Reduction in audit prep time
Hours saved annually across audit cycles
Firewalls managed
The Challenge
Before FireMon, NTT DATA‘s security and network teams managed firewall policy the way most enterprises do: manually. Audit preparation meant logging into individual firewalls, exporting rules, and cross-checking everything in spreadsheets, a process that pulled multiple engineers away from other work for days at a time. Without a centralized way to see across vendors, unused, overly permissive, shadow, and duplicate rules accumulated unnoticed, quietly expanding the attack surface.
The company sought to:
- Centralize policy visibility across a multi-vendor firewall estate (Palo Alto, Fortinet, SonicWall, Check Point).
- Replace manual, spreadsheet-based audit prep with automated risk and compliance reporting.
- Identify and clean up unused, shadow, duplicate, and overly permissive rules at scale.
- Build repeatable governance and change-tracking processes, not just point-in-time audit scrambles.
- Strengthen change tracking to quickly validate whether a rule change introduced risk.
The Solution
FireMon Security Manager gave NTT DATA a single pane of glass across every firewall vendor in their environment, eliminating the need to log into each device separately to understand rule state. Automated risk and rule analysis now surfaces unused, shadow, duplicate, and overly permissive rules directly, and built-in compliance reporting for standards like PCI DSS, ISO 27001, and NIST produces audit-ready evidence without manual report-building.
FireMon Enabled:
- A single, centralized view across Palo Alto, Fortinet, SonicWall, and Check Point firewalls.
- Automated identification of risky, unused, shadow, and duplicate rules — cutting what used to be a manual, months-long cleanup down to about a week.
- Built-in, audit-ready compliance reporting for PCI DSS, ISO 27001, and NIST.
- Structured rule recertification workflows with clear ownership and accountability.
- Reliable performance at scale — from dozens of firewalls to a couple hundred, with no degradation.
- Change tracking that documents what was modified and why, streamlining audit evidence.
“[FireMon] changes policy management from a reactive task to a proactive, governed process."
Results
- Cut audit preparation time by 40–50%, moving from manual, spreadsheet-driven reviews to automated risk and compliance reporting
- Saved an estimated 80+ hours per year across quarterly audit cycles, by NTT DATA’s own calculation (roughly 20 hours saved per cycle × 4 cycles annually)
- Reduced rule cleanup from months to about a week, removing hundreds of unused or risky rules per pass
- Scaled from dozens to a couple hundred firewall devices across four+ vendors with no performance degradation
- Rated 8/10 by the customer, citing strong ROI, stability, and support — with more flexible dashboards and deeper ticketing/change-management integrations as the primary areas for improvement
- Two years in production with no major outages, data loss, or unplanned downtime