, to buy additional products or services. The solutions work very well, there is great technical support and expertise, and the company has been with us every step of the way. I have nothing but good things to say!\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The City of Phoenix in Arizona has deployed endpoint security and services from CrowdStrike including EDR, next-generation antivirus protection, IT hygiene and vulnerability management to protect diverse infrastructure.&nbsp; When Shannon Lawson, CISO at the City of Phoenix, told senior city managers about the costs associated with ransomware attacks on Atlanta and Baltimore, it was the [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":12553,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9,510,17,43,514,49],"tags":[338,1657,2044,3026,149],"class_list":["post-12551","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies","category-case-study-newsletter","category-enterprise-security","category-top-stories","category-used","category-west-coast","tag-crowdstrike","tag-endpoint","tag-endpoint-security","tag-phoenix-arizona","tag-us"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/12551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=12551"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/12551\/revisions"}],"predecessor-version":[{"id":13041,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/12551\/revisions\/13041"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/12553"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=12551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=12551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=12551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}