INTRODUCTION
Foodstuffs South Island is on a mission, working hard to make everyday life better through better service, experiences, value, and community support than any other retailer in New Zealand. Providing groceries and essentials, they operate over 200 locally owned and operated stores, with individual owners on the shop floor directly connected to their teams, their customers, and their communities every day.
Supporting this diverse, highly distributed environment are systems and technology used for every aspect of store operations and administration. This dependency puts cybersecurity on the critical path to success in serving Te Waipounamu (South Island) communities.
The organization needed to architect and operate a secure 24/7 solution to meet the needs of their critical operating environment. They chose Trend Micro—and the Trend Vision One™ enterprise cybersecurity platform—to help secure the systems, networks, and applications powering each store’s retail operation.
"I want to know and trust that a vendor is there to help us grow and improve our outcomes... and be there if I have a major incident... without holding a dollar sign over me looking for more money. Trend did that. They came in... and they just helped.”
A LAPSE IN SECURITY CAN COMPROMISE ESSENTIAL FOOD PROVISIONS
Retail operations of the perishable grocery industry require the continuous availability of the systems and networks connecting local stores with the complex supply chain and distribution network, bringing fresh foods to individual stores. Operating as independently owned and operated retail outlets, each of the over 200 retail locations must function independently while connecting to common systems and infrastructure provided by the broader Foodstuffs organization. These highly distributed operational environments challenge security teams to identify assets, vulnerabilities, and risk, then mitigate risk without disruption to service.
While the fundamentals of cybersecurity frameworks apply within retail, cybersecurity program development and management can be particularly challenging for this locally owned store environment. Strategies to secure both local operations and corporate resources and infrastructure must be managed and coordinated to ensure consistent operations across all locations.
"We first reviewed our existing security controls, technologies, and processes. We then set out to simplify, consolidate, and create a more platform-based approach to security."
Richard Harrison
CISO, Head of Cyber and Technology Risk, Foodstuffs South Island
BEFORE TREND VISION ONE
Prior to implementing Trend Vision One, Foodstuffs South Island experienced many challenges within its technical environment, resourcing, policies, and processes. These left the organization generally unprepared for a major cybersecurity event.
Key challenges included the following:
Limited visibility into assets and environments
Insufficient visibility left Foodstuffs South Island unable to identify or quantify risk, hindering cybersecurity readiness. Lacking alignment with industry standards while facing a shortage of skilled talent, the organization was unprepared for a major cyber threat.
Siloed point security solutions and no threat detection and response program
The use of many siloed point solutions and the lack of any formal threat detection and response tools made it difficult or impossible for the team to correlate signals, identify and understand complex threats, and respond. The high frequency of false positives further exacerbated the problem, consuming valuable time and diverting attention from genuine threats.
Lack of security awareness and education
Insufficient risk insights and a limited attack surface view impacted Foodstuffs South Island's ability to implement effective security training. This made proactively identifying and addressing threats more difficult.
FIVE KEY CYBERSECURITY PROGRAM OBJECTIVES
After assessing the organization's operating environment, Foodstuffs South Island CISO and Head of Cyber and Technology Risk, Richard Harrison, established five key cybersecurity program objectives:
The team developed a set of requirements and engaged four different security solution providers for help. After a rigorous engagement, they interfaced with a wider set of operational teams that included infrastructure, cloud, and end-user support—all whom Harrison’s cybersecurity team would need to work with. This approach added a sense of ownership and understanding about who the vendor is and what its capabilities were. The way Trend engaged in the process helped to build confidence in the vendor and Trend Vision One.
We can see into the environment in a way we never had before, helping us to manage our posture. Trend Vision One improved visibility by 1,000%”
CISO, Head of Cyber and Technology Risk, Foodstuffs South Island
Richard Harrison
TREND VISION ONE IN ACTION
Foodstuffs South Island reports that the adoption of Trend Vision One has enabled the organization to secure its rapidly growing systems and data sets within its hybrid, cloud operating environment.
Trend Vision One supports both proactive and reactive security strategies, including reducing the attack surface, monitoring and assessing risk, and mitigating active threats. The platform consolidated multiple point security solutions to help protect network, endpoint, email, and cloud infrastructure, all while supporting security operations. This includes the proactive Trend Vision One™ Cyber Risk Exposure Management (CREM) solution and detection and response capabilities, helping to assess and quantify risk across the entire attack surface.
Foodstuffs South Island is also utilizing Trend Service One™ for managed detection and response services, extending the internal team and providing expert security resources to monitor the environment 24/7.
BUSINESS IMPACT
Foodstuffs South Island reports significant improvements fueled by Trend Vision One across its entire security program. These include:
Visibility improvements
Harrison reports drastic improvements in visibility from his initial implementation of Trend Vision One. “We can see into the environment in a way we never had before, helping us to manage our posture. Trend Vision One improved visibility by 1,000%.”
Risk reduction
Over a twelve-month period, Foodstuffs South Island recognized a 32% reduction in risk. While admittedly still a work in progress, Harrision believes that Trend Vision One will enable him to soon be able to quantify cyber-risk associated with individual assets groups within Foodstuffs’ operations. He looks forward to being able to help his board of directors understand risk and how it can change at any point in time.
Tools consolidation
“We evaluated tools overlap. We wanted to know, if we were to further invest in or optimize licensing, whether we would operate more efficiently", says Harrison, noting that the team consolidated 70% of its security tools. "With our move to Trend Vision One, we've reduced the number of security tools from more than 20 to five or six, reduced the complexity in both managing tools and using them, and improved the quality for our engineers. This all translates into tangible cost savings on multiple levels.”
Cost reduction
Trend Vision One has helped Foodstuffs South Island avoid costs in multiple areas as it improved its security program:
Faster patching
Within the first month of deployment, Foodstuffs South Island improved MTTP from 21.2 to 16.3, decreasing patch times by 24%. times by 24%.
CONCLUSION
Securing a highly distributed, owner-operated, critical food distribution service network together with a diverse supply chain of product providers requires a carefully crafted balance of flexibility and standardization. Margins are low, as are budgets associated with cybersecurity, so program optimization is critical.
Security leaders supporting this environment, therefore, need all the help they can get to see, protect, and defend this diverse attack surface while carefully monitoring risk to thwart operational disruption. Trusted partnerships with security solution providers such as Trend are helping support security program growth and sustainability, strengthening security posture, simplifying security operations, and easing program management.
The deep and trusted relationship between Foodstuffs South Island and Trend continues to strengthen, enabling the former to focus on food and service delivery while operating a secure, performant environment that serves and supports many local communities.
ABOUT TREND MICRO
Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, the Trend Vision One enterprise cybersecurity platform harnesses AI to protect hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. TrendMicro.com
Ready to transform your cybersecurity approach?