Customer Story

Australia’s Largest Business Bank Protects Customers and Colleagues Through Operational Resilience

NAB is Australia’s largest business bank and one of the country's ‘big four’, offering a portfolio of banking and finance products and services. Formed by the merger of two banks established in the mid-1800s, NAB now has more than 38,000 colleagues providing 10 million customers with secure, easy and reliable banking services. More than 90% of the Group’s workforce are in Australia and New Zealand, with the wider team located in parts of Asia, London, New York and Paris.

NAB is focused on becoming a simpler, better performing bank. Core to this is developing and embracing leading resilient technology with a sophisticated security function front of mind.

“The world continues to change, technology changes and so must we,” Sandro Bucchianeri said.

We need to keep simplifying, we need to keep innovating and we need to keep evolving. Clearly security is an important part of that evolution, and that’s why we design everything with security in mind from the outset.”

Enhancing the Bank’s Frontline Defenses

Endpoint detection and response (EDR) has been an important frontline defense for NAB. In 2019, NAB recognised the need to refresh and further enhance protection and detailed telemetry.

“We knew it was time to test the market, and it was time for a change,” said Sandro Bucchianeri, Global CSO, NAB.

“We were looking for something more behavioral with rich endpoint visibility; a solution that either supported our own proactive threat hunting or came with its own threat hunting capability; and it had to reduce our time to detect, which is one of our core metrics.

“Finally, we needed speed to value in moving to a new solution. We wanted something that we could roll out quickly, and that we could safely deploy at scale.”

Achieving Rapid Time to Value and Closing Visibility Gaps

CrowdStrike was able to meet NAB’s expectations of a quick rollout: the Falcon solution was deployed to workstations in the first four weeks of the new partnership. The progressive rollout to servers was completed in the following two months.

“Integration with NAB’s security platforms meant that security event data and telemetry could be acted upon in a timely manner,” Bucchianeri said.

To date, CrowdStrike has been deployed across the entire NAB Group.

A Security Platform that Evolves with the Business

As NAB has continued to diversify and evolve, CrowdStrike technologies have played a key role in the security due diligence and assessment of its subsidiaries and acquisitions.

“CrowdStrike has been deployed with success across our subsidiaries for supporting breach assessment and ongoing capability,” Bucchianeri said.

NAB continues building a sophisticated security function. This includes focusing on simplification, automation, being secure by design and, most importantly, integrating a layered approach to security by understanding the threats and using solutions and skill sets that support it.

“We’re pleased CrowdStrike has become a key partner that aligns with our sophisticated needs,” Bucchianeri said.

Challenges

  • Maintaining security and visibility across a complex and diverse technology environment
  • Staying ahead of a constantly evolving threat landscape in a highly targeted industry
  • Ensuring protection of corporate and customer information and availability of services

Solution

  • National Australia Bank (NAB) partnered with CrowdStrike to secure its global environment and preserve its ongoing commitment to protect its customers and colleagues through financial and operational resilience. CrowdStrike enables the bank’s own in-house cyber security operations with an additional layer of expertise and capability, and a simple, effective security platform that can adapt rapidly to meet the challenges of an evolving threat landscape.

Results

  • Reduced complexity, improved protection, enhanced risk management and uplifted skills and expertise
  • Enhanced capabilities to develop and retain skilled security resources
  • Gained increased security visibility into cloud environment