the power of cyber protection - cyber & information security · it & cyber security, not as...

CYBER POSTURE AND STRATEGY DESIGN Building Cyber Security Resilience Since 1995 The power of cyber protection

Upload: others

Post on 17-Aug-2020

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: The power of cyber protection - Cyber & Information Security · IT & Cyber security, not as an IT or technology division problem, ... configurations and concluded that the IT team

CYBER POSTURE AND STRATEGY DESIGNBuilding Cyber Security Resilience Since 1995

The power ofcyber protection

Page 2: The power of cyber protection - Cyber & Information Security · IT & Cyber security, not as an IT or technology division problem, ... configurations and concluded that the IT team

Our Offer

We are pleased and honored to offer you our Cyber Posture & Strategy Design service, which includes an in-depth security audit and risk assessment of your entire organization:

The outcome and deliverables will be an IT & Cyber Security master plan that will equip your organization with next-generation cyber defense capabilities.We would like to take your organization to the next level by viewing IT & Cyber security, not as an IT or technology division problem, but rather a Risk Officer and Boardroom issue that requires in depth understanding. This will enable us to construct a roadmap pointing out a series of significant activities necessary for building the appropriate robust infrastructure for IT & Cyber Security suitable for years to come in order to face upcoming challenges.

NetworkIT infrastructureEnd-PointIndustrial networkWeb-server infrastructureOrganization policyTraining levelSecurity operations capabilitiesProcedures of your organization headquarters and facilities.

Page 3: The power of cyber protection - Cyber & Information Security · IT & Cyber security, not as an IT or technology division problem, ... configurations and concluded that the IT team

It is very important for us to emphasize that it is our most sincere desire to provide an extremely high quality work product based on our vast experience that will differ from what most consulting companies would provide in a regular IT security audit, or a penetration test report outcome.

About Us

Avnet is an Israeli Cyber & Information security group, a leader of IT and Communications projects in the ICT market and in the security market for more than 20 years. Avnet has dozens of senior consultants, cyber experts and integration engineers specializing in relevant areas. Our services include preparing technological, networking and operational strategy plans including design, analysis, engineering and implementation of large systems and networks for various customers including governmental institutions, service providers, public and private entities.

Are You Ready to Face a Cyber-Attack?

Cyber incidents are on the rise and everybody is exposed to them. “Target Retail” data breach damage costs so far are estimated by them at $291 million, and may reach $370 million, U.K. mobile service provider TalkTalk attributed more than $80 million in losses to a breach that garnered information on 157,000 customers. Yet, other companies have no idea how much damage their breaches have done. It is just a matter of time until you will find it at your doorstep. Can you answer and say how ready is your organization for such an attack? Can you give a qualified answer? Can you give a scalable answer? If not then you are not prepared for an imminent cyber-attack. This is why you need to take the first initiative and expose beforehand all of your organization cyber security vulnerabilities.

Page 4: The power of cyber protection - Cyber & Information Security · IT & Cyber security, not as an IT or technology division problem, ... configurations and concluded that the IT team

Unique Customer Base

GOVERNMENT MILITARY & HLS BANKING & FINANCE HEALTH CARE HIGH TECH

What Makes Us Different

Over 20 years of global scale experience.Unique accumulated knowledge due to Avnet’s unique divisions’ structure. Each division handles only with its expertise; Penetration, Infrastructure, Applications etc. making them experts at their designated field.Avnet’s Group vast experience place it in a unique position to provide best of breed tailored made cyber solutions and products, and since we are situated in Israel – the world leading cyber capital we have access to the latest cutting edge innovative technologies.Elite team of IDF intelligence unit and gifted hackers with OSCE\OSCP\CISSP certifications.

Page 5: The power of cyber protection - Cyber & Information Security · IT & Cyber security, not as an IT or technology division problem, ... configurations and concluded that the IT team

Cyber Posture & Strategy Design Case Study

An international conglomerate which consists of an HQ Company that manages a series of asset management companies in addition to direct and portfolio investment funds, owning and managing assets in the metals, mining, chemical, construction, transport, energy, telecommunication, high-tech machine building, public utilities and financial sectors in Russia, CIS, Switzerland, Italy, South Africa and USA.

Goals & NeedsThe HQ Company has experienced a local low-intensity cyber incident and was able to mitigate it. The details of the incident were brought to the board of directors. The board raised a question – “What is the company cyber security status in dealing with cyber incidents?” the company has interviewed cyber security companies from the US, Switzerland and Israel and has selected Avnet to answer this question and take care of its cyber security needs as a one stop shop.

Avnet’s ApproachAt the project’s outset, a detailed plan was submitted, and AVNET’s top cyber security experts met with a selection of the HQ Company relevant internal employees for a comprehensive client assets. IT network systems etc.

Methodology

IMODBest

Practice NIST NISAISO

27001

Preliminary Survey

Phase 1

Phase 2

Phase 3

Interviews

Risk Assesment

Penetration test

GRC

Flndings

Recommendations

Implementation

Page 6: The power of cyber protection - Cyber & Information Security · IT & Cyber security, not as an IT or technology division problem, ... configurations and concluded that the IT team

At the project’s outset, a detailed plan was submitted, and AVNET’s top cyber security experts met with a selection of the HQ Company relevant internal employees for a comprehensive reviewing infrastructure, network and security components, procedures, and methodology. Avnet performed cyber-attack simulations to assess vulnerability to internal and external attackers on infrastructure, network and servers, management systems, mails, sensitive documenters etc.

Project Findings

Sensitive information was captured i.e. e-mails, logins, passwords, documents etc.A comprehensive report of the HQ vulnerabilities along with their prioritization and how to mitigate them.

The HQ Company lacked the ability to recognize security events occurring in the corporate network using solutions existing in the corporate network. AVNET has recommended the structure of Security Operations Center (SOC) enabling the organization to monitor all the security events and security devices, coupled with significant training for the security stuff to turn them into Cyber analysts.has demonstrated and explained how an external attacker from the internet can obtain full connection to the internal network via a Trojan horse.AVNET has reviewed all the HQ Company security solutions and their configurations and concluded that the IT team has managed to retrieve the maximum security from the products/solutions existing in the corporate network, but still security based on the network routers and switches was not enough and lacks of segmentation control and flow of information.

Page 7: The power of cyber protection - Cyber & Information Security · IT & Cyber security, not as an IT or technology division problem, ... configurations and concluded that the IT team

Project Results

The HQ Company has launched AVNETs strategic cyber security roadmap and is systematically implementing its milestones.New cyber-security committee to design a standard cyber security policy was established.AVNET has provided recommendations and a set of tailored to their needs cyber-security solutionsAs a result of implementing the cyber security roadmap created by AVNET the HQ Company maturity level is increasing by two levels.AVNET is repeating the process of cyber posture & strategy design for all the HQ company subsidiaries

*By BlueCaot

Page 8: The power of cyber protection - Cyber & Information Security · IT & Cyber security, not as an IT or technology division problem, ... configurations and concluded that the IT team

46 Ha’macabim RoadPO Box 16027Rishon Le-Zion, 75060IsraelTel. +972-3-9560074Fax. [email protected]