ManTech International is a technology service provider and defense contractor based in Herndon, Virginia. The firm provides artificial intelligence (AI), systems engineering, and unique cyber solutions to a wide range of federal government clients, from the space community to the FBI, and from the Department of Health and Human Services to the Department of Defense. Founded in 1968, ManTech is now a multibillion-dollar business.
Netskope One Security Service Edge – Netskope’s SSE solution contains integrated security technologies for complete data security. Learn about our leading Security Service Edge platform.
Netskope One Private Access – Secure Zero Trust access to private apps—without VPNs. Boost performance, reduce risk, and connect users and devices anywhere with Netskope.
Netskope One Data Loss Prevention (DLP) – Netskope provides unified, machine-learning enhanced data loss prevention (DLP) for cloud, web, email , private apps, and devices to help reduce risk.
Zero trust architecture that meets CMMC compliance
Transparent to end users; no “digital friction”
Much better visibility to endpoints and data in transit across Security and IT
As a leading cybersecurity provider to federal agencies, ManTech International must comply with rigorous regulatory standards. “One of the hardest security controls to meet, for any organization, is the CMMC [Cybersecurity Maturity Model Certification] requirement to demonstrate how you manage the flow of controlled unclassified information, or CUI,” says Paul Beckman, ManTech’s Chief Information Security Officer.
Meeting the requirements of CMMC, International Traffic in Arms (ITAR), and other compliance regimes is crucial, both to secure sensitive client data and to show government agencies that ManTech’s security solutions will meet their needs. That is why the firm decided to deploy a zero trust network architecture (ZTNA) several years ago.
“We did a thorough comparison of the options,” says Todd Welsh, Executive Director of Zero Trust Engineering. “As a federal systems integrator, we have seen and deployed a lot of products. When we were looking to adopt a zero trust solution, we did a proof of concept with Netskope and several competitors. Netskope was the clear winner.”
One differentiator of Netskope’s ZTNA solution, Netskope One Private Access, was its service level agreement (SLA) for availability. “Netskope clearly knows their platform is more reliable because of the SLA,” Welsh says. “Also, at the time, Netskope was the only solution that could decrypt TLS 1.3, so we did not have to downgrade our security to deploy the tool.”
ManTech was the first true zero trust infrastructure that [the Defense Contract Management Agency] ever assessed [for CMMC compliance], and they granted us a score of 110 out of 110.
ManTech rolled out Netskope One Security Service Edge (SSE) and Private Access, within the Netskope NewEdge network, in early 2023. NewEdge is the world’s largest, highest-performing security private cloud, and it enables organizations to deploy security at the network edge wherever and whenever it’s needed.
“We completed the basic implementation quickly,” Uster says. “Since then, we have continued to advance with zero trust to make it continuously difficult for adversaries to get into our environment.”
Private Access streamlines management of policy decision points, which are evaluations of whether a user has permission to access a certain resource, and policy enforcement points, which enable or disable access to that resource for the user. “Policy decision points and policy enforcement points are fundamental to ZTNA,” Uster says. “Netskope lets us abstract them and bring them to the network edge, which is very exciting.”
A high-confidence joint surveillance assessment performed by the Defense Contract Management Agency (DCMA) proved that ManTech’s Private Access architecture is CMMC 2.0-compliant. “We showed the auditors how ManTech implemented zero trust, leveraging Netskope One SSE and Private Access as the core components of our policy decision points and policy enforcement points,” Beckman says. “ManTech was the first true zero trust infrastructure that they ever assessed, and it enabled us to obtain a flawless score of 110 out of 110.”
The audit was even sweeter because it progressed extremely smoothly. “The auditors said one portion of the CMMC assessment normally takes a day and a half to get through,” Welsh says. “We planned for that, then finished the entire assessment for that control point in 45 minutes. Netskope brought together all the relevant compliance data in a way that was easy to display to the auditors.”
Netskope works in the background, without any of the digital friction security can create in a traditional IT infrastructure. We want people to be secure. They want things to be easy. We get both with our Netskope solution.
The benefits ManTech has achieved through the Netskope solution are everything Uster had hoped for. Key among them is simplification of management. “Netskope can work with any of our workloads or applications,” he says. For example, integration with the firm’s human capital management system makes it easier to decide what access each employee should have.
The solution’s transparency to end users has also been helpful. “Netskope works in the background, enabling our employees, consultants, and partners to operate securely in our environment, but without any of the digital friction security can create in a traditional IT infrastructure,” Uster says. “We want people to be secure. They want things to be easy. We get both with our Netskope solution.”
ManTech is also using Netskope One Data Loss Prevention (DLP) for Endpoint on user devices, enhancing the IT team’s understanding of each device’s security posture. “The value we receive from Netskope, summed up in one word, is ‘visibility,’” Welsh says. “The Netskope One platform provides visibility to the endpoint and data in transit. That knowledge, in turn, enables us to make, finetune, and enforce effective policies.”
“The aspect of our partnership with Netskope that I am most excited about is the opportunity to take zero trust to our clients,” Beckman concludes. “Government agencies must implement zero trust, and many are scrambling to get the right solutions in place. ManTech exists at the nexus of AI and security, and we can show clients that these solutions are not just theoretical. We have implemented zero trust and can immediately translate the benefits to client environments.”