Organizations continue to increase their security spending – an expense justified by the significant costs associated with data loss and downtime. Compliance with government regulations, such as the Sarbanes-Oxley Act (SOX) and the Health Insurance Portability and Accountability Act (HIPAA), also continues to play a significant role in security spending decisions.
“Security continues to be the top issue for organizations of all sizes, particularly those facing pressure to demonstrate compliance under various regulatory requirements,” said Vince Conroy, CTO, FusionStorm. “Organizations need to have security tools in place to protect against malicious attacks and security incidents, such as leakage of sensitive corporate information.”
However, very few organizations have adequate resources in place to provide comprehensive threat, vulnerability and compliance management. Given the ever-increasing complexity of security and compliance solutions, organizations are increasingly interested in managed security options, particularly in the mid-market space.
“Few customers have sufficient security expertise in house, and even fewer have the staff to monitor systems 24x7. Others don’t have the infrastructure to support it. But probably the number one stumbling block is cost — enterprise-class products are very expensive. The mid-market lacks robust, cost-effective security solutions,” said Conroy. “A high-quality managed services solution eliminates capital outlays and provides expert support around-the-clock.”
Mitigating Threats
FusionStorm’s managed security and compliance services are designed to meet the needs of small to midsized business (SMBs) and mid-market organizations. The FusionStorm Threat Management Service (TMS) and Log Management Service (LMS) offerings, powered by technology from AlertLogic, a leading provider of security and compliance solutions, leverages enterprise-class tools and FusionStorm’s renowned security remediation expertise to provide comprehensive 24x7 protection.
FusionStorm TMS includes an on-site appliance that combines proactive and reactive security using widely recognized signature- and anamoly-based technologies. It probes the network for vulnerabilities and potential threats, and collects intrusion data as actual threats are identified. This data is reported to a user-friendly console that can be monitored by the customer or the FusionStorm security team.
“We offer different service levels depending upon the customer’s requirements. At the basic level, we deliver the information collected by the appliance as a color-coded threat matrix. At the next level, our managed services team uses that information to assess and respond to any active security threats that arise, and remediate any vulnerabilities,” said Conroy.
Aiding Compliance
The FusionStorm LMS product works in a similar fashion — in this case, an on-site appliance collects and sorts through the vast amounts of log information generated by servers, network devices and applications. It produces reports and dashboards that help organizations make sense of log data for regulatory compliance, incident response, forensics, and performance and availability analysis.
“Many regulations require that you maintain and review log data on a regular basis for compliance reporting. However, trying to locate actionable information from the raw data that’s put out by all of these devices is like looking for a needle in a haystack,” Conroy said. “The FusionStorm LMS offering provides organizations with a sophisticated toolset that delivers the log data in a meaningful way.”
There’s no equipment to purchase for either service. For a one-time setup charge and monthly fee, organizations get comprehensive security and compliance solutions backed by world-class FusionStorm support.
“In the past, customers have hesitated to utilize these kinds of services because they were too expensive, too complicated and didn’t do enough,” said Conroy. “FusionStorm has addressed those limitations. The TMS and LMS offerings are affordable, full-featured and turnkey, and can be integrated with our other managed services offerings. I believe these are very competitive options for SMB and mid-market customers.”