Story image

Is any network 100% safe? Tips for hardening cyber defences

15 Jul 2016

Your client’s enterprise network, the data they hold and the application services they support are all directly in the cross-hairs of hackers, spies and opportunists of every stripe. And why not? Stolen data is a commodity worth money (or bitcoins!) on the open market. If your client has any sort of public profile they are a target for cyber-criminals. The bigger the enterprise, the bigger the target.

Your clients want to keep their private and sensitive commercial data safe and secure. And you want to be able to assure them that it is so. But can you really secure your customer’s data from all threats, especially criminals who are prepared to make a major effort to break into your network?

“Is any network 100% safe?” asks Dominic Whitehand, Managing Director of Exclusive Networks, Australia’s most experienced distributor for Fortinet, a global leader in the provision of cyber-security solutions. “Of course not. Even the White House, the Pentagon and the Kremlin get hacked. And they have massive security budgets and thousands of full-time black and white hat experts. But you can make it extremely difficult for all but the most well-funded and relentless crooks to even come close to getting inside your client’s networks. How? By hardening their cyber defences inside and out.”

Advanced persistent threats Today’s most damaging attacks, typically classified as Advanced Persistent Threats (APT), occur across the spectrum of possible attack vectors. Innovative malware, zero-day vulnerabilities and emerging evasion techniques can all render a single approach problematic.

“A deeper, more comprehensive approach is needed,” says Whitehand, “to counter these increasingly sophisticated attacks. Fortinet, and other security vendors, are all working hard to build a multi-layered defence-in-depth framework for combating these APTs.”

Prevent – The known threats Most malware is already known. Last year, nearly a quarter of malware was more than ten years old and almost 90% discovered before 2014.  Known threats can be blocked through next-generation firewalls, secure email gateways, endpoint security and other technologies. Previously unknown malware and targeted attacks, however, can hide from these measures. Dodgy traffic that seems suspicious should be handed off to the next point of your multi-layered defence.

Detect – The unknown Today’s more sensitive filters can detect previously unknown threats and create actionable threat intelligence. Sandboxing, for instance, isolates potentially malicious software in a sheltered environment so its full behaviour can be observed without affecting production networks.

“But sandboxing alone can’t stop everything,” continues Whitehand. “Attackers respond to new technologies by figuring out how they work and then finding ways around them. Indeed, smart crooks are already trying to compromise sandboxes. That’s why it’s important to stay updated. Just as criminals evolve, your client’s defences need to keep up as well.”

Mitigate – Taking action Once an intrusion has been validated, users, devices and content have to be quarantined. “Your clients need to have automated and manual systems in place to ensure the safety of network resources and data,” says Whitehand. “That’s to contain the damage. But you need to fight back. FortiSandbox, for instance, automatically forwards any new threats to the FortiGuard Labs for analysis, de-construction and remediation. This results in updates being fed back to the security devices and providing every layer with up-to-date protection.”

Integration is key “It’s not one particular technology that’s driving Advanced Threat Protection (ATP),” says Whitehand. “It’s the integration and collaboration amongst all of them. ATP relies on multiple types of technologies, products and research, each with different roles and each working in concert with one another. For example, FortiSandbox can integrate into FortiGate Next Generation Firewalls, FortiMail for inspection of attachments and FortiWeb web application firewalls for web-facing services.”

“We can expect to see continued cybercriminal innovation with an even greater focus on datacentres,” concludes Whitehand. “Your best strategy for clients is to deploy a multi-layered approach with established and emerging technologies which work together. No other approach can defend against today’s Advanced Persistent Threats. It’s a challenge, to be sure, but one that has to be met.”

For further information, please contact Exclusive Networks: E: fortinet@exclusivenetworks.com.au P: 1300 137 993 W: www.40net.com.au

Slack users urged to update to prevent security vulnerability
Businesses that use popular messaging platform Slack are being urged to update their Slack for Windows to version 3.4.0 immediately.
Secureworks Magic Quadrant Leader for Security Services
This is the 11th time Secureworks has been positioned as a Leader in the Gartner Magic Quadrant for Managed Security Services, Worldwide.
Deakin Uni scores double win with Exabeam partnership
Australia’s Deakin University is partnering with SIEM security company Exabeam in an effort to boost the university’s cybersecurity degree program and strengthen its SIEM capabilities.
Google puts Huawei on the Android naughty list
Google has apparently suspended Huawei’s licence to use the full Android platform, according to media reports.
Voter vulnerabilities: Cybersecurity risks impact national elections
The outcome of elections have an enormous impact on the political and cultural landscape of any democratic society. 
Using data science to improve threat prevention
With a large amount of good quality data and strong algorithms, companies can develop highly effective protective measures.
General staff don’t get tech jargon - expert says time to ditch it
There's a serious gap between IT pros and general staff, and this expert says it's on the people in IT to bridge it.
ZombieLoad: Another batch of flaws affect Intel chips
“This flaw can be weaponised in highly targeted attacks that would normally require system-wide privileges or a complete subversion of the operating system."