small-image

20 Apr
Protect your website

Denial of Service (DoS) and Distributed Denial of Service (DDoS)

DoS (Denial of Service) or DDoS (Distributed Denial of Service) attacks are attempts by hackers to make an online business or service unavailable. Some hackers use attacks to take down websites for political or other motives, or to access confidential information, but most commonly they are used to disrupt the online operations of a business.

Protect your online services

Today, more and more people use the internet to search for the products or services they need. Having a website means customers are always able to find you. It offers the user convenience as they can access the information, products and services they need, anytime and from anywhere, even outside of business hours.

Whether your website is just used to show images of your location and products or is a full blown e-commerce site, if prospective customers can’t get to or use your website they are likely to look elsewhere, potentially losing you income and profit.

Excellent corporate
protection

Protect complex, globally distributed web systems and keep maintenance under control.

Avoid blocking legitimate requests

Ensure your customers are able to access your services without being mistaken for a malicious entity.

Protect against a wide range of attacks

Protect against the complete range of web application attacks across the complete stack.

Trusted Knight's Cloud-DMZ

To help protect against DoS and DDoS attacks, we recommend Trusted Knight’s Cloud-DMZ, which provides enterprise-grade web application security and DDoS protection by actively scanning the application, understanding its functionality and serving a secure, cloud-based replica.

Cloud-DMZ prevents attackers from gaining unauthorized access to web systems, compromising sensitive data and defacing websites while minimizing the organizations dependency on secure development and third party patches.

Cloud-DMZ eliminates vulnerabilities such as:
  • Cross-Site Scripting (XSS),
  • SQL Injection,
  • Remote File Inclusion
  • OWASP Top-10.

Contact us today for more information on
Trusted Knight’s Cloud-DMZ

20 Apr
Comply with GDPR

We can help you to comply with the General Data Protection Regulation

The new General Data Protection Regulation (GDPR) became law on 25 May 2018 and all businesses who hold data relating to EU citizens need to ensure that they comply. Failure to do so could result in fines of up to 4% of annual global company turnover or €20 million, whichever is greater.

The GDPR seeks to give people more control over how organisations use their data and expands the rights of individuals to control how their personal information is collected and processed and places a range of new obligations on organisations to be more accountable for data protection.

Understanding what you need to do to become compliant can seem daunting. While many of the GDPR’s requirements are much the same as those in the current Data Protection Act (DPA), there are some significant additional responsibilities. The good news is that if you’re complying with the DPA, you have a sound basis on which to build on toward GDPR compliance.

While the following requirements may seem burdensome and complex, our Consultancy Services team can help you. From the initial in-depth assessment into the data you hold, how and where it’s used within your own business and how it may be shared with third parties, penetration testing to identify vulnerabilities in your infrastructure, to developing and implementing a full GDPR Compliance Action Plan, we can support you.

GDPR compliance

To be compliant, you will need to:

  • Perform an information audit to map data flows.
  • Document what personal data you hold, where it came from, who you share it with and what you do with it.
  • Identify your lawful bases for processing data and document them.
  • Have systems and processes in place to record and manage ongoing consent.
  • If you rely on consent to offer online services directly to children, ensure that you have systems and processes in place to manage it.
  • Confirm whether you need to be registered with the Information Commissioner’s Office.
  • Ensure that if you offer online services directly to children, you communicate privacy information in a way that a child will understand.
  • Be able to recognise and respond to individuals’ requests to access their personal data.
  • Have processes to ensure that the personal data you hold remains accurate and up to date.
  • Have a process to securely dispose of personal data that is no longer required or where an individual has asked you to erase it.
  • Have procedures to respond to an individual’s request to restrict the processing of their personal data.
  • Have processes to allow individuals to move, copy or transfer their personal data from one IT environment to another in a safe and secure way, without hindrance to usability.
  • Have procedures to handle an individual’s objection to the processing of their personal data.
  • Have identified whether any of your processing operations constitute automated decision making and have procedures in place to deal with the requirements.
  • Have an appropriate data protection policy.
  • Monitor your own compliance with data protection policies and regularly reviews the effectiveness of data handling and security controls.
  • Provide data protection awareness training for all staff.
  • Review how you ask for and record consent.
  • Have a written contract with any data processors you use.
  • Manage information risks in a structured way so that management understands the business impact of personal data related risks and manages them effectively.
  • Have provided appropriate privacy notices to individuals.
  • Have implemented appropriate technical and organisational measures to integrate data protection into your processing activities.
  • Understand when you must conduct a Data Protection Impact Assessment (DPIA) and have processes in place to action this.
  • Have a DPIA framework which links to your existing risk management and project management processes.
  • Have a nominated data protection lead or Data Protection Officer (DPO).
  • Ensure that decision makers and key people in your business demonstrate support for data protection legislation and promote a positive culture of data protection compliance across the business.
  • Have an information security policy supported by appropriate security measures.
  • Ensure an adequate level of protection for any personal data processed by others on your behalf that is transferred outside the European Economic Area.
  • Have effective processes to identify, report, manage and resolve any personal data breaches.

Contact us today for more information on our range of consultancy and project management services

19 Apr
Safeguard computers and mobile devices

Securing the endpoints

Most networks are accessed remotely by devices such as laptops or other wireless and mobile devices, and each device with a remote connection to the network creates a potential entry point for security threats, such as viruses and spyware. Comprehensive Network and Endpoint Security is a key part of an organisation’s response to cyber threats.

ESET® Endpoint Security provides comprehensive IT security for your business via multiple layers of protection including their field-proven ESET NOD32® detection technology, providing complete data access protection and fully adjustable scanning and update options. Thanks to low system demands, virtualisation support and optional cloud-powered scanning, it will keep your system running at its best.

Features include:

Comprehensive endpoint protection for Windows

Virtualization support + new technology

Supports VMs and provides protection from hackers and botnets.

Built-in data access control

With web control to limit website access, and two-way firewall.

Remote management

Fully manageable via the new ESET Remote Administrator web-console.

Low system demands

Protect against the complete range of web application attacks across the complete stack.

User-friendly remote administration

ESET Endpoint Security comes fully manageable *

Customizable user interface visibility

Visibility of the Graphical User Interface (GUI) to end users can be set to full, minimal, manual or silent. **

Replacing legacy anti-virus

Other security software is detected and uninstalled automatically during installation of the ESET Endpoint solutions.

* Via ESET Remote Administrator, delivering a perfect “look & see” overview of the network security status.

** The presence of the ESET solution can be made completely invisible to end users if required, including no tray icon or notification windows. By hiding the GUI completely, the “egui.exe” process does not run at all, resulting in even lower system resource consumption by the ESET solution.

Contact us today for more information on
ESET® Endpoint Security

19 Apr
Find your weaknesses

Find (and fix) your vulnerabilities before an attacker does

Penetration testing (pen testing) is an effective way to assess the security of your network and systems. It is a controlled form of hacking where experienced testers can emulate the actions of attackers. Systems are put through their paces to assess vulnerability by identifying weaknesses in hardware or software, system configuration or other operational issues.

An organisation that conducts regular penetration tests stands a greater chance of blocking cyber attacks as they’re far more aware of their potential vulnerabilities. It also means that resources, both financial and personnel, can be focused on those areas requiring most attention, maximising the value of your IT spend.

Penetration testing services

EnterpriseRed offers a range of pen testing and security review services to help you identify vulnerabilities in your network and systems before the bad guys do. We will help you fix them to improve your defences, whether in the core network or associated devices .

A key component in ensuring that your data remains secure.

  • Penetration testing for infrastructure, web applications, mobile applications and wireless networks
  • Infrastructure vulnerability assessment
  • Configuration security review
  • Architecture security review
  • Phishing attack simulation
  • Source code security review

Contact us today for more information on our
penetration testing solutions

19 Apr
Training and asessment

Turn your team into a human firewall

Our cybersecurity training and assessment services are the perfect complement to the products we offer. We can help identify the gaps in your cybersecurity armour, and recommend products or solutions to address those gaps.

Training

Data breaches are often caused by human error, primarily due to lack of training and cybersecurity awareness.

Failure to provide appropriate training for their employees means a business is vulnerable to attack, risking their reputation, the trust of their customers and their bottom line.

Employees are your front line in managing your response to cybersecurity threats, and our tailored assessment and training services can help to ensure that they are part of an effective security response, a human firewall, rather than creating vulnerabilities for your business.

Cybersecurity assessment

At EnterpriseRed, we believe cybersecurity is more than just a technological solution.

It’s about risk management – and that means understanding the information you have and needs protecting, identifying threats to that information and the consequences of an attack on your business operations and reputation. We would then recommend solutions to enable you to strengthen your defences against the increasing volume and severity of cybercrime, both in terms of products and, potentially, employee training.

Contact us today for more information on our
training & assessment services

  • 1
  • 2
Sidebar: