We collect cookies to analyze our website traffic and performance; we never collect any personal data. Cookie Policy
Accept
NEW YORK DAWN™NEW YORK DAWN™NEW YORK DAWN™
Notification Show More
Font ResizerAa
  • Home
  • Trending
  • New York
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
  • Crypto & NFTs
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Travel
    • Fashion
    • Art
  • Health
  • Sports
  • Entertainment
Reading: Id as the brand new perimeter: Nationwide Oilwell Varco’s strategy to stopping the 79% of assaults which can be malware-free
Share
Font ResizerAa
NEW YORK DAWN™NEW YORK DAWN™
Search
  • Home
  • Trending
  • New York
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
  • Crypto & NFTs
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Travel
    • Fashion
    • Art
  • Health
  • Sports
  • Entertainment
Follow US
NEW YORK DAWN™ > Blog > Technology > Id as the brand new perimeter: Nationwide Oilwell Varco’s strategy to stopping the 79% of assaults which can be malware-free
Id as the brand new perimeter: Nationwide Oilwell Varco’s strategy to stopping the 79% of assaults which can be malware-free
Technology

Id as the brand new perimeter: Nationwide Oilwell Varco’s strategy to stopping the 79% of assaults which can be malware-free

Last updated: April 18, 2025 10:51 pm
Editorial Board Published April 18, 2025
Share
SHARE

Nationwide Oilwell Varco (NOV) is present process a sweeping cybersecurity transformation beneath CIO Alex Philips, embracing a Zero Belief structure, strengthening identification defenses and infusing AI into safety operations. Whereas the journey will not be full, the outcomes, by all accounts, are dramatic – a 35-fold drop in safety occasions, the elimination of malware-related PC reimaging and hundreds of thousands saved by scrapping legacy “appliance hell” {hardware}.

VentureBeat just lately sat down (nearly) for this in-depth interview the place Philips particulars how NOV achieved these outcomes with Zscaler’s Zero Belief platform, aggressive identification protections and a generative AI “co-worker” for its safety staff.

He additionally shares how he retains NOV’s board engaged on cyber threat amid a worldwide menace panorama the place 79% of assaults to realize preliminary entry are malware-free, and adversaries can transfer from breach to interrupt out in as little as 51 seconds.

Beneath are excerpts of Philips’ current interview with VentureBeat:

VentureBeat: Alex, NOV went “all in” on Zero Belief various years in the past – what have been the standout good points?

Alex Philips: Once we began, we have been a standard castle-and-moat mannequin that wasn’t maintaining. We didn’t know what Zero Belief was, we simply knew that we wanted identification and conditional entry on the core of all the pieces. Our journey started by adopting an identity-driven structure on Zscaler’s Zero Belief Alternate and it modified all the pieces. Our visibility and safety protection dramatically elevated whereas concurrently experiencing a 35x discount within the variety of safety incidents. Earlier than, our staff was chasing 1000’s of malware incidents; now, it’s a tiny fraction of that. We additionally went from reimaging about 100 malware-infected machines every month to nearly zero now. That’s saved a substantial quantity of money and time. And because the answer is cloud-based, Equipment hell is gone, as I wish to say.

The zero belief strategy now provides 27,500 NOV customers and third events policy-based entry to 1000’s of inside purposes, all with out exposing these apps on to the web.

We have been then capable of take an interim step and re-architect our community to make the most of internet-based connectivity vs. legacy costly MPLS. “On average, we increased speed by 10–20x, reduced latency to critical SaaS apps, and slashed cost by over 4x… Annualized savings [from network changes] have already achieved over $6.5M,” Philips has famous of the challenge.

VB: How did shifting to zero belief really cut back the safety noise by such an unlimited issue?

Philips: An enormous purpose is that our web visitors now goes by way of a Safety Service Edge (SSE) with full SSL inspection, sandboxing, and information loss prevention. Zscaler friends straight with Microsoft, so Workplace 365 visitors bought sooner and safer – customers stopped making an attempt to bypass controls as a result of efficiency improved. After being denied SSL inspection with on-prem gear, we lastly bought authorized approval to decrypt SSL visitors because the cloud proxy doesn’t give NOV entry to spy on the info itself. Which means malware hiding in encrypted streams began getting caught earlier than hitting endpoints. Briefly, we shrunk the assault floor and let good visitors circulate freely. Fewer threats in meant fewer alerts total.

John McLeod, NOV’s CISO, concurred that the “old network perimeter model doesn’t work in a hybrid world” and that an identity-centric cloud safety stack was wanted. By routing all enterprise visitors by way of cloud safety layers (and even isolating dangerous net classes through instruments like Zscaler’s Zero Belief Browser), NOV dramatically minimize down intrusion makes an attempt. This complete inspection functionality is what enabled NOV to identify and cease threats that beforehand slipped by way of, slashing incident volumes by 35x.

VB: Have been there any unexpected advantages to adopting Zero Belief you didn’t initially count on?

Alex Philips: Sure, our customers really most popular the cloud-based Zero Belief expertise over legacy VPN shoppers, so adoption was easy and gave us unprecedented agility for mobility, acquisitions, and even what we wish to name “Black Swan Events”. For instance, when COVID-19 hit, NOV was already ready! I advised my management staff if all 27,500 of our customers wanted to work remotely, our IT methods may deal with it. My management was shocked and our firm saved shifting ahead with out lacking a beat.

VB: Id-based assaults are on the rise – you’ve talked about staggering stats about credential theft. How is NOV fortifying identification and entry administration?

Philips: Attackers understand it’s usually simpler to log in with stolen credentials than to drop malware. In reality, 79% of assaults to realize preliminary entry in 2024 have been malware-free, counting on stolen credentials, AI-driven phishing, and deepfake scams, in line with current menace experiences. One in three cloud intrusions final yr concerned legitimate credentials. We’ve tightened identification insurance policies to make these ways tougher.

For instance, we built-in our Zscaler platform with Okta for identification and conditional entry checks. Our conditional entry insurance policies confirm units have our SentinelOne antivirus agent operating earlier than granting entry, including an additional posture examine. We’ve additionally drastically restricted who can carry out password or MFA resets. No single admin ought to have the ability to bypass authentication controls alone. This separation of duties prevents an insider or compromised account from merely turning off our protections.

VB: You talked about discovering a spot even after disabling a consumer’s account. Are you able to clarify?

Philips: We found that for those who detect and disable a compromised consumer’s account, the attacker’s session tokens would possibly nonetheless be energetic. It isn’t sufficient to reset passwords; you need to revoke session tokens to actually kick out an intruder. We’re partnering with a startup to create close to real-time token invalidation options for our mostly used sources. Basically, we wish to make a stolen token ineffective inside seconds. A Zero Belief structure helps as a result of all the pieces is re-authenticated by way of a proxy or identification supplier, giving us a single choke level to cancel tokens globally. That method, even when an attacker grabs a VPN cookie or cloud session, they will’t transfer laterally as a result of we’ll kill that token quick.

VB: How else are you securing identities at NOV?

Philips: We implement multi-factor authentication (MFA) virtually in every single place and monitor for irregular entry patterns. Okta, Zscaler, and SentinelOne collectively kind an identity-driven safety perimeter the place every login and system posture is constantly verified. Even when somebody steals a consumer password, they nonetheless face system checks, MFA challenges, conditional entry guidelines, and the chance of immediate session revocation if something appears off. Resetting a password isn’t sufficient anymore — we should revoke session tokens immediately to cease lateral motion. That philosophy underpins NOV’s identification menace protection technique.

VB: You’ve additionally been an early adopter of AI in cybersecurity. How is NOV leveraging AI and generative fashions within the SOC?

Philips: We’ve a comparatively small safety staff for our world footprint, so we should work smarter. One strategy is bringing AI “co-workers” into our safety operations middle (SOC). We partnered with SentinelOne and began utilizing their AI safety analyst device—an AI that may write and run queries throughout our logs at machine velocity. It’s been a recreation changer, permitting analysts to ask questions in plain English and get solutions in seconds. As a substitute of manually crafting SQL queries, the AI suggests the following question and even auto-generates a report, which has dropped our imply time to reply.

We’ve seen success tales the place menace hunts are carried out as much as 80% sooner utilizing AI assistants. Microsoft’s personal information exhibits that including generative AI can cut back incident imply time to decision by 30%. Past vendor instruments, we’re additionally experimenting with inside AI bots for operational analytics, utilizing OpenAI foundational AI fashions to assist non-technical workers shortly question information. After all, we now have information safety guardrails in place so these AI options don’t leak delicate info.

VB: Cybersecurity is now not simply an IT concern. How do you interact NOV’s board and executives on cyber threat?

Philips: I made it a precedence to deliver our board of administrators alongside on our cyber journey. They don’t want the deep technical trivia, however they do want to know our threat posture. With generative AI exploding, for instance, I briefed them on each the benefits and dangers early on. That schooling helps after I suggest controls to forestall information leaks—there’s already alignment on why it’s mandatory.

The board views cybersecurity as a core enterprise threat now. They’re briefed on it at each assembly, not simply yearly. We’ve even run tabletop workout routines with them to indicate how an assault would play out, turning summary threats into tangible determination factors. That results in stronger top-down help.

I make it some extent to always reinforce the fact of cyber threat. Even with hundreds of thousands invested in our cybersecurity program, the chance isn’t absolutely eradicated. It’s not if we could have an incident, however when.

VB: Any closing recommendation, primarily based on NOV’s journey, for different CIOs and CISOs on the market?

Philips: First, acknowledge that safety transformation and digital transformation go hand in hand. We couldn’t have moved to the cloud or enabled distant work so successfully with out Zero Belief, and the enterprise price financial savings helped fund safety enhancements. It actually was a “win, win, win.”

Second, concentrate on the separation of duties in identification and entry. Nobody individual ought to have the ability to undermine your safety controls—myself included. Small course of adjustments like requiring two folks to vary MFA for an exec or extremely privileged IT workers, can thwart malicious insiders, errors, and attackers.

Lastly, embrace AI fastidiously however proactively. AI is already a actuality on the attacker facet. A well-implemented AI assistant can multiply your staff’s protection, however you should handle the dangers of knowledge leakage or inaccurate fashions. Be certain that to merge AI output along with your staff’s talent to create an AI-infused “brAIn”.

We all know the threats preserve evolving, however with zero belief, robust identification safety and now AI on our facet, it helps give us a preventing likelihood.

Each day insights on enterprise use circumstances with VB Each day

If you wish to impress your boss, VB Each day has you lined. We provide the inside scoop on what firms are doing with generative AI, from regulatory shifts to sensible deployments, so you may share insights for optimum ROI.

An error occured.

You Might Also Like

Effective-tuning vs. in-context studying: New analysis guides higher LLM customization for real-world duties

Typical Gamer’s JOGO doubles down on UEFN maps with acquisition of RHQ Inventive

What your instruments miss at 2:13 AM: How gen AI assault chains exploit telemetry lag – Half 1

Henk Rogers’ actual story behind Tetris, the Excellent Sport | The DeanBeat

OpenAI’s $3B Windsurf transfer: the actual purpose behind its enterprise AI code push

TAGGED:approachattacksidentitymalwarefreeNationalOilwellperimeterstoppingVarcos
Share This Article
Facebook Twitter Email Print

Follow US

Find US on Social Medias
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Popular News
‘Buried,’ ‘Night Comes On’ and More Streaming Gems
Entertainment

‘Buried,’ ‘Night Comes On’ and More Streaming Gems

Editorial Board January 24, 2022
In Senate Battle, Democrats Defy Biden’s Low Standing (for Now)
Tonsil most cancers: What’s it and how one can forestall it
The Sport Firm raises $10M on blockchain-based cloud gaming
2 Men Convicted of Killing Malcolm X Will Be Exonerated

You Might Also Like

Id as the brand new perimeter: Nationwide Oilwell Varco’s strategy to stopping the 79% of assaults which can be malware-free
Technology

Zencoder launches Zen Brokers, ushering in a brand new period of team-based AI for software program improvement

May 9, 2025
Id as the brand new perimeter: Nationwide Oilwell Varco’s strategy to stopping the 79% of assaults which can be malware-free
Technology

The walled backyard cracks: Nadella bets Microsoft’s Copilots—and Azure’s subsequent act—on A2A/MCP interoperability

May 9, 2025
Resurgens Gaming raises funds to launch Ghost Launchpad sport accelerator
Technology

Resurgens Gaming raises funds to launch Ghost Launchpad sport accelerator

May 9, 2025
Sq. Enix’s Symbiogenesis onchain recreation debuts on Sony’s Soneium blockchain
Technology

Sq. Enix’s Symbiogenesis onchain recreation debuts on Sony’s Soneium blockchain

May 9, 2025

Categories

  • Health
  • Politics
  • Sports
  • Entertainment
  • Technology
  • World
  • Art

About US

New York Dawn is a proud and integral publication of the Enspirers News Group, embodying the values of journalistic integrity and excellence.
Company
  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • Accessibility Statement
Contact Us
  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability
Term of Use
  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices
© 2024 New York Dawn. All Rights Reserved.
Welcome Back!

Sign in to your account

Lost your password?