Nuance Drives Down Business Disruption, Automating Incident

Nuance
HEXADITE CASE STUDY
Nuance Drives Down Business
Disruption, Automating Incident
Response with Hexadite AIRS
A market leader in changing the ways people interact
with technology innovates incident response to drive
efficiency.
An Innovative Approach to Cybersecurity
Nuance Communications is changing the way people interact with
technology by developing the most human, natural, and intuitive ways to
take command of information by leveraging optical character recognition
(OCR), speech and natural language understanding, and artificial intelligence.
The information security team at Nuance has taken a similarly innovative
approach to cybersecurity, seeing incident response as more than just a
process solved by hiring more people and buying more tools.
“The challenges of scaling security resources to meet the volume of alerts is
well understood by security practitioners,” said Doug Graham, Chief
Information Security Officer at Nuance. “It’s easy to end up in a cycle where
one buys more tools, gets more alerts and, despite working hard to correlate
those alerts, still finds the volume of resulting actions staggering. Companies
need to find ways to break this cycle or turn down the volume of alerts, as
there will never be enough staff bandwidth to properly process every alert.”
AT A GLANCE
CUSTOMER
Nuance Communications
EMPLOYEES
14,000
INDUSTRY
Software
CHALLENGE
Business Disruption
SOLUTION
Hexadite AIRS
RESULTS
Moved to automated
incident response, offloaded
triage and repetitive IR
duties from overtaxed staff.
Building Cybersecurity into the Organizational DNA
The team at Nuance sees the discipline of cybersecurity not only as a function of IT, but as a company-wide
priority.
“Information security needs to be everybody's job. It’s easy to say that, and many companies do say it, but
we have to build it into the DNA of the organization. The days are gone when it would be some specialist's
job to do security,” said Graham.
Intelligent Security Orchestration and Automation
HEXADITE CASE STUDY
Nuance
With over 14,000 employees worldwide, it’s important to be able to automatically and remotely investigate
and remediate threats on employee computers. Prior to automating a large proportion of these events, the IT
and security staff at Nuance focused scarce resources on investigating, diagnosing, cleaning, and often
reimaging computers resulting in higher costs and potential disruption to the affected employee.
“The environment today means that we're seeing more alerts from more sources, and we were spending a
lot of time, and cost on dispatching IT techs to deal with security incidents. This not only takes away from
the ability to drive value to the business, but it's an unattainable business model to scale.”
“Aside from the obvious functionality elements, whenever we evaluate security tools, we look for two
must-have items,” said Graham. “First, will the tool be a force multiplier for efficiency or will it simply give
someone else more work to do? Secondly, will the tool allow us to automate what is currently being done by
people? To consider purchasing anything, both requirements must be met.”
Automating Low-Level Security Tasks to Let People Focus on High-Value
Initiatives
After implementing Hexadite AIRS, Nuance dramatically reduced the need to reimage machines. Using the
security orchestration and automation capabilities, Nuance is able to investigate all alerts from its detection
systems automatically, remediating issues in minutes, worldwide and without business disruption.
“Automation is in our company's DNA, so it stands to reason that we should be doing that with security as
well,” said Graham. “Fast remediation in security is the key point to everything. The quicker we can
intervene, the quicker we can maintain our defensive perimeter and the quicker we can isolate the problem
and stop that lateral movement. It’s not only about efficiency and cost, it's about effectiveness. With Hexadite,
we're seeing effectively a 90-95% automation rate from these actionable alerts.”
Intelligent Security Orchestration and Automation
Nuance
HEXADITE CASE STUDY
Continued Value Added by Hexadite
“Without Hexadite, we'd simply be either adding more people to the problem, or doing less in other areas of
security, rather than scaling people out then losing them because they are buried in a sea of alerts,” said
Graham. “Now I don't have to burden them with that—I can give them more interesting work, and create a
happier work environment for everybody.”
“When we first saw the technology from Hexadite, it seemed too good to be true. We tried the
technology, and it all came true—it solved our problems and greatly reduced costs.
That’s what lead us to form a deeper and longer partnership with Hexadite.”
----Doug Graham
CHIEF INFORMATION SECURITY OFFICER, NUANCE COMMUNICATIONS
Intelligent Security Orchestration and Automation