Showing posts with label managed security services. Show all posts
Showing posts with label managed security services. Show all posts

Tuesday, October 13, 2009

In-the-Cloud Approach to Cyber Security


Security breaches or other unexpected interruptions can happen anytime to anyone -- whether you are a large enterprise or a small business. Fully maintaining communication network security is a demanding responsibility -- and typically not the best use of your limited IT resources, that would be better applied to delivering incremental new business technology benefits to your organization.

Fortunately, there are alternatives to a do-it-yourself comprehensive security solution. Skilled managed service providers continue to enhance their network security offerings.

AT&T announced the availability of Security Event and Threat Analysis and Security Device Management, two new managed security services available for businesses of all sizes.

Customized to Your Unique Business Needs

The services enable you to engage AT&T security professionals selectively and simply to provide customized security support. Services range from security event analysis and threat management analysis to targeted security device management including firewalls, intrusion detection sensors and VPN servers.

These new services use AT&T’s expertise in security analysis to evaluate, correlate, and report on information from multiple devices and device types, both on your premises and embedded in the AT&T network.

AT&T Managed Service Benefits Include:
  • Prioritizing security events based on threat and risk management methodologies using AT&T and customer-defined standards.
  • Rapid notification when security events are detected and identified as critical by the AT&T Security Network Operations Center.
  • Event mitigation and security analyst counseling during critical security incidents.
  • Global Security Operation Centers and 24X7 T1-T4 Analyst Coverage with portal access through AT&T’s BusinessDirect Portal.
With Security Device Management, AT&T provides complete, customizable monitoring and management of your security hardware and software, with a range of services including managing your organization’s current security capabilities up to assessing, designing and implementing a custom security infrastructure.

Full Suite of Professional Services
These new services are a natural complement to AT&T’s existing Security Consulting services, which include independent assessments of vulnerabilities inherent in customers’ networks, as well as the policy and procedures surrounding them. Security Consulting services include Log Management, Security Policy Management, Vulnerability Analysis, Application Security, Trusted Advisor services and Payment Card Industry Solutions.

AT&T delivers a suite of security and business continuity services to help assess vulnerabilities, protect infrastructure, detect attacks, and respond to suspicious activities and events. The upcoming AT&T Cyber Security Conference is an annual day-long conference offered by the AT&T Chief Security Office.

Tuesday, October 6, 2009

Managed IT Enhances JetBlue Business Model


New York-based JetBlue Airways created an airline focused on value, service and style. They've proven to be a trailblazer in the U.S. airline industry. They're also a communication technology early-adopter. JetBlue introduced complimentary in-flight e-mail and instant messaging services on their aircraft -- a first among U.S. domestic airlines.

However, their core competency is centered upon air travel. They out-task the rest to service providers, wherever possible.

JetBlue signed a new, six-year strategic agreement with Verizon Business to manage the airline's information technology ( IT) data center and communications network needs, as well as provide security and IT consulting services.

Built on an IP Network Foundation
Verizon Business will design and manage the transition of JetBlue's existing systems to a new global IT network infrastructure. The newly built Internet-protocol-based (IP) voice and data network will support state-of-the-art airport kiosks, wireless Internet access and an advanced reservation system.

"JetBlue has built a reputation of consistently providing excellent customer service," said JetBlue CIO Joe Eng. "The agreement with Verizon Business to strengthen our IT capabilities is further proof that we are taking the steps necessary to evolve our business to meet our customers' changing needs. With this enhanced IT infrastructure, JetBlue will be even better positioned for the future."

The new converged voice and data network will help support JetBlue's vision to deliver enhanced customer service and better collaborative tools for its employee crewmembers.

Verizon Business will connect JetBlue crewmembers, customers and partners to each other and the Internet. The infrastructure will serve as the foundation to deliver new customer and collaboration services -- including audio, net and video conferencing and enhanced contact center applications that will enable JetBlue's reservations agents to better serve customers.

Securing and Protecting Critical Data
Verizon Business will also manage the transition of JetBlue's data centers to Verizon's redundant managed service centers. In addition, they will manage the critical infrastructure components of JetBlue's internal systems including its data centers, voice and data networks and internal service desk -- ensuring continuous availability and improved resiliency and reliability.

Through its managed security practice, Verizon Business will help safeguard critical company data as well as ensure JetBlue meets strict industry requirements for secure credit card transactions online, over the phone and at the airport.

JetBlue currently serves 58 cities with 650 daily flights. In 2009, the carrier ranked "Highest in Customer Satisfaction Among Low-Cost Carriers in North America" by J.D. Power and Associates.

Wednesday, August 5, 2009

Next-Generation Managed Security Services


Reports of network attacks and stolen data are commonplace. Consumers routinely undergo the stress of fraudulent charges or compromised credit cards. Computer hacker terms like "botnet" are becoming a part of our everyday vocabulary.

As a result, enterprise security and risk professionals find themselves on a never-ending quest to maintain the integrity of their communication networks, according to the latest study by Forrester Research. Fortunately, managed service providers offer solutions to help relieve the burden.

In its latest initiative to help businesses protect their vital assets from cyber threats and other online attacks, Verizon Business is now offering its next-generation managed security services (MSS) platform, complete with new options.

This enhanced platform is designed to safeguard corporate networks by proactively identifying vulnerabilities and prioritizing threats across the extended enterprise -- resulting in better visibility, enhanced security and reduced risk.

Businesses can now identify the threats that could do the most damage, and then respond quickly. The Verizon Business platform is available immediately to customers throughout the U.S., Europe and Asia-Pacific.

Risk-Based Approach to Network Security
Going beyond first-generation threat and vulnerability strategies to address underlying risk, Verizon’s new platform enables the management of multiple security platforms, changing business requirements and increased security compliance requirements.

It also enables enterprises that lack in-house security expertise and have limited resources to effectively secure their networks while obtaining a consistent quality of service at an affordable, predictable cost.

"The Verizon Business risk-based approach to network security gives enterprise customers a better understanding of the threats to their businesses so they can plan accordingly," said Amy DeCarlo, principal analyst - Managed IT Services at Current Analysis. "This pragmatic approach, coupled with the global availability of this service platform, makes this a compelling managed security offering for the enterprise."

Benefits of Flexible Service Levels
Verizon customers can choose from one of the following three new service tiers to address individual requirements -- including providing effective security solutions across multiple networks in different parts of the world, each with country-specific requirements.
  • Basic Monitoring: Allows customers to outsource only the monitoring of security devices to while leveraging in-house staffing and retaining management control.
  • Premium Monitoring: Provides continuous monitoring of security devices with analytical support. Security logs and alerts generated by security devices are analyzed and interpreted by security analysts located in one of the company's global security operations centers.
  • Premium Monitoring and Management: Incorporates the Premium Monitoring service, and also proactive management of all devices. This includes installing security patches, managing security policies and restoring devices.

Thursday, February 19, 2009

How to Stay Ahead of Hackers and Cybercriminals


My conversation with Jonathan Nguyen-Duy, Director of Product Management for Verizon, ended up being very thought-provoking. We were supposed to talk about a new security offering, a backbone-based solution aimed at stopping Internet-based attacks even before they hit a company's network. (I'd spoken previously to Nguyen-Duy about Verizon's risk-correlation service.)

Nguyen-Duy is a fount of knowledge about the changing landscape of international cybercriminals. Verizon is expanding its denial-of-service (DOS) detection and mitigation capabilities into eight network management centers serving 24 countries with new levels of scalability -- in part because of an increase in international cybercrime, according to Nguyen-Duy.

"Our customers are telling us that the frequency and complexity of DOS attacks has grown. We're now seeing cyberattacks based on social and political activism. We're also seeing less sophisticated hackers getting access to attack methodologies."

A case in point: consider the following related events.

Item: The Bureau of Alcohol, Tobacco, and Firearms, he says, recently arrested "the eBay of cybercrime" in Phoenix, Arizona which was selling automated attack programs, called botnets.

Item: A CIA official said at a conference that the recent power outages in South Florida were results of an unauthorized probe of the utility network originating from China.

Item: Crime syndicates are more frequently attacking financial services firms, online retailers, and government agencies for extortion purposes, in countries where there may be no laws or no enforcement of the laws.

"If you're a global enterprise or agency with deep pockets and a brand to protect, the challenge is real," Nguyen-Duy says.

"This gives rise to a clear problem: If you have a DOS attack that floods a device with five times the normal amount of traffic, do you have the capacity on site to parse through it and separate the legitimate traffic, and can you do it in real time so you don’t have degradation in service?" Remember that typical consumers won't sit through a transaction if they experience latency of more than 10 seconds.

Protection: Around the Clock, Around the Globe
No, we're not trying to write the script for Die Hard V here. However, because globalization is increasingly driven by the ability to share information anywhere, companies that take advantage of it are also making themselves more vulnerable.

Unless you want to deploy high-priced security experts everywhere you do business, it would be prudent to consider how expanded managed security services can protect your multinational communications network. And, thereby prevent the unthinkable from becoming a reality.

Tuesday, February 3, 2009

Managed Security Services Growing Among SMBs


A new report from Forrester Research on the state of IT security at small to midsize businesses (SMB) in North America and Europe predicts ongoing growth in the managed security space.

In a result similar to that of enterprise respondents, SMB executives reported that the two top drivers for using managed security services is the demand for a specialized skill set that security requires (cited by 31% of the respondents) and the need to reduce costs (cited by 24%).

Other reasons cited for adopting managed security services include:
  • The need to reduce complexity (19%)
  • The need for 24/7 security coverage (19%)
  • The rest of the IT environment is outsourced (5%)
Managed Services Tops for Filtering and Monitoring
The report also revealed that the top two services SMBs ask from their managed security provider are e-mail or Web content filtering (36%) and network firewall monitoring (33%). Forrester believes that the biggest uptick in the next year, however, will come from increased use of vulnerability management and assessment. Some 20% of SMBs plan to deploy these services in the next twelve months.

The Forrester report clearly shows that SMBs have a strong interest in all facets of managed security services. Some 23% are already using it for identity and access management, and another 35% are interested in it, but either have no plans or no budget for adding it to their slate of services.

Similar proportions of SMB executives recognize these issues: host event log monitoring or management (31% are interested but have no plans or budget); IDS/IPS monitoring or management (30%); endpoint security (34%); and regulatory compliance monitoring and assessment (31%).

When To Add Managed Services
The Forrester survey didn't tackle one of the most interesting questions from a managed services standpoint (in fairness, the focus was on security, not managed services). That is, what will it take for SMBs to start adopting the services in which they express interest, but have not yet budgeted for?

Our recommendation is to be proactive and deliberate about adding services. Don't wait for the need to arise; develop a plan to takes into account your security needs and build capabilities into both your budget and deployment plans on an incremental basis. That way, you'll enjoy the highest level of protection with a minimum amount of disruption.

Friday, January 23, 2009

Managed Security with a Strategic Twist


Managed services provider Verizon Business has added an interesting twist to its security toolbox. Traditionally, managed security services are tactical: they monitor a network for potential attacks, using virus signatures and other definitions.

Earlier this month, Verizon upgraded its customers' security capabilities with what it calls its "Risk-Correlation Service," designed to add strategic insight to security.

The RCS works with vulnerability scans -- either those it does for customers or those from vendors such as McAfee, Qualys, and others -- to determine where potential vulnerabilities exist. The service also documents your system to create a map of devices and the business processes that run on them. "It marries threat information with vulnerability information," says Jonathan Nguyen-Duy, Director of Product Management for Verizon.

Calculating Risks
The result is a Web-based scorecard that shows Verizon customers not only where potential problems exist, but rank the level of relative importance of those devices. "We can tell you the likelihood of an event on a particular device, but also the business process associated with that device," says Nguyen-Duy. "Using the information from the vulnerability scan, we can tell you about the impact on availability. Is the device running real-time transactions, or is it a database server that might have less sensitive information?"

Strategically, companies can use the information presented in the online scorecard to get a sense of where to improve their online protection. Not all information is created equal, and not every database server requires the same level of protection.

The scorecard is designed to help companies prioritize their security budgets and their business continuity programs. "With limited resources, it's important to understand the relative risk of each vulnerability," he says.

Protection from Attacks
The online scorecard also works when attacks are underway. In those instances, it helps customers work with Verizon to identify where remediation is most important. "Sometimes you have to work in real-time to figure out where attacks are happening," Nguyen-Duy says. "Your ability to respond is improved when you have better information on the threat and what business process might be affected."

Being proactive about security is like flossing your teeth; you know you should do it more often, but it doesn't always happen. Applying a methodology that combines both strategic and tactical security needs is very wise. Clearly, when it comes to security, it's easier to be reactive when you've already been proactive.

Besides, the complexity of providing comprehensive network security protection, and keeping it fully up to date, is something best left to the experts. That's why managed security is one of the most utilized managed service offerings.