$100K in cost savings
Eliminating unnecessary services yielded $100K in cost savings over three years
Global language education and cultural training company reduces costs and enhances security and compliance
Download the PDF
Eliminating unnecessary services yielded $100K in cost savings over three years
Gained continuous visibility into the complete external attack surface for the first time
Automation and centralized management improved efficiency and reduced the need for new hires
Achieved an 86% reduction in critical alerts in three years, from 140 to just 20
Daniel Schlegel, Global CIO for Berlitz Corporation, spearheads IT strategy, security, and data privacy for the organization and its subsidiaries. Schlegelâs team is the companyâs first line of defense, keeping the organization operational, safe, and successful in an ever-shifting threat landscape.
Berlitzâs digital infrastructure is complex and has faced challenges identifying and assessing potential security vulnerabilities across its diverse systems and applications. With a history of decentralized operations, Schlegel predicted that unknown and unmanaged assets were hiding in their external landscape.
âOur organization has been around for 145 years, and until recently, a lot of operational functions were decentralized and regionally operated,â Schlegel says. âAt that time, anyone with a little budget could authorize a public-facing resource.â
Previously, much of Berlitzâs processes were largely manual and provided insufficient visibility, causing potential security gaps. It took significant manual effort to carry out risk management, vulnerability management, and penetration testing.
This added a substantial operational load for his team, spiraling resource costs as they continually increased headcount to keep pace with their growing external attack surface. This wasted time failed to identify or protect their entire external attack surface.
âWe were looking for a platform to automate tasks such as ongoing scanning and proactive assessment of our external attack surface,â Schlegel says. âWe wanted to keep abreast of general vulnerabilities and whether they potentially impacted the business.â
âCyCognito helped us discover external assets we previously had no idea about; there is no question of the benefit this platform provides to my team members and me.â
Daniel Schlegel ă» Global CIO
Schlegel launched a search for an automated platform to manage external attack surfaces that would unify security practices across decentralized operations. They evaluated several vendors and conducted thorough research.
CyCognito was the clear frontrunner, not only for its robust technology but for the genuine care the team behind the platform showed.
âThey showed genuine interest in our success as a customer,â says Schlegel. âThe communication was good, and weâve continued to have good mutual exchanges.â
Berlitz initially ran a proof of concept with CyCognito. The process and the results left them no doubt it was the platform for them.
âWe felt comfortable relatively early on with CyCognito,â he says. âThe overall approach that was taken and more so the results that we saw even during a proof of concept, there were assets discovered that we generally had no idea about, and so this gave us the confidence that this was the right solution for us.â
CyCognito gave Schlegel and his team complete visibility and insights across its global external attack surface. This was the pivotal âahaâ moment for him.
âThere was an âahaâ moment on a somewhat regular basis; there were findings initially that came out of it,â he says. âWe really did not necessarily know the level of detail at this point, and we developed an understanding of what assets and threats may be out there that perhaps we werenât aware of.â
âThe biggest thing for us is the built-in Exploit Intelligence and the Attack Surface Management; these two key aspects are what emphasize the most.â
Daniel Schlegel ă» Global CIO
A dashboard lays out what systems and assets are at critical risk, where theyâre exposed, and how to eliminate that exposure.
âFirst, we have the visibility, and then the prioritization, so we know week-over-week where we need to focus our time,â says Schlegel.
CyCognitoâs Exploit Intelligence gives his team the latest data on how vulnerabilities are exploited and how they map to Berlitzâs security landscape.
âThe biggest thing for us is the built-in Exploit Intelligence and the Attack Surface Management; these two key aspects are what emphasize the most,â adds Schlegel.
In the first full year running the platform, CyCognito alerted Berlitz to 140 critical items that needed to be prioritized and remediated.
âIâm pretty sure out of those 140 items, we would have only come across a fraction doing it ourselves manually,â he says.
As a result of their efforts, the number of critical alerts continues to decrease year-over-year. After the first full year of utilizing the platform, the 140 alerts were reduced to nearly 60 in the second year, and last year, they hadnât even reached 20.
âThere was a large number of items to manage at the start, but now that those items are resolved, the number is much smaller,â he says. âThe platform's value keeps increasing; it validates our efforts- the smaller the number, the better everything works, and thatâs key to us.â
CyCognito boosted Schlegelâs teamsâ efficiency, optimizing their operations without requiring a significant increase in headcount.
âCyCognito was a force multiplier for our small team, allowing us to do more,â he says. âThe automation that is built into the platform means we donât need to exponentially increase our headcount just to manage our assets.â
Automated workflows and centralized management, enabled his team to focus their efforts based on actual risk exposure to their most critical assets and remediate faster. When vulnerable assets need patching, the platform automatically flows that evidence into Berlitzâs existing tools without any intervention from IT. Support tickets are created automatically when new risks are detected. Tickets are pushed directly to the relevant teamâs Jira queue, so Schlegel knows theyâll be resolved in a timely way.
âThe efficiency gains were substantial, particularly in remediating vulnerabilities,â says Schlegel. âCyCognito brought accountability and centralized visibility to our assets, enhancing governance.â
âCyCognito enables us to bring all our external assets under one umbrella, to look at this more holistically and centrally manage whatâs happening.â
Daniel Schlegel ă» Global CIO
In a specific instance, they consolidated disparate business systemsâbased on insights from the CyCognito platformâwhich reduced business costs and improved IT hygiene. Trusted data from CyCognito also led them to shut down numerous assets, strengthening security and saving dollars. This was another âahaâ moment for Schlegel.
âWhen we started shutting things down, we saved several thousands of dollars on a monthly recurring basis, over a number of years, you quickly get into six-digit savings,â says Schlegel.
Schlegel is confident that CyCognito proactively monitors Berlitzâs external attack surface, addressing vulnerabilities and potential threats before they are exploited.
âCyCognito enables us to bring all our external assets under one umbrella, to look at this more holistically and centrally manage whatâs happening,â says Schlegel.
Get a free scan of your attack surface and gain valuable insight into your organization's risk posture by allowing CyCognito to discover, contextualize, and test externally.
Request a Scan