The United States Senate Federal Credit Union first landed on VMware because it wanted to virtualize its IT environment. And then it realized the security benefits that stem from VMware’s “unified ecosystem” approach, CIO Mark Fournier said.
Fournier describes a poster that a previous managed security reseller gave him. It says “Security Is Hard” across the top, and hundreds of security vendors’ logo fill the 11-inch-by-17-inch space. “I think this poster is in every single VAR and MSP’s office,” he said. “It’s a way to say, ‘hey, security is really hard, and you need us to help you buy it.’”
That’s how a lot of companies, and especially those with smaller IT teams, approach security, Fournier said. But, he added, the whole security-is-hard mantra doesn’t need to be the only way forward.
“Having a unified ecosystem is not only super practical for a smaller team or a tightly integrated team, but it makes it easier to operationalize and be successful,” Fournier said. “I wouldn’t say that we’re not keeping an eye on other offerings that are out there, but for us having that ecosystem is a really solid starting point.”
The Virginia-based credit union is a 85-year-old organization with about 40,000 members and $1.1 billion in assets. It has two back offices, three branches, and a number of ATMs. When Fournier joined about five years ago, the entire IT environment was on premises. “There was no virtualization, and saying the word cloud was the furthest thought from anyone’s mind,” he said. “There were about a dozen physical servers in a server room, and the actual data center environment was a server room in each of the two back offices.”
Credit Union Moves Beyond MicrosegmentationPart of the reason the credit union hired Fournier was to help virtualize the IT environment, and so initially the organization tapped VMware for its SDN platform NSX. “Microsegmentation was what we were looking for to address this east-west concern, and this lack of visibility,” he said. “And the case from VMware was: it’s in the hypervisor, all the way down to the virtual NIC on the workload.”
The credit union started with an earlier NSX version with its two main use cases being microsegmentation and stretching layer 2 virtual networks between sites. Over time it added more network security-related products including NSX Intelligence, which provides network and security analytics, NSX Service-defined Firewall, and most recently Identity Firewall and NSX Distributed Intrusion Detection and Prevention (IDS/IPS).
The organization also uses VMware products for workload and application security. “AppDefense was something that caught our eye back when it was first announced,” Fournier said, referring to VMware’s first standalone security product it co-developed with Carbon Black in 2017 before buying Carbon Black two years later. “We did acquire AppDefense, and integrate it into our stack, and then we converted from AppDefense to Carbon Black Workload Protect. Today we have Carbon Black Workload Protect integration with IDS/IPS.”
When the credit union first started down the security road with VMware, these types of integrations weren’t available. “But we certainly saw the long-term potential and we hoped that those types of integrations, that unified ecosystem, would be part of the end game,” Fournier said.
Benefits to an Ecosystem ApproachIn addition to cost savings — using VMware’s internal software firewalls cost less than deploying multiple hardware perimeter firewall appliances at various points across all of its sites — the credit union benefits from these deep integrations between its security and networking products, Fournier said.
“We are a small team,” he said. “And so operationalizing is really fundamental to our success. Anything that speaks more towards a central point of solution or more homogenous point of solution is inherently winning.”
Comments