VINCI standardises on Cortex XDR across 200,000 endpoints worldwide

SUMMARY

VINCI is a global player in construction, concessions, and energy, employing 280,000 people across more than 120 countries and 7,000+ locations. Headquartered in France, the organisation designs, finances, builds, and operates infrastructure and facilities. It has annual revenues of €72 billion (2024).

VINCI’s 200,000 endpoints support large-scale multi-industry activities across the globe. For example, in France, the operation of 4,000 kilometres of autoroutes and the construction of new tunnels, bridges, and roads; in Brazil, the development of a renewable energy plant; in Cairo, the launch of a new metro system; and in Senegal, the building of a new electricity infrastructure. They’re also vital to daily operations at 70 airport concessions worldwide. Whatever the use case, VINCI needs to ensure these endpoints are secure from cyberthreats and available 24/7 to support business operations.

RESULTS

3 hours

mean time to detect threats that previously took days

200,000

endpoints now have complete visibility for faster threat remediation

10s to 2

sources to monitor and detect a threat
challenge

Until recently, the decentralised nature of VINCI’s organisation meant it had no standard global approach to endpoint protection across its different lines of business – construction, energy, and concessions. This led to increased overhead, complexity, and business risk. It was also difficult to detect malicious behaviour on the endpoints. If there was an alert, the team needed to physically investigate the endpoint on site. With operations in 120 countries, this was an almost impossible task. The team needed to:

  • Reduce manual intervention
  • Streamline SOC operations
  • Reduce downtime

“We have multiple SecOps teams worldwide. One connected endpoint security platform worldwide would accelerate mean time to detect and respond, safeguarding the business from threats.”

Yann Sladek

Head of CyberDefense
VINCI

SOLUTION

AI and behavioural analytics block malicious activity

VINCI was already a satisfied Palo Alto Networks network security customer and chose Cortex XDR because of its native technology integration and the collaborative nature of the Palo Alto Networks team.

Almost all of VINCI’s 200,000 endpoints are now supported by the Cortex security operations platform. With a single agent on each endpoint, Cortex XDR uses local AI and behavioural analytics to block malicious activity. Building on endpoint detection and response, Cortex XDR also analyses data from across the VINCI network to detect attacks before they result in a breach. VINCI now has complete, 360-degree visibility into malicious behaviour, allowing threats to be isolated and remediated before they can enter the network.

Endpoints can be remediated quickly and remotely, without the need for IT technicians to fly to site and investigate the endpoint. This saves on people’s time and travel costs. “Previously, if an endpoint was threatened, it could take weeks to check it – and even then we might only reach 80% of the threat scope. Now, using Cortex, we can remediate the entire incident in just a few hours,” says Yann Sladek, VINCI’s Head of CyberDefense.

Several of VINCI’s SOCs have already integrated Cortex XDR with Cortex XSOAR for orchestration and response automation. Prebuilt playbooks are at the heart of XSOAR, allowing the SOC teams to automate multiple security processes, such as handling investigations and managing tickets.

Learn more about Palo Alto Networks AI-driven Security Operations Platform or request a demo

Be a thought leader

Become an advocate for Prisma SASE and gain exposure for your organization.