Layered Security Solutions
Security works best when it is layered, so that there are multiple locks that the potential thief must "pick" to gain access. By placing multiple barriers between an attacker and your business information your security risk profile is increased as it is harder for an attacker to succeed and there is a greater likelihood the attacker will be detected earlier.
Organisations need to ensure that they protect all aspects of their IT infrastructure by implementing layered security defences as follows:
- The device being used to communicate with the company needs protection, commonly called desktop or device protection.
- The communication between the device and the corporate network needs to be evaluated. If using an insecure network, it is normal to encrypt the communication between device and gateway using common protocols such as SSL or IPSec.
- The gateway to the corporate network needs, at the very least, to challenge the user and request strong authentication. The smarter gateways today also enforce policy and authorise the user to only perform certain specific functions, acting at the applications level.
- Site infrastructure and servers where the mission-critical information is situated needs to be protected through the deployment of several elements - perimeter firewalls acting as the first line of defence and intrusion and protection systems to detect deeper level traffic threats. These systems act as the alarm system and first defence and check for unauthorised activity and anomalous behaviour on the site infrastructure.
Remote scanning and vulnerability assessment must also be a key part of any organisation's arsenal as it provides valuable information on weaknesses, which others could exploit. It is best if you close the open doors and weaknesses before the hackers find them.
Many organisations believe that security is just too big an issue to deal with by themselves, given the complexities, the corporate regulations and the need to acquire the necessary in-house skills to ensure that every possible security measure has been taken to protect mission-critical business processes and the corporate brand. Instead, many organisations mitigate risk and use experienced providers who can provide a number of key benefits.
The answer to keeping your company secure in an insecure world is our Managed Security Services portfolio.
