By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
PulseReporterPulseReporter
  • Home
  • Entertainment
  • Lifestyle
  • Money
  • Tech
  • Travel
  • Investigations
Reading: NOV CIO fused AI and Zero Belief to slash threats by 35x
Share
Notification Show More
Font ResizerAa
PulseReporterPulseReporter
Font ResizerAa
  • Home
  • Entertainment
  • Lifestyle
  • Money
  • Tech
  • Travel
  • Investigations
Have an existing account? Sign In
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
PulseReporter > Blog > Tech > NOV CIO fused AI and Zero Belief to slash threats by 35x
Tech

NOV CIO fused AI and Zero Belief to slash threats by 35x

Pulse Reporter
Last updated: April 19, 2025 12:49 am
Pulse Reporter 2 months ago
Share
NOV CIO fused AI and Zero Belief to slash threats by 35x
SHARE

Be a part of our day by day and weekly newsletters for the most recent updates and unique content material on industry-leading AI protection. Be taught Extra


Nationwide Oilwell Varco (NOV) is present process a sweeping cybersecurity transformation beneath CIO Alex Philips, embracing a Zero Belief structure, strengthening id defenses and infusing AI into safety operations. Whereas the journey just isn’t full, the outcomes, by all accounts, are dramatic – a 35-fold drop in safety occasions, the elimination of malware-related PC reimaging and tens of millions saved by scrapping legacy “equipment hell” {hardware}.

VentureBeat just lately sat down (nearly) for this in-depth interview the place Philips particulars how NOV achieved these outcomes with Zscaler’s Zero Belief platform, aggressive id protections and a generative AI “co-worker” for its safety staff.

He additionally shares how he retains NOV’s board engaged on cyber danger amid a worldwide risk panorama the place 79% of assaults to achieve preliminary entry are malware-free, and adversaries can transfer from breach to interrupt out in as little as 51 seconds.

Beneath are excerpts of Philips’ current interview with VentureBeat:

VentureBeat: Alex, NOV went “all in” on Zero Belief quite a lot of years in the past – what have been the standout positive aspects?

Alex Philips: After we began, we have been a conventional castle-and-moat mannequin that wasn’t maintaining. We didn’t know what Zero Belief was, we simply knew that we wanted id and conditional entry on the core of the whole lot. Our journey started by adopting an identity-driven structure on Zscaler’s Zero Belief Alternate and it modified the whole lot. Our visibility and safety protection dramatically elevated whereas concurrently experiencing a 35x discount within the variety of safety incidents. Earlier than, our staff was chasing hundreds of malware incidents; now, it’s a tiny fraction of that. We additionally went from reimaging about 100 malware-infected machines every month to nearly zero now. That’s saved a substantial quantity of money and time. And because the resolution is cloud-based, Equipment hell is gone, as I wish to say.

The zero belief method now provides 27,500 NOV customers and third events policy-based entry to hundreds of inside purposes, all with out exposing these apps on to the web.

We have been then in a position to take an interim step and re-architect our community to reap the benefits of internet-based connectivity vs. legacy costly MPLS. “On common, we elevated pace by 10–20x, decreased latency to important SaaS apps, and slashed value by over 4x… Annualized financial savings [from network changes] have already achieved over $6.5M,” Philips has famous of the venture.

VB: How did shifting to zero belief really scale back the safety noise by such an infinite issue?

Philips: A giant motive is that our web visitors now goes by means of a Safety Service Edge (SSE) with full SSL inspection, sandboxing, and information loss prevention. Zscaler friends immediately with Microsoft, so Workplace 365 visitors obtained quicker and safer – customers stopped making an attempt to bypass controls as a result of efficiency improved. After being denied SSL inspection with on-prem tools, we lastly obtained authorized approval to decrypt SSL visitors because the cloud proxy doesn’t give NOV entry to spy on the information itself. Meaning malware hiding in encrypted streams began getting caught earlier than hitting endpoints. Briefly, we shrunk the assault floor and let good visitors move freely. Fewer threats in meant fewer alerts total.

John McLeod, NOV’s CISO, concurred that the “outdated community perimeter mannequin doesn’t work in a hybrid world” and that an identity-centric cloud safety stack was wanted. By routing all enterprise visitors by means of cloud safety layers (and even isolating dangerous net periods by way of instruments like Zscaler’s Zero Belief Browser), NOV dramatically reduce down intrusion makes an attempt. This complete inspection functionality is what enabled NOV to identify and cease threats that beforehand slipped by means of, slashing incident volumes by 35x.

VB: Had been there any unexpected advantages to adopting Zero Belief you didn’t initially anticipate?

Alex Philips: Sure, our customers really most popular the cloud-based Zero Belief expertise over legacy VPN shoppers, so adoption was easy and gave us unprecedented agility for mobility, acquisitions, and even what we wish to name “Black Swan Occasions”. For instance, when COVID-19 hit, NOV was already ready! I instructed my management staff if all 27,500 of our customers wanted to work remotely, our IT programs might deal with it. My management was surprised and our firm stored shifting ahead with out lacking a beat.

VB: Identification-based assaults are on the rise – you’ve talked about staggering stats about credential theft. How is NOV fortifying id and entry administration?

Philips: Attackers comprehend it’s typically simpler to log in with stolen credentials than to drop malware. In reality, 79% of assaults to achieve preliminary entry in 2024 have been malware-free, counting on stolen credentials, AI-driven phishing, and deepfake scams, based on current risk stories. One in three cloud intrusions final yr concerned legitimate credentials. We’ve tightened id insurance policies to make these ways tougher.

For instance, we built-in our Zscaler platform with Okta for id and conditional entry checks. Our conditional entry insurance policies confirm units have our SentinelOne antivirus agent working earlier than granting entry, including an additional posture test. We’ve additionally drastically restricted who can carry out password or MFA resets. No single admin ought to be capable of bypass authentication controls alone. This separation of duties prevents an insider or compromised account from merely turning off our protections.

VB: You talked about discovering a niche even after disabling a consumer’s account. Are you able to clarify?

Philips: We found that in the event you detect and disable a compromised consumer’s account, the attacker’s session tokens would possibly nonetheless be energetic. It isn’t sufficient to reset passwords; you need to revoke session tokens to really kick out an intruder. We’re partnering with a startup to create close to real-time token invalidation options for our mostly used assets. Basically, we wish to make a stolen token ineffective inside seconds. A Zero Belief structure helps as a result of the whole lot is re-authenticated by means of a proxy or id supplier, giving us a single choke level to cancel tokens globally. That method, even when an attacker grabs a VPN cookie or cloud session, they’ll’t transfer laterally as a result of we’ll kill that token quick.

VB: How else are you securing identities at NOV?

Philips: We implement multi-factor authentication (MFA) virtually in every single place and monitor for irregular entry patterns. Okta, Zscaler, and SentinelOne collectively type an identity-driven safety perimeter the place every login and machine posture is constantly verified. Even when somebody steals a consumer password, they nonetheless face machine checks, MFA challenges, conditional entry guidelines, and the danger of instantaneous session revocation if something appears off. Resetting a password isn’t sufficient anymore — we should revoke session tokens immediately to cease lateral motion. That philosophy underpins NOV’s id risk protection technique.

VB: You’ve additionally been an early adopter of AI in cybersecurity. How is NOV leveraging AI and generative fashions within the SOC?

Philips: We’ve got a comparatively small safety staff for our world footprint, so we should work smarter. One method is bringing AI “co-workers” into our safety operations heart (SOC). We partnered with SentinelOne and began utilizing their AI safety analyst device—an AI that may write and run queries throughout our logs at machine pace. It’s been a sport changer, permitting analysts to ask questions in plain English and get solutions in seconds. As a substitute of manually crafting SQL queries, the AI suggests the subsequent question and even auto-generates a report, which has dropped our imply time to reply.

We’ve seen success tales the place risk hunts are carried out as much as 80% quicker utilizing AI assistants. Microsoft’s personal information reveals that including generative AI can scale back incident imply time to decision by 30%. Past vendor instruments, we’re additionally experimenting with inside AI bots for operational analytics, utilizing OpenAI foundational AI fashions to assist non-technical employees shortly question information. In fact, we have now information safety guardrails in place so these AI options don’t leak delicate data.

VB: Cybersecurity is not simply an IT problem. How do you have interaction NOV’s board and executives on cyber danger?

Philips: I made it a precedence to carry our board of administrators alongside on our cyber journey. They don’t want the deep technical trivialities, however they do want to grasp our danger posture. With generative AI exploding, for instance, I briefed them on each the benefits and dangers early on. That schooling helps after I suggest controls to stop information leaks—there’s already alignment on why it’s obligatory.

The board views cybersecurity as a core enterprise danger now. They’re briefed on it at each assembly, not simply every year. We’ve even run tabletop workout routines with them to indicate how an assault would play out, turning summary threats into tangible choice factors. That results in stronger top-down assist.

I make it some extent to continuously reinforce the truth of cyber danger. Even with tens of millions invested in our cybersecurity program, the danger isn’t absolutely eradicated. It isn’t if we can have an incident, however when.

VB: Any remaining recommendation, based mostly on NOV’s journey, for different CIOs and CISOs on the market?

Philips: First, acknowledge that safety transformation and digital transformation go hand in hand. We couldn’t have moved to the cloud or enabled distant work so successfully with out Zero Belief, and the enterprise value financial savings helped fund safety enhancements. It really was a “win, win, win.”

Second, concentrate on the separation of duties in id and entry. Nobody particular person ought to be capable of undermine your safety controls—myself included. Small course of modifications like requiring two individuals to alter MFA for an exec or extremely privileged IT employees, can thwart malicious insiders, errors, and attackers.

Lastly, embrace AI fastidiously however proactively. AI is already a actuality on the attacker aspect. A well-implemented AI assistant can multiply your staff’s protection, however you will need to handle the dangers of information leakage or inaccurate fashions. Be sure to merge AI output together with your staff’s talent to create an AI-infused “brAIn”.

We all know the threats hold evolving, however with zero belief, robust id safety and now AI on our aspect, it helps give us a combating likelihood.

Day by day insights on enterprise use instances with VB Day by day

If you wish to impress your boss, VB Day by day has you lined. We provide the inside scoop on what corporations are doing with generative AI, from regulatory shifts to sensible deployments, so you possibly can share insights for max ROI.

Learn our Privateness Coverage

Thanks for subscribing. Take a look at extra VB newsletters right here.

An error occured.


You Might Also Like

Gmail can now ‘polish’ your e mail drafts

Star Wars Outlaws rolls out extra modifications and fixes in bid for extra buys

‘Startup Nation’ Teams Say They’re Assembly Trump Officers to Push for Deregulated ‘Freedom Cities’

‘House 7A’ clip reveals evil lurks past the Bramford

Slack now lets customers add AI brokers from Asana, Cohere, Adobe, Workday and extra

Share This Article
Facebook Twitter Email Print
Previous Article Fast Factors: Use Flying Blue’s calendar search software to seek out cheaper award tickets Fast Factors: Use Flying Blue’s calendar search software to seek out cheaper award tickets
Next Article Home windows 11 Professional | Mashable Home windows 11 Professional | Mashable
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

More News

From These 18 Pink Motion pictures, Which One Is The Finest?
From These 18 Pink Motion pictures, Which One Is The Finest?
6 minutes ago
Sterling Inventory Picker AI deal — simply £51 for all times
Sterling Inventory Picker AI deal — simply £51 for all times
27 minutes ago
Chase switch bonus to Air Canada Aeroplan: Obtain 20% bonus factors
Chase switch bonus to Air Canada Aeroplan: Obtain 20% bonus factors
28 minutes ago
We're making a highway journey playlist, what tune do you suppose we should always add?
We're making a highway journey playlist, what tune do you suppose we should always add?
1 hour ago
Databricks, Noma Deal with CISOs’ AI Inference Nightmare
Databricks, Noma Deal with CISOs’ AI Inference Nightmare
1 hour ago

About Us

about us

PulseReporter connects with and influences 20 million readers globally, establishing us as the leading destination for cutting-edge insights in entertainment, lifestyle, money, tech, travel, and investigative journalism.

Categories

  • Entertainment
  • Investigations
  • Lifestyle
  • Money
  • Tech
  • Travel

Trending

  • From These 18 Pink Motion pictures, Which One Is The Finest?
  • Sterling Inventory Picker AI deal — simply £51 for all times
  • Chase switch bonus to Air Canada Aeroplan: Obtain 20% bonus factors

Quick Links

  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Disclaimer
2024 © Pulse Reporter. All Rights Reserved.
Welcome Back!

Sign in to your account