
The Challenge
Tasked with quickly conducting a full rule cleanup while housing over 400 decentralized firewalls, the company, which was relying on time-consuming and error-prone manual audit preparation and rule review processes, needed a solution to empower their network security team to meet a rapidly-approaching deadline.
The company sought to:
- Conduct a full rule cleanup to remove redundant, overly permissive, and unused rules
- Automate lifecycle policy management for rule cleanup and review
- Audit in one centralized platform that becomes the record of data for enforcing policy management
- Gain a comprehensive view of policy across all devices in their multi-vendor environment which includes Fortinet, Palo Alto Networks, and Zscaler devices
The Solution
With continuous compliance, change automation, and risk management solutions from FireMon, the company gained real-time visibility, control, and management capabilities for all network security devices across its vast multi-vendor environment.
- Continuous compliance checks and automated custom firewall policy reporting simplified the audit process, increased accuracy, and eliminated the need to hire additional headcount
- Automated workflows for firewall rule review, recertification, and removal saved tremendous time while reducing errors caused by manual processes
- A single pane-of-glass console provided unified visibility and management
After being in the news for the wrong reason because of a ransomware attack, we knew we needed to reduce the chance of another attack by taking a close look at our policies and removing any unused or overly-permissive rules. FireMon’s automated security assessments and cleanup allowed our small team to conduct a full rule cleanup in a fraction of the time.”
Results
- $2M annual cost savings with FireMon compared to manual processes
- No longer need to hire or outsource 6 additional security engineers to manage rule changes and conduct compliance audits
- Reduced risk through identification and removal of overly permissive rules and unauthorized traffic
- Automation of policy changes streamlined remediation processes and shortened time to mitigate violations

Annual cost savings with FireMon compared to manual processes

Firewalls currently managed
Additional FTE no longer needed for rule changes and compliance audits