Critical services, powerful protection: The City of Whittier modernizes cybersecurity

SUMMARY

Serving over 100,000 residents, the City of Whittier, California, is a dynamic municipal government that delivers essential services. Before partnering with Palo Alto Networks®, the city's lean IT team struggled with a sophisticated threat landscape, facing mounting cybersecurity challenges that put critical infrastructure and data at risk.

RESULTS

100%

visibility into enterprise devices, including IoT, up from zero

5 minute

MTTD with Unit 42 MDR

9 hours/week

saved in manual labor
CHALLENGES

Whittier’s IT department grappled with a series of interconnected challenges that threatened security and operational continuity.

  • Understaffing led to delayed response capability: The small team struggled to establish solid defenses against threats and respond quickly to issues, incurring risk to the city’s infrastructure and data.
  • Fragmented tools: Too many disconnected security products created a heavy administrative burden and reduced overall visibility.
  • Lack of insight into device landscape: The city had virtually no visibility into its burgeoning IoT network, leaving significant blind spots that could be exploited.
  • Dire potential impacts to critical services: If public systems were compromised, life-sustaining services could be interrupted, including emergency responses.

"When you’re looking for a platform vendor, Palo Alto Networks has the reputation for being at the top of the industry. And in our experience, it has lived up to that reputation."

Bob Ambroso

IT Manager, City of Whittier

SOLUTIONS

The full breadth of advanced coverage.

Whittier sought a solution that would not only provide robust security but also consolidate its fragmented security infrastructure. The city’s previous positive experience with Palo Alto Networks, coupled with the desire to work with a single vendor, led it to expand the relationship. The comprehensive platform approach—offering a deep bench of best-in-breed products under a consistent management UI—was a decisive factor, and the deployment process was completed in six months.

  • Illuminating the network with unified firewall management

    In an earlier engagement, Whittier had adopted Palo Alto Networks Next-Generation Firewalls with Panorama®—a game-changing move that enabled its IT team to manage multiple firewalls from a single interface and push out policies uniformly.

    Building on that infrastructure, the city is leveraging Palo Alto Networks’ deep packet inspection and application awareness capabilities to gain comprehensive network insight. The firewalls examine the full content of network packets—not just headers—providing visibility into application traffic, user behavior, and data flows. Beyond security benefits, this visibility enables capacity planning, with upgrades informed by bandwidth usage data. Now, Whittier is implementing Strata Cloud Manager to enhance its security posture even further with automated vulnerability identification and best-practice evaluation.

  • Bringing the unseen to light with device visibility

    Bringing the unseen to light with device visibilityOne of the most impactful initiatives for the City of Whittier was the implementation of Palo Alto Networks Enterprise Device Security. Initially operating with 0% visibility into its device landscape, the city now has 100% visibility. “I can’t overstate the value in knowing which devices are vulnerable—and why,” states Bob Ambroso, IT Manager. The insights allow his team to quickly identify and remediate vulnerabilities, including outdated firmware on cameras and open ports on library computers. The system also instantly notifies the city of new, potentially unauthorized devices—like personal routers plugged in by the police department—enabling real-time threat intelligence and rapid remediation. For deployment, Whittier enlisted the support of Professional Services to get the job done “quickly and correctly the first time,” Ambroso reports—“not to mention the invaluable transfer of knowledge during the process.”

  • Empowering the lean team with 24/7 threat detection and response

    Cortex XDR, backed by Unit 42 MDR, has reduced both the operational burden and the time it takes for the Whittier team to detect and respond to threats. By managing day-to-day issues, Unit 42 allows the city’s staff to focus solely on threats that meet their critical threshold. The result has been a reduction in mean time to detect (MTTD) to approximately five minutes and a significant efficiency boost—giving the team back nine hours a week to dedicate to strategic initiatives. Additionally, “Cortex XDR can get granular really quickly so I see finer details and visibility into my endpoints compared to our previous vendor, CrowdStrike,” Ambroso notes. “The policy development ability in Cortex is also way more comprehensive.” Furthermore, Unit 42 MDR provides invaluable proactive threat hunting and threat intelligence, including two to three weekly reports on current threats, educating the team on indicators of compromise and vulnerability entry points.

  • Building resilience with elite incident response expertise

    Building resilience with elite incident response expertiseThe city’s investment in a Unit 42 Retainer has provided not only incident response support on demand but significant strategic value. “Luckily, we haven’t needed the retainer for an incident,” explains Ambroso, “but the dollars didn’t go to waste.” Whittier redirected its credits toward proactive improvements like IR planning and policy development, an area where the team consistently struggled to find time. Unit 42’s expertise also proved invaluable during the Enterprise Device Security implementation, with specialists helping Whittier understand issues, fine-tune configurations, and determine appropriate response priorities. By the end of the first year, Whittier had comprehensive and validated incident response policies and a business email compromise plan—critical security frameworks that previously didn’t exist. The proactive approach dramatically improved the city’s incident preparedness rating, increasing it from a 4 to an 8 on a 1–10 scale.

Continuous innovation through an authentic partnership.

As it continues to advance its security posture—and as new security challenges emerge—Whittier is strengthening its partnership with Palo Alto Networks. The city is actively evaluating Prisma® Access Browser to enhance web application security and remote access capabilities. And as AI adoption accelerates across municipal operations, Whittier recognizes the need to stay ahead of the vulnerabilities it creates. The ongoing partnership ensures that Whittier’s lean IT team can continue focusing on core municipal services while maintaining cutting-edge security defenses. “Things are evolving so quickly, and we can leverage Palo Alto Networks to stay in front of all that for us,” reflects Ambroso.

"I sleep better at night knowing Palo Alto Networks is watching the place and ready to alert us if anything requires immediate attention."

Bob Ambroso

IT Manager, City of Whittier

Get started with platformization.

We're here to help you simplify your security approach.