Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Energy provider selects Beyond Trust to mitigate admin rights

by The Gurus
March 25, 2015
in Case Studies
Vibrations in Lightbulbs allowing Individuals to Eavesdrop
Share on FacebookShare on Twitter

BeyondTrust helps RWE Supply & Trading mitigate administrative rights and unauthorised download risks
 
BeyondTrust has announced a project to helping RWE Supply & Trading, a leading pan-European energy trading house, to reduce security risks while meeting budgetary and regulatory constraints.
 
RWE Supply & Trading is a key player in the European energy sector serving as the interface between the global wholesale markets for energy and energy-related raw materials, and the RWE Group, one of Europe’s five leading electricity and gas companies.
 
As part of its ongoing strategy to protect and continually strengthen its IT security posture, RWE considered the tightening of administrator rights to ensure that users download only applications applicable to their responsibilities and mitigate the risk of rogue software and potential harmful malware damaging its critical IT systems. However, RWE was also concerned that simply removing admin rights from employees would hamper productivity, especially in an environment that makes extensive use of Citrix VDI technologies.
 
Loucas Parikos, IT security architect for RWE Supply & Trading, said: “We wanted to reduce the attack surface and our chances of being exploited and without negatively impacting on a productive work environment while meeting all regulatory constraints.”
 
Following an extensive evaluation and Proof-of-Concept phase, RWE selected BeyondTrust PowerBroker for Windows which has allowed the company to eliminate ad-hoc admin rights on all users’ PCs as well as allow fine grained control of privileges on the Windows Servers. With PowerBroker, RWE is able to control the functions permitted on servers, whether accessed by local employees, contractors, employees from other divisions, or by groups to which RWE outsourced.
 
Once local admin issues had been resolved, Parikos next moved on to reducing its attack surface and vulnerabilities across all IT resources. After undertaking another Proof of Concept of several vulnerability management products and an extended evaluation period, RWE deployed Retina CS from BeyondTrust to scan its disparate and heterogeneous environment to identify security exposures using the results in a consolidated set of actions based on specific vulnerabilities found during the scans.
 
“The reporting capabilities provide insight and help us prioritise our risks across the entire environment based on industry data about specific vulnerabilities,” Parikos noted. The project was capped by a final stage that used the PowerBroker Password Safe to track who accessed various privileged accounts on RWE’s estate of 1000+ Windows servers and 200+ UNIX systems to enable detailed audits of what had been done during each access session.
 
The success of the solution has helped RWE retain its strict regulatory and industry best practice security controls. According to Parikos: “Our initial success in working with BeyondTrust to eliminate admin rights propelled us to seek other components that could also be monitored from BeyondInsight. The reporting capabilities and recommendations are excellent, and the more assets we scanned, the more useful those insights became in prioritising our remediation efforts.”

ShareTweet
Previous Post

Through the barricades

Next Post

Rise of threat intelligence is leading to too many sources, finds MWR, CPNI and CERT-UK

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol