Domino's is one of the leading pizza brands in the UK, delivering over 100 million freshly baked pizzas each year from over 1,200 stores nationwide. However, innovation for the company isn't just about pushing the boundaries of pizza making (please see theDouble Decadence as a prime example), but is also about using modern digital technologies to improve customer experience.
We at diginomica have writtenfrequently about the company's digital investments, which have delivered strong returns for the organization in recent years. And last week we got the chance to hear from Marius Poskus, IT Security Operations Analyst at Domino's, about how the company is using automation in the cloud to shift towards a proactive approach to threat management.
Poskus was speaking at theAvantra Summit, where he said that whilst moving to the cloud can deliver significant benefits, buyers also need to recognize the associated risks - particularly as it relates to operations management and security. Poskus said:
What I find with companies that have decided to lift and shift into the cloud, is there's a misunderstanding of responsibility. Companies use IaaS, PaaS or SaaS, but you need to remember that when you lift and shift to the cloud, if you use virtual machines for example, the cloud provider is only responsible for the bare metal.
You still need to patch your operating systems, you need to be configuring your virtual networks, applications and all the data. I think sometimes companies misunderstand where their responsibilities lie and have problems. There is a real challenge there but that challenge can be solved in a way, with automation.
Poskus said that cloud allows companies to improve the speed and ease of their deployments, and means easier scalability and virtually unlimited capacity. However, organizations need to be mindful of shifting to operational costs and a change in control structures. He added:
Depending on which responsibility model you choose, there's a certain loss of control. Depending how and what you use, there's cost variation, so it can be hard to predict how much you're going to spend over the next year. There's also potentially a lack of support - you're not always going to get your questions answered very quickly. There's also a reliance on the internet and potential security threats.
The overarching theme from Poskus's presentation is that Domino's is using automation to target low hanging fruit, in terms of its security incident and response approach. Poskus provided numerous examples of how Domino's is automating as much as possible so that the company's Cyber Security Operations can invest time in tackling more complex issues.
For instance, Domino's is using automation to identify malware across its virtual machines - but is also changing its response depending on the time of day a threat is identified. Poskus explained:
We run a hybrid automation model at Domino's. We automate a very simple response to incidence, but we scale our automated response depending on the times as well. So, for example, some of the events we can automate 24/7, but some we only want to automate overnight.
We want to automatically collect packages from the machines where malware has been found, for example. But if it happens at midnight when we are not working, we might want to automatically isolate that machine, collect the logging package, and then when I come online at 9am, I know that the machine has been isolated and can't infect anyone else. And then I can investigate and see what has happened.
Poskus said that there is a lot of scope when it comes to automating to improve security in the cloud, and plenty of quick wins to be had. But added that it's important to remember that what works for one company, may not work for another - and so a lot of time needs to be invested in figuring out how your business operates and where the use of automation will be most impactful. He said:
Build up stories of how departments work together, where you can get quick wins from automation, where you don't need human interaction.
Domino's is using Microsoft Azure as its cloud platform of choice and Poskus pointed to its cloud policy feature as a way of further improving security automation. Cloud policy allows organizations to govern every existing or future resource deployed, managing policies in a centralized location, where compliance can be tracked and changes can be quickly identified. GCP and Azure have similar features too.
Poskus said:
When launching virtual machines, you can launch a policy that means scanning all virtual machines, say, every 24 hours, which then reports to me the machines that don't have a vulnerability management agent installed on them. It can report the machines that don't have the latest security patch on them. And we can remediate all of that.
It's an easy example of how we can monitor all of our infrastructure. If you've got hundreds or thousands of virtual machines it's impossible, or at least very painful, to find out what is missing. Also with some of the policies you can build in a quick fix, so you can fix it with one click of a button.
Domino's is also using automation playbooks to identify anomalies for threat detection. Playbooks allow for rules to be written for certain scenarios that enable automation technologies to identify potential threats. Poskus explained:
For example, we have alerts coming in for impossible travel. Sometimes people might be travelling or they might be using a VPN. Most of our people are based in the UK, but sometimes you can get a login from the UK and then from Thailand within 60 minutes. That creates an impossible travel alert.
So we created a playbook, which says that when an incident is created in Azure Sentinel that matches impossible travel, if the user has passed MFA successfully, please close the incident because we know that that's the person that logged in. If false, then please send us a report so we can investigate.
Poskus said that the key for Domino's in thinking through its approach to automation, is that it wants its security analysts to be working on threats that need human attention - rather than wasting time on tasks that could be carried out by machines. This will mean a more thoughtful, proactive approach to security response. He added:
Automating means better decision making, because you can automate some of the decisions. We can reduce the time of analysts actually working and investigating some low severity incidents, because we can automate them. It's damage limitation, as well. If your Security Operations Center does not have a team that can operate 24/7, you can use automation out of hours and prevent specific incidents from spreading. Once that human interaction is needed, you can pick it up on the next day.
I think what's happening with Cyber Security Operations, scaling up means moving from reactive defence to being proactive and chasing the bad guys. Instead of reacting to what happened yesterday, we try to predict and detect what might happen in the future.
See the rest here:
How Dominos UK is using automation in the cloud to improve security - Diginomica
- Automation Personnel Services - Temporary Staffing ... [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | Define Automation at Dictionary.com [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | Definition of automation by Merriam-Webster [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation | The Car Company Tycoon Game [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation - Wikipedia, the free encyclopedia [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Automation - Cloud process & workflow automation | Microsoft ... [Last Updated On: June 29th, 2016] [Originally Added On: June 29th, 2016]
- Riverside Automation - Machine Controls [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Automation: The Car Company Tycoon Game Windows - Mod DB [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- System Integration | Industrial Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- WinAutomation - Smart Macro Recorder, Web Automation ... [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Automation Solutions - Home [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- The Automation Conference [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Rohtek Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- JL Automation, LLC | Home Automation, A/V Automation [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Four fundamentals of workplace automation | McKinsey & Company [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- Leviton Security & Home Automation [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- EVA Automation [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- News | Automation | The Car Company Tycoon Game [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Automation - The Car Company Tycoon Game on Steam [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Test automation - Wikipedia, the free encyclopedia [Last Updated On: September 6th, 2016] [Originally Added On: September 6th, 2016]
- Job Seekers - Automation Personnel Services [Last Updated On: October 8th, 2016] [Originally Added On: October 8th, 2016]
- Custom Automation & Machine Design | Automation GT [Last Updated On: October 31st, 2016] [Originally Added On: October 31st, 2016]
- iAutomation [Last Updated On: October 31st, 2016] [Originally Added On: October 31st, 2016]
- Test automation - Wikipedia [Last Updated On: November 16th, 2016] [Originally Added On: November 16th, 2016]
- Automation - Official Site [Last Updated On: November 19th, 2016] [Originally Added On: November 19th, 2016]
- Beckhoff Automation - Wikipedia [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- Automation - Security Hyperstore [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- IT Automation - BMC [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- ID Automation [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- The Best Home Automation Systems of 2016 | Top Ten Reviews [Last Updated On: December 24th, 2016] [Originally Added On: December 24th, 2016]
- What is Home Automation? | Home Automation Systems [Last Updated On: December 24th, 2016] [Originally Added On: December 24th, 2016]
- Beyond Automation - hbr.org [Last Updated On: December 25th, 2016] [Originally Added On: December 25th, 2016]
- Build automation - Wikipedia [Last Updated On: December 26th, 2016] [Originally Added On: December 26th, 2016]
- Home automation - Wikipedia [Last Updated On: January 10th, 2017] [Originally Added On: January 10th, 2017]
- Automation | Food Engineering [Last Updated On: January 13th, 2017] [Originally Added On: January 13th, 2017]
- Home Automation - Enerwave Home Automation [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Automation - DESHAZO [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- Robots, Automation, EOAT, Grippers, Conveyors, Guarding [Last Updated On: January 26th, 2017] [Originally Added On: January 26th, 2017]
- Werner Electric | Automation [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automationtechies | Automation Engineering Recruiting [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automation - Mazak Corporation [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Automation | Technologies | Systems | Integrator ... [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Test Automation Services for Development of Regression ... [Last Updated On: January 28th, 2017] [Originally Added On: January 28th, 2017]
- Carlo Gavazzi Automation Components [Last Updated On: January 30th, 2017] [Originally Added On: January 30th, 2017]
- UI Automation Overview - msdn.microsoft.com [Last Updated On: February 5th, 2017] [Originally Added On: February 5th, 2017]
- New telecom transformation goals require service automation - TechTarget [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Global Hazardous Waste Handling Automation Market: By Products ... - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- 2M Automation wins IoT support from Schneider - Electronics EETimes (registration) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Futures Shaped by Automation and Catastrophe: Peter Frase on Capitalism's Endgame - Truth-Out [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Automation expected to displace insurance underwriters, real estate brokers - CIO Dive [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Automation, robots could replace 250000 public sector workers in the next 15 years - Computer Business Review [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Design Automation Conference - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- The Perks Of Automation And The Risks: Why To Think Twice About Getting Into That Driverless Uber - Forbes [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Lib Dems Should Embrace Automation of the Workforce - Liberal Democrat Voice [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Voices Reinventing enterprise finance by overhauling AP automation - Accounting Today [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How Accountants Can Use Automation Their Advantage - Accountingweb.com (blog) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- DFLabs Launches the First Security Automation and Orchestration Platform based Upon Supervised Active Intelligence - Business Wire (press release) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- QAD Automation Solutions is Honda Approved - Yahoo Finance [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- VIDEO: Going Big on Automation in a Small Footprint Facility - ENGINEERING.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Building a better model of human-automation interaction - Phys.Org [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- AlixPartners examines automation in manufacturing and logistics management - Logistics Management [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Report: Test automation is increasing - SD Times - SDTimes.com [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Automation is the unavoidable future of the economy - The Daily Cougar [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- GM's Cruise Automation Is Testing An App to Order Self-Driving ... - Fortune [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Speeders beware: Legislation would allow automation crackdown ... - SFGate [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Orbita Ingenieria: New Age Terminal Automation - Port Technology International [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- A Sharper Focus on the Edge - Automation World [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Rockwell Automation Surged 10% in January as Growth Picked Up Steam - Motley Fool [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Most people are optimistic about workplace automation, social data suggests - ZDNet [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Improving Behavior Through Automation of Vehicle Systems - School Transportation News (blog) [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- 'We employ insane levels of automation' Kris Canekeratne - Times of India [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Why Don't We See More Automation in Federal Networks? - Nextgov [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Technobabble: Automation and the modern worker - CIO Dive [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Readers Write (Feb. 12): The moose population; jobs, start-ups and automation; diversity in the funny pages - Minneapolis Star Tribune [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation Nightmare: Philosopher Warns We Are Creating a World Without Consciousness - Big Think [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation can replace bureaucrats and save taxpayers money - Hot Air [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Automation can revitalize the US workforce - Fox News [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- TigerStop hopes to ride automation to new heights - The Columbian [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Hexadite Unveils Custom Playbooks Following One Millionth Automated Cybersecurity Investigation - Yahoo Finance [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- NEC updates postal automation system for Hongkong Post - ETCIO.com [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]