A leading global engineering service provider in the automotive industry turned to TEAL to consolidate and best secure an evolved Active Directory environment with two forests. The focus was on better integration of IT services and usability for the 6000 customer employees.
With the help of our assessment, we analyzed both forests for technical vulnerability or deviation from design recommendations. Requirements and goals were defined in workshops. The resulting packages of measures were prioritized by the customer and a roadmap for achieving the target was created.
TEAL supports the customer in securing and standardizing the Active Directory. Extensive information is also available in our blog series on the topic of (E)SAE.
Started approaches are consequently continued, which accelerate and optimize the implementation.
A customer in the healthcare industry was operating in a relatively inhomogeneous security infrastructure world, which led to two challenges:
1. The security setup is not optimal and
2. employees, IT services could only be provided with difficulty, resulting in inconsistent service usage.
Together with the customer, an analysis of the current situation was carried out and guard rails as well as requirements for a new IT infrastructure were defined. In the further course, TEAL developed several target architectures and evaluation criteria for a management decision.
The customer has several options and evaluation criteria to decide how to make the IT infrastructure secure and efficient in the future.
An internationally active development partner in the automotive industry for complex metal and hybrid structures with a large number of locations and more than 10,000 employees approached us to secure the complex and globally distributed infrastructure. In the course of security-relevant incidents in the said industry, TEAL was commissioned to check and secure the Active Directory infrastructure. TEAL was also commissioned to make preparations for the use of cloud services.
For this purpose, a detailed analysis of the customer’s security infrastructure was undertaken, risks were evaluated and weighted, and finally an action plan was proposed. TEAL was then commissioned to implement this plan. For this purpose, we designed a new security concept (TIER0), which we implemented with the customer in a cooperative atmosphere.
The security aspects of the customer infrastructure are thus conceptually re-implemented and secured, and at the same time prepared for the use of cloud services. This minimizes potential attack risks while at the same time future-proofing the core infrastructure.
The goal was to migrate the existing Groupwise infrastructure of a leading retail company (nearly 10,000 employees) with decentralized personal archives to Microsoft Exchange Online.
We supported the customer in project management as well as the selection of suitable technology partners, migration software and adaptation measures for end users. This also included establishing rollout support and integrating the local helpdesk.
The project we managed was already able to migrate 10,000 mailboxes within eight months. The migration of the personal archives to Exchange Online Archive also worked smoothly. In addition, an Office365 backup solution was introduced.
After in-depth online research, a government agency approached us to analyze and secure their existing Active Directory infrastructure for full protection against cybersecurity attacks.
Due to the ever-increasing security awareness factor in the media, the customer wanted to restructure in this area and stabilize the basic pillars of infrastructure and identity management through external expertise.
In order to work out a suitable solution, we first carried out a three-day assessment in the customer’s environment to find out how possible attackers could get into the company’s network and how the customer could ideally protect itself against this. This resulted in a roadmap with recommendations and concrete implementation measures to effectively increase infrastructure security.
In further steps, implementation packages were derived, structured and prioritized. These packages were then implemented together with the customer. This included both organizational and technical measures and individualized concepts, which were adapted on the basis of the customer’s environment and other circumstances.
First, we started by establishing the common SAE basics. These include both the tiering concept and the introduction of PAW systems combined with consistent account separation. Extensive info is also available in our blog series on (E)SAE.
In the future, we will use the Enforce Suite to achieve extensive and permanent system hardening of the infrastructure as well as compliance with established hardening standards such as BSI or CIS.