Endpoint

An effective cyber risk management strategy includes a deep understanding of the range of persistent cyber threats, a robust assessment of their potential impact, plans for both cyber risk prevention and response, and a management approach that reflects the role of all employees – from the boardroom to the backroom – in implementing cyber defenses.

Detect Services

Detect provides the enhanced visibility your organisation needs to improve its cyber security posture by:

  • Extending detection capabilities beyond network-based monitoring.
  • Identifying threats missed by traditional preventative security.
  • Helping to quickly identify the root cause of attacks.
  • Hunting for threats that exhibit suspicious patterns of behaviour.

Vulnerability Assessment

Vulnerability assessment helps you to understand how vulnerable your critical assets are to cyber-attacks.

  • Gain visibility of assets to understand how vulnerable your critical assets are.
  • Understand effectiveness of defensive controls, vulnerability assessment reviews the capability of your internal and external defences.
  • Improve cyber security planning by prioritises your organisation’s cyber security risks to highlight those requiring greatest attention.
  • Meet regulatory and government security requirements (e.g., POPI, GDPR, ETC.).

Patch Management

Ransomware And Malware Services

Ransomware incidents can impose significant operational and financial costs on organizations. Recently, organizations across 150 countries fell victim to the WannaCry outbreak.

  • Determine the initial point of entry and root cause of the attack.
  • Identify the full scope of system(s) targeted with ransomware.
  • Explain the type of data affected by the ransomware attack.
  • Explain the type of data affected by the ransomware attack.
  • Conduct ongoing monitoring and hunting.

Mobile

Managed Compliance Monitoring

Compliance failures can seriously endanger your organisation’s reputation.

Security Policies

  • Improved productivity and introductory policies and standards, including information security management structure and responsibilities.
  • Organize information security policies and standards into meaningful categories.
  • Information classification and control.

Security Controls

Security controls must be kept up to date multiple times to meet the demands of an evolving threat and vulnerability landscape.

  • Discover your information assets and estimate their value; think through potential attacks against those assets.
  • Assess the organization’s current state of information security controls as compared best practices.
  • Fill the priority gaps first and focus on remedies that you can achieve in the short term.

System Hardening

A hardened system is one that is fundamentally secure and rendered hack-proof. Hardening a device requires known security ‘vulnerabilities’ to be eliminated or mitigated.

  • A secure, locked down configuration requires care to achieve a good balance between security and operational function.
  • Benchmarks, authoritative hardening checklists for all platforms, database systems and applications.
  • Windows, Linux and Unix platforms.
  • Database Systems such as SQL Server, Oracle, DB2 and MySQL.
  • Applications such as web servers, email servers, LDAP, DNS and Browsers.

Data

Any information that your business stores digitally needs to be properly protected. From financial information and payment details to contact information for your staff and customers.

Data Activity Monitoring (Dam)

  • The ability to independently monitor and audit all database activity, including administrator activity.
  • The ability to store this activity securely outside the database.
  • The ability to aggregate and correlate activity from multiple heterogeneous Database Management Systems (DBMSs).
  • The ability to enforce separation of duties on database administrators.

Data Access

There are many types of insider attacks; both malicious and unintentional. Monitoring the actions of these users is paramount for security and compliance reporting.

  • System sabotage: This type of attack is malicious in nature and usually consists of a disgruntled insider destroying data or rendering an operating system or applications unusable in some way.
  • Theft of assets data or: Usually malicious, this attack can be very difficult to identify and may be one of the most damaging overall.
  • Introduction of “bad code”: An attack of this nature may be deliberate or accidental.
  • Introduction of malware: This is an attack that may not be deliberate in nature; many malware infections are unintentional.
  • Social engineering: It is often said that the weakest link in the chain of security is people, and by exploiting them, insiders can easily bypass policies and controls.

Database Vulnerability Assessment

  • Looks deeper than patch levels, down to specific configurations and even an analysis of user entitlements.
  • Database inventory and user accounts – DBAs, root, system admins – which have access to the database.

Networks

Network forensics is categorized as a single branch of digital forensics; it includes the areas of monitoring and analysing computer network traffic and allows individuals to gather information, compile evidence, and/or detect intrusions.

Network Forensic Monitoring

  • Find proof of attacks—whether they’ve just begun or occurred days ago–so that IT engineers and security teams can understand the attacks and stop them.
  • Apply filters to isolate malicious behaviour.
  • Equip your network IT team with a powerful incident response to Pinpoint a Security Attack.

Managed Firewall

Managed Firewall – “Through 2018, more than 95 percent of firewall breaches will be caused by misconfigurations, not firewall flaws.”

Stolen data fuels a highly profitable cybercrime economy and organizations are constantly under attack. The risk of data breach drives the need to add more security and the need to see and control network traffic, especially at the network perimeter or between network segments within an organization.

  • Improved TCO and reduced costs. To provide your organisation with ample protection against complex security threats, it is necessary to deploy multiple technologies such as threat prevention applications, an Intrusion Prevention System (IPS), firewalls, and content filtering systems.
  • 24×7 firewall administration, log monitoring, and response to security and device health events.
  • Protect systems and data: 24×7 monitoring to alert you to threats before damage is done.
  • Which rules allow this access.

Segmentation

Network segmentation is a best practice to enable the enterprise to add additional layers of protection around sensitive data to isolate these assets from the touch of would be hackers and unauthorized users.

  • Visualize and manage network segmentation.
  • Centrally alert on policy violations.
  • Visibility to better manage network security policies and network segmentation.

Patching

Vulnerabilities multiply like fruit flies. You can spot them, sure. But how do you know what to patch? Which patches could go from exposure to exploit?

  • Mapping vulnerabilities and seeing their pathways to exploit.
  • Patch simulation patches systems virtually so you can compare various patch scenarios to prioritize efforts to those with the biggest impact.
  • Patch systems virtually, re-run a complete analysis in seconds and compare various patch scenarios to ensure the biggest impact on efforts.

Threat Intelligence

Cyber Threat Intelligence Services design and build cyber threat intelligence (CTI) processes and solutions within your security operations to optimize your ability to consume, analyse and apply threat intelligence to protect the business.

Advisory

  • Anticipate, identify and prioritize threats to reduce exposure and adapt defences.
  • Assess risk based on the adversary’s motivation, capability and impact.
  • Contextualize and communicate cyber threats across business operations.
  • Better align security resources to the most relevant, impactful threats.

Gap Analysis

An information security gap analysis is a critical step in the Business Continuity Planning process and is a form of risk assessment. A gap analysis is designed to determine the differences between the present state of information security within an enterprise and its ideal, or optimum state.

  • Quite possibly the most important benefit of conducting a gap analysis is that it identifies a beginning point from which an organization can measure its improvement over time.
  • Gap analysis can frequently identify capabilities that already exist within an organization, offering the ability to promote these capabilities rather than adopt new ones.
  • Gap analysis can diagnose problems and provide recommendations on how to solve these problems. Since it enables long-term planning by setting goals and outlining changes and practices.

Proactive Services

Having spent over a decade breaking into most targets, we have a very good understanding of what it takes to make them more robust and secure.

Indicators Of Compromise

In the quest to detect data breaches more quickly, indicators of compromise can act as important breadcrumbs for security pros watching their IT environments.

  • Anomalies in Privileged User Account Activity, the name of the game for a well-orchestrated attack is for attackers to either escalate privileges of accounts they’ve already compromised or to use that compromise to leapfrog into other accounts with higher privileges.
  • Other Log-In Red Flags, Log-in irregularities and failures can provide excellent clues of network and system probing by attackers. Check for failed logins using user accounts that don’t exist — these often indicate someone is trying to guess a user’s account credentials and gain authorization.
  • Swells In Database Read Volume, once an attacker has made it into the crown jewels and seeks to exfiltration information, there will be signs that someone has been mucking about data stores. One of them is a spike in database read volume.

Internet Of Things (Iot)

Fast forward to this year, and the idea of having I-P on everything does not seem so far away. More devices that used to be offline, are becoming online devices every day. The growth of IoT devices will have important implications for everyone especially those which are providing IT support and services.

The growth of IoT

The growth of IoT devices will have important implications for everyone especially those which are providing IT support and services.

Privacy And Confidentiality

The types, amount, and specificity of data gathered by billions of devices create concerns among individuals about their privacy and among organizations about the confidentiality and integrity of their data.

Security

Not only will organizations that gather data from billions of devices need to be able to protect those data from unauthorized access, but they will also need to deal with new categories of risk that the Internet of Things can introduce.

Training

Education Services enhance your team’s operational skills and improve their ability to prevent, detect, and respond to cyber attacks.

  • Education Services enhance your team’s operational skills and improve their ability to prevent, detect, and respond to cyber attacks.
  • We follow a proven training methodology that is enhanced by our significant experience responding to real-world attacks.
  • We help our clients respond to sophisticated security breaches daily — we are able to leverage our understanding of attackers’ methodologies, tools and tactics to identify security vulnerabilities.

Awareness

Campaigns