SlideShare ist ein Scribd-Unternehmen logo
1 von 15
Boxing OrangeSIEM E-Crime Roundtable
Agenda Introduction to Boxing Orange  MSSP Market Drivers Introduction to ArcSight Common Use Cases Customer Success  Why Use an MSSP for SIEM Services? How Boxing Orange Deploy ArcSight Boxing Orange Security Operations Centre  Questions
Who are Boxing Orange? One of the largest Managed Security Service Providers (MSSP) in the UK  Privately funded and owned with over 10yrs experience in the IT security marketplace Providing 24/7 fully managed and monitored security services Helps to increase your security posture, manage risk and improve compliance
What Do Boxing Orange Do? “Boxing Orangewill provide your organisation with the right level of IT security service on a 24/7 basis whilst reducing your overall security spend” “Boxing Orangeis one of the UK’sleading Managed Security Service Providers(MSSP). We focus exclusively on Information Security Services, offering a complete set of both Managed Security and Professional Services. We employ best of breed products from leading security vendors to underpin our Managed Services portfolio. We provide 24/7 services from a dedicated Secure Operations Centre (SOC) to some of the UK’s most successful companies in sectors such as government, gaming, retail and banking/finance”
MSSP – Market Drivers Need to Access a Wider Range of Services Outside Internal Expertise Need to Access 24/7/365 Monitoring  & Reporting Needs Arising from Regulatory Pressure Increasing Number of Security Failures & Vulnerabilities Increased Use of Secure Extranets / Portals Need to Deal with Information Overload Produced by n x Security Systems
MSSP – Market Drivers Market & Technology Maturity MSSP Competence = Trust of Clients Flexibility to Adapt to Client Changes Economies of Scale Offered by MSSPs  Job Market Lacks Qualified IT Security Specialists Flexibility of Partnership and Agreements Increasing Complexity of Networks and Networking Equipment
Gartner’s View of the MSSP Market Enterprises are engaging managed security service providers (MSSPs) to meet security monitoring and device management requirements for several reasons: The inability to increase resources or expertise because of the business climate  Compliance requirements for monitoring and reviewing security and user-related activities  The trend toward providing local Internet connections to branch offices, rather than through a central corporate gateway  The increasing use of mobile workforce and consumer-grade technology to access corporate resources
Why Use an MSSP for SIEM Services? Use Case Assistance to Achieve Maximum Value & Rapid Results Pay for What You Need – Reduce Capital Expenditure Access to World Class SIEM software from ArcSight Scalable Pricing Model to Maximise Operating Expenditure Fast Start Partner to Achieve SIEM Project Goals and Objectives 24/7/365 Analysis of Event Information by Trained and Security Cleared Analysts Wide Security Vigilance and Shared Threat Knowledge
Boxing Orange SIEM 24/7 Support Systems Industry Leading SIEM Platform Industry Leading 24/7 SOC Boxing Orange SIEM Service
Customer Dashboards & Reports Managed Service Portal & Extranet 24/7 Secure Operations Centre Security Event & Incident Feeds Managed Service Platform & Systems Enterprise Security Management Platform & Systems Boxing Orange Collector Boxing Orange Collector Customer Devices
Security Operations Centre (SOC) Boxing Orange operate a 24/7/365 Security Operations Centre (SOC) 24/7 on-line reports 24/7 single point of contact 24/7 secure customer portal 24/7 access to Boxing Orange security analysts 24/7 monitoring of client’s security infrastructure 24/7 trouble ticketing via email, portal, telephone 24/7management of client’s security infrastructure 24/7 web view provides a read only view for clients
Boxing Orange “The trustedpartner in providing  ManagedSecurity Services, Managed SIEM Services, Advice & Solutions to businesses and organisations across the UK”
Questions Any Questions?
Thank You

Weitere ähnliche Inhalte

Andere mochten auch

Andere mochten auch (13)

"You Got That SIEM. Now What Do You Do?"  by Dr. Anton Chuvakin
"You Got That SIEM. Now What Do You Do?"  by Dr. Anton Chuvakin"You Got That SIEM. Now What Do You Do?"  by Dr. Anton Chuvakin
"You Got That SIEM. Now What Do You Do?"  by Dr. Anton Chuvakin
 
So You Got That SIEM. NOW What Do You Do?  by Dr. Anton Chuvakin
So You Got That SIEM. NOW What Do You Do?  by Dr. Anton ChuvakinSo You Got That SIEM. NOW What Do You Do?  by Dr. Anton Chuvakin
So You Got That SIEM. NOW What Do You Do?  by Dr. Anton Chuvakin
 
SIEM vs Log Management - Data Security Solutions 2011
SIEM vs Log Management - Data Security Solutions 2011 SIEM vs Log Management - Data Security Solutions 2011
SIEM vs Log Management - Data Security Solutions 2011
 
Security Onion Conference - 2015
Security Onion Conference - 2015Security Onion Conference - 2015
Security Onion Conference - 2015
 
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
Five Best and Five Worst Practices for SIEM by Dr. Anton ChuvakinFive Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
 
SOC Foundation
SOC FoundationSOC Foundation
SOC Foundation
 
Siber güvenlik ve SOC
Siber güvenlik ve SOCSiber güvenlik ve SOC
Siber güvenlik ve SOC
 
Implementing and Running SIEM: Approaches and Lessons
Implementing  and Running SIEM: Approaches and LessonsImplementing  and Running SIEM: Approaches and Lessons
Implementing and Running SIEM: Approaches and Lessons
 
Security Operations Center (SOC) Essentials for the SME
Security Operations Center (SOC) Essentials for the SMESecurity Operations Center (SOC) Essentials for the SME
Security Operations Center (SOC) Essentials for the SME
 
Building a Next-Generation Security Operation Center Based on IBM QRadar and ...
Building a Next-Generation Security Operation Center Based on IBM QRadar and ...Building a Next-Generation Security Operation Center Based on IBM QRadar and ...
Building a Next-Generation Security Operation Center Based on IBM QRadar and ...
 
NetSecTR - "Siem / Log Korelasyon Sunumu" Huzeyfe Önal
NetSecTR - "Siem / Log Korelasyon Sunumu" Huzeyfe ÖnalNetSecTR - "Siem / Log Korelasyon Sunumu" Huzeyfe Önal
NetSecTR - "Siem / Log Korelasyon Sunumu" Huzeyfe Önal
 
SOC presentation- Building a Security Operations Center
SOC presentation- Building a Security Operations CenterSOC presentation- Building a Security Operations Center
SOC presentation- Building a Security Operations Center
 
HP ArcSight
HP ArcSight HP ArcSight
HP ArcSight
 

Boxing Orange Siem Roundtable Presentation

  • 2. Agenda Introduction to Boxing Orange MSSP Market Drivers Introduction to ArcSight Common Use Cases Customer Success Why Use an MSSP for SIEM Services? How Boxing Orange Deploy ArcSight Boxing Orange Security Operations Centre Questions
  • 3. Who are Boxing Orange? One of the largest Managed Security Service Providers (MSSP) in the UK Privately funded and owned with over 10yrs experience in the IT security marketplace Providing 24/7 fully managed and monitored security services Helps to increase your security posture, manage risk and improve compliance
  • 4. What Do Boxing Orange Do? “Boxing Orangewill provide your organisation with the right level of IT security service on a 24/7 basis whilst reducing your overall security spend” “Boxing Orangeis one of the UK’sleading Managed Security Service Providers(MSSP). We focus exclusively on Information Security Services, offering a complete set of both Managed Security and Professional Services. We employ best of breed products from leading security vendors to underpin our Managed Services portfolio. We provide 24/7 services from a dedicated Secure Operations Centre (SOC) to some of the UK’s most successful companies in sectors such as government, gaming, retail and banking/finance”
  • 5. MSSP – Market Drivers Need to Access a Wider Range of Services Outside Internal Expertise Need to Access 24/7/365 Monitoring & Reporting Needs Arising from Regulatory Pressure Increasing Number of Security Failures & Vulnerabilities Increased Use of Secure Extranets / Portals Need to Deal with Information Overload Produced by n x Security Systems
  • 6. MSSP – Market Drivers Market & Technology Maturity MSSP Competence = Trust of Clients Flexibility to Adapt to Client Changes Economies of Scale Offered by MSSPs Job Market Lacks Qualified IT Security Specialists Flexibility of Partnership and Agreements Increasing Complexity of Networks and Networking Equipment
  • 7. Gartner’s View of the MSSP Market Enterprises are engaging managed security service providers (MSSPs) to meet security monitoring and device management requirements for several reasons: The inability to increase resources or expertise because of the business climate Compliance requirements for monitoring and reviewing security and user-related activities The trend toward providing local Internet connections to branch offices, rather than through a central corporate gateway The increasing use of mobile workforce and consumer-grade technology to access corporate resources
  • 8.
  • 9. Why Use an MSSP for SIEM Services? Use Case Assistance to Achieve Maximum Value & Rapid Results Pay for What You Need – Reduce Capital Expenditure Access to World Class SIEM software from ArcSight Scalable Pricing Model to Maximise Operating Expenditure Fast Start Partner to Achieve SIEM Project Goals and Objectives 24/7/365 Analysis of Event Information by Trained and Security Cleared Analysts Wide Security Vigilance and Shared Threat Knowledge
  • 10. Boxing Orange SIEM 24/7 Support Systems Industry Leading SIEM Platform Industry Leading 24/7 SOC Boxing Orange SIEM Service
  • 11. Customer Dashboards & Reports Managed Service Portal & Extranet 24/7 Secure Operations Centre Security Event & Incident Feeds Managed Service Platform & Systems Enterprise Security Management Platform & Systems Boxing Orange Collector Boxing Orange Collector Customer Devices
  • 12. Security Operations Centre (SOC) Boxing Orange operate a 24/7/365 Security Operations Centre (SOC) 24/7 on-line reports 24/7 single point of contact 24/7 secure customer portal 24/7 access to Boxing Orange security analysts 24/7 monitoring of client’s security infrastructure 24/7 trouble ticketing via email, portal, telephone 24/7management of client’s security infrastructure 24/7 web view provides a read only view for clients
  • 13. Boxing Orange “The trustedpartner in providing ManagedSecurity Services, Managed SIEM Services, Advice & Solutions to businesses and organisations across the UK”