Insurance

Insurance Company Gains Full DDoS Visibility Across a Complex Network

The customer gained full visibility into its DDoS vulnerabilities and misconfigurations within three months of the initial, on-prem. deployment, and has decided to extend RADAR testing to include AWS, GCP, and Azure cloud infrastructure.

The Customer​

The customer is an insurance company running  a complex network environment. The North American-based headquarters runs international operations, iuncluding a number of regional subsidiaries. Customer services are managed across multiple on-prem. data centers and multiple cloud providers, including AWS, Google Cloud Platform (GCP), and Microsoft Azure. This network architecture results in a more complex attack surface with a higher potential for misconfigurations  to “hide.”

Key Takeaways

Customer Challenges

  • >40% vulnerability exposure, uncovered by RADAR™
  • Inconsistent DDoS protection (from node to node)
  •  Unnecessary traffic duplication across the network

 

Customer Benefits

  • Remediated 1,082 vulnerabilities using RADAR’s vulnerability data 
  • Ran > 1,900 simulations on active targets in the first year of deployment 
  • Gained full visibility into DDoS vulnerabilities within 3 months of deployment 
  • Maintained zero downtime since RADAR was deployed
  • Defined new internal processes for validating DDoS defense readiness

The Challenge​

At the outset, RADAR’s assessment of the customer’s environment surfaced a network problem that had nothing to do with DDoS attacks: unnecessary traffic duplication across the network was putting unnecessary load on on-prem. services, causing service disruption and lost traffic.

Once that network issue was identified and fixed, a second problem surfaced: DDoS protection was inconsistent from node to node. Certain attack types were automatically blocked on some nodes and not on others. By making the configurations consistent, the company was able to signtificantly improve its DDoS defense posture. 

Once it was fully deployed, RADAR tested and uncovered more than 40% vulnerability exposure in the customer’s deployed DDoS mitigation stack.

Our Solution

MazeBolt deployed RADAR into the customer’s on-prem. data center environment first. The customer used RADAR’s testing and validation results to work directly with its existing DDoS protection vendor, establishing a shared remediation workflow. 

The result enabled the security team to fix DDoS vulnerabilities quickly and use RADAR to validate each fix in real time. RADAR pinpointed inconsistent and misconfigured protections, so the team could correct those specific configurations, instead of re-tuning the entire environment.

Within a period of three months, the customer was able to dramatically reduce its vulnerability risk for the targets that RADAR originally tested. 793 vulnerabilities have been remediated thus far. In parallel, MazeBolt has continued to add new targets and to identify vulnerabilities in this expanded target set.

Customer Benefits

The customer gained full visibility into its DDoS vulnerabilities and misconfigurations within three months of the initial, on-prem. deployment. 845 active targets are now protected and the total number of targets tested by RADAR continues to grow, as MazeBolt expands its simulation activities to include new targets.

Due to the reduction in risk enabled by RADAR, the customer has decided to extend RADAR testing to include AWS, GCP, and Azure cloud infrastructure. Today, RADAR’s continuous testing, remediation, and validation is operating for the customer’s multi-cloud footprint.