Download PDF
Netskope > Case Studies > Multinational Hotels Company Enables Google Apps While Ensuring PCI Compliance with Google Apps and Netskope
Netskope Logo

Multinational Hotels Company Enables Google Apps While Ensuring PCI Compliance with Google Apps and Netskope

Technology Category
  • Application Infrastructure & Middleware - API Integration & Management
  • Cybersecurity & Privacy - Cloud Security
Applicable Functions
  • Business Operation
Use Cases
  • Regulatory Compliance Monitoring
  • Remote Collaboration
Services
  • Cloud Planning, Design & Implementation Services
  • Cybersecurity Services
The Challenge
The multinational hotel group, a long-time Google Apps customer, underwent an internal security audit. The audit highlighted the cloud as an area where there was very little visibility, particularly concerning PCI. The company's customer support operations and corporate employees often interact with consumers and business guests, taking customer information such as credit card and other personally-identifiable or sensitive information during those conversations. Furthermore, the corporate employees have access to a tremendous amount of valuable content such as booking information, customer lists, partner contracts, corporate plans, M&A documents, non-public financials, and more. The organization needed to discover where that content is, understand what it is, and ensure that it has proper protections around it.
About The Customer
The customer is a multinational hotel group with nearly 5,000 hotels in 100 countries around the world. The company has more than 100,000 employees and uses Google Apps extensively, with employees particularly using Google Drive, Docs, and Sheets. The company has more than a thousand cloud apps in use to achieve a host of use cases ranging from customer relationship management to marketing to supply chain and e-commerce, but the majority of cloud usage and data movement are in Google Apps. The company's customer support operations and corporate employees often interact with consumers and business guests, taking customer information such as credit card and other personally-identifiable or sensitive information during those conversations.
The Solution
The company used Netskope for Google Apps to automatically discover content within their corporate sanctioned Google Drive, which houses all of their content created in or uploaded to any Google App. They developed a handful of custom DLP profiles using the Netskope policy wizard, including “PCI,” “PII,” and “confidential,” and identified tens of thousands of content violations. After discovering sensitive content against the above profiles, the customer was able to drill down, see who the content owners were, and understand the sharing status of the content, including percentage of sensitive data that was shared outside of the company and how many people outside of the company still had access. They were also able to restrict access as well as download several documents for later review by legal. They also used Netskope to notify content owners of the actions they had taken to create process and policy transparency.
Operational Impact
  • The customer can now be in maintenance mode, discovering content as it’s being uploaded and taking action accordingly.
  • They can also discover cloud apps that compete with Google Apps and drive usage to Google Apps in order to consolidate onto one app to reduce complexity and reduce risk.
  • They get an added benefit of ensuring collaboration. When everybody’s using the same app, it makes it easier to sync, share, collaborate, and enable workflows with content.
Quantitative Benefit
  • Identified tens of thousands of content violations.
  • Reduced complexity and risk by consolidating onto one app.

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.