How Clal Insurance Gains Visibility and Saves Time in Security Operations
David
Operational Security Lead, Clal Insurance
“XM Cyber shows me everything happening in my company. From password changes to unauthorized account usage. Before, I couldn’t see these things. Now I can see the entire scenario.”
David, Operational Security Lead, Clal Insurance
TL;DR
Clal Insurance, one of Israel's largest insurance and long-term savings groups, lacked end-to-end visibility across dozens of sites. XM Cyber mapped dynamic attack paths across the environment, cut incident resolution from a full day to under an hour, and gave the security team complete attack path visibility for the first time.
Meet the Client
- Location
- Balingen, Germany. Global operations in 120+ countries
- Industry
- Manufacturing
- Employees
- ~4,500
- About the Company
- A global technology company founded nearly 160 years ago, Bizerba designs customized hardware, software, and service solutions for weighing and production systems. Annual sales of €830 million.
The Challenge
Clal Insurance is one of Israel’s largest insurance companies, managing a broad digital footprint across dozens of sites. For David, the Operational Security Lead, the challenge was clear and costly: too much time spent on security operations without a complete understanding of the underlying risks.
“Before XM Cyber, solving a single problem could take me an entire day. I couldn’t always understand what was really happening.”
David, Operational Security Lead, Clal Insurance
With multiple sites, applications, and users, the Clal security team lacked the essential, end-to-end visibility they needed to connect the dots and act quickly on threats. They were reacting to individual incidents instead of seeing the full attack scenario.
The Solution
After exploring other options, the team at Clal approached XM Cyber. The platform immediately transformed the security team’s operations by mapping dynamic attack paths, proactively identifying misconfigurations, and exposing suspicious behavior across their ecosystem. “XM Cyber shows me everything happening in my company,” David said. “From password changes to unauthorized account usage. Before, I couldn’t see these things. Now I can see the entire scenario.”
The deployment was seamlessly supported by XM Cyber’s dedicated team, who assisted in building a robust gateway architecture to secure all agent traffic. David highlighted the value of this partnership: “Whenever I need help, I just call them. They listen, analyze, and solve my problems. The service is excellent.”
“Whenever I need help, I just call them. They listen, analyze, and solve my problems. The service is excellent.”
David, Operational Security Lead, Clal Insurance
Benefits & Outcomes
Clal Insurance saw immediate and lasting results across their security posture and operational efficiency:
- Dramatic Time Savings: Incident resolution dropped from a full day to less than an hour, freeing David and his team to focus on strategic security initiatives.
- Complete Scenario Visibility: The team gained the ability to track lateral movement, credential misuse, and domain escalations in real time, moving from incident response to true scenario tracing.
- Proactive Hardening: XM Cyber highlighted critical risks in Active Directory and Azure, such as orphaned groups and inactive accounts, allowing for rapid and effective remediation.
- Simplified Executive Reporting: Intuitive dashboards and risk scores now translate complex security posture into actionable information that senior management can easily understand.
The platform proved its critical value during a recent real-world test: “We saw someone enter the admin domain group by stealing a certificate,” David recounted;
“Without XM Cyber, I would never have detected it. With XM Cyber, I traced the full scenario back to the source.”
David, Operational Security Lead, Clal Insurance
Key Takeaways
- Clal's security team used to spend a full day untangling a single incident. With Xm Cyber, it takes less than an hour, freeing the team to get ahead of problems instead of reacting to them.
- During one incident, an attacker used a stolen certificate to enter the admin domain group. XM Cyber caught the incident in real time, traced the path back to the source, and remediated it in real time.
- XM Cyber's support team is responsive and hands-on, which it crucial for a lean team like David's.
- XM Cyber found orphaned groups and inactive accounts in Clal's Active Directory and Azure environment that had gone unnoticed until then.
- XM Cyber’s clear reporting means security findings can now reach senior management without getting lost in translation along the way.
Stop Attackers Exploiting Identity Exposures
Preemptively neutralize exposures that lead to your business-critical assets.