hummgroup partners with Mantel and Palo Alto Networks for Zero Trust network design and adoption
- Fragmented point solutions consolidated into one cloud-delivered platform, Palo Alto Prisma Access
- Legacy VPN and network security infrastructure retired
- Least-privileged access and consistent data loss prevention across all application types
- Reduced operational overhead and complexity for internal teams
Background and objectives
Security of customer data is a core component of hummgroup’s technology transformation program, with specific drivers including technology platform rationalisation to reduce operational and capital cost, cloud migration, enhanced secure access to applications and data by adopting contemporary security principles and approaches such as Zero Trust. These objectives led hummgroup to modernise its secure remote access strategy through the adoption of Palo Alto Prisma Access.
By consolidating multiple VPN solutions into a unified cloud-delivered platform, hummgroup aimed to rationalise its technology landscape, support its ongoing cloud migration, and strengthen secure access for its distributed workforce. This transition enabled application and data-level protection aligned with modern security principles such as Zero Trust, while simplifying management and enhancing the user access experience.
Solution
hummgroup partnered with Mantel to develop the solution, which consisted of a number of phases summarised as follows.
1. Design of a Zero Trust Network architecture
The initial phase involved Mantel defining a set of requirements with key hummgroup stakeholders to support a design that covered securing access to applications, data and systems across multiple environments and key technology platforms including AWS, Azure, O365, Snowflake as well as a range of other key business SaaS platforms and various profiles of business users and access patterns. This established architecture then enabled the subsequent solution and platform evaluation phase.
2. Solution evaluation
This phase involved Mantel assisting with the evaluation of Security Service Edge (SSE) solutions. Mantel applied a defined evaluation framework for reviewing and assessing solutions and were able to bring this knowledge, expertise and IP to accelerate the evaluation process.
Mantel developed a set of evaluation criteria driven by both business and technical requirements, aligned with the high-level architectural design. Applying these criteria, a market scan of leading solutions was conducted, which resulted in a shortlist of three top SSE vendors for further consideration.
These three solutions were then evaluated in detail against the full set of evaluation criteria; which were in turn weighted and scored to support a recommendation.
Assessment
The assessment focused on the following key capability areas:
- Core Zero Trust Network Access (ZTNA) capabilities
- Pricing and licensing
- Integration with existing systems and platforms
- Secure Access Service Edge (SASE) integration
- Product innovation, roadmap and future development alignment
Evaluation categories
The chosen solution was Palo Alto Prisma Access, in combination with Palo Alto Software Firewalls deployed in the hummgroup cloud environment to provide secure, authenticated and authorised access to applications, data and systems for authorised users and services.
3. Implementation and migration
During the Implementation and Migration phase, the focus was on the detailed design and execution of the Prisma Access Zero Trust solution, ensuring it integrated seamlessly with existing operational tools.
Mantel began by developing a connectivity design to provide secure access to private applications across cloud and on-premises environments, including AWS and Azure. As part of this, security controls were implemented to support secure and consistent access across cloud environments. Next, essential integrations were established, connecting Prisma Access with hummgroup’s identity, security monitoring and operational management platforms.
The solution was then rolled out in a phased approach, starting with a platform pilot involving internal users. This was followed by carefully planned migration waves for users and applications, ensuring minimal disruption and complete organisational adoption prior to decommissioning legacy VPN infrastructure.
Benefits
Optimised security controls around user and service access to data, applications and systems through:
- Least-privileged access controls: hummgroup users and devices are granted access only to the specific applications or resources required for their roles, significantly reducing potential exposure to malicious actors.
- Continuous trust verification: The Prisma Access solution enables continuous assessment of user and device activity throughout each session, supporting the application of additional controls where elevated risk or anomalous activity is identified.
- Standardisation: A single, consistent Data Loss Prevention (DLP) policy can be applied across all required applications, including private, SaaS, cloud-native, and legacy systems, protecting sensitive data from both inadvertent and malicious exfiltration.
- Simplified management: Strata Cloud Management provides a unified platform with single-pane-of-glass visibility and management, enabling consistent policy enforcement and streamlined management across all hummgroup users and applications.
Outcomes
- Reduced operational complexity and administrative burden: hummgroup’s internal cloud, infrastructure, and security teams benefit from increased efficiency, enabling them to focus on higher-value initiatives.
- Improved user experience: By leveraging a global, cloud-native architecture, hummgroup provides more consistent and secure access to applications and services for its distributed workforce.
- Reduced infrastructure footprint: Reduced reliance on legacy infrastructure and associated maintenance activities has simplified platform management and supported hummgroup’s broader technology modernisation objectives.
”Protecting customer information is a core priority for hummgroup. As part of our broader technology transformation, we have modernised secure access across our cloud environments, strengthening security controls while simplifying the experience for our people. The work delivered with Mantel and Palo Alto Networks supports our ongoing commitment to maintaining a secure, resilient and scalable technology platform.
Andy TamaraHead of Security, hummgroup