One UTM Fits All for ING Hipotecaria
About ING Hipotecaria, BFSI
ING is a financial services company worldwide serving 85 million customers operates in over 50
countries and is one of the 20 largest companies in the world.
Currently ING Group is a leader in managing the assets of individuals and businesses through
its banking products and services, investments, life insurance and retirement services.
Their vision is to help the customers manage their financial future and be the best company in
Mexico of savings products for retirement and for specific purposes in the short, medium and
long term for their clients, and to do work every day to offer the existing and potential clients
financial products and services according to their needs, a service of the highest quality and
professional advice to facilitate the administration of estate.
“The bank contains client sensitive
information and data that can be
targeted by attacks from external
entities and outside access
Mr. Victor Valenzuela
Mr. Victor Valenzuela, the IT Manager for ING Hipotecaria was looking for a reliable Internet
security platform to protect the bank and its users. Says Mr. Valenzuela, “We did not want to
take any chances with our security requirements. We were in search for a solution which adds
value by bundling features that most rival vendors sell separately. Also we needed a solution
which would give us highest ROI while addressing our major security concerns - all in a single
pack up.” The concerns are listed below.
Basic Perimeter Protection
The bank was looking for a gateway firewall to make your network invisible from online attackers
and some malicious software such as viruses, worms, and Trojan horses. The bank contains the
contract document and other client sensitive information and data that can be possibly targeted
by attacks from external entities and outside access attempts. The organization, therefore,
needed a gateway firewall to regulate user authentication and access control.
Protection against Virus & Malware
The bank was looking for a gateway anti-virus solution to prevent both web- and email-borne
malware from entering the network. For ING Hipotecaria, a regular virus attack in the network,
particularly in a mixed form, would translate into a lot of unwelcomed problems - corrupt files,
defaced web pages, PDF, and huge downtime. For this, they wanted their anti-virus solution to
scan viruses for HTTP and FTP over HTTP/HTTPS traffic on the web.
Monitoring Website Access
The bank wanted to block unwanted sites while enforcing productive surfing among employees
and to prevent phishing and pharming.
They wanted a suitable content filtering solution with reporting feature for showing graphs and
traffic results on specific sites accessed by staff when they switch computers.
Continuous Network Uptime
Data is an important aspect of their banking business and from this perspective; the business
goal is to have continuous business connectivity. Continuous Internet connectivity with no
breakdown or downtime was the most important requirement for ING Hipotecaria. Also, the bank
was looking for a solution which could bridge the geographical distance between the head office
and the branches so that users could securely connect from any location and use the bank‘s
The Cyberoam Solution
ING Hipotecaria looked into a number of security products including Fortinet, Cisco ASA and
Watchguard in order to address their business challenges. During the demo of Watchguard they
found that it had a difficult set up and administration. The search was on for a new appliance
which would have a large number of features at the same price. The bank then took the decision
of deploying Two (2) 300i and One (1) 200i Cyberoam appliance at head office in Gateway Mode
The following Business Benefits were observed:
- User Integration
Cyberoam UTM adds up with a unique identity-based security solution which protects against
insider threats by giving absolute visibility into “Who is doing What” in the network and allows
creation of user identity-based policies. Mr. Valenzuela used Cyberoam‘s Active Directory (AD)
facility to achieve the task of integrating ING‘s users in the network through a wizard to trade in
users. This ensures only bank employees are allowed network access, and outsiders kept at bay.
- Firewall Protection
ICSA and Checkmark - dual certified Cyberoam‘s stateful inspection firewall now cordons off ING
Hipotecaria‘s network against any unauthorized access. ING‘s users are given controlled access
to network and internet resources, ensuring that no security loopholes are left open.
- Up-to-date Protection from Viruses
Cyberoam‘s Gateway Anti-virus feature defends the bank‘s network from newer malware variants
- worms, rootkits, Trojans and many more due to ability to update in real time against such
attacks. In addition, Cyberoam‘s Virus Outbreak Detection (VOD) feature protects the bank
against any mail-based virus, adware, phishing attacks.
- Surfing Control
Cyberoam UTM‘s web content filtering feature controls Internet access in the Bank by blocking
inappropriate and unsafe Web content, including phishing and other malware-laden sites. This is
done through a constantly updated database of millions of sites divided into 82+ categories
including pornography, P2P, entertainment and job search. Moreover, Cyberoam‘s identity-based
filtering allows sets individual user Internet access policy, surfing quota, time limits and bandwidth
- Continuous Data Availability & Uninterrupted Business Connectivity
Cyberoam‘s SSL VPN solution bridged the geographical distances between the bank‘s branch and
head offices. This now ensures that the user can connect securely from any location and use the
Also, Cyberoam ensures transparent VPN failover for branches in order to provide uninterrupted
connectivity for branch users. When an Internet connection fails, this feature dynamically switches
traffic over to the active connection, maintaining uninterrupted VPN service.
- Useful Reporting
Cyberoam‘s reporting feature gives overview of what the users are up to in the network, including
blocked sites visited, time spent on each site. According to Mr. Valenzuela, “This has led to
increased productivity as the staff knows that they are being monitored or restricted from
accessing blocked sites.”
- To Wrap it Up
“The main thing that impressed me about Cyberoam UTM was that it precisely met all our
business requirements as a result of which, our productivity related to banking operations has
gone up.”, said Mr. Valenzuela.