Café Zupas Extends WatchGuard Simplicity and Protection from the AWS Network to the Endpoint
Challenge
Café Zupas first opened its doors in 2004 with the desire to create a family-friendly restaurant where their guests could enjoy a quick meal without compromising on the nutritional benefit that real homemade food provides. To do that, Café Zupas has a clear, company-defining mission “to make each soup by hand, each dressing and sandwich spread from scratch and create dishes just as you would at home.” While others in the industry doubted it could be done, and particularly at scale, Café Zupas found a way to never sacrifice quality for convenience. Today, Café Zupas serves their “house-made” food at nearly 70 locations across eight different states.
As a company in the hospitality industry, Café Zupas is a prime target for cyber-attack. “Being in hospitality, we are one of the most heavily targeted industries for hackers looking for credit card numbers or personal information. We have to stay ahead of the cyber criminals and on top of our PCI DSS compliance audits. We are constantly evaluating security products to make sure we have the best solutions we can for our hybrid network environment,” explained Wes Beaman, CIO at Café Zupas.
Solution
Café Zupas, a longtime WatchGuard customer, deployed their first set of Fireboxes in 2014. Today, they continue to trust WatchGuard to secure their hybrid network and restaurants - with a physical Firebox T45 deployed at each location, physical Firebox M390s at the corporate headquarters and virtual Firebox Cloud instances to secure their Amazon Web Services (AWS) Virtual Private Cloud (VPC) environment. Specifically, WatchGuard’s Firebox Cloud is designed to extend robust network security into AWS by leveraging core AWS infrastructure services. First, Firebox Cloud is deployed as an Amazon Machine Image (AMI) within Café Zupa’s VPC which allows them to apply WatchGuard's advanced threat prevention capabilities, such as intrusion prevention, malware detection, and web filtering, to their AWS-hosted applications and data. Secondly, it uses the AWS Elastic Compute Cloud (EC2) infrastructure to host Firebox Cloud, thus protecting Café Zupa’s many EC2 instances and other resources within their VPC.
Furthermore, the integration with AWS allows for flexible and scalable security deployments. Customers can utilize AWS's elasticity to adjust their Firebox Cloud resources based on their changing security needs. Additionally, the ability to integrate with AWS services like CloudWatch enables enhanced monitoring and logging of security events, providing valuable insights into the security posture of their cloud environments.
Results
The IT team at Café Zupas has come to expect simplified management and deployment with WatchGuard. “We were able to deploy the entire solution to all of our restaurant devices and corporate endpoints in less than a week. It was really very simple,” Beaman attests. In addition, with the use of WatchGuard Cloud which provides management an reporting for physical firewalls as well as Firebox Cloud in AWS. “The reporting is substantially better. With this deployment, my senior engineer expects to save at least two hours each week managing reports. With only six people on my team managing all of the company’s IT and security needs, that’s huge.”
Best of all, Café Zupas was able to consolidate their network, Wi-Fi and endpoint security solutions under one vendor that they’ve grown to trust. “I wanted to consolidate our security products under one vendor. With the addition of Endpoint Security products to WatchGuard’s already robust network security portfolio, I’m able to do that,” said Beaman.