Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Network Security

End of Bibblio RCM includes -->
7/7/2017
07:40 PM
Arlen Free
Arlen Free
News Analysis-Security Now

Small Businesses Need Secure ISPs

Small businesses can't do it alone: They need secure services from ISPs and MSPs to survive today's hostile environment.

It's no secret that SMBs are highly vulnerable when it comes to cyber threats. The anecdotal numbers paint a pretty dire picture: It seems that half of all SMBs are attacked at least once by cyber crime, yet many owners think they're safe from online threats. Recent news stories indicate that one of the most common attacks on SMBs is a phishing scheme, which often lead to costly ransomware infections and loss of sensitive personal data and account credentials. In my many years in the security industry, most recently with a leading cloud security provider, I have seen the cyber threat landscape change dramatically -- and unfortunately, the security solutions provided by vendors lack the specific requirements of SMBs, and also leave little room for management and control of the network with the ISP. With everything moving to the cloud, end-point security alone is no longer adequate. But most cloud security solutions are still priced out of reach of the small and midsized business, and offer a tremendous disadvantage to ISPs: They take away network control and visibility from the service provider, making it difficult for them to keep the network running optimally when something goes awry.

Compounding the problem, small business owners are generally not cybersecurity or IT experts, and they typically lack in-house expertise to keep their networks and all connected devices adequately protected, especially given the number of threats and variants that inflict damage on a daily basis. Most available solutions on the market are geared towards large enterprises -- companies with big IT budgets and dedicated teams of people to handle ongoing management of those tools. This scenario leaves SMBs largely under-protected -- and cyber criminals are all too aware of this.

ISPs, which are often the only IT "staff" an SMB has, are in a perfect position to serve this market segment with an easily managed, convenient security solution, at the cost of a weekly cup of coffee. By offering their own cloud-based security-as-a-service (SECaaS) solution, ISPs can fill a much-needed gap with a security service that requires no hands-on deployment or management from the business end user and which protects all internet-connected devices from phishing, ransomware and other malware, at a cost that SMBs can easily afford.

Security in the carrier cloud: DNS is key to blocking and protecting
DNS is utilized in a vast majority of cyberattacks -- more than 90% to be exact. Why? Because DNS is what powers every web site look-up and web application request, and it can be easily used by bad actors to create malicious domains for phishing or ransomware campaigns without the targeted victim’s knowledge. Yet much can be learned from DNS queries that take place on the service provider network, which helps ISPs -- and their DNS provider -- pinpoint new threats before they’re even executed or within minutes of being launched. DNS data also helps identify infected devices so subscribers can be notified right away, and those devices isolated from doing harm to the service provider network and possibly infecting others.

DNS plays a critical role in a layered security strategy, also called "defense in depth," which is basically a multi-layered approach to cyber defense. The truth is no single solution will do it all. In today’s digital economy, businesses and individuals are increasingly targeted with fast-changing exploits that use advanced methods to avoid detection, and individual, point security solutions (e.g., firewalls, endpoint protection) do not provide adequate protection on their own.


Want to learn more about the tech and business cases for deploying virtualized solutions in the cable network? Join us in Denver on October 18 for Light Reading's Virtualizing the Cable Architecture event – a free breakfast panel at SCTE/ISBE's Cable-Tec Expo featuring speakers from Comcast and Charter.

Perhaps more importantly though, and the main reason a DNS-based approach to a SECaaS offering makes sense for ISPs, is that keeping the service in the ‘carrier cloud’ (rather than a third-party security provider’s cloud) allows ISPs to maintain visibility and management of the network, which only enhances the value and customer experience of the service they're providing. In other words, a DNS-based approach -- especially when it’s backed by data science and deep analytics, along with machine learning -- means threats are quickly detected and blocked, attacks are stopped, and devices are protected. Period. There is very little manual intervention that needs to happen on the ISP side, and none required from the business user.

Because DNS exists in all service provider networks already, it is an easy step to take for ISPs to utilize this infrastructure and offer a SECaaS solution to their business customers. The benefits to ISPs are the ability to maintain network visibility/control, increase revenues and strengthen brand loyalty. The benefit to small businesses is that their needs for broad, deep security are met without worry or difficulty.

Cyber crime is not going away. In fact, it's becoming more prevalent and more damaging every day, and SMBs are at a disadvantage when it comes to keeping themselves protected. As their needs for powerful, affordable security continue to increase, the opportunity for ISPs to deliver an effective cloud-based service that can be monetized will also grow.

Related posts:

As General Manager for Nominum's security and applications portfolio business, Arlen Frew oversees the company's go-to-market strategy, including sales, engineering, support and product management, as well as extending its OEM technology licensing business to security-as-a-service.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Practical Network Security Approaches for a Multicloud, Hybrid IT World
The report covers areas enterprises should focus on for their multicloud/hybrid cloud security strategy: -increase visibility over the environment -learning cloud-specific skills -relying on established security frameworks -re-architecting the network
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-30333
PUBLISHED: 2022-05-09
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
CVE-2022-23066
PUBLISHED: 2022-05-09
In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to tra...
CVE-2022-28463
PUBLISHED: 2022-05-08
ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.
CVE-2022-28470
PUBLISHED: 2022-05-08
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
CVE-2022-1620
PUBLISHED: 2022-05-08
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.