Catalent

Catalent Revises Their Security Approach, Implementing Core Changes

The Customer

Catalent is a global leader in enabling pharma, biotech, and consumer health partners to optimize product development, launch, and full life-cycle supply for patients around the world. With broad and deep scale and expertise in development sciences, delivery technologies, and multi-modality manufacturing, Catalent is a preferred industry partner for personalized medicines, consumer health brand extensions, and blockbuster drugs. Catalent helps accelerate over 1,000 partner programs and launch over 150 new products every year. Its flexible manufacturing platforms at over 50 global sites supply around 80 billion doses of nearly 8,000 products to over 1,000 customers annually. Catalent’s expert workforce of approximately 18,000 includes more than 3,000 scientists and technicians. Headquartered in Somerset, New Jersey, the company generated nearly $5 billion in revenue in its 2022 fiscal year.

The Challenge

Gaps and Noise

When Jody Jenkins, Head of Cybersecurity Operations, EUC, & IAM began working at Catalent, he uncovered areas of improvement in security operations.  The SIEM solution needed to be replaced with one that included SOAR capabilities.

“Specifically, there were gaps in the data and alerts we received from the existing SIEM solution.  We were bringing in about 10-12G per day, which was too little.  Additionally, the data coming in was the wrong data, which resulted in a lot of noise and alert fatigue.  We were alerted on things that were trivial and should’ve already been corrected with automated rules,” explained Mr. Jenkins. The disruptions caused by poorly qualified alerts inhibited Catalent’s ability to effectively detect threats and optimize its security posture.

Quote:

“I knew Netrix Global was a perfect fit, not just for our current business activities but also to help us get Microsoft tools configured and set up.”- Jody Jenkins, Head of Cybersecurity Operations, EUC, & IAM, Catalent

The Solution

Security Rebirth

“I was hired to clean up security operations, so it was a reset.  We weren’t just addressing individual gaps, but rather undertaking a full review and implementing core changes with many other tools that were in place. I viewed it as starting over with a complete rebirth of security” explained Mr. Jenkins.

Needed Reliability and a Consultative Approach

Catalent began looking for vendors and sought reliable businesses that could meet their SLAs and understand Catalent’s tools, including Microsoft Sentinel SIEM.  Mr. Jenkins also described how he sought more than a vendor, but a partner who could provide guidance and assistance with queries.

“It’s one thing to do everything we ask, but we were looking for a consultative approach to suggest better options and inform us of what’s coming around the corner.”

“I had previous experience working with Netrix Global for several years, and I knew Netrix Global was one partner I wanted to bring in.  I knew Netrix Global was a perfect fit, not just for our current business activities, but also to help us get Microsoft tools configured and set up,” stated Mr. Jenkins.

Netrix Global’s broad cybersecurity expertise and breadth of services enabled it to serve as the consultative partner Catalent sought.

The Results

Fast Turnaround

As part of the security changes, Catalent purchased Microsoft Office 365 E5 licenses for its users and the Microsoft Sentinel SIEM solution.  Catalent relied on Netrix Global to help configure the tools and provide ongoing support with Managed Detection & Response (MDR) services.  Catalent’s contract with its former MSSP was ending, necessitating a quick turnaround.  The project launched in January and was fully operational in February, taking just over two weeks.

Ashley Ward, Senior Manager, Cybersecurity & Infrastructure Portfolio, Catalent, said, “In my experience dealing with contracts, all the Netrix Global project managers have all been very professional and helpful and made things a lot smoother.  We didn’t have issues getting our contracts through the review process or signed.  Things went very quickly.  I’ve been very pleased with Netrix Global.”

Quote:

“To me, it’s about the trust and the partnership” – Mr. Jenkins, Head of Cybersecurity Operations, EUC, & IAM, Catalent

Seamless Implementation with a Very Smooth Transition

The scope of the implementation included roughly 4,000 servers, 12,000 end user computer endpoints globally, and 24,000 identities combining employees, contractors, and vendors.

Although the implementation involved numerous, substantial technical changes, the process was efficient and agile, resulting in a smooth transition.  When asked if employees outside of IT understood the transition, Mr. Jenkins responded, “No one knew.  That says a lot.  We were able to have Netrix Global implement the new solution without causing any business impact.”

24x7x365 Monitoring and Actionable Alerts 

Netrix Global’s MDR combines Azure Sentinel capabilities with critical Security Orchestration, Automation, and Response (SOAR), delivered as a service to Catalent via the Netrix Security Operations Center (SOC).  Every alert generated by Sentinel is scrutinized by a human analyst in Netrix’s Threat Operations group to validate and put it into context.  Netrix Global handles investigations and, in most cases, response.

The Netrix Global team of security analysts provide 24x7x365 monitoring, providing Catalent with complete coverage at a predictable monthly fee.  The MDR service alleviates the pressure on Catalent’s team to respond to alerts, while also eliminating the burden of Catalent to continuously replenishing their own SOC team with training and new hires.

Catalent brings roughly 500GB of data per day into Microsoft Sentinel.  With actionable, quality alerts, the Catalent infrastructure team now knows what truly needs attention and is empowered to take the appropriate countermeasures.  They’re able to find and correlate incidents to make data-driven decisions, such as what must be blocked at the firewall.

Night-and-Day Difference

As a long-term partnership, Netrix Global is currently supporting Catalent through an E5 deployment, Azure Workday integration, and single sign-on projects.

Mr. Jenkins stated, “In the last six months, it’s been a night and day difference.  To me, it’s about the trust and the partnership. We’re getting great service for what we’re paying, as well as the knowledge base that we didn’t have from our previous MSSP.”

Responsive and Collaborative

Mr. Jenkins gave the Netrix Global team kudos for being present.  “They pick up the phone, and we can talk to them and have good conversations.  Rather than merely answering our specific questions, we work together. I love the dialogue back and forth, which I wasn’t seeing from our previous vendor.”

Chris Beyer, Senior Cybersecurity Engineer, Catalent added, “Their integrity, responsiveness, and knowledge are big things.  We chat in Teams and I get responses immediately.”

Seamless Implementation with a Very Smooth Transition

The scope of the implementation included roughly 4,000 servers, 12,000 end user computer endpoints globally, and 24,000 identities combining employees, contractors, and vendors.

Although the implementation involved numerous, substantial technical changes, the process was efficient and agile, resulting in a smooth transition.  When asked if employees outside of IT understood the transition, Mr. Jenkins responded, “No one knew.  That says a lot.  We were able to have Netrix Global implement the new solution without causing any business impact.”

24x7x365 Monitoring and Actionable Alerts 

Netrix Global’s MDR combines Azure Sentinel capabilities with critical Security Orchestration, Automation, and Response (SOAR), delivered as a service to Catalent via the Netrix Security Operations Center (SOC).  Every alert generated by Sentinel is scrutinized by a human analyst in Netrix’s Threat Operations group to validate and put it into context.  Netrix Global handles investigations and, in most cases, response.

The Netrix Global team of security analysts provide 24x7x365 monitoring, providing Catalent with complete coverage at a predictable monthly fee.  The MDR service alleviates the pressure on Catalent’s team to respond to alerts, while also eliminating the burden of Catalent to continuously replenishing their own SOC team with training and new hires.

Catalent brings roughly 500GB of data per day into Microsoft Sentinel.  With actionable, quality alerts, the Catalent infrastructure team now knows what truly needs attention and is empowered to take the appropriate countermeasures.  They’re able to find and correlate incidents to make data-driven decisions, such as what must be blocked at the firewall.

Night-and-Day Difference

As a long-term partnership, Netrix Global is currently supporting Catalent through an E5 deployment, Azure Workday integration, and single sign-on projects.

Mr. Jenkins stated, “In the last six months, it’s been a night and day difference.  To me, it’s about the trust and the partnership. We’re getting great service for what we’re paying, as well as the knowledge base that we didn’t have from our previous MSSP.”

Responsive and Collaborative

Mr. Jenkins gave the Netrix Global team kudos for being present.  “They pick up the phone, and we can talk to them and have good conversations.  Rather than merely answering our specific questions, we work together. I love the dialogue back and forth, which I wasn’t seeing from our previous vendor.”

Chris Beyer, Senior Cybersecurity Engineer, Catalent added, “Their integrity, responsiveness, and knowledge are big things.  We chat in Teams and I get responses immediately.”

Experience The Impact

No matter what challenge you’re facing today, our team of technical experts can get you started on a path to a better solution. We’ll partner with you to: 

  • Understand your current technology environment
  • Interview key stakeholders to understand the root of the business issue(s)
  • Propose a solution with projected timelines, budget, and dependencies