PassportCard doubles SecOps productivity with Cortex XSIAM

SUMMARY

PassportCard’s journey is one of global growth. What began as a local Israeli medical insurance provider has developed into a leading international health and travel insurance company, with operations in 150 countries.

With global expansion, however, the scale and complexity of PassportCard’s operations increased significantly. Though an existing SIEM platform was providing a solid foundation, PassportCard recognised a more unified, AI-driven architecture would be needed to support its next phase of growth.

Now, Palo Alto Networks Cortex XSIAM – deployed in partnership with SySec – is enabling PassportCard to achieve proactive, AI-driven, and autonomous SecOps.

RESULTS

80%

of SecOps operations automated

90%

faster case remediation

100%

increase in productivity

3

security employees redeployed to strategic tasks
CHALLENGE

Securing global business growth

PassportCard provides insurance coverage to millions of travellers abroad, expatriates relocating, digital nomads, and others seeking international health insurance. Collectively, the company handles hundreds of terabytes of sensitive personal and medical data – all of which needs to be protected against fraud, data leakage, and other threats.

A long-term Cortex XDR customer, PassportCard was looking to modernise its SecOps to ensure cybersecurity could keep pace with its ambitious business growth. The organisation needed to address the following challenges:

  • Managing expanding attack surface: Increasingly sophisticated threats were accelerating across a spectrum of sources – cloud and on-premises, multinational operations, users, and devices.
  • Coordinating SecOps tools and data: Complexity was creating inefficient workflows, potentially leading to oversight of threats. Also, lack of integration was delaying threat detection and response.
  • Decreased uptime: Performance issues decreased kiosk uptime, creating data and accounting problems.

“Our SOC was operating in an increasingly complex environment, with more threats, more data sources, and more devices than ever before. We needed to build a new architecture based on automated data integration, analysis, and triage.”

— Yoni Maman

VP, Cyber Security and IT Infrastructures, PassportCard

SOLUTION

AI magnifies the SecOps advantage

Partnering with its long-term consultant SySec, PassportCard deployed Palo Alto Networks Cortex XSIAM to support its global operations. This converged platform reduces SOC complexity by integrating disparate systems into an agile, unified view of the business.

“Cortex XSIAM transforms the way PassportCard handles cases,” says Shay Toashi, CEO of SySec. “We manage the case response and escalations on behalf of PassportCard, and I’ve never come across a SecOps platform as agile, flexible, and intuitive as XSIAM. The AI technology magnifies the advantage.”

  • Underpins world-class insurance operations

    By stopping threats at scale, Cortex XSIAM is supporting the company’s growing, uninterrupted insurance operations.

    Across The Middle East, Europe, Australia, and beyond, PassportCard can confidently deliver reliable and rewarding insurance coverage to millions of customers.

    “The AI technology in Cortex XSIAM has transformed our SOC operations and reimagined our security posture. We’re proactively detecting threats in real time – so our customers continue to receive a consistently great service,” says Yoni Maman, VP, Cyber Security and IT Infrastructures, PassportCard.

  • Simplifies and accelerates SecOps

    Simplifies and accelerates SecOpsCortex XSIAM centralises PassportCard’s data and SOC capabilities to streamline security operations. This allows for the seamless inclusion of perimeter firewalls and third-party portals that were previously impossible to unify.

    This total visibility has transformed detection. With enhanced visibility and correlation capabilities, the team now identifies and prioritises relevant threats more effectively than ever before, ensuring nothing is missed. This has enabled the security team to accelerate mean time to detect (MTTD) by 70%.

    “Our mean time to remediation has taken a quantum leap forward. We’re talking from days to minutes. Routine cases are recognised, handled, and closed automatically,” says Yoni.

  • Delivers agile and efficient SecOps

    Delivers agile and efficient SecOpsThe numbers speak for themselves: 80% of security issues are now automated. PassportCard has doubled SecOps productivity, with processes executed twice as fast as before. Eliminating manual security tasks has freed three specialists to focus on strategic, value-added work that strengthens PassportCard’s long-term security posture.

    Yoni adds, “The prebuilt playbooks offer us a huge advantage. When an issue occurs, it is automatically channelled through to an automated response or escalated for further investigation.”

  • Drives trusted, collaborative success

    As a PassportCard partner for nearly a decade, SySec provides essential SOC response and escalation services. The team’s proactive, expert support has been instrumental in PassportCard’s growth, defining a highly successful long-term collaboration.

    “SySec is always bringing new ideas to the table, pointing out small vulnerabilities in our security, or recommending new solutions. We can call any member of the team, at any time, and always receive a professional response,” says Yoni.

    Looking ahead, PassportCard is considering the use of Prisma Access to enable more powerful secure connectivity across its endpoints worldwide. The natively integrated capabilities of this platformization strategy will further extend the impact of AI and automation on PassportCard’s operations. “You can never get enough of Palo Alto Networks,” says Yoni.

Advanced capabilities lead to improved security posture