Managed Security Service Common IT Security Challenges • Does my network security protect my IT environment and sensitive data and meet the regulatory compliances? • How do I keep my cloud based servers, IT assets and MPLS network protected from malicious intruders and malware? • How can I lower or eliminate the CAPEX and OPEX of deploying and managing multiple firewall devices at all my locations? • How do I get my limited IT staff refocused on strategic revenue generating initiatives? 2 Security & Compliance Issues Grow Approximately 80 percent of small businesses that experience a data breach go bankrupt or suffer severe financial losses within two years of a security breach. - Small Business Computing Magazine 93% of companies that have lost their data center for 10 days or more have filed for bankruptcy within one year. - U.S. National Archives and Records Administration 3 Number of Breaches by Threat Type Source: Verizon 2014 Data Breach Investigations Report These Headlines Are All-Too-Common 4 April 2014: Heartbleed January 2014: vulnerability in Michaels Stores Open SSL publicly loses data on disclosed; left more 100M than 2M servers December customers (NY vulnerable to 2013: Target Times) unencrypted data hacked for leaks (IBM X-Force info on more Threat Intelligence than 100M Quarterly 2014) customers (NY Times) September 2014: Home Depot announces data breach; 54M credit cards were breached (Krebs Onsecurity blog) September 2014: Apple iCloud accounts hacked for celebrity photos (CNN) Can You Afford the Risk? • If your business is faced with data theft, what would you do? • What do you think the impact would be (tangible and intangible)? • How would your customers react? • How would your investors react? • What would your competitors do to capitalize on your problem? • How long would it take for your business to recover? ? 5 Cost of Security Compromises • $5.85M - average cost of data breach in US, growing 15% over last year (IBM/Ponemon Institute 2014) – Average US lost business cost: $3.3M in customer turnover, increased customer acquisition activities, reputation losses and diminished goodwill • $148M – cost of Target breach and ousted CEO (Forbes) • 10 hours of unplanned downtime has potential cost from $125,000 for an SMB to as much as $17M for an enterprise firm (IDC) $ 6 How much can you afford to lose? How Managed Security Can Help • Shift the burden of security management to EarthLink • Provide an outsourced security solution with 24/7 monitoring, protection and support • Reduce the amount of internal resources needed to manage network security and administration Empower your business • Lower upfront capital resources • Simplify IT management • Rapidly scale up and down Lower the time and cost of managing day-to-day IT operations, and free your IT budget and staff to focus on strategic initiatives. 7 EarthLink Managed Security Solutions • Managed Security provides a comprehensive suite of security services to manage and protect your network assets – Managed Firewall • Managed Premises Firewall • Data Center Firewall – Secure Remote Access – PCI Compliance Solutions • PCI Protect • PCI Assist • PCI Certify 8 Managed Firewall • Managed Premises Firewall • Data Center Firewall – Designed for Hosted solutions, Colocation customers, or MPLS networks Secure managed firewall to reduce Internet threats by stopping both inbound and outbound security threats. We lower cost and ensure that your most valuable and confidential information stays secure. 9 Managed Firewall Features Managed Premises Firewall Data Center Firewall Stateful inspection x x Antivirus and antispam x x Intrusion detection and protection x x URL and content filtering x Optional Category-based filtering x Optional Features Available: Active Directory integration 10 Optional Application control x x Unlimited policy changes x x Monthly reporting x x Self-serve portal x On-demand reporting x Configuration backup and restore x x 24/7/365 device/availability monitoring x x Performance and availability management x x Managed Firewall Benefits • Managed security solution – Provides Unified Threat Management (UTM) – Experts on staff to support your business – Proactively deploys latest security patches • • • • Protects against theft Protects your key business information assets 24/7 Reduces need for security experts on staff Eliminates maintenance and management of customer-owned firewall • Improves network performance by blocking data from nonapproved sites, applications and content 11 Firewall Reports • • 12 Self-serve portal available for on-demand reporting and changes Examples of reports available: – Basic Security Report – Bandwidth Analysis Report – Web Filtering Reports – Forensic Analysis Report – Threat Analysis Report Managed Premises Firewall Options • Basic Option – – – – – Policy Management Backup/Restore Performance Monitoring Troubleshooting and Alerting Unlimited Policy Changes per month • Premium Option (Includes Basic Option plus) – – – – – – 13 URL Filtering Web Content Filtering Category-based filtering Customized Content Filtering and Application Control Intrusion Prevention (IPS) Antivirus Data Center Firewall • • • • • Provides Unified Threat Management (UTM) Security experts on EarthLink staff to support your business Proactively deploys latest security patches Reduces need for security experts on staff Eliminates maintenance and management of customerowned firewall • Improves network performance by blocking data from nonapproved sites, applications and content 14 Data Center Firewall Features • Protection against data theft, unauthorized network access, inappropriate web content, infected files and malware • Safeguard your MPLS locations from the Internet • Intrusion Prevention Service • Antivirus/Malware/Spyware protection • Application Control • Log retention • Complete security reporting • 24x7 support • Performance guarantees • Web Content Filtering including Category and URL whitelisting/blacklist filtering (optional) • Multiple web content profiles (optional) • Active Directory integration (optional) 15 Secure Remote Access • Provides remote access to your private network – Customers control adding or removing users – Restrict access based on security Access method for mobile users, telecommuters, small offices, provided as firewall feature or standalone. 16 Secure Remote Access Benefits • Secure connectivity • Improve employee and business productivity with instant access to network and information • Support for Windows, Mac, Linux, iPhone, iPad, Android 17 What is PCI Compliance? • Definition – Payment Card Industry Data Security Standard (PCI-DSS) 6 Control Objectives 12 Core Requirements 250+ Audit Procedures 18 • Set up by Visa, MasterCard, American Express, Discover, and JCB to reduce the risk of credit card theft and transfer liability to merchants • Requires mandatory adoption by all businesses that store, process, transmit credit/debit card data Impact of a Breach on a Business 1. 2. 3. 4. Must stop accepting credit cards Pay for forensic audit Pay fines and credit card replacement costs Pay to implement remediation actions and for future on-site audits by a Qualified Security Assessor A credit card breach can take months to remediate The average U.S. business loses $3.3M per breach incident due to customer churn, brand damage, etc. (IBM and Ponemon Institute) 19 Secure Solutions for Merchants & Retailers • SMB to Fortune 500 retail customers • Tens of thousands of store locations • Comprehensive network and IT services to support PCI compliance: – Nationwide private MPLS – Direct Connect • Secure Point of Sale connectivity – SSAE 16 compliant data centers; connect directly via MPLS – Managed security services – PCI Compliance Validation with Breach Protection 20 Managed Security Services Benefits Peace of Mind – Minimize risk and protect your business’ mission-critical information Save Money – Lower operational costs and upfront capital expense associated with managing, monitoring and securing your infrastructure Make Your Life Easier – Comply with government and industry regulations through proactive security monitoring, documented security policies and procedures Save Time – Shift the burden of security management to EarthLink – On-demand reporting provides easy access and visibility to your critical business assets 21 Why EarthLink? • Security experts to help you mitigate risks, achieve and maintain industry compliance requirements while driving down the total cost of securing and managing your IT systems • Private MPLS infrastructure and nationwide footprint • Advanced Data Center Firewall protects both your cloud services and MPLS network from inbound and outbound threats • Personalized support from EathLink’s IT consultants - an extension of your IT staff • Online portal will consistently monitor your network and automatically open trouble tickets 22