$add_header('Content-Security-Policy', $replace('default-src \'self\' https://racecenter.letour.fr https://emeaclientportal.datacenter.hello.global.ntt https://unpkg.com/web-vitals/dist/web-vitals.iife.js https://s1329636.t.eloqua.com https://www.google.com.br https://www.google.com.hk https://www.google.com.sg https://www.google.co.in https://www.google.co.nz https://www.google.com.bh https://www.google.co.kr https://www.google.com.my https://www.google.ca https://www.google.ie https://www.google.lt https://www.google.com.au https://www.google.com.pa https://www.google.nl https://www.google.co.jp https://*.fls.doubleclick.net https://prodau-cdn.azureedge.net https://prodeu-cdn.azureedge.net https://www.google.com https://resources.digital-cloud.medallia.eu https://*.licdn.com https://s7.addthis.com https://vars.hotjar.com/ https://connect.facebook.net/ https://www.facebook.com/ *.crazyegg.com https://youtube.com https://www.youtube.com https://youtu.be https://i.ytimg.com/vi_webp/PfZzvGGRaOM/mqdefault.webp; img-src \'self\' blob: data: https://*.emtana.com:* https://emeaclientportal.datacenter.hello.global.ntt/servlet/servlet.ImageServer?id=0151i000000vC0y&oid=00D58000000H2jR https://portal.webolytics.com/ https://admin.bound360.com/images/logos/bound-logo-full.png https://cdn.bizible.com https://cdn.bizibly.com https://px4.ads.linkedin.com https://ad.doubleclick.net https://www.google.be https://pbs.twimg.com https://*.analytics.google.com https://*.google.com https://*.brightfunnel.com https://q.quora.com https://alb.reddit.com https://www.marketing-town.com https://assets.getsmartcontent.com https://www.google.co.in https://www.google.com.hk https://www.google.com.sg https://www.google.co.nz https://www.google.co.jp https://www.google.com.br https://www.google.com.bh https://www.google.co.kr https://www.google.com.my https://www.google.ca https://www.google.ie https://www.google.lt https://www.google.com.au https://www.google.nl https://di3c8wks3odob.cloudfront.net https://maps.gstatic.com https://maps.googleapis.com https://www.google.de https://www.google.it https://pixel.tapad.com https://decibel-49-adswizz.attribution.adswizz.com https://www.google.co.uk https://attribution.decibelads.com https://reverseads.matomo.cloud https://tracking.connect.services.global.ntt https://fonts.gstatic.com https://cdn.cookielaw.org https://analytics.twitter.com https://analytics.google.com https://*.terminus.services https://match.adsrvr.org https://prodeu-strgacc-cdn.azureedge.net https://prodau-strgacc-cdn.azureedge.net https://*.leady.com/ https://resources.digital-cloud.medallia.eu https://j.mrpdata.net https://857338121.privacysandbox.googleadservices.com https://720787047.privacysandbox.googleadservices.com https://apt.techtarget.com https://620993155.privacysandbox.googleadservices.com https://p.adsymptotic.com/ *.crazyegg.com https://tracking.hello.global.ntt/ https://www.google.co.za https://*.kampyle.com https://vars.hotjar.com https://pubads.g.doubleclick.net https://script.hotjar.com http://script.hotjar.com www.googletagmanager.com https://www.google.com https://www.google.com.pa https://googleads.g.doubleclick.net https://www.google-analytics.com https://ssl.gstatic.com https://www.gstatic.com https://prodeu-cdn.azureedge.net https://prodau-cdn.azureedge.net https://t.co/ https://px.ads.linkedin.com/ https://connect.facebook.net/ https://www.facebook.com/ https://www.linkedin.com/ https://s2190102.t.eloqua.com/ https://storage.googleapis.com/ https://*.akstat.io; style-src \'unsafe-inline\' \'unsafe-eval\' \'self\' *.crazyegg.com https://cdn.jsdelivr.net/npm/swiper@8/swiper-bundle.min.css https://prodeu-strgacc-cdn.azureedge.net https://prodau-strgacc-cdn.azureedge.net https://cdnjs.cloudflare.com/ajax/libs/tiny-slider/2.9.1/tiny-slider.css https://fonts.googleapis.com https://tagmanager.google.com https://www.googletagmanager.com; font-src \'self\' https://prodeu-strgacc-cdn.azureedge.net https://prodau-strgacc-cdn.azureedge.net https://fonts.gstatic.com data: http://script.hotjar.com https://script.hotjar.com; upgrade-insecure-requests; block-all-mixed-content; frame-ancestors https://cm.euprod.services.global.ntt https://prodeu-strgacc-cdn.azureedge.net https://prodau-strgacc-cdn.azureedge.net https://vars.hotjar.com https://bid.g.doubleclick.net https://*.crazyegg.com; script-src [nonce] \'unsafe-inline\' \'unsafe-eval\' \'self\' blob: https://*.emtana.com:* https://emeaclientportal.datacenter.hello.global.ntt https://*.adobe.io https://*.go-mpulse.net https://portal.webolytics.com https://cdn.bizible.com https://secure.intelligentdata52.com https://a.quora.com https://unpkg.com/web-vitals@3.0.0/dist/web-vitals.attribution.iife.js https://*.brightfunnel.com https://*.analytics.google.com https://*.google.com https://www.redditstatic.com https://cdn.jsdelivr.net/npm/swiper@8/swiper-bundle.min.js https://maps.googleapis.com https://www.google.co.in https://www.google.co.nz https://www.google.com.pa https://www.google.de https://www.google.it https://cdn.matomo.cloud https://s.getsmartcontent.com https://cdn.getsmartcontent.com https://attribution.decibelads.com https://tracking.connect.services.global.ntt https://snippet.ramblechat.com https://munchkin.brightfunnel.com https://*.terminus.services https://analytics.google.com https://prodeu-strgacc-cdn.azureedge.net https://prodau-strgacc-cdn.azureedge.net https://*.leady.com/ https://www.gstatic.com https://trk.techtarget.com https://visitor.reactful.com https://*.crazyegg.com https://script.crazyegg.com https://connect.facebook.net/ https://cdn.cookielaw.org/ https://secure.east2pony.com/ https://protect-eu.mimecast.com/ https://www.google.co.za/ https://*.addthisedge.com https://z.moatads.com https://*.addthis.com https://script.hotjar.com http://script.hotjar.com http://static.hotjar.com https://static.hotjar.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://www.google-analytics.com https://ssl.google-analytics.com https://tagmanager.google.com https://analytics.twitter.com https://static.ads-twitter.com https://resources.digital-cloud.medallia.eu https://nebula-cdn.kampyle.com https://img03.en25.com https://script.crazyegg.com https://www.youtube.com www.googleadservices.com https://pubads.g.doubleclick.net https://snap.licdn.com https://cdnjs.cloudflare.com/ajax/libs/tiny-slider/2.9.1/min/tiny-slider.js https://geolocation.onetrust.com https://vidassets.terminus.services https://acrobatservices.adobe.com; connect-src \'self\' https://*.t.eloqua.com https://*.adobe.io https://*.go-mpulse.net https://portal.webolytics.com https://px.ads.linkedin.com https://*.brightfunnel.com https://*.analytics.google.com https://*.google.com https://ibc-flow.techtarget.com https://cdn.linkedin.oribi.io https://udc-neb.kampyle.com https://www.google.com.pa https://s.getsmartcontent.com https://chat-messaging.terminus.services https://www.gstatic.com https://maps.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/mapConfigs https://reverseads.matomo.cloud wss://a1kkx7muourfsi-ats.iot.us-east-1.amazonaws.com https://chat-visitor-info.terminus.services https://iotas.terminus.services https://chat-team-management.terminus.services https://di3c8wks3odob.cloudfront.net https://realtime.ramblechat.com https://idx.liadm.com/ https://geolocation.onetrust.com/ https://api.brightfunnel.com https://analytics.google.com https://*.leady.com/ https://tracking.reactful.com https://resources.digital-cloud.medallia.eu https://visitor.reactful.com *.crazyegg.com https://www.facebook.com/ https://connect.facebook.net/ https://cdn.cookielaw.org/ https://stats.g.doubleclick.net/ https://www.google-analytics.com http://*.hotjar.com:* https://*.hotjar.com:* https://vc.hotjar.io:* https://surveystats.hotjar.io wss://*.hotjar.com https://script.crazyegg.com/* https://api-public.addthis.com https://*.addthis.com https://privacyportal-de.onetrust.com/ https://*.akstat.io https://*.akamaihd.net https://acrobatservices.adobe.com; object-src blob: ; frame-src https://connect.services.global.ntt https://racecenter.letour.fr https://block.opendns.com https://td.doubleclick.net https://ssp2.gin.ntt.net https://www.google.com.pa https://10155546.fls.doubleclick.net https://resources.digital-cloud.medallia.eu https://extraordinary-platypus-f5e0bb.netlify.app https://nttbdttour.netlify.app/ https://cm.euprod.services.global.ntt https://www.youtube.com https://www.google.com https://youtu.be https://acrobatservices.adobe.com', '[nonce]', $str('\'nonce-') + $(randomNonce) + $str('\''))) NTT Ltd. moves security operations back to the office

Moving security operations back to the office – NTT Ltd.’s experience

by Quentene Finnegan

06 August 2020

A person holding a laptop bag and mask

Topics in this article

Moving a global SOC to Distributed Workforce

Without doubt the last few months have been hugely challenging for all of us. But, hopefully we’re all now looking forward to the future and how we can learn from our unique experiences of dealing with COVID. Many of us who recently experienced the mad dash of getting everyone Working From Home (WFH) are now navigating the even harder task of returning to the office, and the provision of a safe working environment. NTT Ltd’s own security operations are moving through exactly this process right now, and our experience could be relevant to clients and others in the industry.

Lockdown was imposed in most countries where we maintain Security Operations Centers (SOCs) literally overnight. Everyone was expected to WFH, while maintaining strict security levels for clients. Fortunately, as a company with years of experience in collaborative workspaces and with access to some of the best brains in the business, we initiated our Business Continuity Plan and successfully implemented a smooth and successful transition to WFH.

A woman working from home with her baby

We had to rapidly activate our Business Continuity Plan and get all of our people working from home

Planning a phased return

However, just as we were all thinking what a great job we’d done, we realized that all of our focus had been on WFH and, in reality, we’d not considered the task of getting people back to working in the office during a pandemic. At the same time, many of the internal and external organizations they collaborate with would remain remote in the near term. In essence, our security operations needed to move to a distributed workplace.

Preparing ourselves, our facilities and our colleagues to return to work has been a massive undertaking. We formed a committee comprising HR, facilities, corporate risk, IT, finance, marketing and individual business leaders within the company. Together we planned how we could provide safe, socially distanced working environments, across multiple and shifting regulatory guidelines. I’m proud to say that on July 6th we welcomed back our critical Secure Operating Centre (SOC) staff across six countries.

People wearing in masks bumping elbows as a greeting

We had to rethink a lot of things that we take for granted to ensure our people safe when they returned to the office

Obvious things such as socially distanced workstations, perspex shields everywhere, hand sanitizers at every door (I’m now an expert on hand sanitizer alcohol content!), and the provision of masks were straight forward. But the most challenging aspect by far were all the things we normally take for granted. For example, we had to consider our air-conditioning and ventilation systems, re-think the provision of tea and coffee facilities (especially access to biscuits!), and consider how people physically move around the office with one-way flows, etc.

In addition, we decided that to protect our colleagues as much as we could we’d provide rapid COVID testing kits and temperature testing equipment - both of which are completely new to our normal working practice.

As everyone says, ‘we’re living in unprecedented times’ and despite all of our plans, we’re having to deal with challenges daily, such as temporary reclosure in some locations.

Looking ahead

My advice after all this is to build your team across as many business areas as possible and to listen to everyone’s advice and experience. Take the time and invest in the effort required to make everything as safe as possible, but be pragmatic (for example, do we really need a $30k thermal camera when a digital thermometer costs $100?). Share information, don’t horde it and remain flexible (COVID doesn’t care about processes). Communication with stakeholders and colleagues is vital to any venture. Finally, our greatest asset is your people, so treat them with the greatest of care and ensure that everything you ask them to do you’re prepared to do yourself.

Quentene Finnegan

Quentene Finnegan

Chief Operating Officer, Security Division, NTT Ltd.