Get to know us better! Gain valuable insights into how we think by visiting our blog, or take a look at the industry events we're frequenting on our events page. You can also geek out with us by attending one of our security management webinars, or dive head first into the products and solutions we provide in our Resource Library. There's lots to keep you busy!
In Part 1, we built the case that SIEMs are ineffective for threat hunting, based on the following reasons:
To date, SIEM vendors have not provided the market with the functions needed for producing world-class threat hunting. Again, threat hunting is a method. In order to follow this method, we have to have tools that accelerate and amplify our human work, rather than using technologies that brush aside our method in favor of operating within their paradigm. Too many threat hunting programs are sputtering because we continue to believe that the method should conform to the technology, but that gets things backwards.
Threat hunting remains an undeveloped competency for far too many organizations. When surveyed, security professionals confess an overall lack of competency to detect and respond to advanced attacks that slip through their defenses. In my experience, many organizations still rely on alerts from a SIEM (among other prevention systems). Most security teams will painstakingly build models for indicators of compromise, receive alerts from their SIEM, and “do the best they can” to eliminate the intrusion. What are the results?
How do you know if your security posture is where it needs to be? Most organizations look at standards, be it national standards, industry standards or their own corporate standards. They may also look at their industry’s best practices. But if you aren’t looking at your risk vulnerability, you are likely not looking at the entire spectrum of your network’s security posture.
El nuevo paradigma de la automatización es la “Administración del Ciclo de Vida”
Te mostraremos cómo FireMon Intelligent Policy Automation utiliza la tecnología de automatización e inteligencia para reducir el esfuerzo e incrementar la eficacia en cada etapa del proceso de cambios.
Proactive Security Intelligence Leader to Showcase Integration with Next-Generation Firewall Platforms and Support for Cutting-Edge Panorama Management Console
OVERLAND PARK, Kan., September 17, 2014
FireMon, the industry leader in proactive security intelligence solutions, today announced that the company will be participating at the Palo Alto Networks Americas Partner Conference, which will take place September 17-19, 2014 at the JW Marriott in Chicago, Illinois. FireMon will be showcasing its Security Intelligence Platform in Booth #7.
Palo Alto Networks’ integrated, application-centric solutions have dramatically shifted the market for network security device management. By combining FireMon’s Security Intelligence Platform with Palo Alto device infrastructure, organizations can address strategic processes such as firewall rules and policy cleanup and change, optimization of overall network enforcement and prioritization of underlying risks.
Notably, FireMon’s Security Intelligence Platform integrates directly with Palo Alto’s Panorama management console, allowing customers to leverage advanced automation in order to address network security complexity and change. And for channel partners, FireMon-Palo Alto joint solutions deliver several benefits including: increased profits via faster, successful firewall deployment and management; demonstrated ROI for device implementation; and consistent, vendor-supported firewall device and policy migration.
The FireMon Security Intelligence Platform allows organizations to remediate exposed vulnerabilities and optimize their existing defenses. The recently introduced Policy Optimizer module helps organizations adapt network security device rules to changing threats, emerging management challenges and evolving compliance requirements such as PCI DSS.
Policy Optimizer is the first solution to automate a traditionally manual, fragmented process bridging the “access gap” existing between network security teams and other involved officials. In conjunction with Security Manager and Risk Analyzer – the core components of the Security Intelligence Platform – Policy Optimizer isolates any potentially problematic rules or policies, allowing users to alter or eliminate risky access and improve their overall security posture.
FireMon is the industry leader in proactive security intelligence solutions for large organizations that deliver continuous control of infrastructure, policy and IT risk. The FireMon Security Intelligence Platform is a massively scalable, high-performance foundation for network risk detection, change workflow automation, firewall rule base clean-up, compliance audit assessment and security operations cost reduction. For more information, visit http://www.firemon.com.
Helping Enterprise Security Teams Improve Resource Efficiency & Reduce Overall Risk Exposure
Firewall technology has come a long way since its initial, most rudimentary forms. Next-Generation Firewalls (NGFW) are the latest development, and organizations are accelerating adoption to the new technology. But NGFWs aren’t a fix-all solution.