We have three instances of environments:
- All of our corporate stuff.
- A fake company that we test things with.
- An area for all the shows.
Each show is treated as its own company. When you have green-lit a movie, you say, "I have $50 million to make this movie," then they just burn it down. Once the money is gone, it's gone. Once you make the movie and you deliver it for distribution, then you don't need the company anymore. You just dissolve it and everybody who invested into that gets the return on investment.
We are cloud first, so we are 100% cloud. We don't have a data center. We use SaaS applications and platforms. Avanan is a cloud-based solution that is bolted into Office 365 via an API. We are using a service that is provided to us from Microsoft. We added the Avanan API from the Microsoft stack to integrate into our Office 365 environment. So, we are using Avanan's service, then we just link the two together.
We have had a significant decline from people accidentally or intentionally clicking on things. For the most part, that is just a lot of education, training, and awareness. There are also the notifications that Avanan does when it may let something go through because it's a legitimate sender but it might give you some information on it, saying, "Hey, this person always sends you an email from their corporate email address. Now, they are sending you something from their personal email address. Be very skeptical, heads up on it, and see what is going on."
We have had attackers send emails to everybody where they were completely fine and nothing was wrong with them whatsoever. They were trying to trick the system to create a confidence level to say, "Oh, yeah. We've always had emails from this person and they're fine. When they send us something that looks like phishing, or is bad, just ignore it because it's a trusted sender." Avanan doesn't do that. Avanan looks at everything independently regardless of if there is historical information. It will say, "This person has already sent you stuff and it's trusted," because at any given time that person's email account could be compromised, or they could be forwarding something that was compromised. They don't discriminate in regards to trust of letting something go through because they inspect everything regardless if it's trusted or not.
The customization was not necessarily a factor for corporate, but it was for television shows and movies because they have different requirements as they go through and have different technology stacks. Because every movie is different, e.g., they want to use different cameras, technology, and solutions, we have to be very flexible in how we roll out the different technology and security to these different pieces.
We just pay attention to see what is going on. Avanan helps us with some trending and modeling of where the attacks are going and who may be the next perceived victim of an attack. This has reduced our SOC team's workload, especially on the administration side of email. The standard things that you would have to do on your remediation paths, workflows, etc. It has really freed up a lot of time.
Avanan has allowed our business to really focus on other different pieces. However, when you look at the tabletop map of the whole battlefield, i.e., the whole war plan, it allows you to reposition resources in other areas that need more attention.