securitylinkindia

Skybox’s Security Threat-Centric Vulnerability Management for Virtual and Cloud Networks

Expands solutions to enable organizations to consistently and securely manage day-to-day security processes across all networks in one platform Skybox™ Security continues to expand its cloud security management solution, Skybox for the Cloud™. The solution now includes threat-centric vulnerability management (TCVM) for virtual and multi-cloud environments and extends capabilities for security policy management, attack surface visibility and network path analysis. With one platform, the Skybox™ Security Suite, organizations are now able to consistently and securely manage day-to-day security processes across their entire network infrastructure, whether on premises or in the cloud. As businesses continue to migrate to virtual and cloud environments, security becomes more complicated due to the nature of cloud architecture, from multi-tenancy to elasticity and the shared responsibility for the computing stack. For example, security mechanisms in virtual and cloud networks are different from physical environments, and even differ amongst cloud service providers. In addition, cloud elasticity means virtual machines are quickly spun up and down, making traditional vulnerability scanning insufficient as the environment may change significantly between scans. To counteract these challenges and reduce the chance of human error, Skybox helps automate security processes not only in virtual and cloud environments, but across all networks within a single, unified dashboard. Whether an organization’s network infrastructure is physical, virtual, cloud or a hybrid of all three, Skybox for the Cloud addresses a number of use cases in the following areas: Comprehensive visibility of the attack surface in a single network model, capable of incorporating data from 120+ security and networking technologies. End-to-end path analysis from any source to any destination across or within physical, virtual and multi-cloud networks, including detailed path analysis on the devices, rules, etc., along the path. Unified security policy management across all networks including out-of-the-box compliance checks for key industry regulations such as NIST and PCI DSS. Vulnerability discovery, prioritization and remediation planning with the context of an organization’s on-prem and multi-cloud networks; this information is correlated to current threat intelligence of exploits in the wild. As cyber events like the Equifax breach (caused by the Apache Struts vulnerability) continue to increase, it’s obvious that organizations are struggling to quickly identify and effectively remediate vulnerabilities in their systems. This challenge can be compounded by the nature of cloud environments and even procedural requirements from service providers that impact third-party scans. Skybox for the Cloud gives security teams the power to assess vulnerabilities in the cloud on demand by combining data from cloud-based patch and asset management systems, scanners and network devices. The results are analyzed and prioritized using the TCVM approach, taking into account: The vulnerabilities on the virtual machine and its importance to the organization. The virtual machine’s exposure based on the hybrid network topology and security controls in place. Threat intelligence on available and active exploits in the wild. TCVM also gives prescriptive guidance of what action can be taken to prevent exploitation and how urgently that action should be performed. IT teams are tasked with launching new services and applications on a daily basis. By leveraging cloud architecture, they can achieve that in minutes – opposed to days of work. The challenge is that this leads to a fluid security situation where assets (virtual machines) can be assigned to the wrong security group, resulting in immediate exposure. Security teams need to be on the top of this, and the only way to do it is to have global visibility and management across all your networks – Ravid Circus Skybox VP of Products

Read More

IFSEC International Takes New Industry Role Addressing Critical Global Security Challenges

Security has never been a more critical discussion. 2017 has been a year where organisations and governments became increasingly aware that the manner of threat which they were working to prevent has changed irrevocably. Europe fell victim to a string of unpredictable attacks; Yahoo saw their share value fall by $350 billion over 48 hours after the largest security breach in history was revealed; the NHS found their physical assets left vulnerable after a ransomware attack disrupted their ambulance service; the FBI and Apple went to war on encryption and Airbnb properties were left in chaos when a smartlock update went wrong. These represented a pivotal theme, the need for all those influencing security to adapt to reflect the more complex world, and the ever-closer interweaving of physical and cyber security. The time is now for the security profession to unite their knowledge and their technologies to protect people, property and profits. As of 2018, it is IFSEC’s commitment to become the place for the profession to create a safer world. More than just a prominent trade show, IFSEC must foster the global security conversation, be the vessel that sets and carries the agenda and be the antenna for broadcasting the safety and security dialogue. 2018 will be the inauguration year of a transformation of IFSEC’s 40 year heritage as a physical security show into a high level security summit and integrated security event. When IFSEC was first conceived, the threats were merely physical. Society has adapted and this is the year we must too. The security profession must evolve to meet modern needs. IFSEC is gladly becoming the arena for the big discussions, however difficult they may be. The security profession must discover solutions that are a driving force in protecting businesses, people and data. IFSEC will give the security industry the platform to display and discover products and services to help national, corporate and home security adapt to the changing tides of tomorrow’s challenges. The security profession must drive the agenda. IFSEC will exist for the world’s leading security experts to find a platform for provocative debate on global security and propel intercommunication forward between the installer, integrator, end user and vendor. To pilot this in 2018, IFSEC will drive an emphasis on major keynote addresses from strategic global security leaders in a dedicated Summit, host a multitude of high level panel debates from government and industry influencers in the striking Amphitheatre and provide the opportunity to hear from those leading the way in identifying, installing and maintaining transformational security practices between physical and IT. Establishing the impartial voice of security equipment will also be key to the IFSEC 2018 proposition, rigorously holding technology up to the test in real-life Testing, across attack scenarios and surveillance situations. This will allow security innovation to be delivered to the world, revealing thousands of differentiated products that will filtrate from government, to the boardroom, and to every individual in the security profession. Tall Building Fire Safety Conference 2018 The tragedy at Grenfell Tower, along with several other similar fires in tall buildings around the world has highlighted the need for a review of fire safety practice, engineering and risk management. The rate and complexity of tall building construction is increasing, and cities will house many more people in tall buildings. The 5th International Tall Building Fire Safety Conference will take place on 19-21 June 2018 at Excel, London alongside the FIREX International Exhibition, supported by organisers UBM. Day 1 will consider design and fire engineering in tall buildings; day 2, management and insurance of fire risk in tall buildings; while the last day will consider firefighting in tall buildings. With Early Bird rates available, anybody interested in attending is advised to book now as space will be limited. Conference Director Russ Timpson commented, “This is a timely opportunity to get the Global fire safety community together and discuss a ‘way forward’ for tall building fire safety. FIREX provides a great platform to encourage people to travel to London and take part. With a great line up of world class speakers, this should be a seminal event for those concerned with learning lessons from Grenfell and other recent tall building fires”. All delegate will also get VIP access to FIREX and associated exhibitions.

Read More

Videx Secures North Tyneside Housing

Videx has expanded its presence in the housing market by winning a three year contract with North Tyneside Council. North Tyneside Council provides a range of accommodation across the region to meet the differing needs of the local community. The Council wanted to refurbish 16 sheltered housing schemes with better suited door entry systems and provide new systems to a further 10 new builds. These schemes ranged in size from a new build development comprising 8 bungalows to a 54 bed extra care scheme. The number of properties in total that required access control additions or modifications was 1,000. Videx, working with Goldshield Securus, has provided door entry systems that offer flexible access control that meets both the changing needs of the residents and also the operational aspects of the staffing arrangements. Steve Natton, Projects Manager at Videx, said, “The requirement was clear – the Council wanted an easy way for residents to report issues such as anti-social behaviour, general maintenance faults and any other non-emergency related issue that did not require a call through their warden call system. With the Videx IP based door entry system, tenants have been provided with a remote IP help line through to a dedicated team at North Tyneside Council. By using the door entry handset the tenant can place a call through to the Council which is handled by an operator on a PC based concierge. The operator views the call on the screen and can call the resident back over the IP connection. This call has no cost associated to it as it utilises the authority intranet and also provides inclusion for all tenants living within their schemes whether they have a telephone line or not. Another main benefit of this feature is that it also relieves the strain on the Warden Call system freeing up time for emergency calls.” A full access control and CCTV system with IP remote monitoring covers the external perimeter, controlled access doors, lobby area, and an additional camera is set up in the Scheme Manager’s office. The controlled access door cameras are made available on the residents’ communal IRS TV system allowing them to validate the visitor and the office camera can be switched on to also broadcast on to the TV system to allow the residents to view the Scheme Manager during morning calls. This feature was a specific request by the client to provide the residents with a visual presence if they wish during the call process. Perimeter intruder alarm detection was also provided with remote monitoring which interfaced with the CCTV and provided a complete security package. Steve added, “What’s particularly reassuring for the Council is that our door entry systems come with a lifelong guarantee of support so if the client has any issues with the system or needs to modify it to meet the changing needs of residents, they can. That is one of the most unique aspects of the Videx service – lifelong support – and one of the reasons why we are able to grow our client base in the housing market.”

Read More

STM32H7 Series MCU

STMicroelectronics, a global semiconductor provider serving customers across the spectrum of electronics applications and a leading supplier of Arm-based microcontrollers (MCU) used in Internet-of-Things (IoT) devices, welcomes Platform Security Architecture (PSA) from Arm as a major enabler for ubiquitous, best-in-class cyber security. ST’s STM32H7 high-performing MCUs are designed with the same security concepts as the PSA framework, and combine these principles with STM32-family enhanced security features and services. People and organizations are increasingly dependent on connected electronic devices to manage time, monitor health, handle social interactions, consume or deliver services, maximize productivity, and many other activities. Preventing unauthorized interactions with these devices is essential to protecting identity, personal information, physical assets, and intellectual property. As the IoT grows in scope and pervasiveness, public safety and national security are also at stake. As device manufacturers must always innovate to beat new and inventive hacking exploits, PSA helps them implement state-of-the-art security cost-effectively in small, resource-constrained devices. “Security is a major priority to ensure the success of the IoT. Winning the confidence of end users – from individual consumers to businesses and government agencies – is critical to adoption,” said Michel Buffa, Microcontroller Division General Manager, STMicroelectronics, “PSA from Arm is making core security capabilities like device identity and over-the-air (OTA) updates more affordable and scalable for small autonomous IoT devices, and we’ve made it work with the existing security features of STM32 microcontrollers including on our high-performing STM32H7 series.” ST’s STM32H7 MCU devices integrate hardware-based security features including a true random-number generator (TRNG) and advanced cryptographic processor, which will simplify protecting embedded applications and global IoT systems against attacks like eavesdropping, spoofing, or man-in-the-middle interception. In addition, secure firmware loading facilities help OEMs ensure their products can be programmed safely and securely, even off-site at a contract manufacturer or programming house. To enable secure loading, security keys and software services already on-board the MCU permit OEMs to provide manufacturing partners with already-encrypted firmware, making intercepting, copying, or tampering with the code impossible. This enables programming and authenticating the device to establish the root-of-trust mechanism needed for the device to be connected to the end-user’s network and remotely updated over the air (OTA) to apply security patches or feature upgrades throughout the lifetime of the device. “Arm is working with our ecosystem to shift the economics of security with the introduction of PSA as a common industry framework for securing the next trillion connected devices,” said Paul Williamson, Vice President and General Manager, IoT Device IP, Arm, “To secure hardware blocks and firmware-loading services ST has embedded in the Cortex-M based STM32H7 series, and utilizes the Arm PSA principles to drive innovation in security for a broad range of applications, including communication gateways and connected objects.”

Read More

Wavesight Appoints New Director

Wavesight India appoints Shrikant Gupta as the Director who is joining on 1 December 2017. Shrikant is a passionate leader with proven abilities to conceptualize long term goals and rally the team on that path. He would be the change agent to deliver results. A business manager with sales experience in wireless for over 17 years and business development experience across IT and Telecom domains, Shrikant has specifically excelled in building new relationships/ verticals, recruitment of channel partners and growing new business into multimillion US dollar successes. Prior to joining Wavesight, Shrikant was the Head of Cambium Networks in India for 7+ years. Earlier he helped set up and establish Radwin in India. Some of the key projects he has worked on in India include Airtel, Tikona, TCL, Reliance, Dialog, Grameen phone, Assam e-Govt, Tripura e-Govt, Nepal Telecom Authority and rural connectivity for Wi-Fi with Aircel.

Read More