Home / Business and Politics / Here is how you can protect yourself from cybercrime

Here is how you can protect yourself from cybercrime

Vedran Vujasinović
Vedran Vujasinović / Image by: foto

Companies are increasingly exposed to cyber attacks, but there are solutions to ensure and preserve confidential data. Security is a process, requiring digital transformation, a change in awareness that implies that reactive action with mutually unrelated technological solutions is no longer sufficient. Cloud-based analytics, monitoring, and correlation of information along with automation and orchestration is the path to achieving this goal. Setcor, as a company specialized in secure cloud, is in an ideal position to apply the awareness and expertise gained through years of specialization in cybersecurity to each of our users through a new managed SOC as a service, explains Vedran Vujasinović, Head of the Cybersecurity Department at Setcor.

As Vujasinović states, more and more companies are seeking solutions in specialized Security Operations Centers (SOC) which are recognized as a key measure for effective protection against cyber attacks. A Security Operations Center is a centralized unit that addresses security issues at both organizational and technical levels, integrating all available technological solutions, people, and processes. It is a central place from where security analysts monitor the security situation 24/7, conduct investigations on assigned cases, classify alerts, prevent and resolve security threats using technology, expertise, and accepted processes to arrive at a concrete solution to the situation.

– As a primary goal, the SOC is tasked with preventing attacks at this stage for the largest number of threats through early detection, i.e., indicators of possible malicious activity enriched with contextual information, so that the secondary goal of monitoring intrusions and eliminating threats, known as malware hunting which has found its way into the user’s local infrastructure, can be conducted for a smaller number of critical events that can be managed – as they often imply rebuilding part or all of the systems from scratch or from backups, thus causing unavailability and damage. For this to be achievable, the SOC must have visibility of all security events and incidents from the moment of arrival to all boundaries of the company, whether through the employee’s endpoint, email, internet, or cloud applications, and through monitoring further lateral movement through the local infrastructure. Once the SOC receives all necessary alerts and integrates with all key control points, it arrives at information that describes the event, i.e., the context around each alert. Through analysis, we arrive at a precise and concrete context based on which it is possible to conclude whether it is a critical alert, a new threat that poses a risk, or something irrelevant to the user’s environment, and based on that we can conclude whether to open a detailed investigation or close the incident. With rapid detection and focused response, it is possible to prevent most threats, reduce downtimes and risks to IT systems – explains Vujasinović.

Companies, on the other hand, can form such a unit within their organization and try to fight today’s modern threats ‘in-house’. In this case, it is necessary to designate employees solely for these activities, continuously invest in the education of this internal team that is expected to fight with a large number of alerts day and night without interruption, and then, as a particularly important item, find ways to keep them updated with the latest threats in the world because without visibility of threats on a surface larger than just one company, this task becomes extremely challenging and difficult to achieve. In this case, it is advisable to turn to specialized companies that offer their clients the service of establishing such a managed comprehensive system for monitoring and overseeing security events on the information system, including specialized support for operational system monitoring (known as Managed SOC).

In Croatia, this service is also offered by Setcor, and their Head of the Cybersecurity Department, Vedran Vujasinović, emphasizes that their key advantage lies in the approach to cybersecurity as a process, rather than a single technological product, and in years of work on secure cloud with a large number of various users, with high demands on cybersecurity, thanks to which they are constantly on the front line of defense and up to date with the latest security threats regardless of the vector they come from.

– Setcor is in a position to provide secure cloud services, through the applied “security by design” strategy in all its services, having a unique insight into events or threats across a large surface of users. The knowledge gained in this way can be applied in the design of each of our services and for each of our users. Through the SOC, we can provide our users with the previously mentioned proactive protection intertwined with a technological and process approach with top cybersecurity analysts as a management and control factor. Automation of enriching contextual information as well as key elements of machine responses to known IOCs, detecting threats before they cause damage, and stopping threats that have found their way into the company’s infrastructure, along with recommendations for improvements that are used to increase the efficiency of existing security tools, procurement of tools aligned with cybersecurity processes, resulting in cost minimization and maximum reduction of business risks – all of this orchestrated together makes ‘SETCOR Managed SOC as a Service’ that every user can rely on – concludes Vujasinović.

{embed_digitalno_izdanje}{/embed_digitalno_izdanje}