Cygna Labs
Book a Demo
shield

N3K becomes Cygna Labs Germany

Partner Success Story

Change Auditing and Recovery for optimizing the use of Active Directory in the NRW Fiscal Authority

cover-img

Change Auditing and Recovery for optimizing the use of Active Directory in the NRW Fiscal Authority

The North-Rhine Westphalian fiscal authority comprises the Finance Ministry of the State of North- Rhine Westphalia as the highest state institution along with various higher regional authorities and mid-level authorities such as the State Office of Salaries and Pensions, the State Finance Office, the Regional Finance Authority, as well as the individual tax offices including company audits and tax fraud investigations as lower-level state institutions. The fiscal authority also runs training institutions such as the University of Finance at Schloss Nordkirchen, the Regional School of Finance, and its academy of professional development. The fiscal authority’s central data center also functions as top-level regional processing institution responsible for the operation of the entire IT infrastructure. This data center serves as the central service provider for approximately 140 locations with ca. 30,000 users across the state.

Naturally, information technology is a sensitive subject for any fiscal authority, since it processes largely confidential and personal data. This makes it essential to set up and then implement highly detailed rules about which personnel members have access to which types of data and applications. The Fiscal Authority of the State of North-Rhine Westphalia uses Microsoft’s Active Directory (AD) to securely manage its users and their access rights and permissions. AD serves as central directory, managing all IT objects such as users, groups, applications, and devices. It also allows administrators to control access to resources determining and managing user permissions.

Change Auditing and Recovery for optimizing the use of Active Directory in the NRW Fiscal Authority

“Even after the start of productive operation, we have always had somebody with a great deal of expertise at our side. But operation is so problem-free that we only rarely have to draw on that resource.“ 

Dietmar Rilk

Dietmar Rilk

Head of Windows Systems at the NRW Fiscal Authority

Active Directory as Critical Resource 

As a central service, AD has a great deal of significance when it comes to the availability of data and applications across North-Rhine Westphalia’s entire network of financial institutions. Failures, even partial ones, invariably lead to personnel being unable to complete their tasks, limiting the functionality of all departments across the board. Furthermore, AD offers no simple, in-application means of recovery, so that such problems can be solved only manually and with high personnel and man-hour costs. In particular Ad’s protocol functions are extremely limited, often making it impossible to track changes. At the same time, it is usually those very changes that lead to errors and failures.

Just such a partial failure of Active Directory was the Fiscal Authority’s main reason to look for a solution that would enable efficient change management as well as comprehensive auditing. In addition, the solution had to offer a simple way to fully recover objects in AD after potential failures, and to roll back changes, ideally in increments. Auditing would also support revision-proof electronic filing, and would enhance security, since nowadays the early phase of most cyber-attacks focuses on changes to the Active Directory system in order to give attackers additional room for exploits using expanded access rights.

It was a recommendation that first attracted the attention of Dietmar Rilk, head of the Authority’s Windows Systems division, and his team to Cygna Labs and its Cygna Auditor platform, distributed in Germany by N3K Network Systems, among others. The application’s function module “Cygna Auditor for Active Directory” monitors all administrative activity within the critical directory service Active Directory in real time, thus giving administrators the ability to recognize all changes and, if desired, raise alarms on unauthorized changes in real time. Based on these audit data, any changes can be reversed if necessary—regardless of whether they were caused by faulty configuration or external attack. For this purpose, the Cygna Auditor platform and its “Cygna Recovery” function module offers an accurate rollback function based on the collected AD audit data with no back-up time point. This means that data can be restored for any desired point in time, with a high degree of granularity of all AD objects down to the attribute level, even incrementally, if called for. 

Change Auditing and Recovery for optimizing the use of Active Directory in the NRW Fiscal Authority

“In planning and implementation phases, working with N3K as system integrator was extremely easy and unobtrusive.”

Dietmar Rilk

Dietmar Rilk

Head of Windows Systems at the NRW Fiscal Authority

Centralized Event Monitoring and Evaluation

Since the previous partial failure had been classified as a serious security risk, the Fiscal Authority was able to implement the Cygna Auditor platform in August 2021 in compliance with public procurement law. “What was particularly important to us was being able to centrally monitor and evaluate events in AD,” Dietmar Rilk explains. “That is the precondition for recognizing critical events and being able to offer a largely automated reaction to them rather than just spitting out alarms on the console.” What is more, its seamless documentation of access and changes meant that the Cygna Auditor platform and its “Cygna Auditor for AD” simplified the compliance with the GDPR and all specifications of Germany’s BSI (Bundesamt für Sicherheit in der Informationstechnik, Federal Office for Information Security).

In particular, traceability of all changes in AD was one of the main reasons for choosing the Cygna Auditor platform. Although Active Directory, too, offers native event logging on the domain controller, old log entries are overwritten with newer entries every 30 to 60 minutes depending on the configuration, so that there is no long-term documentation. The Cygna Auditor platform, on the other hand, uses an independent SQL database for storing events, thus offering not only a capacity limited only by the storage medium, but also immense ease of access. All Active Directory changes are tracked seamlessly using an independent mechanism without recourse to the native log files. This ensures better data quality with approximately 75% lower data volume. In addition, the Cygna Auditor platform boasts a simple, modern, and clear-cut web GUI allowing simple, cross-platform operability.

At the Fiscal Authority of the State of North-Rhine Westphalia, the Cygna Auditor platform and its function module “Cygna Auditor for AD” and “Cygna Recovery for AD” support an environment in which the management of hardware, software, and identities is highly centralized. “Yes, there are responsibilities delegated to our individual locations, but there are no local administrators,” Rilk says. “All administration is handled centrally at our data center, and higher-level access rights at the locations are granted only if there are compelling reasons to do so—and even then, only temporarily. We consistently implement the principle of least privilege.” The Fiscal Authority, Rilk adds, simplifies centralized administration through a high degree of standardization and harmonization, with all servers and clients sharing identical configurations.

“Since roll-out in August of 2021, the Cygna Auditor platform and its function modules ‘Cygna Auditor for AD’ and ‘Cygna Recovery for AD’ have been in failure-free operation at the Fiscal Authority.” 

Dietmar Rilk

Dietmar Rilk

Head of Windows Systems at the NRW Fiscal Authority

Home Improvement
Home ImprovementHome Improvement

“Cygna Auditor not only provides us with comprehensive and deep insight into events inside of our Active Directory, but also enables us to remedy errors in a very simple way.”

Florian Johann

Florian Johann

Technology team leader at Hornbach

Read the story
Telecommunications
TelecommunicationsTelecommunications

“With more and more web-enabled devices and applications demanded, service providers have to run ever faster just to stand still. IPControl™ from Cygna Diamond IP brings the control we need to manage IP addresses now and in the future.”

Kevin Bates

Kevin Bates

Lead Designer IP Address Management, BT Design and Innovation

Read the story

Press

Cygna Labs Extends DNS Security Features with Cygna DDI Guard 4.1

Newest release extends DNS security visibility and controls for Cygna DDI custom...

January 14, 2025

Cygna Labs announces the general availability of VitalQIP Appliance Manager 24

Cygna Labs announces the general availability of VitalQIP Appliance Manager 24

December 20, 2024

Cygna Labs Announces the General Availability of VitalQIP

Enhancement release enables Cygna Labs customers to holistically manage DDI acro...

December 12, 2024

Cygna Labs announces the general availability of VitalQIP 23 and Appliance Manager (AM) 23

Cygna Labs is pleased to announce the availability of the VitalQIP 23 and Applia...

March 19, 2024

Cygna Labs Expands Native Cloud DNS Management for Diamond IP

IPControl release provides a new user interface to streamline DDI management of ...

September 07, 2023

Cygna Labs Corp. Announces Expansion of its DNS Firewall Service

DNS Firewall Service is now available to VitalQIP customers to ensure continuous...

August 31, 2023

Cygna Labs Launches Log Consolidator for Windows Event Logs

Product extends the Cygna Auditor platform to provide the collection and central...

June 20, 2023

Cygna Labs Expands VitalQIP DDI Security with Cygna Radar

Cygna Labs delivers new capabilities for VitalQIP customers with its latest DNS ...

June 04, 2023

Cygna Labs Completes Acquisition of Nokia’s VitalQIP, Positioning the Company as the Second-Largest Global DDI Vendor

Augmenting its intellectual property and increasing its client roster, this late...

May 09, 2023

Cygna Labs Signs Definitive Agreement to Acquire Nokia’s DDI Business Unit

Combination places Cygna Labs as the number two provider of DDI solutions global...

March 07, 2023

Cygna Labs Attains ISO 27001 Information Security Certification

Certification demonstrates Cygna Labs’ commitment to information security best ...

February 02, 2023

Cygna Labs to Acquire NCC Group’s DDI business

Investment establishes Cygna Labs’ presence in the UK and further strengthens it...

January 19, 2023

Cygna Labs Introduces Entitlement and Security for Active Directory

Standalone product provides permission insights for Active Directory security a...

January 17, 2023

Cygna Labs Completes Acquisition of Diamond IP, Third-Largest Global DDI Vendor

Investment augments the company’s intellectual property and enhances its ongoing...

March 17, 2022

Cygna Labs Signs a Definitive Agreement to Acquire Diamond IP from BT

Deal enhances Cygna Labs’ intellectual property by adding third-largest DDI vend...

February 17, 2022

Cygna Labs Adds SIEM Event Forwarding and Identity Grouping Features to Cygna Auditor

Cygna Labs, a leading provider of Hybrid-Multi-Cloud Auditing, Reporting and Com...

January 19, 2021

Cygna Labs Adds SIEM Event Forwarding and Identity Grouping Features to Cygna Auditor

Cygna Labs, a leading provider of Hybrid Multi Cloud Auditing, Reporting and Com...

July 30, 2020

Following Agreement to Assume Management of the BeyondTrust Auditor Suite, Cygna Labs Appoints Morgan Holm as Vice President of Products

Leading provider of Microsoft-Hybrid Auditing, Reporting and Compliance Platform...

February 14, 2020

Cygna Labs Assumes Management of Auditor Suite from BeyondTrust

Deal ensures ongoing maintenance, support and future product development of the ...

February 05, 2020

N3K Acquires Cygna Labs to Deliver Compliance Solutions Across Microsoft-hybrid IT Infrastructures

Leading German systems integrator acquires Cygna Labs and its Microsoft-based hy...

February 19, 2019