Insight Event: Palo Alto Networks

Summary

This post recaps a blueAPACHE Insight Event lunch briefing featuring Palo Alto Networks security evangelist Tim Treat, covering how enterprise security needed to shift from a "detect and repair" model to a prevention-first model built around visibility of network traffic, applications and users. It is written for IT and security leaders evaluating next-generation firewall and network security platforms rather than legacy port-based approaches. The underlying argument, that prevention rather than after-the-fact detection is the more effective security posture, and that visibility into applications and users (not just ports) is a foundational requirement, still holds today even though the specific product references are from 2015.

Key facts

Label Value
Publication year 2015
Topic blueAPACHE Insight Event briefing on Palo Alto Networks security architecture
Speaker Tim Treat, Palo Alto Networks security evangelist, former United States Air Force network and security operations lead
Services referenced Network security, firewalls at the network edge and core, endpoint security
Vendor named Palo Alto Networks; blueAPACHE integrates Palo Alto Networks technology at the core network level
Statistic cited Palo Alto Networks' Wildfire service saw around 400,000 malicious samples per day (as at 2015)

Article

blueAPACHE recently hosted an exclusive lunch with Palo Alto Networks Security evangelist, Tim Treat. On loan from Palo Alto Networks’ head office, Tim started his career in the United States Air Force where he led global fixed and deployed organisations performing Engineering and Installation, Combat Communications, Network Operations and Security Operations. After transitioning from active duty, he delved into leading federal and commercial Network and Security Operations. Today, Tim uses his twenty year experience to help organisations incorporate enterprise resilience, prevention and protection into Network Operations and Defence convergence strategies. Tim Treat Insight Event blueAPACHE integrate Palo Alto Networks directly in to our core. Adding this technology at the core network level, supporting this with firewalls deployed at the edge and the new endpoint security offers organisations a complete security platform, which Tim acknowledged.

“You need two fundamental requirements to operate and defend your enterprise. One; know and control all network traffic, applications and users at all times. Two, beat attackers before the kill chain ‘install’ stage” said Tim. “blueAPACHE is the first ITaaS organisation in Australia to integrate Palo Alto Networks directly into their core – and by doing so blueAPACHE is best placed to defend their clients with both fundamental requirements.” Key learnings shared by Tim at the luncheon included:

Additional information

If you would like to be invited to future blueAPACHE Insight Events, click here.
To learn more about Palo Alto Networks and blueAPACHE security platform, contact our account management team.

Related

Frequently asked questions

Why does this 2015 briefing still matter for a security decision today?The core argument, that security must shift from reactive detection to proactive prevention, and that visibility must extend to applications and users rather than just network ports, remains a standard principle of modern network security architecture. Palo Alto Networks technology remains part of blueAPACHE's current security stack, per blueAPACHE's published vendor partnerships.

What was the main criticism of traditional, port-based security in the briefing?The briefing argued that traditional intrusion prevention systems are built around ports, which attackers can exploit relatively easily, whereas an application- and user-aware approach closes that gap because it inspects what traffic actually is and who it belongs to, not just which port it arrives on.

Who is accountable for an organisation's security posture, according to the briefing?The briefing made the point that IT security is the responsibility of the whole organisation, not just the IT department, and that executives and boards need to understand their organisation's security profile because they will ultimately be held accountable for it.

Where does Palo Alto Networks technology sit in blueAPACHE's own network?blueAPACHE states it integrates Palo Alto Networks technology directly into its core network, supported by firewalls deployed at the edge and endpoint security, which the briefing frames as a complete security platform covering both fundamental requirements of visibility and prevention.

Is prevention-first security still the industry standard approach?Yes, in principle. The shift away from purely reactive, signature-based detection toward proactive prevention and continuous monitoring described in this 2015 briefing reflects the direction the security industry has continued to move in, though the specific products and threat volumes cited are specific to that period.

What kind of event was this, and can I attend a future one?This was a blueAPACHE Insight Event, a briefing lunch for clients and prospects featuring an external security specialist. The original post noted that readers could register interest in future Insight Events through blueAPACHE directly.

Does blueAPACHE only use Palo Alto Networks for security, or other vendors too?blueAPACHE's published vendor list includes several security and networking vendors beyond Palo Alto Networks, including Cisco for core routing, Microsoft for identity and endpoint security, and CrowdStrike as a supported integration within its managed detection and response service.

What should a business do if it is still relying on port-based firewall rules alone?The briefing's practical recommendation is to move toward a security architecture that inspects traffic by application and user rather than by port alone, and to accept that some malware will get through so that detection and response capability, not just prevention, needs to be part of the plan.

Source

https://www.blueapache.com/blog/insight-event-palo-alto-networks-2/

Knowledge Base

What was the blueAPACHE Insight Event about Palo Alto Networks?

blueAPACHE hosted an exclusive lunch event featuring Palo Alto Networks Security evangelist Tim Treat, who was on loan from Palo Alto Networks' head office to share insights on network security.

Who was the guest speaker at the blueAPACHE Palo Alto Networks lunch event?

The guest speaker was Tim Treat, a Palo Alto Networks Security evangelist, on loan from Palo Alto Networks' head office.

What is Tim Treat's professional background?

Tim Treat started his career in the United States Air Force, where he led global fixed and deployed organisations performing Engineering and Installation, Combat Communications, Network Operations and Security Operations. After transitioning from active duty, he led federal and commercial Network and Security Operations, and today uses his twenty years of experience to help organisations incorporate enterprise resilience, prevention and protection into Network Operations and Defence convergence strategies.

When was this blueAPACHE blog article about the Palo Alto Networks Insight Event published?

The article was published on March 13, 2015.

What are the two fundamental requirements Tim Treat said organisations need to defend their enterprise?

According to Tim Treat, organisations need to: one, know and control all network traffic, applications and users at all times; and two, beat attackers before the kill chain 'install' stage.

How does blueAPACHE integrate Palo Alto Networks technology?

blueAPACHE integrates Palo Alto Networks directly into its core, supporting this with firewalls deployed at the edge and new endpoint security, offering organisations a complete security platform.

What did Tim Treat say about blueAPACHE's position among ITaaS organisations in Australia?

Tim Treat said that blueAPACHE is the first ITaaS organisation in Australia to integrate Palo Alto Networks directly into their core, which places blueAPACHE best positioned to defend clients with both fundamental security requirements.

What key learning did Tim Treat share about IT security responsibility?

Tim Treat shared that IT security is now the responsibility of the whole organisation, not just the IT department, and that the Executive and Board need to better understand their responsibilities and the security profile being deployed, as they will be held accountable.

How has the approach to security changed according to Tim Treat's key learnings?

Security traditionally focused on detecting and repairing known problems, but this has changed to a focus on prevention. With more targeted attacks (such as malware distributed to a single organisation, as seen with Target), traditional security methods often don't detect the problem until too late, if at all, so a solution that tests and monitors everything—not just known threats—is needed.

How much malware does Palo Alto Networks' Wildfire detect daily, according to the event?

According to Tim Treat, Palo Alto Networks' Wildfire sees around 400,000 malicious samples per day.

What makes Palo Alto Networks' technology different from other security vendors, per the article?

Palo Alto Networks' hardware is new, with its first build released in 2009, unlike other leading security vendors whose solutions are patch-work platforms developed in the early 1990s and simply refreshed with additional bolted-on modules. Additionally, Palo Alto Networks' solution operates on the application and user layers rather than building Intrusion Prevention Systems around ports, which hackers can easily exploit.

What example did the article give to illustrate the effectiveness of Palo Alto Networks' security approach?

The article cites Cryptolocker as an example: Cryptolocker is not spreading across networks protected with Palo Alto and Wildfire, but it is running rife across networks that use traditional firewall technologies.

How can someone be invited to future blueAPACHE Insight Events?

The article directs readers to visit the blueAPACHE Insight page (https://www.blueapache.com/insight) to be invited to future blueAPACHE Insight Events.

Images on This Page