{"id":499951,"date":"2021-05-26T11:51:56","date_gmt":"2021-05-26T10:51:56","guid":{"rendered":"https:\/\/pulse.microsoft.com\/?p=499951"},"modified":"2021-06-01T12:35:39","modified_gmt":"2021-06-01T11:35:39","slug":"fa1-sgs-creating-a-more-secure-agile-and-sustainable-infrastructure-in-the-cloud","status":"publish","type":"post","link":"https:\/\/pulse.microsoft.com\/en\/work-productivity-en\/na\/fa1-sgs-creating-a-more-secure-agile-and-sustainable-infrastructure-in-the-cloud\/","title":{"rendered":"SGS: creating a more secure, agile and sustainable infrastructure in the cloud"},"content":{"rendered":"<p class=\"intro\">\u201cIf you ask anyone at SGS what\u2019s in the DNA of the company, they will all say the same two words: integrity and safety. We want to add a third word to the list: security.\u201d<\/p>\n<p>Frederic Ducret, Global Head of Cloud and IT Infrastructure at SGS is talking about the core qualities that define the world\u2019s largest and most successful auditing, testing, inspection and certification company.<\/p>\n<p>\u201cSince I joined SGS a quarter of a century ago, we have always talked about the critical importance of integrity, because our business relies on the trust that our customers have for SGS,\u201d Ducret continues. \u201cWe have zero-tolerance against any deviation from our integrity policy within our network, as it could ruin our reputation if someone does something bad somewhere.<\/p>\n<p>\u201cIn the digital age, you need to secure your infrastructure, data and applications to enforce integrity. That\u2019s a big piece of our move to the cloud.\u201d<\/p>\n<p>It is a move that has been ongoing since Ducret\u2019s team presented the case to move the company\u2019s infrastructure from on-premise data centers housed primarily in SGS offices across the globe, to the Azure cloud.<\/p>\n<p>With over 80% of the company\u2019s servers now based in the cloud, the team are well on their way to achieving their ultimate goal of being a cloud-only company. And they are reaping the security benefits that cloud-based solutions like Azure Sentinel are bringing the company.<\/p>\n<h2>Unifying the company\u2019s infrastructure in the cloud<\/h2>\n<p>Established in Switzerland in 1878, SGS has grown over nearly a century and a half into the industry leader in inspection, verification, testing and certification. With more than 89,000 employees operating from some 2,600 offices and laboratories around the world, SGS has established itself as the global benchmark for quality and integrity.<\/p>\n<p>\u201cWe provide analysis of products and substances for our customers,\u201d explains Ducret. \u201cSo we could go to a tanker, for example, take a sample of the oil, analyze it and then provide an objective analysis of whether it is compliant with our customers\u2019 requirements.\u201d<\/p>\n<p>Making sure that SGS\u2019s operations are robust is a key priority for Ducret. \u201cWe need to make sure our services and applications are always-on,\u201d he says. \u201cOur reputation depends on it, so that is my number 1 priority.\u201d<\/p>\n<p>But in the last couple of years, there has also been an increased focus on introducing some agility to the operations at SGS. \u201cWe want to be able to deliver new services to the business, things like IoT and other digital innovations,\u201d he says. \u201cAnd the cloud strategy we have in place is the foundation of that.\u201d<\/p>\n<p>Another key driver of the company\u2019s cloud strategy is the unification of SGS\u2019s vast infrastructure. \u201cWe came from a situation where we had applications distributed in 180 local data centers. And these weren\u2019t state of the art data centers. In some cases, it was just a computer room with a couple of servers and some basic facility services.\u201d<\/p>\n<p>So in 2017, the company took the decision to move to Azure. And it has ushered in a new era for the company. One that is more agile, optimized and secure.<\/p>\n<h2>Gaining company-wide security visibility with Azure Sentinel<\/h2>\n<p>\u201cWhen we presented our case for moving to Azure to the top management, security was the big area we focused on,\u201d recalls Ducret, who oversaw cyber security for SGS until the end of 2020. \u201cWe showed them that the setup we had with our applications running in 180 different data centers across the world was far from optimized from both a security and a cost perspective.\u201d<\/p>\n<p>\u201cIf we wanted to improve the security, it would cost a fortune because in each location we had different technologies. For example, if you wanted to implement web application firewalls across the network, you would have to buy, implement and maintain a specific solution at each location.\u201d<\/p>\n<p>But the security case for the cloud was about more than the bottom line. It was also about increasing visibility across the network. \u201cWe have something like 75,000 computers and 85,000 users distributed across more than 140 countries worldwide,\u201d says Ducret. \u201cOf course, from a network perspective, that presents a challenge.<\/p>\n<p>\u201cBefore the cloud, at group level, we had limited visibility over the compliance of our local affiliates across the world to the high standards SGS needs to respect. Now with Azure, we have this global visibility and we are able to automate some processes to help our Security Operations Center prevent and detect any anomalies they may have.\u201d<\/p>\n<p>The company has been using various cloud-based security tools, including Azure Sentinel \u2013 a cloud-native security information and event management (SIEM) platform that uses built-in AI to help analyze and correlate large volumes of data across enterprises.<\/p>\n<p>The solution allows SGS to define different use cases to detect security threats across its network. \u201cWe have defined 12 use cases,\u201d says Ducret. \u201cIt allows us to correlate different events and convert them into a security incident, if it is indeed a security incident. We have 75,000 computers and 4,000 servers, so we have many security events every day. It&#8217;s not manageable if you don&#8217;t have something which automatically analyzes those events and identifies which ones require an action.<\/p>\n<p>\u201cYou also get some forensic capabilities with Azure Sentinel,\u201d he adds. \u201cThe logs of these incidents are centralized and Sentinel gives us the tools to make some queries and do some forensic analysis of cybersecurity threats.<\/p>\n<p>\u201cAnd of course, the ease of integration with Azure and the broader Microsoft ecosystem is game changing, especially when it comes to quickly deploying and leveraging a solution in a Microsoft environment.\u201d<\/p>\n<h2>Boosting the company\u2019s security posture<\/h2>\n<p>One of the most important aspects of having Azure Sentinel is that SGS can reassure their customers that they have comprehensive cybersecurity solutions and practices in place. \u201cNowadays, customers will ask if we are using an SIEM,\u201d says Ducret. \u201cAnd it\u2019s important for our security posture score that we can say yes.\u201d<\/p>\n<p>Companies like BitSight and Scorecard can scan the external exposure of companies like SGS and publish reports detailing the effectiveness of the solutions they are using.<\/p>\n<p>\u201cIncreasingly, customers looking for testing and certification services like ours will check the external security posture scores of the companies that they are going to work with,\u201d says Ducret. \u201cSo for us It&#8217;s very important to have a good ranking.\u201d<\/p>\n<p>With Azure Sentinel, the company is increasing that external security posture. But SGS are also working to create their own security ranking internally too.<\/p>\n<p>\u201cWe&#8217;ve started to create an internal security index to compare affiliates within our network and put them in friendly competition with each other,\u201d says Ducret. \u201cOne part of this security index is the completion rate of the security awareness program which we have developed. Each SGS employee has to undertake three per year, and we report the compliance by the completion rate based on location.<\/p>\n<p>\u201cAnd it is all possible because of how easy the cloud makes it to track this sort of information across our network,\u201d he adds.<\/p>\n<h2>Increasing the company\u2019s sustainability credentials<\/h2>\n<p>Aside from the security, agility, optimization and cost-saving benefits of the company\u2019s move to the cloud, there are also more profound impacts linked to sustainability.<\/p>\n<p>\u201cA cloud supplier like Microsoft will be much better at optimizing the datacenter\u2019s energy consumption, or consuming blue or green energy, than SGS,\u201d says Ducret. \u201cWe cannot achieve the same level of optimization with our internal datacenters \u2013 that\u2019s not part of our core business to do that.<\/p>\n<p>\u201cSo from this sustainability point of view, there are also considerable benefits of the cloud,\u201d he continues. \u201cAnd this is important because more and more companies are reporting to an external sustainability index. SGS is very proud to be one of the top companies in the sustainability index. And that\u2019s partially due to the fact that we have been adopters of cloud technology like Microsoft 365 and Azure.<\/p>\n<p>\u201cNow we want to move all our applications to the cloud and embrace not just a cloud-first approach, but become a cloud-only company.\u201d<\/p>\n<p>A big part of that next step will be to introduce Microsoft Teams telephony to the company. \u201cWe are already using Teams telephony in our Geneva office and we want to develop a global strategy so that our affiliates can adopt this technology too,\u201d says Ducret.<\/p>\n<p>\u201cSo going forward, I think we have a great cloud foundation. It puts us in a strong position to introduce new innovations and strengthen the business with capabilities like IoT technology. It will help us become much more data-driven,\u201d he concludes.<\/p>\n<p>\u201cWe have a great footprint for us to take the next step.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cIf you ask anyone at SGS what\u2019s in the DNA of the company, they will all say the same two words: integrity and safety. We want to add a third word to the list: security.\u201d Frederic Ducret, Global Head of Cloud and IT Infrastructure at SGS is talking about the core qualities that define the [&hellip;]<\/p>\n","protected":false},"author":792,"featured_media":499957,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1804,1829],"class_list":["post-499951","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-customer-stories-en","category-security-privacy-en","specials-work-productivity-en","stories-how-can-i-work-secure","stories-working-secure-en","businessPriorities-applications-infrastructure"],"_links":{"self":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/499951"}],"collection":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/users\/792"}],"replies":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/comments?post=499951"}],"version-history":[{"count":6,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/499951\/revisions"}],"predecessor-version":[{"id":504526,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/499951\/revisions\/504526"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/media\/499957"}],"wp:attachment":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/media?parent=499951"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/categories?post=499951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}