Case studies and EBR Flashcards

1
Q

Versant Health, what city and what is the name of the CISO?

A

San Antonio, Texas, Derek Vorpahl

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Versant Health, what is their Zero Trust posture?

A

{Long term} Zero trust - trusted endpoints, granular policies, etc. Derek looking for specific actionable steps to take in the short-term to start building towards the zero trust model.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Xavier University, what city and what is the name of the director of security?

A

Cincinnati, Ohio, Brian Rappach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What was Xavier University big win with Duo and KnowBe4?

A

Combination of Duo rollout and KnowBe4 phishing education has led to a drop of 500 compromised O365 accounts last fiscal year to 1 this year.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Children’s Hospital of Colorado, what city and what is the name of the CISO?

A

Aurora, Colorado, DJ McArthur

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Children’s Hospital of Colorado, what is their Zero Trust posture?

A

Deploy ISE starting with guest and wireless first; Improve the VPN end user experience; Block EOL devices; Continue to configure granular polices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Henry Ford Health, what city and what is the name of their CISO?

A

Detroit, Michigan, Christy Wheaton

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

MidMichigan Health, what city and what is the name of their director?

A

Midland, Michigan, John Kelley - Director, IT Infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What technologies does MidMichigan Health want to integrate with Duo MFA?

A

Windows UAC, Box (Cloud SSO), Cisco ISE and VPN, CyberArk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Cerner Corporation, what city and what is the name of their director of IAM?

A

Kansas City, Jim Slinkard - Sr. Director IAM & Security Architecture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What was the impact of Cerner installing Duo on phishing and business email compromise?

A

** Disclaimer: Cerner has a no publicity clause in their contract so while these are awesome stories, they will not do a case study or other public facing forms of promotion **

Prior to Duo, Cerner had 202 credentials phished and 68 of those credentials used for unauthorized access to Cerner mailboxes. After Duo, the rate of credentials successfully phished increased to 422 incidents, but they only had 1 incident of unauthorized access to a mailbox

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What was the impact of Cerner switching to Duo on total cost of ownership (TCO)?

A

** Disclaimer: Cerner has a no publicity clause in their contract so while these are awesome stories, they will not do a case study or other public facing forms of promotion **

Went from 400 users and a handful of apps on RSA to 22,000 users and 40-50 apps with the same support staff. Justification for purchasing Duo was the minimal TCO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are Cerner’s objectives?

A
Choosing a new IDP (Sailpoint, Savian, One Identity Hitachi) 
Rolling out Microsoft Intune
Full migration to AzureAD eventually
Adopting the NIST 800-63 standard 
Cisco ASA SAML config
2FA on all networking devices
Continue to protect internal apps
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

BJC Healthcare, what city and who is their CISO?

A

Saint Louis, Missouri, Chris Niekamp

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What EMR is BJC Healthcare running?

A

Epic - Duo replaced RSA in protecting Epic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are BJC Healthcare’s objectives?

A

Protecting MyTime, Saba, ServiceNow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

American Public Media (APM), what is the name of their IT director featured in the case study?

A

Brad Rosenberger, Director of IT Infrastructure at American Public Media

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What added benefit did American Public Media (APM) receive in addition to two factor authentication?

A

Device insights. With many organizations pushing toward a Bring Your Own Device (BYOD), APM wanted to proactively get the visibility into what employee-owned devices are trying to access their networks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Ars Technica, what is the name of their director of technology featured in the case study?

A

Jason Marlin, Director of Technology

20
Q

What was the primary benefit Ars Technica realized in implementing Duo?

A

Security without slowing down busy writers. Jason Marlin: “You hear horror stories about the new security model and the difficulty in revving up security in your organization, but Duo is so easy”

21
Q

Boise Cascade, what city are they located in and what is the name of their CISO?

A

Boise, ID, and John Stifler - CISO

22
Q

What does Boise Cascade do?

A

Boise Cascade is a North American manufacturer of wood products and wholesale distributor of building materials, headquartered in Boise, Idaho.

23
Q

What does Boise Cascade need help with for multi-factor authentication?

A

Onboarding new employees. Duo is not completely baked into their new hire process and they need some assistance working with HR to help make this happen.

24
Q

Boise Cascade is using Duo Access. Which Access feature do they need advice on?

A

Phishing. Boise Cascade is using our phishing tool and would like some recommendations on phishing best practices.

25
Q

Citizen Union Bank, what is the tag line for the case study?

A

How the Financial Institution Quickly Implemented Their Secure Remote Access Program

26
Q

What were the use cases for Citizen Union Bank?

A

AD Sync, Citrix, and Checkpoint. In addition, the solution they chose needed to satisfy regulations, be easy to
use, and quick to deploy.

27
Q

Who was the Vice President Network Operations in the Citizen Union Bank case study?

A

Mickey Twyford, Assistant Vice President Network Operations

28
Q

Betsson Group, what is the tag line for the case study?

A

How the Online Entertainment Leader Deployed Duo to

1,500 Users in a Single Day

29
Q

Who was the Information Security Manager in the Betsson Group case study?

A

Adrian Romano, Information Security Manager

30
Q

What were the use cases for Betsson Group?

A

Moving off the McAfee one-time password (OTP) method of 2FA; Supporting the transition from Juniper to Checkpoint remote access;

31
Q

Calgary Board of Education, where are they located and who is our primary point of contact?

A

Calgary, Alberta, and Ryan Opperman - Senior Solutions Architect

32
Q

Union teachers pushed back at Calgary Board of Education’s use of Duo. Why? And what was the solution?

A

Union employees did not want to use their personal phones. We were able to find middle ground with many folks by offering SMS or Phone Call Back as an auth method.

33
Q

What is the next step for Calgary Board of Education’s deployment of Duo?

A

Phase 2 applications include Desire2Learn (D2L) and Powerschool (student records system)

34
Q

Where is Peloton located and who is their director of technology?

A

New York, Dave Brown

35
Q

Why are Peloton users relying on phone call authentication?

A

There is resistance to installing Duo Mobile on personal devices. There are also users who strongly prefer to keep PIN / FaceID disabled.

36
Q

Where is the Bank for International Settlements (BIS) located and who heads up their security team?

A

Basel, Switzerland, and Brian Ritchot

37
Q

What applications is Bank for International Settlements (BIS) looking to protect with Duo?

A

PeopleSoft HR, Openlink Findur

38
Q

What IAM products does Bank for International Settlements (BIS) use?

A

SailPoint, Airlock IAM, CyberARK

39
Q

Where is Cimpress and who is their CTO?

A

Boston, Maarten Wensveen (CTO)

40
Q

Where is Mayo Clinic and who is their director of enterprise systems?

A

Rochester, MN, and Ely Pelowski - Director of Enterprise Systems

41
Q

What is Mayo Clinic’s compliance objectives?

A

Protect EPCS for DEA compliance
Phase 1: Florida and Arizona (complete! - to be validated)
Phase 2: Minnesota and Wisconsin (in progress)
Phase 3+: Iowa? (to be confirmed)

42
Q

What other MFA providers does Mayo Clinic have installed?

A

RSA in place today - VPN & server access
Secure auth - smart cards for work stations
O365 with Microsoft MFA - rolling out in a couple of months
Imprivata used with Epic

43
Q

What siem does Mayo Clinic want to integrate with Duo?

A

LogRhythm - they are interested in doing more with our Admin API. We want to work directly with the security operations center to help develop a list of recommended alert

44
Q

Where is Polaris Industries and who is their compliance manager?

A

Minneapolis, MN, and Adam Knutson - Information Security and Compliance Manager

45
Q

What HR systems are on Polaris Industries roadmap?

A

They are planning to roll out Workday and Office365, which would cover a larger subset of users that aren’t currently in Duo.

46
Q

What siem has Polaris Industries integrated with Duo?

A

They utilize Splunk to ingest the device insight data, but don’t currently take any action off the dashboards they have built.