• >
  • >
  • >
  • >
  • >
Netskope > Case Studies > Sainsbury’s Case Study

Sainsbury’s Case Study

Netskope Logo
Customer Company Size
Large Corporate
Region
  • Europe
Country
  • United Kingdom
Product
  • Netskope SaaS protection with Cloud DLP
  • Advanced Threat detection and remediation
  • Complete O365 protection
Tech Stack
  • Cloud Services
  • Data Loss Prevention (DLP)
  • Threat Detection
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Cost Savings
  • Customer Satisfaction
  • Digital Expertise
Technology Category
  • Cybersecurity & Privacy - Cloud Security
  • Cybersecurity & Privacy - Database Security
Applicable Industries
  • Retail
  • Finance & Insurance
Applicable Functions
  • Business Operation
  • Human Resources
Use Cases
  • Cybersecurity
Services
  • Cloud Planning, Design & Implementation Services
  • Cybersecurity Services
  • Data Science Services
About The Customer
Sainsbury’s is one of the UK’s leading retailers across food, clothing, general merchandise and financial services. The company has been trading for 150 years and is one of the best known and loved retail brands in the country. Sainsbury’s Tech Security team is responsible for defining and delivering the technology security strategy and roadmap across all of Sainsbury’s brands and channels, including Argos, Tu clothing, Nectar loyalty, Habitat and Sainsbury’s Bank, as well the core grocery business. The team works in partnership with the CTOs of all of Sainsbury’s business areas to support the tooling, processes and resourcing across three outcome areas: Protecting data, Protecting systems, and Meeting regulatory commitments. Mun Valiji is Chief Information Security Officer (CISO) at Sainsbury’s and works at a peer level with the business CTOs, reporting directly to the Board.
The Challenge
Sainsbury’s, a leading UK retailer, faced several challenges in its tech security department. The company operates in a 'cloud first' environment, which is crucial for scalability during peak seasons. However, this approach led to incomplete visibility of cloud services, risk of sensitive data loss and non-compliance, restricted Data Loss Prevention (DLP) capabilities, exposure to threats, and lack of consistent policy enforcement. The company needed to ensure visibility across a complex web of cloud services used both internally and with partners. The Data Protection Officer role within Sainsbury’s Data Governance team relied on the insight and controls that the Security team owns. The company handles a lot of data, governed by a range of regulations, making strict adherence to best practice for data governance critical.
The Solution
Sainsbury’s implemented Netskope, a cloud-native platform that maps billions of transactions, enabling Sainsbury’s to understand user activity across tens of thousands of SaaS and IaaS services, and millions of websites. Netskope gives line of sight into both sanctioned apps (such as Office365) and unsanctioned apps. This ensures the security team can identify shadow projects that may have accidentally overlooked integration with the security team. Netskope decodes these activities to reveal rich details about users, groups, locations, devices, and data. This enables Sainsbury’s to go beyond seeing byte movement to gaining real insights and taking granular, policy-based action to mitigate cloud risks, protect sensitive data, and stop online threats. Netskope helps the security team answer questions and enforce policies such as: “Block users from Team-X from posting non-compliant messages on social media,” and “Alert if any user uploads personally identifiable information (PII) to any big data app.”
Operational Impact
  • Sainsbury’s has defined appropriate use cases and policies across all cloud services—both sanctioned and unsanctioned.
  • Starting with basic discovery to fully understand the organisation’s cloud estate, Sainsbury’s is now in a position to identify potential points of contagion or leakage —if any documents or data are sitting unprotected outside of the network.
  • The security team updates the data governance committee regularly.
  • The team has done a lot of work to identify and tune native controls within common apps such as OneDrive, where a new document is created with sharing as the default setting.
  • They also work to educate colleagues to avoid oversharing of documents, using specific names instead.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that AGP may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from AGP.
Submit

Thank you for your message!
We will contact you soon.