Menlo Security

Menlo Security

Nissay Asset Management Corporation

Web isolation technology protects important operational assets Realizes reliable security measures while keeping costs down

Point of introduction

  • Web isolation provides reliable security measures for web browsing
  • Significantly reduced the number of responses to malware detection, reducing the operational load
  • The actual state of usage, including applications, has been visualized
Mr. Hiroshi Ootagaki

Nissay Asset Management Corporation
System Development Department
system manager Mr. Hiroshi Ootagaki

Mr. Takashi Mori

Nissay Asset Management Corporation
System Planning Office, System Development Department
Assistant manager Mr. Takashi Mori

Aiming to realize a secure web browsing environment
Consider introducing web isolation

Nissay Asset Management was established by bringing together the asset management capabilities of the Nippon Life Insurance Company, which has a long history and track record. The company's management philosophy is "for customer satisfaction," "pursuit of professionalism," and "cultivation of a fair and sincere corporate culture." We aim to contribute to long-term asset formation and social development.

In 2015, the company started considering a new system with the aim of realizing a secure web browsing environment in order to ensure safety and security in asset management. Mr. Hiroshi Otagaki, General Manager of Systems Development Department, Systems Development Department, explains the reason for this, saying, "Around this time, the Basic Act on Cybersecurity was enacted, and cybersecurity measures were clearly specified in the Supervision Guidelines and Inspection Manuals of the Financial Services Agency. Leakage incidents also occurred, and the momentum to strengthen cyber security measures, including management, has increased at once.In cyber security measures, it is required to take multi-layered measures for entry, exit, and internal, but internal measures are especially important. It will affect the existing system and it will take time to deal with it.As a result, cases including the parent company of separating the Internet as an effective entrance and exit countermeasure have been heard, and the Company are forced to consider it as well. ” explains.

The company said it initially considered implementing a Double browser solution. This provides two browsers, one for web access and one for internal network, in one client. By using a virtual machine or a secure browser for web access, the user environment and the Internet were separated.

At the time, this was the only technology that could realize web separation, but when we actually investigated it, it had a large impact on business and many problems in terms of operation. Regarding this point, Mr. Takashi Mori, assistant manager of the system planning department of the system development department, said, "In the Company case, we often use web systems for external business partners, etc., and in particular, we cannot upload or download files directly with a browser, and we have to use two browsers. Having to use them differently leads to a significant deterioration in work efficiency.In addition, the hardware cost of virtual machines and the time it takes to start up the browser were bottlenecks."

Sanitization by original web isolation technology
Appreciated for its ability to be quickly introduced without the need for a large investment

Nissay Asset Management was then searching for alternative solutions when they came across an advertisement for Menlo Security. This was in 2016, when Macnica had signed a distributorship agreement with US company Menlo Security and had just begun selling the product domestically. "We were attracted to the new method of neutralizing threats using unique web isolation technology. We were also attracted by the fact that it didn't require a large investment and could be implemented quickly," says Otagaki.

The company carefully considered Menlo Security and conducted various tests with the intention of introducing it at the end of 2016. Full-scale in-house verification began in early 2017. Verification within the system development department revealed no major problems, and formal implementation work began in September 2017. When introducing the system, it took three months to gradually expand the target departments in order to register sites that could not be viewed or displayed properly as exceptions and eliminate them.
"Immediately after we started testing, we found multiple sites that could not be accessed every day, but Macnica provided support on how to set it up, and we were able to fix it right away. Also, if it was difficult to fix it, we would be able to help you with it at the Menlo Security headquarters in the United States. I was grateful that the response was speedy and flexible.Thanks to that, I didn't have to worry about proceeding with internal verification.'' (Mr. Mori)

In line with this work, we also collect access logs from applications other than browsers. Based on this, specific safe websites are whitelisted and access from applications other than browsers is permitted.

Reliable security measures for web browsing are realized
Reduced operational burden on system administrators

Nearly three years have passed since Nissay Asset Management introduced Menlo Security, and its effectiveness is largely due to the realization of reliable security measures for web browsing without significantly impairing user convenience due to web isolation. In addition, from the standpoint of system administrators, reducing the operational load is also a major achievement.
“For example, the number of responses to malware detections has decreased significantly. In the past, there were 5-6 cases a month, sometimes close to 10 cases, but after the introduction, it has decreased to less than 1 case. Most of them are either false positives or overactive detections, and none of them are critical.By not being bothered by this kind of response, we can concentrate on our priority tasks." (Mr. Mori)

Nissay Asset Management Corporation

In addition, Menlo Security has made it possible to clearly distinguish between browser and non-browser communication, visualize the actual state of use, including applications, and strengthen exit measures. Mr. Otagaki said, "By whitelisting the communication of applications other than browsers, it is possible to block communication with CC servers from malware on PCs in targeted attacks. Combined with entrance countermeasures by sanitizing websites, , I was able to gain a great sense of security by introducing Menlo Security." He also said, "Although it is not a cybersecurity measure, the Company prohibit employees from uploading files as a measure to prevent information leaks. We have taken countermeasures by categorizing web filters, but there was still a possibility that they could be bypassed.Menlo Security can cover all communications, so such concerns have been dispelled." .

On the other hand, when working with Excel files, etc., I had to go through a two-step process of browsing in Safe View and then downloading if necessary, but I quickly got used to the operability. After that, although it was necessary to strengthen the line, the number of cases of exception registration decreased due to the functional expansion of Menlo Security, and the operational load was reduced.

Consider simple operation centered on Menlo Security

Nissay Asset Management expects simple operation of entry and exit measures centered on Menlo Security in the future. “Menlo Security has greatly improved entry and exit measures, but exception management is important to maintain the quality of operations. We also hope to expand functions such as visualization of SaaS, whose usage is rapidly increasing, and inventory of exception registrations." (Mr. Mori)

Regarding Macnica 's response, they highly praise the fact that the staff, including the sales staff, are knowledgeable about the product and technology.
``We have regular follow-up and solid support, so we feel reliable.If I had to make a wish, I'd like to have a place where users can exchange opinions with each other.I think it would be great if there was a knowledge base that could be used for operational purposes.'' (Mr. Mori)

User Profile

Nissay Asset Management Corporation
location Nippon Life Marunouchi Building, 1-6-6 Marunouchi, Chiyoda-ku, Tokyo
Introduction time December 2017
URLs https://www.nam.co.jp/
Nippon Life Insurance Company 's asset management company established in April 1995. Utilizing the know-how of “long-term” and “stable” asset management that Nippon Life has cultivated over many years and the research and development of unique investment methods that Nippon Life has been working on as an investment professional, we manage our assets for customers of pension funds and investment trusts. provide service. We offer a wide range of product lineups in order to provide a variety of asset management solutions that meet the needs of our customers. In recent years, it has been ranked No. 1 in private pension trust balance for six consecutive years.

Inquiry/Document request

In charge of Macnica Menlo Security

Mon-Fri 8:45-17:30