Encode helps the University of Aberdeen strengthen security and reduce management burden
Two week project streamlines security processes and enables detection of brute force and subtle network attacks
Aberdeen, Scotland – 8th December, 2015 – Encode, a provider of cutting edge Security Analytics and Response Orchestration platforms has helped the University of Aberdeen strengthen security and reduce false positives with a successful implementation of an advanced security intelligence platform.
Ranked consistently among the top 1% of the world’s universities, Aberdeen is also one of Scotland’s largest with an IT infrastructure serving over 16,000 staff and students around the clock. As part of an ongoing strategy to deliver secure IT to ‘any device, anytime, anywhere’; the University contracted Encode to help it proactively detect and prevent cyber-attacks through the deployment of an advanced Security Information and Event Management (SIEM) solution.
The university has a highly diverse environment including network elements from Cisco, Juniper, F5 Networks, Bluecoat, HP and Radius. The diversity extends to the operating system and application layer, which includes critical software running on Linux, UNIX and Microsoft Windows. The SEIM needed to be seamlessly integrated with this environment and able to adapt to new threats posed by growth of its Bring-Your-Own-Device (BYOD) strategy.
Working closely with Encode, the University deployed a QRadar SIEM and engaged in a structured education programme to transfer the core skills needed to allow the IT services team to manage the platform and quickly gain more visibility into its diverse infrastructure.
QRadar offers a Security Intelligence Platform within a unified architecture for integrating security information and event management, log management, anomaly detection, incident forensics and configuration and vulnerability management. The SIEM provides near real-time correlation and behavioural anomaly detection to identify high-risk threats. Working with Encode, the University went through a “tuning” process to ensure that data was correctly flowing into QRadar from over 40 sources including server and network elements.
Within just two weeks, the IT services team were up and running and able to significantly reduce its largely manual workload associated with correlating security logs across its infrastructure. Using the out of the box rules engines; the SIEM was able to quickly alert the team to a number of issues such as brute force attacks against user logins as well as more subtle attempts to subvert DNS and other core network routing processes.
As Garry Wardrope, IT Security Manager for the University explains, “With Encode’s help we have successfully deployed QRadar and are benefiting from increased visibility across our infrastructure which is vital as we extend the scope and reach of our IT services across more devices.”
QRadar also ties into several existing securities software applications and uses correlation across a number of metrics to help reduce false positives and prioritise alerts to focus investigations on an actionable list of suspected incidents. “The SIEM means we have the ability to build new rules that can adapt to our evolving IT demands while improving our ability to detect more complex IT security threats and deal with them in a timely fashion,” Wardrope adds.
— End —
About Encode Group
Launched in 2001, Encode has conducted thousands of security projects for more than 200 major organizations. Our client-base includes European and Middle East banks, along with other major companies, telecom and public sector organizations from more than 20 countries. Encode delivers a cutting edge Security Analytics & Response Orchestration platform and best of breed Cyber Security Operations and Services, empowering organizations with early warning and adaptive response capabilities against advanced cyber threats.
Encode’s powerful Enorasys Security Analytics & Response Orchestration platform enables continuous cyber situational awareness and targeted response, the only effective antidote to advanced cyber threat actors and APT attacks. The solution is customer centric, agile and delivered as a Managed Security Service, Cloud/SaaS, or on-premises solution.
With global operations and local expertise, Encode combines its cutting edge technology with best of breed Cyber Security Operations and Services to augment its clients’ cyber security capabilities for the continuous and effective management of advanced cyber threats.
For more information, please visit: http://www.encodegroup.com/
Media contact for Encode:
The Message Machine
P: 07887 682943