Autoleague boosts security with BeyondTrust access management
Autoleague, a major player in Australia's automotive retail sector, has implemented a privileged access management platform from BeyondTrust to strengthen its password and network security across its national operations.
Autoleague operates over 60 franchises across Australia and employs around 2,000 staff who sell more than 60,000 vehicles annually, generating revenues in the region of AUD $3 billion. The company's operations include new and used car showrooms, after-sales service centres, and trading in boats and motorcycles, all supported by a sophisticated IT platform handling stock management, ordering, administration, parts inventories, and customer support.
IT platform demands
The IT platform at Autoleague not only supports frontline business operations at its dealerships, but also serves an administrative team based in Sri Lanka. This offshore team is responsible for a range of back-office tasks and requires secure, reliable access to Autoleague's Australian systems. The company needed a solution that would provide this access without the complexity of traditional virtual private networks (VPNs).
As cyber security requirements have increased and in light of complex cyber insurance obligations, Autoleague reviewed its approach to the management of administrator and user passwords. Ian Melton, Head of Information Technology at Autoleague, described the company's core challenge:
"We needed a way to separate admin logins from daily logins to reduce the likelihood of unauthorised access to the IT platform. We also recognised that persistent passwords are regarded as a security risk and needed to be removed from use."
Following a review of various security vendors, Autoleague selected BeyondTrust's Privileged Access Management (PAM) platform in 2022. The deployment enabled the firm to implement automated password rotation, which, according to the company, has improved security while reducing the management burden on users.
The BeyondTrust solution is used to automatically vault, rotate, and secure local admin account credentials. This has allowed Autoleague to avoid deploying and managing separate Local Administrator Password Solution (LAPS) accounts for emergency repair of domain trust relationships on roaming devices.
Remote access challenge
The addition of the Sri Lankan back-office team introduced further complexity, as the team operates from an office using a shared internet connection. Secure access between the remote team and Australian systems became a priority.
"We needed to have a way to let the Sri Lankan team have secure access into our Australian platforms," says Melton.
Autoleague decided to deploy BeyondTrust's Privileged Remote Access (PRA) capabilities. This allowed the overseas staff to access required resources through a secure tunnel, ensuring protection regardless of whether staff worked from the office or remotely from home. Melton summarised the benefit:
"Thanks to BeyondTrust, we now have in place industry-leading password and access management capabilities. This ensures our core systems remain protected but also readily accessible to those who require it. The result is that we can offer support to our national network of franchisees who can meet their client's needs."
Due diligence and acquisitions
The company has also applied its PRA solution during the due diligence phases of potential acquisitions. This is done to secure connectivity to the network of the company being acquired, allowing the safe sharing of information and reducing the risk of malware or other cyber threats entering Autoleague's own systems. Melton observed:
"It is often an overlooked part of the process. There is the onus on us to protect our resources and systems while conducting our due diligence."
Vendor partnership
Reflecting on the relationship with BeyondTrust, Melton said:
"BeyondTrust has proven to be a solid vendor with a great product portfolio. We were looking for a vendor who could cover our requirements for both Privileged Access Management (PAM) and Privileged Remote Access (PRA) capabilities, and BeyondTrust has industry-leading products in both categories. They took the time to fully understand our needs and ensured the deployments added real value to our operations."
Melton added that with both PRA and PAM tools now underpinning operations, he sees the environment as secure and robust, providing support for Autoleague's franchisees as the business continues to grow. The password management process has been streamlined, and remote teams report stable and secure connectivity. He commented:
"There are many security vendors from which you can choose, however BeyondTrust stands out because it has strong solutions in both the PAM and PRA spaces. I look forward to continuing to work with the company as a trusted technology provider."