Support for Palo Alto Networks Strata Cloud Manager is available now. Learn more →

Case Study

Centralised Visibility and Compliance Across a Fleet at Sea

A global cruise operator offering leisure travel and onboard hospitality.

The Results

30%

Less Time Spent Preparing Compliance Reports and Audit Evidence

160

Firewalls in Scope for Centralised Policy Visibility

20%

Less Manual Effort for Firewall Change Reviews and Approvals

The Challenge

Manual compliance reporting, limited change visibility and legacy firewall rules made it difficult to maintain consistent security policies across the company's distributed environments at sea. Satellite connectivity meant each ship had to manage its firewalls independently, leaving the network team without centralised oversight of policy changes, compliance and risk.

As the fleet expanded, time-consuming audits, rule reviews and manual change requests placed increasing demands on engineering resources.

The company set out to:

  • Gain a single, comprehensive view of firewall policies across maritime and shoreside environments.
  • Automate reporting for payment card industry (PCI) requirements and internal compliance standards.
  • Track who changed firewall policies, when and where.
  • Identify unused, redundant, shadowed and overly permissive rules.
  • Streamline firewall change requests and approvals without altering the existing distributed architecture.

The Solution

The company selected FireMon Security Manager, Policy Optimizer and Policy Planner to bring centralised policy governance to its distributed Palo Alto firewall environment. The key requirement was architectural: deliver consistent visibility, compliance reporting and change oversight while allowing each ship to continue managing its firewalls independently.

FireMon Delivered

  • Centralised policy visibility and detailed firewall change tracking.
  • Automated compliance assessments and customisable audit reporting.
  • Policy analysis to identify unnecessary and overly permissive access.
  • Structured workflows for rule reviews, change requests and approvals.
  • Access path analysis to validate connectivity and help avoid unnecessary firewall changes.

Results

  • Less time spent preparing audit evidence and compiling compliance reports.
  • Improved visibility and accountability across independently managed firewalls.
  • Faster rule reviews and clean-up to support stronger security policies.
  • Reduced manual effort in firewall change management.
  • Consistent policy governance established to support additional ships and firewall coverage.

"Our ships need to manage their firewalls independently, but we still need a consistent view of policy across the fleet. With FireMon, we can see what changed, focus our rule reviews and spend less time pulling information together for audits."

[Network Engineering Leader] managing the selection and deployment of FireMon

Case Study: FireMon Delivers Centralised Visibility and Compliance Across a Fleet at Sea