Petronect is an information technology company that operates one of the largest Marketplaces in Brazil providing solutions for supply chains in the Energy, Oil and Gas sector.
Cloud Access Security Broker (CASB) – Confidently adopt cloud applications and services without sacrificing security.
Next Gen Secure Web Gateway (SWG) – The foundation for SSE web and cloud inline security providing threat and data protection.
Netskope One Private Access – Private Access (NPA) for Zero Trust Network Access seamlessly connects users anywhere to private resources everywhere.
Easy on-premises to cloud migration with lower risk
Reduction of Shadow IT
Greater flexibility of use and authorization of applications for users
At the beginning of the pandemic, Petronect saw the need to migrate from an on-premises technological infrastructure to cloud services. This would give it the flexibility and scalability to support business growth, as well as the need to implement a more comprehensive and effective security system. To this end, the company began adopting a next generation secure web gateway.
The company then searched for market-leading solutions until it opted for Netskope’s technology. According to Leandro Rodrigues, Security Coordinator at Petronect, his team got to know Netskope because of its leadership in the CASB segment in the Gartner Magic Quadrant. “We’ve seen a lot of positive information about Netskope in the Gartner quadrants and we’ve read several successful testimonials from large companies about Netskope’s security platform in Gartner Peer Insights,” he explains.
Petronect has part of its infrastructure on premises and part in the cloud with partner companies Amazon (AWS), Google and Azure, as well as the SAP Cloud Platform. These environments are connected and exchange information intensively.
When Petronect employees identified cases of insecure applications being used without the knowledge or authorization of the IT department, known as Shadow IT, while they were still operating on-site, it became necessary to have greater control over data traffic and application management. “At that time it was important to have visibility of which applications the users, almost 350 professionals at the start of 2020, were using on a daily basis to solve their problems. We needed greater control over information traffic, as well as closer management of cloud services,” says Rodrigues.
We’ve seen a lot of positive information about Netskope in the Gartner quadrants and have read several successful testimonials from large companies about Netskope’s security platform in Gartner Peer Insights
Petronect was carrying out a POC (Proof of Concept) of Netskope’s solutions in February 2020, when the following month, the first social distancing actions were taken due to the COVID-19 pandemic in Brazil. During the POC, the project was brought forward and promoted to the production environment in less than a month.
With the migration of employees to the home office, the company already had security controls in place on the internal network, but was not fully prepared to operate with the entire workforce on a remote system. Therefore, even before users started working from home, Netskope technology was implemented to provide visibility of the entire technological environment, greater control over data traffic and the use of applications, resulting in enhanced security and greater efficiency in all environments. After deciding to use Netskope, the project was implemented in 10 days and users migrated to the home office in just three days.
“The security team was very concerned about migrating all 350 employees to the home office, because we knew that the number of threats (ransomware, malware, phishing, etc.) would increase significantly. Implementing Netskope’s solutions gave us greater security, a very important pillar for Petronect, since access to the web would no longer be a problem. We had already implemented the Next Generation Secure Web Gateway with very strict rules, using the Cloud Confidence Index (CCI) feature to inhibit the use of applications with a low reputation,” Rodrigues points out.
With the CCI solution, Petronect has automated the selection of systems suitable for corporate use. The tool also analyzes more than 50 criteria including compliance certifications, DLP policy controls, encryption, etc.
Another important highlight of Netskope’s solutions is being able to control the use of cloud applications according to the service instance. With this feature it is possible to give users greater flexibility, since it only blocks specific services and not all of them. “We are currently able to use Google’s corporate instance and block its personal instance if we need to,” says Leandro.
Another highlight of the Netskope platform is that it can be integrated with other security tools, such as the Palo Alto Networks firewall and the Crowdstrike solution.
It’s worth noting that the process of evaluating the use of cloud applications has been optimized using the intelligence delivered by Netskope. “The CCI (Netskope Cloud Confidence Index) feature delighted us with the resources of the Netskope solution, as we had a great deal of work to do analyzing documentation and application security requirements and we were able to automate the entire process of controlling these applications with the CCI,” says the Security coordinator.
Both during the testing phase and after the project was implemented, the Netskope team was very willing to contribute and answer questions.
The work of Contacta, Netskope’s partner in this project, was also highlighted. According to Petronect’s security coordinator, “the channel’s work was fundamental, especially during the testing period, because we knew little about Netskope’s tools, and they were very willing to help us,” says Rodrigues.
The Netskope team carried out a high-level project follow-up, closely monitoring the implementation and providing all the necessary support.
The project with Netskope helped Petronect with the LGPD, generating greater visibility of corporate and personal data traffic. The company has created rules with Netskope’s technology to see what kind of data (personal or not) is being trafficked, which makes it possible to control the flow of this data by applying DLP rules. “We’ve come a long way in relation to the LGPD and we’re on the final road to complete compliance,” says Rodrigues.
Petronect has clear Compliance and Information Security policies, follows the principles and promotes Compliance guidelines to its employees, customers and suppliers, as well as disseminating the culture and practice of Compliance. With this, it reinforces the importance of knowing and complying with the legal, regulatory, normative and procedural determinations, both external and internal, adopted by the company.
With regard to information security, the company has strict guidelines that standardize procedures, as well as enabling and ensuring the protection of its own services, operations, developments and assets, as well as those of its clients and employees, from deliberate or accidental threats in its business processes.
Security is one of Petronect’s main pillars. The company aims to use more cloud services and cloud infrastructure with its partners Amazon, Google, Microsoft and SAP. According to Rodrigues, the company is aiming for an architecture as close to Zero Trust as possible. “With Netskope we are going to make significant progress in terms of Zero Trust, especially in web access. We also intend to expand to other services with new control points such as user authentication, device authentication, etc. We also plan to implement a reverse proxy with cloud services with proactive control of user operations that can be inspected,” says Petronect’s security coordinator.