Carnival Corporation is the largest global cruise company and among the largest leisure travel companies, with a portfolio of world-class cruise lines – AIDA Cruises, Carnival Cruise Line, Costa Cruises, Cunard, Holland America Line, P&O Cruises, Princess Cruises, and Seabourn. Carnival Corporation trades under the ticker symbol CCL on the NYSE and is included in the S&P 500.
Behind Carnival Corporation’s mission to deliver happiness is a silent security engine protecting a complex digital ecosystem across 90+ ships. With SentinelOne on board, the global cruise company has established pervasive visibility across both fleet and shoreside operations, reducing threat detection time by 94%, cutting triage time by nearly 90%, and helping safeguard the critical shipboard systems behind every voyage.
Behind Guest Happiness: Navigating a Complex Digital Ecosystem
At Carnival Corporation, the overarching corporate directive is to deliver unforgettable guest experiences. Operating a global portfolio of eight distinct cruise lines across more than 90 passenger vessels, the enterprise brings this promise to life through complex operational layers, spanning world-class dining, digital hospitality networks, retail hubs, casinos, onboard medical centers, and massive physical propulsion plants.
Securing this infrastructure requires managing a digital ecosystem that acts as a network of self-sustaining floating cities moving across international waters.
“We protect shoreside environments, but one of the most important parts of our role is protecting our floating cities around the world,” explained Margarita Rivera, Global Chief Information Security Officer at Carnival Corporation.
In this high-stakes environment, operational downtime directly impacts consumer safety, brand reputation, and corporate continuity. Architectures run deeply specialized systems where data disruption can create immediate cascading effects across navigation, life safety, and transaction perimeters.
“I remember going aboard a ship for the first time as CISO, standing on the bridge, looking at all the technology and realizing the seriousness of what we do,” Rivera said. “Shipboard systems support the guest experience as well as navigation, propulsion and operations. Anything that changes the expected experience aboard our ships is a problem.”
Scaling Autonomous Protection Across 85,000 Endpoints
Prior to deploying SentinelOne, Carnival Corporation’s landscape was fragmented across roughly five antivirus solutions. This decentralized mix introduced administrative complexity, making it difficult to maintain unified asset visibility or execute synchronized incident response across shoreside and maritime operations. During side-by-side technical proofof-concept testing, the platform instantly validated its capabilities.
“SentinelOne caught an incident that every other tool missed. That gave us confidence,” recalled Alex Tabares, Associate Vice President, Threat Management and Intel, Carnival Corporation. “The platform could work at global scale, simplify a complex environment, and bring visibility and speed to protect the business.”
The resulting implementation shattered historical enterprise deployment timelines.“We reached 85,000 endpoints in three months instead of an expected three years,” Tabares said. “Instead of spending so much time managing the tool, we could focus more on protecting the environment.” Singularity Network Discovery helped close protection gaps, while Singularity RemoteOps kept the rollout moving by giving the team a faster way to troubleshoot agent issues remotely.
Faster Response Across Fleet and Shoreside Operations
Operating nearly 100 massive vessels means defending systems where stable satellite connectivity is not guaranteed. SentinelOne addresses this challenge by embedding local behavioral AI models directly into the edge agent, allowing the platform to independently inspect execution chains, block anomalous files, and execute automated remediations while entirely offline.
“On ships, connectivity isn’t always guaranteed,” Tabares said. “SentinelOne gives us endpoint protection that can keep working even offline, and that kind of resilience is critical in our environment.”
Carnival Corporation also integrated the unified Singularity console with their monitoring partner’s internal operations stack, cutting latency from their detection pipeline. With roughly 2 billion events flowing through the environment each quarter, filtering that volume down to a small set of true positives is what makes fast detection possible in the first place.
“We went from about 90 minutes down to five minutes for threats to reach analysts,” Tabares said.
Adding another layer of speed, the team leverages Singularity RemoteOps to instantly open secure, remote administrative loops on compromised systems anywhere in the world. Analysts can immediately gather advanced forensic logs, run custom inspection binaries, or completely isolate a machine from the vessel network without needing local IT or end-user intervention. In one notable incident, when a critical shipboard point-of-sale file was erroneously quarantined, the SOC used RemoteOps to safely verify and restore access fleet-wide in minutes, avoiding a manual machine-by-machine recovery process.
Extending Protection to Hard-to-Reach Environments
Beyond deployment, Singularity Network Discovery supports the team in closing visibility gaps by identifying devices that still need protection. Scripts can initiate SentinelOne installation on those machines, helping the team extend protection across a complex, constantly changing environment.
To reduce risk to air-gapped operational systems, the team collaborated with their dedicated SentinelOne Technical Account Manager (TAM) to engineer a rigorous, fleet-wide USB scanning framework. Before any external flash drive can be introduced into critical shipboard engineering or control nodes, it must pass through a dedicated checkpoint terminal running advanced Singularity inspection scripts to guarantee the media is clean.
“Our TAM has been incredibly responsive and valuable,” Tabares said. “It’s almost like having another analyst in the SOC who is a subject matter expert on the Singularity Platform, helping us move much faster.”
As Carnival Corporation’s security needs continue to evolve, they have integrated Purple AI to accelerate investigations, triage, reporting, and proactive threat hunting. Rather than manually building complex query syntax across third-party log aggregation utilities, analysts use natural language prompts to search across the environment, and quickly find suspicious executables, known-bad hashes, or other indicators before related activity can impact the business.
“Before, the team used to have to look through logs, look at machines, and write a query in Splunk,” Tabares said. “Now we have that information at our fingertips with Purple AI.”
Of the roughly 2 billion events Carnival Corporation generates each quarter, only about 300 rise to the level of true positives requiring analyst follow-up. Purple AI is central to that filtering, and once a real signal surfaces, it accelerates tactical triage time by nearly 90%, turning a tedious two-hour manual log review into an automated 10 to 15-minute verification loop. Beyond raw data interrogation, Purple AI’s natural language summarization engine converts complex forensic timelines into clean, executive-ready summaries that help the CISO articulate threat scope to corporate leadership.
The team also brought containerized environments under protection and is building Singularity Hyperautomation workflows that reduce manual effort and improve SOC efficiency.
Strengthening the Silent Engine Behind the Guest Experience
As Carnival Corporation continues to expand its technology roadmap, they are utilizing Prompt Security to establish a granular layer of visibility over internal prompt interactions, preventing confidential corporate assets, PII, and financial records from leaking into public language models.
“Prompt Security has been incredible for our organization. It gives us a first layer of visibility and protection to help control AI usage across the environment and better protect our information assets,” Rivera said.
For Rivera, SentinelOne strengthens the silent foundation behind the smooth guest experience, not only through faster protection and response, but through a partnership that can continue evolving with Carnival Corporation.
“Guests book because they want joy, connection, and adventure. They want to have fun and create memories,” Rivera said. “When security works well, it’s practically invisible. SentinelOne helps support that silent engine, keeping systems secure so the guest experience can stay as seamless as possible. They are a true partner in our technology strategy.”







