Inside Track: Security horrors still being ignored

Longform
(Image: Stockfresh)

9 March 2015

Addressing requirements
“Security is about covering all the bases; a defender needs to manage all vulnerabilities, whilst an attacker needs to exploit only one” eoin_keary BCC Risk Advisory: Eoin Keary, CTO
A number of factors are driving the need for managed security services (MSS), namely expertise, cost and consistency. Key concerns when considering an MSS should be included as detailed below.Cost: The associated cost benefits of using some MSS providers may appear a very attractive proposition. MSS provides the ability for a company to have deep security expertise without the associated cost of full time employees. For example our edgescan service gives our clients access to our security engineering team whom manage the security posture of their assets. A managed service should give you the ability to reduce your capital expenditure and control your security-spend without sacrificing quality.

Using an MSS, you can maintain your security posture but reduce overall cost of ownership.

Accuracy: Security is about covering all the bases; a defender needs to manage all vulnerabilities, whilst an attacker needs to exploit only one (vulnerability).

Accuracy covers two aspects of MSS. Firstly the ability to detect and manage discovered vulnerabilities with confidence and secondly to reduce the time required by the business to patch, fix or configure due to the quality of the vulnerability information delivered via the MSS provider.
For example, our clients value the hybrid approach we have to vulnerability management which involves human validation of every discovered vulnerability and results in virtually “false positive free” security intelligence. Your MSS should provide you with accurate, actionable security information.
Compliance and continuous management: Threat and Vulnerability management and meeting compliance requirements via a 24/7 security assessment remain the primary drivers for considering an MSS. Internal threat and vulnerability management can be costly from a staff and tooling standpoint. Your MSS should assist with demonstrating compliance and continuous improvement via management information dashboards and extensible API calls for integration into your technology “stack”.

MSS can also assist you in reallocating existing resources to other security areas, or the need to engage deeper or broader expertise than is available in-house. Your MSS should address requirements where you do not have in-house expertise.
Edgescan is a managed security service developed, managed and delivered by BCC Risk Advisory. It is a cloud based vulnerability management platform and helps clients discover and manage system vulnerabilities on an ongoing basis. It significantly reduces the cost of ownership while increasing cybersecurity resilience significantly.

The edgescan service provides continuous vulnerability assessment coupled with a customised reporting portal and APIs set to help you understand what vulnerabilities your business faces. It assesses the security of both web/mobile applications and associated servers, or indeed any deployed systems, giving you “full-stack” vulnerability management.

 

Two types
“You cannot manage for improvement if you do not measure and chart the performance for better or worse” John_ryan_ceo_zinopy_web
Zinopy Ltd: John Ryan, CEO
“There are two types of companies: those who have been hacked and those who don’t yet know they have been hacked,” John Chambers, CiscoThis raises a number of questions for IT departments and beyond as cyber security rapidly evolves from a niche IT issue to a consumer and boardroom priority.

So how can businesses like yours safeguard intellectual property, customer data and most importantly your brand, when you are exposed to more attacks, from increasingly sophisticated attackers?

And then there is the biggest question of all: how do you know?

In short, you cannot manage what you do not measure. You cannot manage for improvement if you do not measure and chart the performance for better or worse.

But you can use a Zinopy Managed Security Service to provide the metrics, monitoring and management to address the security, compliance and risk analysis requirements of your organisation. Zinopy has the in-house skills and employs world-class toolsets to deliver features including log management, advanced correlation and threat management, forensic analysis, audit readiness, enhanced reporting, full range of dashboards from operation to management.

The benefits are manifold:
• Improved protection of infrastructure, information and interactions.
• Customer control of an on-premise or off-premise solution.
• Compliance with control objectives.
• Support for in-house staff providing security expertise.
• Fixed cost for enterprise-wide protection with a flexible subscription model.
• Full visibility through Regular Reports / Console Access

 

Security posture
“The risk to a business’ data and its customer’s information is often all too great not to implement a managed security service” darragh_fegan_symantec
Symantec: Darragh Fegan
The key concern for an organisation when considering a Managed Security Service is ensuring they are significantly increasing their security posture by implementing a high-performance, comprehensive security infrastructure that is resilient, trustworthy and cost effective.At Symantec, we help our customers by removing the need to manage the increased complexity and scale of cyber threats. This allows organisations to eliminate the worry of whether they have the adequate level of in-house security expertise and experience to identify and manage the new sophisticated threats that we see today.

One of the obstacles Symantec comes across, is the customer concerns over ‘letting go’. However, as CSO’s and IT managers face the day-to-day reality of combating the relentless battle against these threats they are increasingly turning to Symantec to assist them. The risk to a business’ data and its customer’s information is often all too great not to implement a managed security service.

The costs associated with building and maintaining an in-house cyber defence are great. For that reason, organisations around the world look to our Managed Security Services to build and sustain a resilient incident management program for them.

Our managed security services offers a global presence and scale to satisfy the largest of enterprises. Every month, we analyse over 275 billion log entries, alongside identifying more than 40,000 potential security events and escalate over 4,000 validated, severe events.

We offer a cost effective solution that allows customers to leverage security analysts and professionals to secure their business, and more importantly provide organisations with the visibility and monitoring across their IT estates. Symantec Managed Security Services allows organisations to put focus back into other critical aspects of their business while we protect their valuable and critical assets.

 

Read More:


Back to Top ↑

TechCentral.ie