Securing the Utility of the Future
The Entergy vision is simple but strong – We Power Life. Their industry leading efforts of keeping the lights on for their 2.9 million customers and improving the quality of life in their communities are second to none. Entergy is recognized as the only utility in the nation to have won an Edison Electric Institute Emergency response award every year since its inception. It has also been named to the Dow Jones Sustainability North America or World index for a remarkable sixteen consecutive years.
Overview
Despite its success, Entergy isn’t comfortable with the status quo. It wants to define the utility of the future. This vision of the “Utility Reimagined” required a challenge to conventional thinking and a new approach – a digital transformation. To do this, Entergy needed technology partners to help it achieve more agility and insight from its data. It wanted to move away from system silos and manual processes that consume working hours and increase risk, and deploy new technologies that intelligently converge, analyze and present data for better decision making and reduce operational cost. Headquartered in New Orleans, Louisiana, Entergy Corporation delivers electricity to 2.9 million utility customers in AR, LA, MS & TX. It operates power plants with 30,000 MW of electricity generation (including 9,000 MW of nuclear power).
Solution
- Streamline and standardize work processes to reduce cost and improve efficiencies
- Reduce human error rate affecting performance
- Integrate 1000+ disparate applications and systems
- One place for access management across the enterprise for IT/OT/physical security
- Maintain regulatory compliance including CIP/Non-CIP
- Reduce risk by eliminating orphan IDs
Objectives
- 20,000+ (Employees/Contractors)
- Guardian Suite
- Big Data Engine
- Mobile Platform
- IT/OT/Physical Connector Framework
- Policy Engine
- Access Reviews and Certification Module
The Process
After multiple internal audit findings for improper user access, it was clear that effective regulatory compliance would require a comprehensive strategy for centralized Identity and Access Management (IAM). Existing unstructured IAM business processes had become a burden for application owners—certification of user accounts typically took months to conclude. At the same time, on-going stringent NERC CIP compliance regulations around access management kept the security department on their toes. The legacy IAM solution failed to fully realize the vision.
Plugging Into the Power of Security as a Business Enabler
Led by their CIO office, Entergy began their digital transformation and security convergence with the vision of being a data-driven organization. A key part the company’s change was an overhaul to their safety and security landscape including enhancing identity and access management for its 20,000+ employees and contractors. Entergy implemented an end- to end AlertEnterprise security convergence solution for its first phase, featuring complete automated hire to retire and access management, delivering enterprise-wide security, governance, compliance, policy enforcement, automation and workforce management with a straightforward and engaging user experience. As a secondary step, Entergy will further tighten the integration and embedded controls by deploying direct connectivity between AlertEnterprise software, SAP® SuccessFactors® HCM Suite and SAP Concur® travel management services. Entergy will also deploy a powerful integration between FireEye Security Suite and AlertEnterprise software to deliver holistic and intelligent situational awareness.
Self-Service
- One stop shop to request access to job roles, applications, and physical access.
- 100% visibility of access requests status, approvals, training, background checks, and built-in workflow SLA and escalations.
- Password resets eliminated the top help desk call issue and enforced company standards – mobile and PC.
- Faster and more reliable access request turnaround as all IT/OT/Physical Systems were integrated and automated at a much lower support cost.
- Intuitive naming conventions, display and reporting made it easier to understand and assess information.
Access Governance & Compliance
- Automated access reviews eliminated high-risk access creep with scheduled access review event alerts.
- Active policy enforcement was built-in including expiring background, training and certification checks, with automatic access shutoff on expiry.
- Frictionless traveler access with SAP Concur® Integration will automate rule based grants of building access for travelers including automatic access removal at the end of a trip.
Insider threat detection is a demo away.
Let’s up your security response and power your digital transformation with machine learning. No coding required.