Be a part of our every day and weekly newsletters for the most recent updates and unique content material on industry-leading AI protection. Be taught Extra
Nationwide Oilwell Varco (NOV) is present process a sweeping cybersecurity transformation beneath CIO Alex Philips, embracing a Zero Belief structure, strengthening id defenses and infusing AI into safety operations. Whereas the journey shouldn’t be full, the outcomes, by all accounts, are dramatic ā a 35-fold drop in safety occasions, the elimination of malware-related PC reimaging and thousands and thousands saved by scrapping legacy āequipment hellā {hardware}.
VentureBeat not too long ago sat down (nearly) for this in-depth interview the place Philips particulars how NOV achieved these outcomes with Zscalerās Zero Belief platform, aggressive id protections and a generative AI āco-workerā for its safety workforce.
He additionally shares how he retains NOVās board engaged on cyber danger amid a worldwide menace panorama the placeĀ 79%Ā of assaults to achieve preliminary entry are malware-free, and adversaries can transfer from breach to interrupt out in as little asĀ 51 seconds.
Beneath are excerpts of Philipsā latest interview with VentureBeat:
VentureBeat: Alex, NOV went āall inā on Zero Belief a lot of years in the past ā what had been the standout features?
Alex Philips: After we began, we had been a conventional castle-and-moat mannequin that wasnāt maintaining. We didnāt know what Zero Belief was, we simply knew that we would have liked id and conditional entry on the core of the whole lot. Our journey started by adopting an identity-driven structure on Zscalerās Zero Belief Change and it modified the whole lot. Our visibility and safety protection dramatically elevated whereas concurrently experiencing a 35x discount within the variety of safety incidents. Earlier than, our workforce was chasing hundreds of malware incidents; now, itās a tiny fraction of that. We additionally went from reimaging about 100 malware-infected machines every month to nearly zero now. Thatās saved a substantial quantity of money and time. And because the answer is cloud-based, Equipment hell is gone, as I prefer to say.
The zero belief strategy now offers 27,500 NOV customers and third events policy-based entry to hundreds of inside purposes, all with out exposing these apps on to the web.
We had been then in a position to take an interim step and re-architect our community to reap the benefits of internet-based connectivity vs. legacy costly MPLS. āOn common, we elevated pace by 10ā20x, lowered latency to crucial SaaS apps, and slashed price by over 4x⦠Annualized financial savings [from network changes] have already achieved over $6.5M,ā Philips has famous of the mission.
VB: How did shifting to zero belief truly scale back the safety noise by such an unlimited issue?
Philips: A giant cause is that our web visitors now goes by way of a Safety Service Edge (SSE) with full SSL inspection, sandboxing, and knowledge loss prevention. Zscaler friends instantly with Microsoft, so Workplace 365 visitors received sooner and safer ā customers stopped making an attempt to bypass controls as a result of efficiency improved. After being denied SSL inspection with on-prem gear, we lastly received authorized approval to decrypt SSL visitors because the cloud proxy doesn’t give NOV entry to spy on the info itself. Meaning malware hiding in encrypted streams began getting caught earlier than hitting endpoints. In brief, we shrunk the assault floor and let good visitors move freely. Fewer threats in meant fewer alerts total.
John McLeod, NOVās CISO, concurred that the āprevious community perimeter mannequin doesnāt work in a hybrid worldā and that an identity-centric cloud safety stack was wanted. By routing all enterprise visitors by way of cloud safety layers (and even isolating dangerous net periods by way of instruments like Zscalerās Zero Belief Browser), NOV dramatically lower down intrusion makes an attempt. This complete inspection functionality is what enabled NOV to identify and cease threats that beforehand slipped by way of, slashing incident volumes by 35x.
VB: Have been there any unexpected advantages to adopting Zero Belief you didnāt initially anticipate?
Alex Philips: Sure, our customers truly most popular the cloud-based Zero Belief expertise over legacy VPN purchasers, so adoption was easy and gave us unprecedented agility for mobility, acquisitions, and even what we prefer to name āBlack Swan Occasionsā. For instance, when COVID-19 hit, NOV was already ready! I informed my management workforce if all 27,500 of our customers wanted to work remotely, our IT programs may deal with it. My management was shocked and our firm saved shifting ahead with out lacking a beat.
VB: Identification-based assaults are on the rise ā youāve talked about staggering stats about credential theft. How is NOV fortifying id and entry administration?
Philips: Attackers understand itās typically simpler to log in with stolen credentials than to drop malware. In truth, 79% of assaults to achieve preliminary entry in 2024 had been malware-free, counting on stolen credentials, AI-driven phishing, and deepfake scams, in keeping with latest menace studies. One in three cloud intrusions final yr concerned legitimate credentials. Weāve tightened id insurance policies to make these techniques more durable.
For instance, we built-in our Zscaler platform with Okta for id and conditional entry checks. Our conditional entry insurance policies confirm units have our SentinelOne antivirus agent operating earlier than granting entry, including an additional posture examine. Weāve additionally drastically restricted who can carry out password or MFA resets. No single admin ought to be capable to bypass authentication controls alone. This separation of duties prevents an insider or compromised account from merely turning off our protections.
VB: You talked about discovering a spot even after disabling a personās account. Are you able to clarify?
Philips: We found that for those who detect and disable a compromised personās account, the attackerās session tokens may nonetheless be energetic. It isnāt sufficient to reset passwords; it’s a must to revoke session tokens to actually kick out an intruder. Weāre partnering with a startup to create close to real-time token invalidation options for our mostly used sources. Primarily, we need to make a stolen token ineffective inside seconds. A Zero Belief structure helps as a result of the whole lot is re-authenticated by way of a proxy or id supplier, giving us a single choke level to cancel tokens globally. That method, even when an attacker grabs a VPN cookie or cloud session, they’llāt transfer laterally as a result of weāll kill that token quick.
VB: How else are you securing identities at NOV?
Philips: We implement multi-factor authentication (MFA) nearly all over the place and monitor for irregular entry patterns. Okta, Zscaler, and SentinelOne collectively type an identity-driven safety perimeter the place every login and gadget posture is constantly verified. Even when somebody steals a person password, they nonetheless face gadget checks, MFA challenges, conditional entry guidelines, and the danger of on the spot session revocation if something appears off. Resetting a password isnāt sufficient anymore ā we should revoke session tokens immediately to cease lateral motion. That philosophy underpins NOVās id menace protection technique.
VB: Youāve additionally been an early adopter of AI in cybersecurity. How is NOV leveraging AI and generative fashions within the SOC?
Philips: We now have a comparatively small safety workforce for our international footprint, so we should work smarter. One strategy is bringing AI āco-workersā into our safety operations heart (SOC). We partnered with SentinelOne and began utilizing their AI safety analyst deviceāan AI that may write and run queries throughout our logs at machine pace. Itās been a recreation changer, permitting analysts to ask questions in plain English and get solutions in seconds. As a substitute of manually crafting SQL queries, the AI suggests the subsequent question and even auto-generates a report, which has dropped our imply time to reply.
Weāve seen success tales the place menace hunts are carried out as much as 80% sooner utilizing AI assistants. Microsoftās personal knowledge reveals that including generative AI can scale back incident imply time to decision by 30%. Past vendor instruments, weāre additionally experimenting with inside AI bots for operational analytics, utilizing OpenAI foundational AI fashions to assist non-technical workers rapidly question knowledge. After all, we’ve got knowledge safety guardrails in place so these AI options donāt leak delicate data.
VB: Cybersecurity is now not simply an IT subject. How do you interact NOVās board and executives on cyber danger?
Philips: I made it a precedence to convey our board of administrators alongside on our cyber journey. They donāt want the deep technical trivia, however they do want to know our danger posture. With generative AI exploding, for instance, I briefed them on each the benefits and dangers early on. That training helps once I suggest controls to stop knowledge leaksāthereās already alignment on why itās mandatory.
The board views cybersecurity as a core enterprise danger now. Theyāre briefed on it at each assembly, not simply every year. Weāve even run tabletop workout routines with them to indicate how an assault would play out, turning summary threats into tangible choice factors. That results in stronger top-down assist.
I make it a degree to continuously reinforce the truth of cyber danger. Even with thousands and thousands invested in our cybersecurity program, the danger is rarely totally eradicated. It’s not if we can have an incident, however when.
VB: Any remaining recommendation, primarily based on NOVās journey, for different CIOs and CISOs on the market?
Philips: First, acknowledge that safety transformation and digital transformation go hand in hand. We couldnāt have moved to the cloud or enabled distant work so successfully with out Zero Belief, and the enterprise price financial savings helped fund safety enhancements. It actually was a āwin, win, win.ā
Second, concentrate on the separation of duties in id and entry. Nobody particular person ought to be capable to undermine your safety controlsāmyself included. Small course of modifications like requiring two individuals to vary MFA for an exec or extremely privileged IT workers, can thwart malicious insiders, errors, and attackers.
Lastly, embrace AI rigorously however proactively. AI is already a actuality on the attacker aspect. A well-implemented AI assistant can multiply your workforceās protection, however it’s essential to handle the dangers of knowledge leakage or inaccurate fashions. Make sure that to merge AI output together with your workforceās talent to create an AI-infused ābrAInā.
We all know the threats hold evolving, however with zero belief, sturdy id safety and now AI on our aspect, it helps give us a combating likelihood.
