Story Poster

Success Story

Securing a Newly Independent Enterprise

NCR Atleos Protects its Expanded Asset Base using Qualys VMDR with Software Composition Analysis

Business

Headquartered in Atlanta, Georgia, NCR Atleos operates the world’s largest independently owned ATM network. A leader in self-service financial access solutions, the company offers clients expertise, operational scale, and always-on services to deliver comprehensive self-service channels.

Executive Summary

When it became an independent company, NCR Atleos faced the challenge of protecting a 10-fold increase in business users and IT endpoints—all while meeting stringent banking industry security standards. With Qualys, the organization has boosted the visibility of threats across its environment by almost 50%, as well as streamlining and accelerating vital remediation activities.

Customer Environment

28,000 endpoint devices across more than 60 countries

Hybrid environment comprising on-premises servers and Amazon Web Services, Google Cloud Platform & Microsoft Azure environments

PCI DSS compliant web applications

Business Background

NCR Atleos was established when its parent company NCR divested its ATM business. As a newly independent enterprise, NCR Atleos aims to unlock growth opportunities in its self-service banking, payments and network, and telecommunications and technology businesses. However, becoming a separate entity also presented challenges. Almost overnight, the company’s information security team faced the challenge of managing a 10-fold increase in business users and IT endpoints. In addition, the security organization needed to discover assets across a far more complex, segregated environment and effectively detect, prioritize and remediate vulnerabilities.

Business Challenges

Discover all assets across the new business, including cloud and on-premises attack surfaces

Continuously scan for and effectively prioritize the remediation of vulnerabilities

Detect vulnerabilities embedded in open-source software libraries

Act fast to mitigate the risk of zero-days, critical vulnerabilities and misconfigurations

Comply with stringent regulatory requirements, including the Payment Card Industry Data Security Standard (PCI DSS)

Secure an enlarged enterprise while keeping operational costs and headcount lean

Quote Icon

With so many new assets coming over following the split from NCR, it was extremely difficult to discover what we had and identify our third-party risks. By ramping up our use of Qualys, we were able to increase our visibility of threats very quickly.

Theo BowmanVulnerability Management Engineer, NCR Atleos

The Solution

By working with Qualys, NCR Atleos streamlined and enhanced its approach to vulnerability management on its journey to becoming an independent company.

With Qualys CyberSecurity Asset Management, the organization can discover unmanaged, internet-facing assets—building up a complete picture of its environment. And using Qualys VMDR with Qualys Security Configuration Assessment (SCA) and Software Composition Analysis (SwCA), NCR Atleos can leverage its Qualys Cloud Agents to check for PCI DSS compliance and gain real-time insight into zero-days in open-source software.

Qualys Shield
"I found out about Qualys SwCA while I was creating activation keys for our Qualys Cloud Agents, and I instantly realized its potential to dramatically increase our visibility,” explains Theo Bowman, Vulnerability Management Engineer at NCR Atleos. “Our management team also recognized the value of SwCA, and we rapidly pushed out the app to 28,000 assets, including laptops, virtual machines, cloud environments, and servers."

After deploying SwCA, NCR Atleos discovered it was significantly exposed to log4j vulnerabilities—and the organization was quick to act. “We remediated all our log4j vulnerabilities within a day, but without Qualys we'd never have known they were there,” confirms Bowman. “Qualys is also very effective for our business-as-usual patching. We've integrated VMDR with ServiceNow, and we can now push out remediation tickets in less than 24 hours.”

Qualys Difference

Increased visibility of assets and vulnerabilities, elevating leadership confidence in vulnerability management reporting

Discovered and remediated significant zero-day vulnerabilities within a key business application

Enabled accurate, risk-based prioritization of vulnerabilities using the Qualys Detection Score (QDS)

Delivered vulnerability detection and security configuration assessment in a single solution

Boosted asset coverage across a hybrid multicloud environment with Qualys CyberSecurity Asset Management

The Business

Benefits

Slide Icon

Increases visibility of vulnerabilities by almost 50% with Qualys SwCA

Slide Icon

Detects zero-day vulnerabilities with zero false positives to date

Slide Icon

Accelerates remediation for the most serious cyber threats

Slide Icon

Automates key vulnerability management processes, improving operational efficiency

Slide Icon

Facilitates compliance with banking industry requirements such as PCI DSS

Slide Icon

Lays the foundation for even more effective prioritization in the future with Qualys TruRisk scores

About Qualys

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. For more information, please visit qualys.com.

Qualys, Qualys VMDR® and the Qualys logo are proprietary trademarks of Qualys, Inc. All other products or names may be trademarks of their respective companies.