In the face of the Log4j vulnerability, Nylas partnered with Lacework to limit exposure.
Nylas is a communications API platform that helps developers quickly and securely build email, scheduling, and work automation features directly into their applications. They have a multicloud environment, operating on both Amazon Web Services (AWS) and Google Cloud, and use a mix of containerized and non-containerized services. When Log4j was disclosed, they turned to Lacework.
Download NowWith the help of Lacework, we rapidly identified instances of the Log4j vulnerability and continuously monitored our environment for any exploitation activity. In less than one hour, we were able to scan our entire cloud infrastructure, including thousands of servers, to assess our exposure to Log4j. We quickly determined that our codebase and our customers were not affected and were able to maintain transparency and open communication with our customers in real-time.
DAVID TING, CHIEF INFORMATION SECURITY OFFICER, NYLAS
Challenges
- Check for critical Log4j vulnerability
- Protect cloud environments and customer data
Solutions
- Scanned thousands of hosts within one hour after Log4j was disclosed
- Monitored for suspicious activity and anomalies while vendors patched their services
Results
- Confirmed that their exposure to Log4j was limited and quickly relayed that information to customers
- Achieved continuous and complete visibility with event monitoring and anomaly detection