Discovery Limited Takes a Proactive Approach to Attack Surface Management with RiskIQ

About Discovery Limited

Discovery Limited is a South African-founded financial services organization that operates in the healthcare, life assurance, short-term insurance, savings, and investment products and wellness markets. Founded in 1992, Discovery is guided by a clear core purpose—to make people healthier and to enhance and protect their lives. The company has expanded its operations globally and currently serves over 5 million clients across South Africa, the United Kingdom, the United States, China, Singapore, and Australia.

Challenges

Over recent years, Discovery’s diversification activities, including the creation of a retail banking subsidiary and expanded global operations, resulted in a rapidly growing Internet presence and increased cyber risk. While they had some elements of brand protection in place, they recognized the need to better understand what was happening outside of their network. These challenges consisted of:

  • Growing breadth and complexity of Internet exposed assets
  • Detecting and responding to threats targeting Discovery brands and customers
  • Resource constraints within the security team

“... RiskIQ is the “spotlight” that removes the traditional dark spaces where the bad guys hide.”

Zaid Parak
CISO, Discovery Limited

The Results

Discovery have successfully deployed an Attack Surface Management platform underpinned by RiskIQ Illuminate. Security teams now have visibility of their existing Internet assets as well as any new assets that are deployed. Various use cases have been implemented both in RiskIQ and Splunk to automatically address areas of weakness across their footprint, with additional use cases planned. Brand infringing assets are automatically detected and triaged by the RiskIQ customer success team. Confirmed violations are sent to Discovery for review and takedown approval, with RiskIQ handling the takedowns and ensuring that the violating URLs are sent to Google Safe Browsing and Microsoft Smartscreen to warn users from visiting those locations.

Conclusion

The RiskIQ Illuminate Platform provides organizations with ‘outside the firewall’ visibility to discover unknowns in their digital attack surface and identify threats targeting their organization and their customers. This actionable intelligence can be used by security teams to address a wide range of security operations use cases to strengthen security and reduce overall cyber risk.