Blind spots. Burnout. Borderless risk.
To maintain its position as a market leader, Puntos Colombia needed to overcome several critical security and operational hurdles:
- Limited ecosystem visibility: The organization struggled to achieve real-time visibility across its technology stack, leading to potential blind spots in a rapidly expanding AWS environment.
- Operational fatigue: A traditional SOC model generated thousands of weekly issues, creating a high manual workload that hindered the team’s ability to pursue strategic security initiatives.
- Hybrid work security gaps: Transitioning to a hybrid work model required securing remote access to business applications and protecting data in transit without relying on a traditional network perimeter.
- Browser-level vulnerabilities: Standard browsers lacked the granular control needed to prevent data leakage during user activity within web, SaaS, GenAI, and private applications.
“Adopting a platform approach has allowed us to simplify operations, reduce technological fragmentation, and obtain a more coherent view of risk.”
— Andrés Alvarez
CISO, Puntos Colombia
A unified platform for digital transformation.
The collaboration between Puntos Colombia and Palo Alto Networks has been strategic and evolutionary, enabling the company to move away from isolated tools toward a unified architecture that mirrors its digital transformation. By deploying a comprehensive suite—including Cortex XDR, Cortex XSOAR, Cortex Cloud, Prisma Access, Prisma Browser, and hardware and software firewalls—the organization has integrated prevention, detection, and response capabilities into a single fabric. This journey has allowed Puntos Colombia to reduce complexity and increase efficiency, providing a coherent way to protect millions of transactions while maintaining the agility of a leading fintech-retail hybrid.
PATH TO PLATFORMIZATION
-
Revolutionizing threat detection and visibility
The implementation of Cortex XDR transformed Puntos Colombia’s ability to identify threats by correlating telemetry across endpoints, network, and cloud. Its Cyber Defense Center, monitored by partner Netdata and powered by the Cortex platform, integrates 15+ data sources into a unified view, eliminating the silos of information that previously led to delayed responses. “This has been key for the organization to move from reacting to events to early intervention in the attack chain,” explains Paulo Cadena, Director of Security and Risk Management. “It significantly reduces detection time and speeds up decision-making.” By providing a single, coherent incident narrative, the platform reduced the MTTR by 5x and MTTD to just four minutes—a stark contrast to the days or hours required under the previous legacy infrastructure. Analysts can now also detect anomalous behaviors, centralize investigations, and identify lateral movements with greater precision.
“Today with Cortex XDR, we have a more robust capability to identify suspicious behaviors from early stages thanks to correlation between multiple telemetry sources and behavior-based analysis. This has given us greater control over threat containment and has increased the team's confidence in their ability to prevent critical scenarios before they materialize.”
— Andrés Alvarez
CISO, Puntos Colombia
-
Scaling IR through orchestration and automation
To combat the massive volume of incoming alerts, Puntos Colombia integrated Cortex XSOAR to orchestrate and automate incident response workflows. By using playbooks that integrate multiple tools and information sources for common tasks (such as phishing analysis and indicator blocking), the team leverages automation to handle 99% of the company’s 9,000 monthly security events. This dramatically optimized the team's operational workload, allowing them to transition from constant manual triaging to strategic oversight and high-priority security engineering projects.
-
Proactive cloud posture management
As a cloud-first organization, Puntos Colombia uses Cortex Cloud to continuously maintain a unified view into its AWS infrastructure. The platform enables security analysts to identify misconfigurations and vulnerabilities before they become incidents and ensure that the rapid pace of DevOps doesn’t outpace security requirements. Cadena adds that having the context to prioritize findings that require immediate attention versus which have a lower impact will improve the speed and consistency of the response to cloud threats.
“The ability of Cortex Cloud to integrate code security, configurations, identities, and workloads into a single solution allowed us to avoid fragmentation and better prioritize risk based on the real context of the environment.”
— Paulo Cadena
Director of Security and Risk Management, Puntos Colombia
-
Establishing a zero trust foundation
To secure its distributed IT environment, Puntos Colombia deployed Prisma Access with Next-Generation Hardware and Software Firewalls, transitioning from a traditional perimeter to a Zero Trust Network Access (ZTNA) model. Next Generation firewalls deliver deep traffic inspection, granular application control, and environment segmentation to reduce the attack surface through a risk-based segmentation model. At the same time, Prisma Access protects remote users with consistent, policy-driven access to corporate applications—independent of traditional network boundaries.
The combination of SaaS Security and Enterprise DLP has been fundamental in maintaining control over sensitive information residing in the cloud, ensuring compliance and data integrity. By integrating these capabilities, the IT team has successfully silenced alert noise and reduced false positives, enabling them to focus on high-value alerts rather than manual triaging. Centralized security policy enforcement across AWS cloud workloads and physical office locations ensures that every connection is verified and monitored in real time. This foundation significantly reduces the attack surface while providing the high-performance connectivity required for a secure and seamless user experience.
-
Closing the last mile with Prisma Browser
With the desire to address vulnerabilities where daily work for the team happens, Puntos Colombia adopted Prisma Browser. The secure browser gives the security team granular visibility and control over user activities in web, SaaS, GenAI and private applications that standard browsers can’t offer. With Prisma Browser, the organization can prevent unauthorized data exposure, such as pasting sensitive transactional data into risky websites or taking screenshots within internal applications. This “last-mile” protection ensures that users are protected from cyber threats and sensitive data is secure from data exposure risks.
“Prisma Browser didn’t just expand our visibility. It made it more relevant and actionable.”
— Andrés Alvarez
CISO, Puntos Colombia
Collaborative defense for long-term digital business growth.
Puntos Colombia views its relationship with Palo Alto Networks as a strategic alliance rather than a transactional vendor-customer arrangement. Moving forward, the company intends to continue maturing its platform approach to ensure that security remains an enabler of business sustainability and digital growth. By maintaining a shared vision of risk and centralized visibility, the security and development teams are positioned to collaborate more effectively, ensuring that every new interaction in the Puntos Colombia ecosystem is protected from the start.
“We’ve seen tremendous value in having a technological ally aligned with a platform vision rather than isolated solutions. This has allowed us to integrate prevention, detection, and response capabilities, reduce complexity, and increase operational efficiency.”
— Andrés Alvarez
CISO, Puntos Colombia