Securing your network

Issue 5 2021 Infrastructure

In the modern era of cybercrime, ransomware and digital threat vectors, your infrastructure security is more essential than ever. After all, a successful attack against a company’s IT infrastructure can easily impact an organisation’s earnings, damage its reputation and compromise its operations.

Therefore, it is important that your infrastructure security encompasses a full suite of solutions, explains Patrick Assheton-Smith, CEO at SymbiosysIT. This would include perimeter, network, application, endpoint, data and cloud security, as well as cryptography management and security architecture.

“One of the major challenges with traditional security is it tends to cater more for traffic from a north-south perspective – essentially traffic coming from outside and entering your network through a firewall or across VLANs. However, as organisations move to the cloud and access to the network begins to change because of this, so a new method of securing things needs to be implemented,” he explains.

Enter micro-segmentation

This is where micro-segmentation comes in, as this is a security technique that allows you to logically divide the network into distinct security segments down to the individual workload level. He suggests that by doing this, you can limit an attacker’s ability to move laterally – or east-west – through the network. This means that even if they get through the perimeter defences, at worst case, the damage they can do is contained.

“Of course, micro-segmentation at a high level is tough to achieve and it is only getting harder. Where most organisations that play in this space focus on the hypervisor, we have instead partnered with Guardicore, which is agent-based. This means that whatever the machine, container and wherever it resides, there is true visibility. This is particularly important in solving one of the key network challenges, which is that they tend to be flat and littered with VLANs, which offer little visibility and are quite restrictive.

“It is worth noting that the Cisco Global Cloud Index 2018 suggests that some 85% of network traffic today is east-west. When you consider that the dwell time after a breach is a huge 191 days – according to the Ponemon Institute’s 2018 Cost of a Data Breach report – it means that without micro-segmentation, you are extremely vulnerable to a ‘low and slow’ attack, which is very difficult to pick up.”

If this happens and your network is locked down with ransomware, your backups become vital. Thus, your backup and disaster recovery strategy also needs to be solid.

Build a spiderweb

“What Guardicore does is it allows you to deploy agents, inspect traffic and build a spiderweb that maps traffic across all systems. Moreover, because you can drill down to the process layer, you can build a secure system according to the specific rules your business requires.”

Modern network security not only provides better visibility throughout your environment, but also allows you to ring-fence important apps, create third party access controls – for external contractors, for example – and protect older, tough-to-secure assets.

It also simplifies and accelerates compliance, enables secure DevOps and improves detection, thus reducing dwell time. The key is to prevent lateral movement, through micro-segmentation, thereby eliminating a critical blind spot. And more, even if your security is penetrated, micro-segmentation helps to greatly reduce the ‘blast radius’.

The true value of data

Data is the lifeblood of any modern organisation and needs to be protected at all costs. Therefore, there are three important questions every business needs to ask:

• Do you know what data you have? The older and more sprawling an enterprise is, the easier it is for these data islands to become ‘lost’.

• What does your data actually relate to? This is how you determine whether the measures you have in place protecting it are sufficient, particularly if the information is among your more valuable digital assets.

• Where is the data stored? This is also crucial, particularly in light of legislation like PoPIA and GDPR.

Assheton-Smith adds, “Micro-segmentation works especially well with a complementary solution we offer called Groundlabs Enterprise Recon. This product provides data security through discovery and data classification – finding it and understanding how vital it is – as well as monitoring and reporting (to better understand the risk) and remediation, which is essentially the process of fixing the risk, once you understand what and where it is.

“With a solution like this, one that supports all data types and on an enterprise storage level, supports all the key players too, means you are able to secure your data whether it is structured, unstructured, cloud-based, on-premise, distributed or remote.”

This solution allows companies to quickly search for the data that they need to secure, by seeking out specific types of information that can then be classified according to format or type of data. It is a very powerful tool for finding all the information you have and where it is – two things you have to clearly understand before you can properly secure it.

“In today’s digital world, data is the world’s most valuable and easily traded resource, which is why it is more crucial than ever to protect it to the best of your ability. After all, if you think it is valuable to your business, imagine how important it is to cybercriminals and they do not care about the damage they cause to your company in obtaining it. Data should thus always be the centre of your world,” concludes Assheton-Smith.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...
Troye exposes the Entra ID backup blind spot
Information Security Infrastructure
If you trust Microsoft to protect your identity, think again. Many organisations naively believe that Microsoft’s shared responsibility model covers Microsoft Entra?ID – formerly Azure AD – but it does not.

Read more...
Secure data protection without hardware lock-in
Infrastructure Information Security News & Events
New Veeam Software Appliance empowers IT teams to achieve instant protection with Veeam’s fully preconfigured, software-only appliance, delivering enterprise-ready simplified deployment and operational efficiency, robust cyber resilience.

Read more...
Hytera supports communication upgrade for Joburg
News & Events Infrastructure Government and Parastatal (Industry)
By equipping Johannesburg’s metro police and emergency services with multimode radios which integrate TETRA and LTE networks, Hytera is bridging coverage gaps and improving response times across the city.

Read more...
Combining TETRA or DMR with 5G broadband
Infrastructure IoT & Automation
As enterprises face rising complexity and connectivity demands, hybrid networks offer a transformative path, combining the proven reliability of TETRA or DMR with the innovation and coverage of 5G broadband.

Read more...
Questing for the quantum AI advantage
Infrastructure AI & Data Analytics
The clock is ticking down to the realisation of quantum AI and the sought-after ‘quantum advantage’. In many boardrooms, however, quantum remains mysterious; full of promise, but not fully understood.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
IoT-driven smart data to stay ahead
IoT & Automation Infrastructure AI & Data Analytics
In a world where uncertainty is constant, the real competitive edge lies in foresight. Businesses that turn real-time data into proactive strategies will not just survive, they will lead.

Read more...
Hydrogen is green but dangerous
Fire & Safety Infrastructure Power Management
Hydrogen infrastructure is developing quickly, but it comes with safety challenges. Hydrogen is flammable, and its small molecular size means it can leak easily. Additionally, fires caused by hydrogen are nearly invisible, making them difficult to detect and respond to.

Read more...
A whole-site solution to crack the data centre market
Fire & Safety Infrastructure Facilities & Building Management
Fire safety consultants and contractors who can offer a comprehensive fire safety solution to the data centre market can establish themselves as a supplier of a key safety features that help guarantee the smooth operation of critical infrastructure.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.