Intelligent CISO Issue 44 | Page 51

COVER STORY nd-user

WORLD FUEL SERVICES REDUCES RISK , INCREASES SECURITY AND MAXIMISES EFFICIENCY

Migrating to the cloud has become a popular business move for organisations and one of strategic importance for surviving the move to hybrid working . Top of the priority list for CISOs , however , is ensuring the migration happens securely . Shawn M Bowen , CISO of World Fuel Services , tells us how the company – as one of the world ’ s leading energy organisations – managed to embed security as a foundation for its large-scale migration to the public cloud , and how Sonrai Security and the Sonrai Dig platform is central to the World Fuel Services cloud security operating model .
orld Fuel Services

W is 91 on the Fortune 500 list and provides energy procurement advisory services , supply fulfilment and transaction and payment management solutions to the aviation , marine and land transportation industries .

The problem
World Fuel Services needed to consolidate its data centres to optimise costs and to deliver technology at the pace of a startup , so it set an audacious goal to migrate to the AWS public cloud and get out of the business of running data centres , within two years .
“ Security is absolutely foundational for any large-scale migration to the public cloud ,” said Richard Delisser , Senior Vice President of Land Technology , Cloud & Infrastructure , World Fuel Services . “ Sonrai Security and the Sonrai Dig platform is central to the World Fuel Services cloud security operating model . The elimination of identity and data risks , automation and continuous monitoring has transformed our cloud security operations and helped accelerate our cloud migration .”
The goal
Reduce risk
Any large-scale cloud migration has to be built off a foundation of strong operational security , and World Fuel quickly realised traditional firstgeneration CSPM platforms would overwhelm cloud and security teams with alerts as the cloud footprint increased . An exploding number of roles and identities would add identity and access complexity which , combined with increasing alerts , would have raised the risk to an unacceptable level .
Maximise efficiency
World Fuel Services knew the current method of triaging and resolving security problems was not suited to an agile
Shawn M Bowen , CISO of World Fuel Services cloud-first company , and a new ‘ Cloud Security Operating Model ’ was needed to bridge operations between cloud , security , audit and DevOps teams . For this reason , WFS partnered with Sonrai to implement best-of-breed cloud security .
Increase security
To date , World Fuel has closed 20 of 22 data centres and Sonrai now provides security controls for World Fuel ’ s 200 + AWS accounts and Azure subscriptions , with over 6,500 AWS roles , 1,000 Azure service principals , 10,000 + compute instances and hundreds of data stores . www . intelligentciso . com
51