Global manufacturer unlocks threat-informed SSL decryption

With Reach, I’m using terms like ‘these users provide more risk to the company overall’, and I’m actually able to give concrete numbers and something valuable to leadership.”

CISO

The challenge

With 80–90% of network traffic encrypted, the company lacked visibility into threats entering and leaving its network. Privacy, performance, and cost concerns had stalled SSL decryption for six years. The security team needed a data-driven way to identify the highest-risk users and traffic categories for a phased rollout.

#AAA8A0

#201F1C

28

Inter

center

The Solution

Reach turns attack data into a phased decryption strategy

Reach analyzed email and endpoint forensics, correlated attacks with workforce data, and identified the users and URL categories driving the greatest risk. The analysis showed that 4% of employees accounted for 70% of company risk, giving leadership the evidence to approve a focused SSL decryption pilot for the most-targeted users and highest-risk traffic.

80%

reduction in control maintenance workload

Months

of engineering work now automated

"With Reach, I'm now able to say 'I'm not decrypting all URL traffic, I'm decrypting these categories based on attacks that we've seen and reviewed. I'm decrypting these categories for our highest risk users. It's much more manageable."

Improving firewall value and downstream security data

Reach revealed that 85% of attacks used encrypted traffic and translated attack activity into actionable content-filtering categories. This helped the company expand firewall visibility without overloading infrastructure, quantify risk reduction, improve SIEM logs and incident data, and prepare stronger file-blocking and DLP policies.

Reach

The Story Continues

Following a successful pilot, the company plans to extend SSL decryption across the workforce within the year. The team will then apply Reach’s file-blocking recommendations, use richer network telemetry to strengthen downstream controls, and continue expanding visibility through a manageable, threat-informed rollout.

"Once SSL decryption is in place for the entire company, I’ll move on to deploying Reach’s file blocking profile recommendations given that files were previously masked in our traffic."
"With Reach, I'm now able to say 'I'm not decrypting all URL traffic, I'm decrypting these categories based on attacks that we've seen and reviewed. I'm decrypting these categories for our highest risk users. It's much more manageable."

Getting Started with Reach

Unlock the full power of your security stack with a free tool rationalization assessment.

Request a Demo

An API key to start

Read-only API key for a security tool of your choice

Setup in 3 minutes

Create your account and setup the integration

Results in < 5 days

Get results across licensing, control mapping, risk exposure, and posture

Would your controls have survived ShinyHunters? Find out with our new security checklist

Get your copy

decorativedecorative