Saving Millions Annually with Real-Time Asset Inventory
With Balbix, a CSP leverages automated real-time asset inventory to identify 158% more assets and leverage a 100x faster risk identification and mitigation workflows.
With Balbix, a CSP leverages automated real-time asset inventory to identify 158% more assets and leverage a 100x faster risk identification and mitigation workflows.
IT and cybersecurity teams in this organization were frustrated by the lack of accurate asset inventory. As a senior executive responsible for securing applications put it:
“Our inventory process was a mess. We were unable to properly identify and categorize assets. Yes, we had dozens of tools and some ad-hoc integration, but it was difficult to correlate the data from these sources into a single, comprehensive inventory.”
Not having a single accurate asset inventory system meant that many IT processes involved manual steps to query multiple tools, tediously collate and sort through the (often conflicting) data, before the desired information was available. For example, identifying, prioritizing, and mitigating cybersecurity vulnerabilities across millions of assets was very time consuming.
With Balbix, this customer was able to implement real-time asset inventory by integrating data from the on-network ground truth and key IT systems.
Balbix connectors were configured to collect data from multiple systems of record, in order to extract business logic information automatically and continuously from these systems. Balbix sensors were also deployed in the customer’s major data centers to monitor north-south and east-west traffic at strategic points in the network. The architecture of the deployment is shown in the picture below.
Using tags imported from these existing systems of record, the customer was able to construct a set of groups in Balbix that reflected the organization structure and asset ownership hierarchy. Assets were automatically discovered, tracked and mapped to relevant groups. Stale and contradictory information was automatically resolved with Balbix’s AI algorithms performing the function of a tireless, very knowledgeable human operator. A small amount of necessary human input was facilitated by simple workflows.
Some of the inventory related use-cases that were enabled include:
“Previously, responding to a new vulnerability like Sambacry required manual work, script-writing and communication between multiple teams to identify assets at risk and perform mitigation tasks. This process would take weeks. With Balbix, we can query for assets at risk and track remediation in real-time, shrinking the response time from weeks to hours.”
The new Balbix-powered setup continuously discovers and prioritizes emerging vulnerabilities based on risk, incorporating information about vulnerabilities, threat levels, asset exposure, security controls and business criticality. Dashboards with powerful natural language search capabilities enable stakeholders across the organization to identify risk areas quickly. APIs trigger automated workflows, enabling the organization to trigger mitigation steps immediately after learning about a new issue.
Since this customer is massive and distributed, Balbix enables the organization to be partitioned into asset groups. We can designate risk owners and SLAs for each asset group, with corresponding dashboards tracking risk mitigation performance against target SLAs, and integrated workflows. Any action taken anywhere in the organization immediately feeds back into these dashboards and reports, enabling hundreds of stakeholders to tightly coordinate risk management and resolve any gaps quickly.
For a major IT project such as implementing real-time inventory at carrier-scale, it is quite hard to get the deployment over the finish line. Many projects never make it, and several fail to deliver the promised value.
We asked our customer to summarize their three biggest takeaways from their Balbix project for this case study. Here is what the customer listed.