EAB Global improves attack surface security within 15 seconds using NetSPI Attack Surface Visibility

NetSPI +

EAB is trusted by thousands of schools to deliver meaningful technology, marketing, and research for their students and communities.

The Challenge

EAB Global faced challenges identifying assets and vulnerabilities on its changing attack surface. The current process required multiple team members to check five or more different, disconnected security tools, such as vulnerability scanners, mobile device management (MDM) tools, and endpoint detection and response (EDR) tools, which provided only parts of the information needed.

Previously, they would use one tool to understand Windows computers, another for Macs, another for servers, and the list goes on. It was a time consuming, manual process, which was further complicated when major security events, such as Log4Shell, occurred. They needed to know what assets they had, which were at risk, and the deep context of them in a single platform.

The Solution

Realizing a nose-to-thegrindstone, work harder approach was not enough, they looked for a way to unify their systems and work better, faster, and smarter.

EAB Global decided to review Attack Surface Visibility solutions to inventory assets, contextualize findings, and consolidate security tools into a single source of truth. They wanted to work with a team that listened to their challenges and hustled to optimize the tool and outcomes for their organization.

NetSPI Attack Surface Visibility gave them a single source of truth about assets, vulnerabilities, and deep data contextualization. This allowed them to accurately answer attack surface questions in seconds. When EAB Global saw the NetSPI team turning their ideas for platform updates into reality, and even building a connector for their unique technology stack, they believed in the product, the vision, and The NetSPI Agents supporting it.

  • NetSPI Solutions
    Attack Surface Visibility
  • Industry
    Higher Education
  • Employee Count
    2,000
  • Headquarters
    Washington, D.C.
  • Website
    eab.com

Results

“NetSPI has saved us time, money, and helped us mature our program by helping answer questions faster and more accurately.”

Brian Markham

CISO at EAB Global

Accelerate Time to Identify Risk Attack Surface Visibility Solutions

  • NetSPI Platform was a turnkey setup process to connect their EDR, MDM, and other tools, consolidating what was once disparate information in a single location. Once connected, they efficiently identified gaps and consistently applied security controls across their network. They have recognized comprehensive inventorying and contextualization of assets and vulnerabilities, which has allowed them to further improve their internal and external attack surface security.

Solve Shadow IT Challenges   Immediately Identifying Risk

  • As a result of NetSPI Attack Surface Visibility, EAB Global has been able to identify and protect against shadow IT risks. One of the biggest values of the CAASM solution has been the ease in immediately identifying risk. For example, when a VPN software vulnerability was recently released, the team checked to see if anyone internally was using the application, despite that it wasn’t company approved.
  • With NetSPI Attack Surface Visibility, it was fast and simple to take action by searching for this software across the entire network and discovering that 20 people were using that vulnerable VPN software.

Contextualization & Visibility Across the Organization

  • EAB Global saw value using NetSPI Attack Surface Visibility across their organization. Junior analysts learned how to think through alerts with blast radius details and enriched data context, and executives used customized dashboards and querying to immediately answer questions, visualize the potential impact of vulnerabilities on systems, and prioritize resources.
“This would be one of the first things I would recommend investing in because it allows you to answer fundamental questions about your environment, and if you don’t know what you’re securing, you can’t possibly secure it.”
Brian Markham
CISO at EAB Global