DON’T LET HACKERS RAID So why do we sometimes treat it that way?
Contact leading UK information assurance company NCC Group for a free trial of advanced managed security services, quoting RETAIL
An erratic model Too many organisations only address digital and cyber security a handful of times a year. Yet they would never approach their physical security in the same manner. For retailers handling card payments, regular
Payment Card Industry (PCI) scanning is mandatory and this can provide a clear annual structure for penetration testing and other security audits. The trouble is that it is all too easy to fall into a pattern – of scanning at a specifi c time each quarter, for example. But how many companies check that their doors and windows are locked only four times a year?
The alternative Achieving total information assurance means being proactive, not reactive. It should be a core business process, not an occasional or erratic one. Digital and information security is essential to ensuring survival in today’s highly evolved threat landscape. In practice, managed security services are an
option, offering a security model with continual issues detection and total peace of mind.
Managed security services combine multiple security processes into a single package: 1. Monitoring of infrastructure confi guration changes, both internal and external.
lnerability scanning of web applications and infrastructures, both internal and external.
3. Compliance scanning such as PCI and Code of Connection assessments.
4. Daily infrastructure delta scans, with further infrastructure vulnerability scans taking place at whatever frequency is required.
5. Non-mandatory processes such as internal system scans, and scans of systems that do not process card payments can also be included.
THE CASH REGISTER Information security is not a one-off. It’s not something that only matters occasionally, or a commodity that can be purchased once and then forgotten about
Ongoing assurance This model of managed security delivers one of the greatest assets of a modern organisation – ongoing information assurance.
Rather than infrequent scans throwing up
vulnerabilities that may have existed for months, managed security services identify them as they happen and present regular reports, giving an up-to- date and well-maintained picture. Rather than a security vulnerability sitting – and
potentially being exploited – for weeks before to the next scheduled scan, managed security services are alerted to it immediately, and can set a fi x in motion.
Added value Managed security services move the responsibility for security externally, the IT department can focus on managing the corporate networks, senior management can focus on running the business. Because vulnerability scanning is executed and managed externally, there are no sudden costs to absorb, no procurement of tools to carry out scanning in-house, and no paying staff overtime during ‘scanning season’. Financial information isn’t the only sensitive data
handled by companies. What about customers’ names and addresses? Or staff contact details, who could be a target for spear phishing attacks on an organisation? What about data relating to suppliers or sales plans, or the information you entrust to your third party suppliers? By identifying infrastructure vulnerabilities as they occur, managed security services can protect all these and more.
A managed model Managed security services offer ongoing assurance, total compliance, cost-effectiveness and added value, helping you to protect a retailer’s brand and reputation. Let the experts run your security – while you run
Why NCC Group? • Europe’s largest team of penetration and security testers, able to react immediately to your requirements.
• The UK’s largest team of CHECK and CREST qualifi ed testers.
• Delivers managed services to four of the UK’s fi ve largest food retailers.
Call: 0161 209 5111 Email: email@example.com
RETAIL TECHNOLOGY MARCH/APRIL 2012
| Page 2
| Page 3
| Page 4
| Page 5
| Page 6
| Page 7
| Page 8
| Page 9
| Page 10
| Page 11
| Page 12
| Page 13
| Page 14
| Page 15
| Page 16
| Page 17
| Page 18
| Page 19
| Page 20
| Page 21
| Page 22
| Page 23
| Page 24
| Page 25
| Page 26
| Page 27
| Page 28
| Page 29
| Page 30
| Page 31
| Page 32
| Page 33
| Page 34
| Page 35
| Page 36
| Page 37
| Page 38
| Page 39
| Page 40