Customer story · Hospitality & Travel
Case Study: Internova Travel Group (ITG)
Internova Travel Group, a global travel brand headquartered in New York City, engaged Avertium for managed security services and PCI-as-a-Service, halving security alarms and extending visibility from 350 million to 600 million events.
Published by Avertium
About Internova Travel Group (ITG)
Internova Travel Group (ITG) is a global travel brand headquartered in New York City. It has a vast network of travel advisors and counts Fortune 500 companies and banks among its customers, so a large amount of personally identifiable information (PII) and payment card data flows through the organization. Max Goldfarb has shaped Internova's technology and cybersecurity infrastructure since 2013 in roles including Chief Technology Officer and Chief Information Security Officer.
The challenge
Internova handles large volumes of customer PII and Payment Card Industry (PCI) data, and while many travel companies still run mainframes in the back end, the company has long been forward-thinking about technology and security. The threat landscape had changed dramatically over the past decade, and Goldfarb's security team consisted mostly of annex management and auditing staff, which made it a challenge to monitor and manage the environment comprehensively, 24x7x365.
Goldfarb wanted human expertise added to the management, monitoring and rule configuration of Internova's security tools so the internal team could stop being bogged down by alerts and focus on strategic priorities. He also needed to move PCI DSS compliance from a legacy, check-the-box approach, which created inefficiencies and inaccuracies, to a proactive model, and to put the organization on the path to HITRUST and ISO 27001.
Phishing was the most pressing threat because of Internova's broad travel agent customer base, and the internal team needed time and space to train the whole company on preventing, identifying and responding to cyber threats. Internova's previous PCI vendor was rigid, did not understand the hospitality market and left the team with a fire drill ahead of every compliance deadline.
Our relationship with Avertium is a true rags-to-riches story. I never get a no. I get a ‘let’s figure something out.’ They always come back with options, even if they have to build something new just for me. Because of Avertium, I now know what we don’t know.
The solution
Goldfarb chose Avertium for managed security services because he saw it as an effective and reliable partner whose business-first, consultative approach matched his own. Avertium identified gaps in Internova's program and helped the internal team fill them, becoming Goldfarb's go-to advisor for building a long-term cybersecurity maturity program that can scale.
Avertium took a holistic approach that connected Internova's security work to the company's strategic goals. It provided a cybersecurity roadmap with tactical 30-60-90-day plans, made recurring recommended changes to the company's Security Information and Event Management (SIEM) platform, and delivered monthly threat briefings to Internova's security team. Avertium also added 30 new filtering rules across Internova's firewall devices, covering threat intelligence, PCI behaviors and indicators of compromise, and acquired more data sources and adjusted log sources to extend visibility.
For compliance, Avertium replaced the rigid, deadline-driven PCI process with a PCI-as-a-Service program that continuously gathers inputs and makes adjustments ahead of the audit horizon. Instead of scrambling to collect information in the three months before an audit, Goldfarb's team gained the space to act on issues as they arose. Avertium's teams now operate as an extension of the Internova team, with monthly stand-ups that balance cyber strategy with tactical recommendations.
The results
- Security alarms cut by 50%, from 2,800 to 1,300, after 30 new firewall filtering rules were added
- Visibility extended from 350 million to 600 million events through new data and log sources
- Events per second doubled through more effective monitoring and continuous tuning
- PCI-as-a-Service replaced pre-audit fire drills with a continuous, proactive compliance process
- Internova has never failed a customer security audit, and its security posture now helps win and retain clients
- Team now tracks KPIs such as event totals, alarm totals, escalated alarms and false positive rates
Get the full case study
Download the original document as published by Avertium (PDF, 1.9 MB).
Your story could be next
Want results like these?
Every result on this page started with one conversation — let's have yours.


