Corpay Secures Its Hybrid Multi-Cloud Infrastructure With Gigamon
Based in Atlanta, Corpay (formerly FLEETCOR Technologies) is a global business payment company. Its corporate spend-management platform integrates with common accounting systems to enable employees to transact on an organization’s behalf, help improve management and spend control, simplify mobility and vendor payment to increase employee efficiency, and allow companies to monitor real-time performance with integrated reporting and analytics.
Late last year, my colleague Stephen Goudreault and I had the opportunity for a three-hour discussion with Corpay’s Global CTO, Waddaah Keirbeck, and his leaders from development, security and infrastructure organizations. In addition to the value of a strong security posture, we were reminded of the outsized consequences poor application performance can have on businesses. We learned that when a credit card transaction takes too long, the consumer will put the card in the back of their wallet and there is a 90 percent or more chance they will use a different card for their next transactions. It’s no wonder that world-class security and performance are must-haves for Corpay.
Over the following weeks, Corpay turned to Gigamon deep observability for a new level of security posture, performance monitoring, and faster troubleshooting of their hybrid multi-cloud infrastructure. Their key requirements were visibility into all data in motion, from physical to container workloads, and being able to extract intelligence from that traffic to feed their data model framework for SIEM and observability tools. A vendor saying, “Here’s the data export — you figure out the use cases and integrate into your system,” was simply not an option.
How Gigamon Transformed Corpay’s Operations
#1. Eliminate blind spots
Deep observability from Gigamon allows Keirbeck and his team to monitor not just inbound and outbound but also lateral East-West traffic, which is where the application trouble often occurs and where the threat actors hide. Gigamon’s centralized observability pipeline makes it possible to eliminate blind spots, particularly blind spots for virtual traffic that does not traverse firewalls.
#2. Support my tools
The Gigamon Deep Observability Pipeline replicates, filters, and selectively forwards network traffic to Corpay’s monitoring, management, and security tools. This included expanding visibility to all lateral East-West traffic for Cisco Stealthwatch for security, SolarWinds for network management, and network-derived metadata to Splunk and Dynatrace for application monitoring and application security.
Two key tools enable Corpay to monitor threat activity across its entire multi-cloud environment:
- Gigamon Application Metadata Intelligence (AMI) provides nearly 6,000 metadata elements through deep packet inspection, which helps Corpay quickly identify performance bottlenecks, quality issues, and potential network security risks
- Gigamon Precryption™ technology eliminates blind spots in lateral threat activity by providing the Corpay security stack with plaintext visibility; no decryption is required
#3. Help with my compliance needs
Meeting the Payment Card Industry Data Security Standard (PCI DSS) is a key requirement for Corpay, and they recognized the need for network telemetry to truly meet this compliance. SIEM’s visibility into PCI compliance generally comes from syslog and EDR-reported data. In practice, EDR agents may not be installed on every relevant host, and syslog only provides superficial data, specifically for network communications. The Gigamon Deep Observability Pipeline is uniquely positioned in data networks to ensure PCI compliance with greater ease and accuracy.
More information about meeting PCI DSS with Gigamon can be found here.
In closing, Corpay needed a solution that could do more than just monitor traffic. They needed to see all traffic moving laterally across their network, accelerate mean time to resolution (MTTR), and eliminate performance bottlenecks and latency. After extensive research, Waddaah determined that the Gigamon Deep Observability Pipeline, including GigaVUE® HC Series appliances, GigaVUE-FM fabric manager, and GigaVUE TA Series appliances, would be the best solution to monitor, optimize, and manage the traffic in Corpay’s hybrid multi-cloud environment.
Learn More About Gigamon Solutions
More details about how Gigamon is helping Corpay are available in the full case study and this video:
Featured Webinars
Hear from our experts on the latest trends and best practices to optimize your network visibility and analysis.
CONTINUE THE DISCUSSION
People are talking about this in the Gigamon Community’s Security group.
Share your thoughts today