Lili achieves PCI DSS compliance using the visibility provided by Wiz

Lili looked to strengthen its cloud security posture with easy to use cloud security tools. Wiz helped the banking platform remediate its most critical risks and perform architecture reviews as part of its PCI DSS audit process.

Lili Bank

산업

금융 서비스

부위

북아메리카

위즈 제품

Wiz Cloud

사용 사례

CSPMCompliance

클라우드 플랫폼

AWS
시작할 준비가 되셨나요?
데모 신청하기

Lili is an online banking platform for small businesses, offering an advanced business checking account with high APY on savings and FDIC coverage of up to $3M, designed to support the needs of high-revenue, multi-employee businesses.

Lili has been cloud-native from day one, leveraging the power and flexibility offered by Amazon Web Services (AWS) to manage its backend infrastructure. When CISO Omri Nachum joined Lili in 2021, he immediately set about strengthening Lili’s cloud security posture and processes. “We were already using other cloud security tools, but we were looking for a more user-friendly experience and better service as these solutions are very complex.”

Wiz is my eyes. Without it, I would be blind.

Omri Nachum
CISO, Lili

Within minutes of connecting Wiz to their AWS environment, Lili started discovering new vulnerabilities and toxic combinations of risk factors that former tools had not. Thanks to its agentless scanning and hundreds of built-in controls, Wiz offers unparalleled visibility into the constellations of risks that malicious actors take advantage of. Lili also discovered that Wiz maps built-in policies to external compliance frameworks like PCI DSS. Moreover, every PCI DSS requirement is listed in Wiz, even those that cannot be automatically checked.

Wiz gives me a complete, detailed map to understand what needs to be done to achieve compliance. It’s my checklist.

Omri Nachum
CISO, Lili

The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard maintained by the PCI Security Standards Council that seeks to enhance global payment account data security and reduce credit card fraud. Companies that process credit card payments are subject to PCI DSS requirements and can face fines from credit card issues for failing to demonstrate compliance.

To prepare for their annual PCI DSS audit, Lili used Wiz to proactively remediate their most critical risks and perform architecture reviews. During the audit, Ohad Zeruya, from Lili’s DevOps team, used Wiz to map network elements and quickly answer the auditor’s specific questions about scanning for vulnerabilities, testing firewall settings, patch management, and the inventory of all applications. Instead of struggling to integrate the siloed perspectives generated by several different tools, he had all of the information he needed in a single intuitive interface.

To answer the PCI auditor’s questions, I just opened Wiz and showed him all of the notifications and reports. He was amazed that Wiz scans for vulnerabilities every day, not just once every three months.

Ohad Zeruya
DevOps, Lili

Looking forward, Lili is building Wiz into its ongoing processes to monitor and maintain PCI compliance. These processes are a key aspect of maintaining PCI compliance, and Wiz provides Lili the visibility and automated alerting to streamline their execution. The DevOps team at Lili is empowered by Wiz to build more quickly, safely, and secure by truly becoming DevSecOps.

Want to learn how your cloud security program can achieve the same results as Lili? Take a closer look at Wiz's cloud security solutions for financial services.

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자