zero trust security - with an immediate roi 08 mssp case study€¦ · mssp case study seceon’s...

9
Cyber breaches are growing in both frequency and severity. Despite the vast amounts being spent on today’s state of the art cybersecurity solutions - data breaches are happening at an increasing rate with over 600 detected and reported in the U.S. alone by August 2016, and greater severity with over 20 million exposed records, a 20% increase over record-breaking years 2014 and 2015, according to the ITRC. Most organizations are unable to properly deal with cyber threats because: they are too slow to identify them and too slow to stop them from inflicting damage once the organization is breached. The challenge is most cybersecurity solutions require human intervention – smart humans that are specifically trained in how to use an array of complicated tools to identify a threat and then figure out how to stop it. The problem, as the 2016 Verizon Data Breach Report exposes, is that 95% of attacks exfiltrate and/or corrupt data within a few hours of a breach. This is not enough time for even the smartest humans to react. Worse yet, analysts at 451 Research estimate that fewer than 4% of enterprises and government organizations have dedicated security staff in a security operations center (SoC) to monitor all these products for possible breaches. Small and medium sized organizations are the most impacted by these security threats and are increasingly asking their Managed Security Service Providers (MSSPs) and service provider partners to help support their security challenges. No longer are MSSPs driven to advocate for the need to invest in security software and services; recent high profile breaches at Yahoo, Eddie Bauer, Oracle’s MICROS system, Anthem and the IRS have done all that is necessary to fuel the demand. The mission for today’s MSSP is to provide security offerings that can lower a customer’s security risk at an acceptable price point. 1 In fact, according to a recent Kaseya Ltd. Sonicwall.com Seceon.com Zero Trust Security - with an Immediate ROI MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security services provides a powerful breach detection and mitigation solution. The combined solution enables a breakthrough in reducing operation cost, which allows for extremely profitable MSSP service offerings.

Upload: others

Post on 15-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

Cyberbreachesaregrowinginbothfrequencyandseverity.Despitethevastamountsbeingspentontoday’sstateoftheartcybersecuritysolutions-databreachesarehappeningatanincreasingratewithover600detectedandreportedintheU.S.alonebyAugust2016,andgreaterseveritywithover20millionexposedrecords,a20%increaseoverrecord-breakingyears2014and2015,accordingtotheITRC.Mostorganizationsareunabletoproperlydealwithcyberthreatsbecause:theyaretooslowtoidentifythemandtooslowtostopthemfrominflictingdamageoncetheorganizationisbreached.Thechallengeismostcybersecuritysolutionsrequirehumanintervention–smarthumansthatarespecificallytrainedinhowtouseanarrayofcomplicatedtoolstoidentifyathreatandthenfigureouthowtostopit.Theproblem,asthe2016VerizonDataBreachReportexposes,isthat95%ofattacksexfiltrateand/orcorruptdatawithinafewhoursofabreach.Thisisnotenoughtimeforeventhesmartesthumanstoreact.Worseyet,analystsat451Researchestimatethatfewerthan4%ofenterprisesandgovernmentorganizationshavededicatedsecuritystaffinasecurityoperationscenter(SoC)tomonitoralltheseproductsforpossiblebreaches.SmallandmediumsizedorganizationsarethemostimpactedbythesesecuritythreatsandareincreasinglyaskingtheirManagedSecurityServiceProviders(MSSPs)andserviceproviderpartnerstohelpsupporttheirsecuritychallenges.NolongerareMSSPsdriventoadvocatefortheneedtoinvestinsecuritysoftwareandservices;recenthighprofilebreachesatYahoo,EddieBauer,Oracle’sMICROSsystem,AnthemandtheIRShavedoneallthatisnecessarytofuelthedemand.Themissionfortoday’sMSSPistoprovidesecurityofferingsthatcanloweracustomer’ssecurityriskatanacceptablepricepoint.1Infact,accordingtoarecentKaseyaLtd.

S o n i c w a l l . c o m S e c e o n . c o m

ZeroTrustSecurity-withanImmediateROIMSSPCaseStudySeceon’szerotrustmodel,combinedwiththeSonicWallnext-generationfirewall(NGFW)securityservicesprovidesapowerfulbreachdetectionandmitigationsolution.Thecombinedsolutionenablesabreakthroughinreducingoperationcost,whichallowsforextremelyprofitableMSSPserviceofferings.

08Fall

Page 2: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

MSPGlobalPricingSurvey2,whichpolledownersandoperatorsfromnearly400MSSPs,overaquarterofallrespondentsidentified"heightenedsecurityrisk"asthenumberoneITproblemorserviceMSPsexpecttheirclientstofacein2016.

ThecombinationofSeceonOTMandSonicWallNGFW,breachescanbeshutdownastheyoccur,notweeksormonthsafterthedataisstolen.It'stheidealsolutiontobeusedbyMSSPswhoareonlyprofitableiftheycandealwiththreatsquicklyanddistributetheirstaffcostsacross10sto100sofcustomers.Considerthefollowingexample

• Agivencustomer’smanagedfirewallgeneratesevents,forNorth-Southtraffic,butdemandsdeeperhumananalysisforcomprehensivethreatdetectionandanalysis

• EventsforEast-Westtrafficareusuallyunderstoodbylookingattheserverlogsandnetworkflows,whichalsodemanddeeperhumananalysisandmanytimesrequirealotmoretimeevenwithagoodautomation

• Thevolumeofeventscanstackuptomorethanevenadedicated,trainedstaffcanhandle,whichnoMSSPcanmanageorafford.

• Oursurveyindicatesatleast3relevantthreatsoccurdailyinaF5000mid-sizecompany.Eachincidenttroubleshootingrequiresweedingthroughthefirewallandserverlogsandmanytimesevenlookingintonetworktrafficorpacketstodeterminetheexactanalysisofthreat.

Flows/LogsTroubleshooting ActivityTypeFlow/LogInstances AnalystsComments

Next-generationfirewall(NGFW)(SonicWall)generatesevents/logsaroundaninstanceofaninfecteddeviceattemptingtoconnecttoabadwebsite.

North-SouthActivity

444 NGFWisresettingconnectionsfromthedeviceovertime.Watchthisdeviceforothernon-criticalflaggedmessages

DeviceisalsoperformingIPSweeps East-WestActivity

135 Fewseparateinstancesacrosstheinternalnetwork

DeviceisalsoperformingIPPortscans

East-WestActivity

92 Fewseparateinstancesacrosstheinternalnetwork

Deviceneedstobeidentified InternalActivity

1 Whatdeviceisit?Whoorwhatgroupitbelongsto?

TotalActivity 672 instancestoinvestigate

• CostsofJuniorandSeniorSOCAnalystsareapproximatelyasfollows:Jr.SOCAnalyst

Sr.SOCAnalyst Costs

Page 3: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

$75,000 $250,000.00SOCAnalystBurdenedrateperyear

$1,442.31 $4,807.69 costperweek$36.06 $120.19 cost/hour$0.60 $2.00 cost/minute

Thecostoftroubleshootingjustoneincidentbyajunioranalystis$600overthecourseof2-3days,thereportofwhichmustthenbereviewedandanalyzedbyamoresenioranalystoverthecourseofanother1-2days.Overtime,thecostintimeandresourcesisapproximately$1800/day,addingupto$450K/year!

Minutesperinstanceinvestigation 1.5Totalminutesofeffortperincident 1006.5Cost/minuteor$/minute $0.60Totalcosttocorrelateoneincident $603.90Typicalincidentsperbusinessdayinvestigatedatamid-sizedF5000(AsperPonemon/VerizonReports) 3Totalcostperbusinessday $1,811.70Totalcostperyear $452,925.00

Automatingthisprocesswouldsavemostofthiscostandmostimportantly,thevariablecostofdatabreaches.Costofdatabreachesmostlydependsontheindustryandthevalueorcriticalityoftheinformationbeingbreached;forexample,forhealthcareindustrytheapproximatecostoflosingonepatient’sPHIrecordis$355.Soafirmthatdealswith100,000patientsinthisindustryisatriskof$35Mifadatabreachhappensstealingallofthesepatients’records.

Seceon+SonicWallZeroTrustapproachisacomprehensivereal-timepreventionmethod,aswellasdetectionandresponseforbothNorth-SouthandEast-Westtraffic.UsingSonicWallnextgenerationfirewallsweofferperimeter-baseddefensesformonitoringNorth-Southtrafficandblockingunauthorizedaccess.Simultaneously,usingSeceon’sOTMforthreatdetectionandelimination,Seceonisabletomonitor,detectandtakeactionforEast-Westtrafficthatwouldnormallygoundetectedintraditionalsecuritydesigns.SeceonintegrateseasilywithSonicWallNGFWandanysourceofEast-Westtraffic,includingrouters,switches,servers,POS.directoriesandapplicationstoprovideasingle,comprehensiveviewofallfacetsofacustomer’senvironment,includingprioritizedthreatalertsandspecificactionstocontainthethreat.Thissolutionnotonlydetectsthreatsinminutesitprovidescompleteanalysisanditautomatesremediationstepstoaclickofabutton.Theaveragetimespentperthreatcanbeafew

Page 4: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

minutespercustomerperincidenttodetectandstoptheproblem.UsingourExample:3threatspercustomerperday–Timespent:5minutesperthreat=yieldsacostof$8perdayThisallowsanMSSPtoofferasuperiorserviceandchargeapremiumwhilekeepingcoststooperatedowntoafewdollarspercustomerperday.ReferenceArchitectureConsiderthefollowingreferencearchitectureonhowmostManagedSecurityServiceProviders(MSSPs)candeploythecombinedsolutionofSonicWallNGFWandOTM.

VisibilityThefirststepinautomatingincidentanalysisandresponseistoprovidevisibilityintoalltrafficandthencorrelateanyabnormalitieswithanomaliesinbehavior.Seceon,theonlythreatdetectionandManagementCompanytovisualize,detect,andeliminatecyberthreatsinreal-time,offersitsOpenThreatManagement(OTM)platformforautomatedthreatdetectionandelimination.SeceonOTMcorrelatesalloftheseeventsfromSonicWall

MSSPReferenceArchitecturewithSonicWallandSeceonOTM

Page 5: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

NGFW,networkflowsandserverlogstogether,usingdynamicthreatmodelsthatleveragemachinelearningtoderivethreatsthatarepostedinpriorityorder,and/orsentbyemailnotification.Moreover,byleveragingmachinelearning,policiesandthreatmodelsupdateautomatically,continuously“learning”andrequiringnointerventionforupdates.Thesesamelearningscanbeappliedacrossmultiplecustomerenvironments,ensuringthecommunicationofvaluablethreatinformationtoalloftheMSSP’scustomers.

OTMenablesMSSPtomaintainacomprehensiveviewofallcustomersthroughasinglepaneofglass--seeingeachcustomer’sthreatstatusinonescreenwhileallowingprotectedportalaccesstoeachindividualcustomerenvironment.Real-timedetectionWhenitcomestoeffectivebreachdetectionandresponse,wealsoknowtimeisoftheessence.Recentindustrydatashowsthatcredentialsarecompromisedinminutesandmostofanorganization’scriticaldataorintellectualpropertyislostwithinthefirsthour.Specifically,accordingtoVerizon’s2016DataBreachInvestigationReport3,81.9percentoforganizationssurveyedreportedthatacompromisetookonlyminutestoinfiltratecompanysystemswith67.8percentofrespondentsshowingthatassociateddatawas“breached”withindaysoftheinitialcompromise.Therefore,anythreatdetectionsolutionthatcannotdetectandremediatethreatsinnearreal-timeisnotmuchuse.ValuableassetscouldalreadybestolenandsoldontheDarkWebbeforeanorganizationknowstheyareevenmissing!Thecostoflosingtheseassetscanmeanmorethanlossofdata.ThePoneman2016report4

concludesthatonanaverageeachdatabreachcosts$4Mforthe383organizationsthatparticipatedin2016databreachcoststudy.Thecostsareexactedintermsoffinancialloss,reputationalimpact,exposureofpersonalinformationandpotentialcustomerreimbursement.AveragedatabreachcostpercapitaishighestisUSA($221)andGermany($213).Thisisacrossalloftheindustries,butcertainindustrieslikehealthcareandfinancialshavemuchhighercostperdatabreachpercapita.Real-timethreatdetectionandeliminationcanbethedifferenceinstemmingsignificantlossesinspiteoftheinevitablebreach.

Seceon Servers

Seceon Corp. Ne...

Public

Seceon IndiaSeceon D

MZ

Web Services

Unknow

nD

ata Center Ser... Em

ail ServersSeceon VPN

-PPTPAm

it

Sece

on Lab

Seceon DM

ZD

ata Center Ser...

Page 6: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

SeceonOTMandSonicWallNGFWsolutionsprovidetheabilitytostopthreatsinreal-timeiby:

• ThreatsdetectedbytheSonicWallNGFWareforwardtotheSeceonOTMforanalysisandwithcombinedenricheddatafromothersources,SeceonOTMcreatesFWpolicies

• PushingpoliciestotheSonicWallNGFWtoblockcommunicationfromaddressesoutsidethenetwork,suchasthoseinvolvedwithDDoS,Bruteforce,APTsandMalwareCNCs.

• Pushingthepoliciestoisolateanysystems(endpointsorservers)thatinsidershaveusedtocapturehighvaluedata,sothattheycannotexfiltrateitoutoverthenetwork.Aswellaspreventingmalwareinfectedfromdoingharmtootherdevices

• Disablingofcredentialsincaseofcompromisedcredentials(databreach),orinsiderswhoareattemptingtoaccessofflimitssystems.

• Preventinglateralpropagationofthreats,suchasransomware,botnets,etc.• Helpingorganizationsseeandstopthreatsastheybecomeactiveinminutes,notin

weeks,whichistoday’snorm

Multi-TenancySupporttoempowerMSSPpartnerswithaSOC-in-a-boxsolution.Poweredbyadvanceddatacollectionandanalysis,machinelearningandpatent-pendingpredictiveandbehavioralanalytics,Seceon’sOTMprovidescustomerswithaproverbial“SOC-in-a-Box™,”automatinghumanandtimeintensiveanalysisanddecision-makingandsignificantlyspeedingthetimetodetectionandremediation.Anticipatingattackers’behaviorchoices,thesolutionenablesMSSPstoseeandstopthethreatsastheyhappen,preventingrisk,damageorlossofvaluableinformation.Immediatelyupondeployment,Seceon’ssolutionbeginstosurfaceaconciselistofthreatsinplainlanguage.Itusesbehavioralanalyticsgeneratedbyanextensivesetofdynamicthreatmodels,aidedbymachinelearningtechniquestodetectbothknownandunknownzero-dayattacks.Seceon’sOTMispurpose-builttobeoperationallyefficientandinstallationfriendly,allowingeasy-to-scaleandeffectivedeploymentwithminimaltraining.Seceon’sOTMprovidesMSSPswithasinglescreenforviewingmultipletenantswitheachtenantorcustomeronlyabletoseeitsownassets.WithOTMdeployedinamulti-tenancyenvironment,allcustomerscanbenefitfromtheplatform’smachinelearningcapabilities.Anynewthreatsarecaptured,reportedandfedbackintothesystem’sthreatmodels,ensuringthecontinuoussharingofthreatintelligenceacrossallcustomers.

o SingleviewforMSSPformultipletenantswitheachcustomerseeingonlyitsownassets.o Easytoapplylearnedsecuritylessonsfromonecustomertoanother

Page 7: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

ImmediateROITodayThreatsaretypicallyfoundusingSIEMsolutions.Typically,mostsecuritysolutionslikeSIEMplatformscangeneratemanyalertsthatcanbeoverwhelmingforteamofsecurityanalyststoprocess.SeceonOTMnotonlyprocessesthemthroughtheirfeed,butalsocorrelatesthemwithotherfeedsandsurfacestherealhandfulofalertsthatneedattention.Theresultsofcombiningfeedstoaneventsavesthesecurityanalystfromcombingthroughhundredsofalertsfromdifferentsystemsandhandcorrelatingthosethatcanbefoundtoberelated.Thesecurityanalystonlyneedstoreviewmajororcriticalalertstodecideuponthecourseofaction–and/orfollowthesystemsrecommendedremediationstepsimprovingtheiroperationalefficiencyandloweringoperationalcosts.OTMhelpsMSSPsbyimprovingtheefficiencyofseniorsecurityanalysts,whoareveryhardtofindandwhosetimeisacostlyMSSPresourcethatneedstobespentwiselyoncybersecurityissuesthatreallymatterratherthanonmanymanualtasksthatcanbetakencareofbyautomation.AlsotheSIEMplatformstypicallyrequireahigherinitialinvestmentsincemostSIEMsrequireaperpetuallicensewithhigherupfrontcost.MostSIEMScan’tbesharedacrossmultiplecustomerswithoutcominglingtheirinformation.ThereforeSIEMsolutionsdonotlendthemselvestoallowingasingleoperatortoeasilymonitortensto100sofcustomersfromasinglescreen.SeceonOTMispricedonanumberofprotecteddevicesSAASmodelallowinga‘Payasyougo’modelidealforMSSPslookingtoofferamonthlyservicetoend-customerorganizationsofanysize.Astheexampleaboveshows-itimmediatelyprovidescostsavingsthroughoperationalefficiencyvs.SIEMsotherthreatdetectiontoolsonthemarket.Thejoint

Page 8: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

Seceon-SonicWallNGFWsolutionhelpsMSSPstoeasilyscalethesecurityserviceswithlowinitialinvestmentthatcanbeincreasedincrementallywithgrowthintheircustomerbase.Seceon’szerotrustmodel,combinedwiththeefficacyofSonicWallNGFWsecurityservices,breachdetectionandmitigationiscontrolledinaswift,costeffectivemanner.Theendresultisasafernetworkforyourcompanyassets,personnel,andfinancialsuccess.AboutSeceon:SeceonanditsOTMAdvancedThreatDetectionandRemediationPlatformistheindustry’smosthighlyawardedplatformduring2016.Itsnovelapproachatfocusingondetectingandstoppingthreatsautomaticallybeforedataiscompromisedhasredefinedtheworkoftoday’sanalysts-freeingthemfromthedifficultworkofdetectingthreatsanddecidinghowtostopthemandallowingthemtofocusonhowpreventthemfromhappeninginthefirstplace.TheOTMsolutionwithitrecentlyaddedMSSPmultitenantcapabilitieshasfinallymadeitoperationallyprofitableforMSSPstomovebeyondonlyofferingmanagedfirewallservicesandoffercustomersofanysizeanabilitytoaddadvancedthreatdetectionandremediationservice–solvingtoday’smostvexingproblemhowtomakethreatanalysisandremediationataskthattakesminutestoperformwhenanincidentarisesbyminimallytrainedstaff.AboutSonicWall:Over25years,SonicWallhasbeentheindustry’strustedsecuritypartner,protectingmillionsofnetworksworldwide.Fromnetworksecuritytoaccesssecuritytoemailsecurity,wehavecontinuouslyevolvedourproductportfoliotofitinquicklyandseamlessly,enablingorganizationstoinnovate,accelerateandgrow.Ourcustomersknowittakesstrongsecuritytosayyes.Wearethetrustedpartnerthatallowsthemtosayyestothefuturewithoutfear.SonicWallsecuritysolutionsarethepreferredchoicefordistributedenterprise,government,education,retail,healthcareandfinancialdeployments.SonicWallproductshavebeenhailedbyindustrypublicationssuchasNetworkWorld,InfoWorld,PCMagazineandSCMagazineforeasy-to-use,high-efficacyandhigh-performanceappliancesandservices.In2016,SonicWallearnedthehighestratingof“Recommended”inthelatestversionoftheNSSLabsNext-GenerationFirewallSecurityValueMapforthefourthyearinarow,andwasratedasoneofthetopproductsforsecurityeffectiveness.SonicWall.Yourpartnerincybersecurity.

Page 9: Zero Trust Security - with an Immediate ROI 08 MSSP Case Study€¦ · MSSP Case Study Seceon’s zero trust model, combined with the SonicWall next-generation firewall (NGFW) security

References:1.Techspective,CyberSecurityThreatDetection-TheCaseforAutomation,September2016http://techspective.net/2016/09/21/cyber-security-threat-detection-case-automation/2.KaseyaLtd.MSPGlobalPricingSurveyhttps://www.channele2e.com/2017/01/09/msp-global-pricing-survey-kaseya-2017-findings/3.Verizon’s2016DataBreachInvestigationReporthttp://www.verizonenterprise.com/verizon-insights-lab/dbir/2016/4.ThePoneman2016CostofCyberCrimereporthttp://www.ponemon.org/library/2016-cost-of-cyber-crime-study-the-risk-of-business-innovationiThestatementscontainedinthiscasestudyregardingtheperformanceofSeceonproductsandservicesandSonicWallproductsandservicesareattributableonlytoeachcompany,respectively,andshouldnotbedeemedtobethestatementsorrepresentationsoftheothercompany.