Be a part of our day by day and weekly newsletters for the most recent updates and unique content material on industry-leading AI protection. Be taught Extra
NOV, the Fortune 500 oil and gasoline big, is present process a sweeping cybersecurity transformation beneath CIO Alex Philips, embracing a Zero Belief structure, strengthening identification defenses and infusing AI into safety operations. Whereas the journey shouldn’t be full, the outcomes, by all accounts, are dramatic – a 35-fold drop in safety occasions, the elimination of malware-related PC reimaging and hundreds of thousands saved by scrapping legacy “equipment hell” {hardware}.
VentureBeat lately sat down (nearly) for this in-depth interview the place Philips particulars how NOV achieved these outcomes with Zscaler’s Zero Belief platform, aggressive identification protections and a generative AI “co-worker” for its safety crew.
He additionally shares how he retains NOV’s board engaged on cyber threat amid a world risk panorama the place 79% of assaults to achieve preliminary entry are malware-free, and adversaries can transfer from breach to interrupt out in as little as 51 seconds.
Beneath are excerpts of Philips’ current interview with VentureBeat:
VentureBeat: Alex, NOV went “all in” on Zero Belief various years in the past – what had been the standout good points?
Alex Philips: After we began, we had been a standard castle-and-moat mannequin that wasn’t maintaining. We didn’t know what Zero Belief was, we simply knew that we would have liked identification and conditional entry on the core of the whole lot. Our journey started by adopting an identity-driven structure on Zscaler’s Zero Belief Change and it modified the whole lot. Our visibility and safety protection dramatically elevated whereas concurrently experiencing a 35x discount within the variety of safety incidents. Earlier than, our crew was chasing hundreds of malware incidents; now, it’s a tiny fraction of that. We additionally went from reimaging about 100 malware-infected machines every month to nearly zero now. That’s saved a substantial quantity of money and time. And for the reason that answer is cloud-based, Equipment hell is gone, as I wish to say.
The zero belief strategy now offers 27,500 NOV customers and third events policy-based entry to hundreds of inside purposes, all with out exposing these apps on to the web.
We had been then in a position to take an interim step and re-architect our community to reap the benefits of internet-based connectivity vs. legacy costly MPLS. “On common, we elevated velocity by 10–20x, lowered latency to essential SaaS apps, and slashed value by over 4x… Annualized financial savings [from network changes] have already achieved over $6.5M,” Philips has famous of the undertaking.
VB: How did shifting to zero belief really cut back the safety noise by such an unlimited issue?
Philips: A giant motive is that our web site visitors now goes by means of a Safety Service Edge (SSE) with full SSL inspection, sandboxing, and information loss prevention. Zscaler friends instantly with Microsoft, so Workplace 365 site visitors bought sooner and safer – customers stopped attempting to bypass controls as a result of efficiency improved. After being denied SSL inspection with on-prem tools, we lastly bought authorized approval to decrypt SSL site visitors for the reason that cloud proxy doesn’t give NOV entry to spy on the info itself. Meaning malware hiding in encrypted streams began getting caught earlier than hitting endpoints. Briefly, we shrunk the assault floor and let good site visitors movement freely. Fewer threats in meant fewer alerts general.
John McLeod, NOV’s CISO, concurred that the “outdated community perimeter mannequin doesn’t work in a hybrid world” and that an identity-centric cloud safety stack was wanted. By routing all enterprise site visitors by means of cloud safety layers (and even isolating dangerous internet classes by way of instruments like Zscaler’s Zero Belief Browser), NOV dramatically reduce down intrusion makes an attempt. This complete inspection functionality is what enabled NOV to identify and cease threats that beforehand slipped by means of, slashing incident volumes by 35x.
VB: Have been there any unexpected advantages to adopting Zero Belief you didn’t initially count on?
Alex Philips: Sure, our customers really most well-liked the cloud-based Zero Belief expertise over legacy VPN shoppers, so adoption was easy and gave us unprecedented agility for mobility, acquisitions, and even what we wish to name “Black Swan Occasions”. For instance, when COVID-19 hit, NOV was already ready! I informed my management crew if all 27,500 of our customers wanted to work remotely, our IT programs might deal with it. My management was surprised and our firm stored shifting ahead with out lacking a beat.
VB: Id-based assaults are on the rise – you’ve talked about staggering stats about credential theft. How is NOV fortifying identification and entry administration?
Philips: Attackers understand it’s usually simpler to log in with stolen credentials than to drop malware. In truth, 79% of assaults to achieve preliminary entry in 2024 had been malware-free, counting on stolen credentials, AI-driven phishing, and deepfake scams, in line with current risk studies. One in three cloud intrusions final 12 months concerned legitimate credentials. We’ve tightened identification insurance policies to make these techniques more durable.
For instance, we built-in our Zscaler platform with Okta for identification and conditional entry checks. Our conditional entry insurance policies confirm units have our SentinelOne antivirus agent operating earlier than granting entry, including an additional posture test. We’ve additionally drastically restricted who can carry out password or MFA resets. No single admin ought to be capable of bypass authentication controls alone. This separation of duties prevents an insider or compromised account from merely turning off our protections.
VB: You talked about discovering a niche even after disabling a person’s account. Are you able to clarify?
Philips: We found that should you detect and disable a compromised person’s account, the attacker’s session tokens may nonetheless be lively. It isn’t sufficient to reset passwords; you must revoke session tokens to really kick out an intruder. We’re partnering with a startup to create close to real-time token invalidation options for our mostly used assets. Basically, we need to make a stolen token ineffective inside seconds. A Zero Belief structure helps as a result of the whole lot is re-authenticated by means of a proxy or identification supplier, giving us a single choke level to cancel tokens globally. That approach, even when an attacker grabs a VPN cookie or cloud session, they will’t transfer laterally as a result of we’ll kill that token quick.
VB: How else are you securing identities at NOV?
Philips: We implement multi-factor authentication (MFA) virtually in all places and monitor for irregular entry patterns. Okta, Zscaler, and SentinelOne collectively kind an identity-driven safety perimeter the place every login and machine posture is repeatedly verified. Even when somebody steals a person password, they nonetheless face machine checks, MFA challenges, conditional entry guidelines, and the danger of immediate session revocation if something appears off. Resetting a password isn’t sufficient anymore — we should revoke session tokens immediately to cease lateral motion. That philosophy underpins NOV’s identification risk protection technique.
VB: You’ve additionally been an early adopter of AI in cybersecurity. How is NOV leveraging AI and generative fashions within the SOC?
Philips: We have now a comparatively small safety crew for our international footprint, so we should work smarter. One strategy is bringing AI “co-workers” into our safety operations heart (SOC). We partnered with SentinelOne and began utilizing their AI safety analyst software—an AI that may write and run queries throughout our logs at machine velocity. It’s been a sport changer, permitting analysts to ask questions in plain English and get solutions in seconds. As a substitute of manually crafting SQL queries, the AI suggests the following question and even auto-generates a report, which has dropped our imply time to reply.
We’ve seen success tales the place risk hunts are carried out as much as 80% sooner utilizing AI assistants. Microsoft’s personal information reveals that including generative AI can cut back incident imply time to decision by 30%. Past vendor instruments, we’re additionally experimenting with inside AI bots for operational analytics, utilizing OpenAI foundational AI fashions to assist non-technical workers rapidly question information. In fact, we’ve got information safety guardrails in place so these AI options don’t leak delicate info.
VB: Cybersecurity is now not simply an IT difficulty. How do you have interaction NOV’s board and executives on cyber threat?
Philips: I made it a precedence to carry our board of administrators alongside on our cyber journey. They don’t want the deep technical trivia, however they do want to grasp our threat posture. With generative AI exploding, for instance, I briefed them on each the benefits and dangers early on. That schooling helps once I suggest controls to forestall information leaks—there’s already alignment on why it’s essential.
The board views cybersecurity as a core enterprise threat now. They’re briefed on it at each assembly, not simply annually. We’ve even run tabletop workout routines with them to point out how an assault would play out, turning summary threats into tangible determination factors. That results in stronger top-down assist.
I make it a degree to always reinforce the fact of cyber threat. Even with hundreds of thousands invested in our cybersecurity program, the danger is rarely absolutely eradicated. It isn’t if we could have an incident, however when.
VB: Any ultimate recommendation, based mostly on NOV’s journey, for different CIOs and CISOs on the market?
Philips: First, acknowledge that safety transformation and digital transformation go hand in hand. We couldn’t have moved to the cloud or enabled distant work so successfully with out Zero Belief, and the enterprise value financial savings helped fund safety enhancements. It really was a “win, win, win.”
Second, give attention to the separation of duties in identification and entry. Nobody individual ought to be capable of undermine your safety controls—myself included. Small course of adjustments like requiring two individuals to vary MFA for an exec or extremely privileged IT workers, can thwart malicious insiders, errors, and attackers.
Lastly, embrace AI rigorously however proactively. AI is already a actuality on the attacker facet. A well-implemented AI assistant can multiply your crew’s protection, however you have to handle the dangers of knowledge leakage or inaccurate fashions. Be certain that to merge AI output together with your crew’s talent to create an AI-infused “brAIn”.
We all know the threats preserve evolving, however with zero belief, robust identification safety and now AI on our facet, it helps give us a combating likelihood.
