To ensure Granite Edvance can continue to achieve their mission-critical goals of helping local families obtain the financial support they need for higher education, all devices and assets connected to the network need to be secure and protected. So when their existing tools, both Lansweeper and Tenable’s Nessus product, were proving to be more difficult, limiting, and time consuming to use and manage than they were worth, Granite Edvance began the search for an improved, alternative solution.
Download PDFGranite Edvance is a non-profit agency committed to helping New Hampshire families plan and pay for higher education for nearly 60 years. It is Chris Nadeau, VP of Information Security, and his team’s responsibility to oversee that all devices and assets connected to the network, from HVAC and OT devices to anything with an IP address, are secure and protected. Their existing tools, Lansweeper and Tenable’s Nessus, proved to be difficult, limiting, and time consuming. So, they began the search for an improved, alternative solution.
While they considered a few other options, they first leveraged runZero’s free 21-day trial to determine if it was the best solution for them. Once they saw runZero’s vast discovery capabilities, leveraging its proprietary, unauthenticated scanner to efficiently extract asset details and accurately fingerprint operating systems, services, and hardware, Nadeau and his team were hooked. Now with a full and accurate inventory of all the assets and devices they have on their networks, Nadeau and his team are able to perform comprehensive cyber risk management and mitigation for a more proactive approach to their security program.
First and foremost, Nadeau and his team are no longer slowed down by time consuming vulnerability scanners to scan their network and provide the asset data they need. runZero’s fast scan times paired with its ease of use have saved Nadeau and his team valuable time to dedicate to more mission critical needs.
With runZero, we can go out and find everything on the network, including open ports, something we couldn’t do with Nessus. It helped us identify when our HVAC company had a bunch of things connected to our network that no one knew about. We ran runZero and were able to see that these things were on the wrong subnet and shouldn’t be tied into our direct network. That has really helped us.” - Chris Nadeau, VP of Information Security, Granite Edvance
Granite Edvance is a non-profit agency committed to helping New Hampshire families plan and pay for higher education for nearly 60 years. They aspire to be recognized as a capable, trusted, and innovative leader in educational loan services that enhance the promotion, advancement, and support of higher education for the state of New Hampshire by providing K-12 and postsecondary students and schools with expertise in the student loan industry.
To ensure that Granite Edvance can continue to achieve their mission-critical goals of helping local families obtain the financial support they need for higher education, Chris Nadeau, VP of Information Security, takes his role very seriously. Along with his small but mighty team of three, it is their responsibility to oversee that all devices and assets connected to the network, from HVAC and OT devices to anything with an IP address, are secure and protected. So when their existing tools, both Lansweeper and Tenable’s Nessus product, were proving to be more difficult, limiting, and time consuming to use and manage than they were worth, they began the search for an improved, alternative solution. “The IT team used Lansweeper to find all the basic IT assets like printers and phones. But it was an old school legacy solution that was very insecure, took a lot of care and feeding to maintain, and required an on-premise server (no SaaS solution). It was spraying the network with domain admin credentials to find everything and we had pentesters come in and they were able to leverage those to attack things. We had just had enough of the product,” explained Nadeau. He went on to add, “On the security side, Tenable’s Nessus has a learning curve to it. I have had issues with the scans impacting database backups, system performance issues with high availability systems, and impacts to other sensitive systems from my previous life in manufacturing where poorly timed and improperly tuned scans had impacted manufacturing equipment processes including SCADA and ICS systems. The problem with using Nessus to do network discovery is that you may not know what you are scanning until the initial scans are run to discover assets, which could impact an unknown number of systems in a negative way. With runZero, I found that I didn’t need to take time to be trained on how to set up scans. I did not need to go through the settings to fine tune everything. It took us 20 minutes to figure out how to use the platform and get it up and running by entering a couple subnet ranges to start scanning. As I expanded the scanning, I found it had no impact on any of our infrastructure and I now have standard subnet ranges scans running on an hourly basis against various subnet ranges. runZero has provided a lot of confidence for us.”
While they considered a few other options, they first leveraged runZero’s free 21-day trial to determine if it was the best solution for them. “What always helps me in my decision making is when a product has a free trial that I can run at home. On the business side, that goes a long way for me, to unleash it on my home network where I can toy with it,” explained Nadeau. Once they saw runZero’s vast discovery capabilities, leveraging its proprietary, unauthenticated scanner to efficiently extract asset details and accurately fingerprint operating systems, services, and hardware, Nadeau and his team were hooked. “With runZero, we can go out and find everything on the network, including open ports, something we couldn’t do with Nessus. It helped us identify when our HVAC company had a bunch of things connected to our network that no one knew about. We ran runZero and were able to see that these things were on the wrong subnet and shouldn’t be tied into our direct network. That has really helped us,” said Nadeau.
Now with a full and accurate inventory of all the assets and devices they have on their networks, Nadeau and his team are able to perform comprehensive cyber risk management and mitigation for a more proactive approach to their security program. “We’re using runZero to go through and classify all of our systems so that we’re doing risk ranking based on what type of data they are and what kind of services they provide,” Nadeau said. runZero also helps Granite Edvance with cyber asset hygiene by way of discovering new devices on the network and determining if they meet their strict security requirements. “runZero is great for new device discovery. If someone adds a new device to the network and it doesn’t have the proper security controls, we have set up alerts to notify us of that,” explained Nadeau.
“The overall experience has been fantastic. It has really provided a lot of insight into our environment, insight we didn’t know we needed. We thought we had great coverage and thought we knew what was on our network until we ran runZero. It helped us identify some significant gaps that we took care of. It’s all been eye-opening.”
Granite Edvance has utilized one of the EDR API integrations runZero has to sync and further enrich their cyber asset inventory in runZero. This has enabled them to discover gaps in their EDR coverage and zero in on endpoints missing endpoint protection to further strengthen their security. “We have runZero linked with our EDR provider. If runZero sees a system and our EDR provider does not, we set it up so that we will get an alert that says, ‘Hey! Our EDR provider is probably not installed on this system,’ and that indicates to us that we need to go check that out,” said Nadeau.
Nadeau and his team are no longer slowed down by time-consuming vulnerability scanners to scan their network and provide the asset data they need. “The difference with runZero is that once we figured out our ranges, we lined them up, and we started getting all the data in. It was instantaneous,” explained Nadeau. runZero’s fast scan times paired with its comprehensibility have saved Nadeau and his team valuable time to dedicate to more mission critical needs. “Because of runZero’s ease of use, I don’t need to have an engineer on it. I can have a help desk employee easily get in there. If they have a question, it’s easy to find the solution or figure it out,” detailed Nadeau.
When asked to sum up his experience, Nadeau explained, “The overall experience has been fantastic. It has really provided a lot of insight into our environment, insight we didn’t know we needed. We thought we had great coverage and thought we knew what was on our network until we ran runZero. It helped us identify some significant gaps that we took care of. It’s all been eye-opening.”
Utilize runZero for cyber asset discovery, inventory, and hygiene for a more proactive approach to your security program.
Start a free trial