Exploits have become dramatically more sophisticated, there has been a great increase in nation-sponsored cyber attacks, and the average employee is far more cyber savvy than even just a couple years ago. All of this results in the exponential growth of unknown threats and zero-day attacks.
An example very close to us, of course, was recently in the news: http://www.bbc.com/news/technology-19293797.
The days of relying solely on signature-based preventative and alerting solutions are over. Anti-virus, firewalls, intrusion detection systems (IDS) and data leakage prevention (DLP) tools are only able to detect what you tell them to look for. Though they will remain a critical piece of the cyber security infrastructure, they are not able to protect you against unknown threats and savvy malicious insiders. It is imperative for organisations to have visibility into all that is happening across the enterprise and optimise their response capabilities to be able to stop the bleeding much faster.
Dynamic Recovery Services (DRS), the African distribution partner for AccessData, has a long-standing partnership in the African region and is proud to share with you Cyber Intelligence & Response Technology (CIRT). This platform is its newest offering and it's truly a game-changer for cyber security practitioners. It is the first and only platform to integrate computer forensics, network forensics, malware analysis, large-scale data auditing, and remediation within a single interface. This solution gives an organisation visibility into everything happening across the enterprise, as well as the laptops of travelling employees, including Internet activity and removable device usage. Even if an employee is not logged into the organisation's network, CIRT is able to monitor all activity, which is a great advantage over relying on other network forensics or enterprise investigations tools. This product will dramatically enhance an organisation's ability to detect, analyse and remediate threats, including advanced persistent threats and zero-day attacks, as well as data leakages, such PCI information or classified documents.
The greatest benefit of using CIRT is the ability to detect unknown threats. You can easily correlate network and host data to more quickly identify anomalies and use the platform's "Cerberus" malware analysis technology to automatically identify suspect binaries and determine behaviour and intent without a sandbox or signature-based tools. With this capability, organisations can detect malware that has not yet been defined and would therefore be missed by conventional tools. In addition, the ability to triage malware before sending it to a malware team for traditional sandbox analysis gives you the actionable intelligence you need to make critical decisions before widespread damage has occurred.
Another advantage of CIRT is that it enables the various cyber security teams (network security, forensics, malware, information assurance) to collaborate in real time via a Web interface.
Finally, CIRT is not just another platform that delivers a mound of data you need to sift through. It actually has built in batch remediation capabilities. So once a threat is detected, you can quickly perform root cause analysis - getting critical data in seconds that would normally take hours or days - and then you can remediate all affected nodes immediately.
As your trusted Security solutions provider, we would urge you to take a look at this solution as existing technologies will not protect you.
In a joint effort with AccessData, we would like to offer you a free consultancy on this matter - how are organizations defending themselves? We can also offer an e-crime gap analysis engagement to identify what can be done to help.
If you are interested in learning more about CIRT, please consider attending the road show in October. Event details and registration at: http://www.eventbrite.com/event/3914789240.
Or contact: Wayne Forsman Regional Account Executive: wforsman@accessdata.com.
Editorial contacts

