headtop

Security News

Discovering Data, then Protecting It - February 3, 2008

Sencilo Solutions will be launching a data discovery and risk assessment service as compliance continues to drive interest in the space.

"Along with the forth coming product we will be launching a new consulting service to help companies discover confidential data as well as gauge and manage risks", say President and Security Expect Brian McCarthy.

Our company is leaning on its many years of experience in the data protection and data activity monitoring space with the new Discovery Service, an offering aimed squarely at helping businesses find sensitive data, identify risks posed by current operating procedures and develop plans to tighten those loose-ends.  Early last year one of our insurance clients called us in to assist them with a SEC order to produce records from 2005.  Our client asked us to provide them with tool so that no data was over looked on their 8 tera-byte EMC SAN, and over 900 desktops and mobile computers.  The request was for file data along with e-mail and databases, "leave no stone un-turned," said their CIO. 

We see the market for consulting services is driven largely by regulations such as the Payment Card Industry Data Security Standard and the Gramm-Leach-Bliley Act. Most companies are unable to address this requirement because they don't have the tools to find and classify private data, officials at Sencilo said. The lack of visibility into critical data assets can equal significant risk of data theft, data breaches and unapproved data access, officials contend.

"Over the years with the proliferation of data centers, databases, applications and data; not to mention acquisitions and mergers; enterprises have data scattered all over the company," said Bill Parrish, vice president of product management at the data auditing vendor. "It's very difficult to keep track of all of the different repositories and data, let alone know what's happening to the data."

Our partner Barracuda Networks recently reported last June launched its IT Risk Assessment service, found that 26 percent of the 323 IT professionals surveyed expect a regulatory non-compliance incident at least once a year. The study also examined 75 security and availability incidents and found 59 percent came down to a failure of processes.

"On one side, the bigger impact on IT performance is training and awareness, but on the other side, it tends to be the least implemented control by many organizations out there," said Samir Kapuria, managing director of Barracuda Advisory Services.

As part of Sencilo's service, consultants work with client companies to develop remediation plans after issuing a risk assessment report. The findings include an overall risk score, as well as risk profiles for all users and applications that access the sensitive data. But the core of the service revolves around finding the sensitive data and determining how it is being used. To do that, the company leverages partner's data monitoring technology.

"This is the first time that we've offered a service like the Discovery Service. However, we have provided database auditing and security consulting to our customers for several years," Parrish said.

"As a matter of fact, it was during customer engagements that we uncovered the need for a discovery service. Our customers were struggling to get a better handle on where their data was located and how it was being used."

ABOUT US
Today, leading companies rely on Sencilo’s innovative approach to protect their mission-critical data. We deliver a comprehensive portfolio of professional and fully-managed on demand services that support the complex storage, data protection, assessments, design, installation, business continuity, disaster recovery, security and compliance needs of our customers. With hundreds of customers Sencilo is unique in its ability to solve the industry's most difficult storage and security challenges.

Sencilo has continuously led the industry in service innovation by simplifying and automating tasks traditionally needed to manage multi-vendor enterprise storage and data protection environments. By outsourcing this essential business requirement, our customers reduce costs, optimize performance, and increase visibility over their storage and backup solutions, enabling them to refocus scarce IT resources in Tampa, Miami, Jacksonville and Orlando.

Call us at (407) 265-6293 or visit us at www.sencilo.com

 

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage and security solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Daytona Beach, Miami, Tampa, St. Petersburg, Orlando, Hialeah, St. Augustine, Gainesville, Ocala, Palm Coast, Clearwater, Kissimmee, Lakeland, Maitland and Cape Canaveral

Offerings Projects: Replication De-Dup De-Dupe iSCSI SAN NAS VMware Security EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant Quadrent LTO Backup Exc Pure Disk NetBackup Networker TSM Commvault BakBone D2D D2D2T compare cloud data deduplication  thin provisioning DXi Global Compression DDX  virtual tape library Data Reduction SEPATON FALCON compare Celerra CLARiiON Equallogic Dell NS20 NS40 CX4 CX3-20 CX3-40 CX3-80 FAS2050 FAS3050 Xiotech Nexsan Avamar DLD3 1500 D3 Storwiz storage compression data Ocarina Networks A-SIS compare Sepaton infopro BlueArc OnStor Microsoft Unified Storage data protection


Financial services firm hacked - January 31, 2008

Financial services firm Davidson Companies this week said an intruder had broken into its network and gained access to a database containing the personal information of its clients.

"Despite our efforts to safeguard client information, a computer hacker using sophisticated techniques illegally accessed a database and obtained access to confidential client information," said William Johnstone, Davidson's president and CEO, in a prepared statement posted on the firm's Web site. "All of us at Davidson are acutely aware of the uncertainty, stress and inconvenience associated with the potential compromise of personal information."
Davidson, based in Great Falls, Mont., and with more than 930 employees, has sent letters to its financial services clientele informing them of the incident and urging them to take various steps to lower the risk of identity theft.

The company said it is offering its clientele a one-year enrollment to Experian’s Triple Advantage three-bureau credit-monitoring service at the company's expense to help them begin the process of regularly reviewing their credit records for abnormalities.

A Davidson spokesperson was not immediately available to respond to questions.  Sencilo Solutions CEO and President stated, "this is not a uncommon of a fact, for Davidson to admit to a breach, shows that companies are now coming forward do to new State laws."  "Now Davidson will spend a lot of money for putting back the pieces, but adding new technology including Intrusion Detection products and services".  "Had they been more proactive they would of avoid public embarrassment, lost of client trust and a certain future class action suite, say McCarthy. 

Sencilo offers a comprehensive suite of Security products and services that help you assess, design, and execute your network and applications in the most secure and cost-effective way. From security audits and virtual private networks to enterprise firewall implementations. Call us today for a independent check-up on your network and information security, you will be glad you did!  Don't wait wait Davidson Financial. 

For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/products-security.php

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage and security solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Daytona Beach, Miami, Tampa, St. Petersburg, Orlando, Hialeah, St. Augustine, Gainesville, Ocala, Palm Coast, Clearwater, Kissimmee, Lakeland, Maitland and Cape Canaveral

Offerings Projects: Replication De-Dup De-Dupe iSCSI SAN NAS VMware Security EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant Quadrent LTO Backup Exc Pure Disk NetBackup Networker TSM Commvault BakBone D2D D2D2T compare cloud data deduplication  thin provisioning DXi Global Compression DDX  virtual tape library Data Reduction SEPATON FALCON compare Celerra CLARiiON Equallogic Dell NS20 NS40 CX4 CX3-20 CX3-40 CX3-80 FAS2050 FAS3050 Xiotech Nexsan Avamar DLD3 1500 D3 Storwiz storage compression data Ocarina Networks A-SIS compare Sepaton infopro BlueArc OnStor Microsoft Unified Storage data protection


Disk Storage or Tape Data Indexing and Classification Services - January 26, 2008

Miami, Florida -  Sencilo Solutions announced this week that is will add another Compliance related service for businesses throughout Florida, that of Indexing and Classificating network information.  "Explosive data growth across the enterprise continues to present significant challenges for IT managers and their companies", say Brian McCarthy, President and Co-founder of Sencilo. "All manner of structured and unstructured data grows exponentially while management faces increasing demands to discover and protect that information," continues McCarthy.  Flat budgets and overloaded IT departments struggle to contain escalating costs, mitigate risks and meet service level agreements in the face of these new demands.

Our Tape Data Indexing and Classification Service streamlines the identification and collection of electronic evidence. The tool-based service is application and infrastructure independent, and easily integrates into the existing online disk environment. It addresses online data and maintains an accurate view of historical and current data assets.

The service is scalable to billions of documents, and delivers the most comprehensive and accurate search results available today. It delivers a comprehensive index of all enterprise data assets, comprising only five percent of the original data with no data copies, and provides an easy-to-use search platform with Internet-type querying capabilities to support any e-discovery initiatives. Key benefits include:


  • Onsite service delivery with no impact to production operations; or, offsite at our secure, state-of-the-art facilities

  • Rapidly process large volumes of tapes or disks, and billions of files and emails

  • Turns the storage arrary or tape library into a searchable repository that is immediately searchable, including both full content and metadata

  • Allows users to select the files to restore and the system automatically generates a request to the administrator with all relevant information


For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/storage-protection.php
About Us

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage and security solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Daytona Beach, Miami, Tampa, St. Petersburg, Orlando, Hialeah, St. Augustine, Gainesville, Ocala, Palm Coast, Clearwater, Kissimmee, Lakeland, Maitland and Cape Canaveral

Offerings Projects: Replication De-Dup De-Dupe iSCSI SAN NAS VMware Security EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant Quadrent LTO Backup Exc Pure Disk NetBackup Networker TSM Commvault BakBone D2D D2D2T compare cloud data deduplication  thin provisioning DXi Global Compression DDX  virtual tape library Data Reduction SEPATON FALCON compare Celerra CLARiiON Equallogic Dell NS20 NS40 CX4 CX3-20 CX3-40 CX3-80 FAS2050 FAS3050 Xiotech Nexsan Avamar DLD3 1500 D3 Storwiz storage compression data Ocarina Networks A-SIS compare Sepaton infopro BlueArc OnStor Microsoft Unified Storage data protection


Report: SPAM Accounts for 90-95% of All Email - January 26, 2008

In 2001, spam accounted for an estimated 5% of our email. In 2007, it clogs our inboxes to the tune of 90-95% of all email sent, according to a new report released today by Barracuda Networks. Barracuda, a leading vendor of spam filtering technology, based their analysis on the over 1 billion emails that the company's software scans each day. The year-over-year increase appears to indicate the failure of the US federal CAN-SPAM Act, which was passed in 2004 when spam only accounted for about 70% of all email sent.

Last month we reported on a study from research firm IDC that predicted that 2007 would be the first time that spam out numbered legit email. Our readers didn't think that sounded right: surely spam outnumbered legit email years ago. "Spam sure as hell surpassed legit emails in my inbox -- years ago. Mine. My mom, dad, sisters, brothers, aunts, uncles, every single friend I've talked to about it, my cat and dog, Boobo my hamster, everyone..." wrote one commenter.

Barracuda's report corroborates those feelings and calls into question the IDC report. Certainly, from my own personal experience, it is a lot easier to believe Barracuda. I use three email accounts on a regular basis, and across them, I get about 2500-3000 pieces of spam each week. I get a lot of legit email, as well, but not enough to outnumber the unsolicited stuff. Luckily (for most users), I am in the minority. According to the report, 65% of email users get less than 10 pieces of junk mail per day (half get less than 5). Just 13% find themselves in the unhappy position of receiving more than 50 spam emails per day.

Barracuda's report also found that spam is not only annoying, but it is the most annoying form of junk advertising. 57% of respondents to a survey question asking what the worst form unsolicited advertising was said spam, compared to just 31% for postal junk mail and 12% for telemarketers.

Unfortunately, spammers continue to evolve their tactics to beat the filters. In 2006 there was a rise of image spam and botnets. This past year, spammers were seen using attachments (like PDF files) as well as using more advanced identity obfuscation techniques.

The good news is that spam filtering technology is evolving right along with the spammers, and it works well. Thanks to filters, I only see about 3-4% of the spam I get (which is still a lot given the immense volume). Here's to a spam free 2008 -- hey, a guy can dream, right?

For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/products-security.php

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage, security and networking solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, NetApp, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Miami, Tampa, St. Petersburg, Orlando, Hialeah, Fort Lauderdale, Tallahassee, Cape Coral, and Pembroke Pines.

Key words:  Barracuda Networks Security RSA Encryption Cisco Decru Neoscale EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant SSL SonicWall Secure Computing Firewall VPN Endpoint


Q1 Labs Announces QRadar 6.1: Converged Network and Security Management Disciplines Delivered in a Single Platform - January 20, 2008

Best of Breed Network and Security Monitoring for Log, Threat and Compliance Management


Q1 Labs, a leading network security management company, today unveiled QRadar™ 6.1, the latest version of its flagship product which reinforces Q1 Labs’ commitment to innovate across multiple monitoring disciplines: Log Management, Security Event Management and Network Behavior Analysis.

QRadar 6.1, delivers key features that enable both network and security teams to effectively monitor their network within the same management infrastructure. Coupled with the functionality included in the release of QRadar SLIM (Simple Log and Information Management; see release issued October 30, 2007), QRadar 6.1 provides several new features and capabilities in the following key areas including:

• New network flow searching capabilities for better network behavior analysis and security forensics
• Quality of Service monitoring for important network applications like VoIP
• Augmented host discovery and asset based alerting
• Tamper proofing of all stored log, event and network flow data

Combining network and security monitoring capabilities serves a growing need in the market. As noted in a recent Gartner report Select the Right Monitoring and Fraud Detection Technology1
“Network security and operations products are different markets; however, we see these markets converging in 2008 so that one product set will provide a common network monitoring infrastructure for the NOC and the SOC”

QRadar 6.1 – More Than Just Another SIEM and NBA Product
Today’s converging enterprise requires access to critical network and security data by both network and security operations teams. QRadar offers best of breed network and security monitoring to meet compliance and threat management drivers from a single platform. Features unique to QRadar 6.1 include:

• Network Behavior Analysis with a simple, flexible flow viewer that provides complete, enterprise network visibility
• Robust Log Management architecture combined with analysis that can monitor the network and intelligently alert on the state of new threats, users, and hosts/assets in the network
• SIEM with extensive monitoring inputs and analysis capabilities that allow customers to converge the monitoring of their network and security infrastructures

“QRadar was the first product to seamlessly combine NBA and SIEM functionality – something that many of our competitors are now attempting to achieve through technology partnerships or first-step technology integrations,” said Tom Turner, VP of Marketing and Product Management for Q1 Labs. “QRadar 6.1 further solidifies our technology lead and provides another step forward in helping the converging infrastructure roll-out leading threat management and compliance management practices.”

Pricing and Availability
QRadar 6.1 is available now. Upgrade to QRadar 6.1 is available for free to existing QRadar customers. Pricing starts at $39,900.

For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/products-security.php

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage, security and networking solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, NetApp, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Miami, Tampa, St. Petersburg, Orlando, Hialeah, Fort Lauderdale, Tallahassee, Cape Coral, and Pembroke Pines.

Key words:  Barracuda Networks Security RSA Encryption Cisco Decru Neoscale EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant SSL SonicWall Secure Computing Firewall VPN Endpoint


Barracuda Web Filter Wins "Best of Connections 2007" Award From Windows IT Pro in Windows Category - January 20, 2008

The worldwide leader in email and Web security appliances, announced today that the Barracuda Web Filter has been named the "Best of Connections 2007 Awards" winner. Penton Media's Windows IT Pro judges declared the Barracuda Web Filter the best in the Windows category.

The judges reviewed more than 60 IT products and services submissions and chose 18 finalists to be evaluated at the Connections Conference in Las Vegas. Interviews were conducted during the event with winners announced on Nov. 7 on the exhibit floor of the Connections Conference.

"This is the first year of this awards program and were thrilled by the high quality of the entries we received," said Karen Forster, group editorial and strategic director." While we had many worthy products, the winners clearly demonstrated their products' strategic importance to the market, their competitive advantages and the value they provide to customers."

The "Best of Connections 2007" awards recognize companies that offer innovative products in the following categories: Exchange, Mobile, .NET, Office, SharePoint, SQL Server and Windows.

"We are honored to have the Barracuda Web Filter recognized as an innovative Windows product at the Connections show," said Dean Drako, president and CEO of Barracuda Networks. "This distinction highlights our success at addressing the growing need with network administrators for affordable content filtering and powerful anti-spyware protection at the gateway level."  "Sencilo Solutions has recently signed up as a Diamond Level Partner", say Brian McCarthy, President and CEO of Sencilo, and Storage and Security Solution Provider based in Orlando Florida. 

About the Barracuda Web Filter
Available in six models, the Barracuda Web Filter combines preventative, reactive and proactive measures to form a complete content filtering and anti-spyware solution for businesses of all sizes. The Barracuda Web Filter is designed to enforce acceptable Internet usage policies by blocking access to objectionable content and unauthorized Internet applications. At the same time, the Barracuda Web Filter's award-winning feature set enables the Barracuda Web Filter to block spyware downloads, prevent viruses, and stop access to spyware Web sites. Unlike the widely available desktop software solutions, the Barracuda Web Filter is easily installed and does not require the additional time, money or resources necessary for downloading and maintaining software on each individual PC. Hourly Energize Updates are made automatically by Barracuda Central so that the Barracuda Web Filter can block the ever-changing virus and spyware variants, as well as maintain the most up-to-date database of the latest productivity-inhibiting Web sites.

About Barracuda Networks, Inc.
Established in 2002, Barracuda Networks, Inc. is the worldwide leader in email and Web security appliances. Barracuda Networks also provides world-class IM protection, application server load balancing and message archiving appliances. More than 50,000 companies, including Coca-Cola, FedEx, Harvard University, IBM, L'Oreal, NASA and Europcar, are protecting their networks with Barracuda Networks solutions. Barracuda Networks' success is due to its ability to deliver easy to use, comprehensive solutions that solve the most serious issues facing customer networks without unnecessary add-ons, maintenance, lengthy installations or per user license fees. Barracuda Networks is privately held with its headquarters in Campbell, Calif. Barracuda Networks has offices in eight international locations and distributors in more than 80 countries worldwide.

For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/products-security.php

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage, security and networking solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, NetApp, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Miami, Tampa, St. Petersburg, Orlando, Hialeah, Fort Lauderdale, Tallahassee, Cape Coral, and Pembroke Pines.

Key words:  Barracuda Networks Security RSA Encryption Cisco Decru Neoscale EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant SSL SonicWall Secure Computing Firewall VPN Endpoint


Missing Iron Mountain backup tapes prompts identity theft fears for J.C. Penny customers - January 18, 2008

GE Money, the firm hired by J.C. Penny to run its credit card operations, announced Thursday that it is missing backup tapes containing the personal information of about 650,000 J.C. Penny shoppers.

The personal information contains about 150,000 Social Security numbers. GE said the tape was discovered missing last October by a worker at a warehouse run by Boston-based data-protection and storage company, Iron Mountain Inc.

It is unclear if the data was encrypted. "When stolen data is encrypted, companies are quick to point it out as a way to ensure customers that their identities are safe," say Security Consultant Brian McCarthy for Sencilo Solutions. GE Money spokesman Richard C. Jones said the company was paying for 12 months of credit-monitoring service for customers whose Social Security numbers were on the tape.

"As is standard practice in our industry, we rarely know the nature of the information stored on the media we transport, nor the level of encryption or security our customers use," said Iron Mountain spokesman, Dan O'Neill in an email exchange. "We understand the tape was created in such a manner that unauthorized access to the data is extremely unlikely and difficult, even for its with specialized knowledge and technology."  Un-true says, McCarthy, 30 day demo backup software is available from most vendors as a free download, and the tape drives are common place via E-Bay", Iron Mountain again is trying to cover its tracks".  The only true and compliance way it to encrypt the tapes using encryption appliances or up-grade to the latest LTO-4 tape drives that have built-in encryption." 

It's the second time in recent months that Iron Mountain lost customer data. In October, Iron Mountain said it lost a decade's worth of bank account data and Social Security numbers for almost all Louisiana college applicants and their parents. The company was moving the backup tapes containing the information. A driver reportedly lost a case full of backup data for every Louisiana application for federal student aid from 1998 through Sept. 13, 2007.

Greg Schulz, an industry analyst with the Stillwater Minn.-based StorageIO Group downplayed the J.C Penny incident saying that it would be too labor intensive for a cybercriminal to steal the data off any missing tapes. 

"A penny theft criminal is not going to target an individual tape," Schulz said.

If the tape was targeted, a sophisticated cybercriminal would need to know the type of tape it is and have a specific device to read the data. Once cracked, the hacker would need to determine how the data was formatted. The work would be labor and financially intensive and therefore not a viable way for a cybercriminal to make money stealing identities, he said.

"Tapes have been lost and misplaced and have never left the building and the reality is that there are probably fewer tapes being lost today than there have been in the past," Schulz said. "Whether they're putting data on a tape or CDs or removable hard drives, the chance of that data getting lost is there."

"To bolster security in the wake of many high profile data breaches, some companies are encrypting data on backup tapes. Some firms are also using radio frequency identification and global positioning to track and maintain a handle on backup data", McCarthy of Sencilo Solutions said.

IBM has introduced encrypting tape drives and most back up software can encrypt but it still has to be turned on, said Eric Maiwald, an analyst at Midvale, Utah-based Burton Group.The potential for losing data because of a failed key management system must also be taken into account, Maiwald said.

"Encryption mechanisms that use appropriate algorithms with appropriate key lengths are effectively impossible to break. However, we have seen poor implementations that are breakable (such as WEP),"  McCarthy said.

For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/storage-area-network.php

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage, security and networking solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, NetApp, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Miami, Tampa, St. Petersburg, Orlando, Hialeah, Fort Lauderdale, Tallahassee, Cape Coral, and Pembroke Pines.

Key words:  DR BC Replication De-Dup De-Dupe iSCSI SAN NAS VMware Security EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant LTO Backup Exc NetBackup Legato TSM Commvault BakBone D2D D2D2T compare cloud data deduplication  thin provisioning DXi Global Compression DDX  virtual tape library Data Reduction SEPATON FALCON compare Celerra CLARiiON Equallogic Dell

 


Destorying Data. How to reduce business risks in an era of ever-increasing regulatory demands. - January 12, 2008

Sencilo Solutions and it's partner PeakData, LLC of Niwot, CO., which developed an innovative set of services, centered on data eradication, to attack a new category of financial and competitive risks head-on.

There was a time, not so long ago, when the primary data-management goal of IT organizations was to preserve data from various forms of loss - from issues related to such things as mechanical (hard) failure, software failure and natural disasters. But the world has changed. A new and multiplying batch of government regulations is keeping both CIOs and CFOs awake at night, according to CarrieAnne Curtis, Media Services general manager and data-security expert at PeakData. Now, enterprises are struggling to find fool-proof ways to get rid of their once-precious data.

Do you know where your data is?
The cost of the new regulations More than 30 new state and pending federal regulations are designed to protect individuals from the loss of their personal information maintained in organizations' IT systems. The net effect of these kinds of security-breach regulations, according to PeakData's Curtis, is that: An organization must maintain total control of personal data it owns or licenses - at all times

If the organization loses track of this data for just minutes, or even seconds, applicable regulations demand that the organization notify, in writing, every individual whose information might possibly have been exposed
According to Curtis, the cost of this type of notification process can run as high as $125 to $175 per person. One well-publicized security-breach case cost the organization involved more than $10 million. Clearly, much is at stake in this new regulatory environment. But what to do?

To destroy or not to destroy?
"Ever more sensitive to complex compliance obligations," Michael Klatman, vice president of Marketing at PeakData, says, "many organizations have gone to extremes to protect data from falling into the wrong hands. In many cases, these extremes include the physical destruction of failed or retired disk drives: an approach that has negative economic as well as environmental consequences." The risks associated with these new regulations are real. But is it really necessary to destroy retired or broken disks in order to avoid falling afoul of some 4,000 laws on data retenion laws such as Sarbanes-Oxley, HIPAA, Gramm-Leach-Bliley, the USA PATRIOT, the California Security Breach Notification Law, PCI Security Standards Council ("PCI SSC"), 21 CFR Part II and many others.

While it eliminates business risk, physically destroying disks also destroys the residual economic value of those disks. And that can cost as much as $1,000 per disk. By contrast, the logical destruction of data through the process of disk eradication permits the enterprise to recover that economic value from their disk subsystem vendor: a strategy that pays for the eradication process many times over.

Destroying data...
Any organization that is destroying (or locking away) retired disk drives, according to Klatman, ought to consider using PeakData's disk-eradication services - whereby PeakData comes onsite and, using its own proprietary system and methodology, logically (rather than physically) removes the data - and certifies, according to the Department of Defense 5220.22-M standard1, that data cannot be recovered from the disk drives in question. Special technologies and methods are required to implement this standard because typical storage firmware and software are not designed to be able to purge all traces of data in this manner.

During the disk-eradication process, the customer's disks never leave the data center, according to PeakData's Curtis, and legacy storage subsystems do not need to be powered up, saving precious energy. Instead, PeakData technicians remove disks from their enclosures and place them in the company's unique Data Eradicator system chassis. The Data Eradicator then performs the minimum required three passes of binary rewrites (over each sector and bit) according to the DoD 5220.22-M standard.

...And proving it
Once the rewrites are complete, the unit automatically generates a customizable XML/PDF certificate for each disk, showing the (embedded) serial number of the disk, the number of passes made, the time and date of the operation, and the names of the technicians and witnesses present. In this way, PeakData can guarantee to its customers that the DoD 5220.22-M disk-eradication standard has been met - and that all of the old data has been purged.

Each Data Eradicator unit can process up to 36 disks at a time - and as many 10 units can be implemented simultaneously: which means that the systems can process 360 disks, or almost 15 terabytes, at once. And the unit is highly secure, according to Curtis, having no writable media of its own; instead, the Data Eradicator's specialized operating system and logic are contained solely on read-only CD/DVDs. The eradication system works with SCSI, FATA, mainframe or open-systems disks.  Or go to http://www.sencilo.com/services-eradication.php 

For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/products-security.php

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage and security solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Daytona Beach, Miami, Tampa, St. Petersburg, Orlando, Hialeah, St. Augustine, Gainesville, Ocala, Palm Coast, Clearwater, Kissimmee, Lakeland, Maitland and Cape Canaveral

Offerings Projects: Replication De-Dup De-Dupe iSCSI SAN NAS VMware Security EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant Quadrent LTO Backup Exc Pure Disk NetBackup Networker TSM Commvault BakBone D2D D2D2T compare cloud data deduplication  thin provisioning DXi Global Compression DDX  virtual tape library Data Reduction SEPATON FALCON compare Celerra CLARiiON Equallogic Dell NS20 NS40 CX4 CX3-20 CX3-40 CX3-80 FAS2050 FAS3050 Xiotech Nexsan Avamar DLD3 1500 D3 Storwiz storage compression data Ocarina Networks A-SIS compare Sepaton infopro BlueArc OnStor Microsoft Unified Storage data protection


Barracuda Networks Protects Salesforce.com Users Against Latest Phishing Malware Attack - January 9, 2008

Barracuda Spam Firewall Blocks Email Containing Malware that Collects Usernames and Passwords


Barracuda Networks, Inc., a leading provider of network security appliances, today announced that its Barracuda Spam Firewall has implemented specific countermeasures to block the phishing malware attacks targeted at salesforce.com users. These attacks were outlined in a broadcast email yesterday to all salesforce.com users advising them of the latest malware threat.


The attack on the Salesforce.com user base is a variant of known attacks that attempt to lure users into installing malware that can collect passwords to online systems, including banks, credit cards, shopping Web sites, and even salesforce.com itself.


“What makes this form of the attack unique is its social engineering,” said Stephen Pao, vice president of product management for Barracuda Networks. “The email masquerades itself as part of the Salesforce Identity Confirmation feature, which ironically was intended to enhance legitimate salesforce.com security measures against the latest wave of phishing attacks. Because of its clever design, unsuspecting salesforce.com users may inadvertently install the malware.


“While existing defense layers targeting malware in the Barracuda Spam Firewall have been effectively blocking these attacks, Barracuda Central today added another layer of defense specifically targeting this social engineering,” added Pao.


Barracuda Central, an advanced technology center at Barracuda Networks, consisting of highly trained engineers who continuously monitor and block the latest Internet threats, responded to the salesforce.com announcement by quickly adding additional levels of protection in the event that the attack starts using new malware variants. The additional levels of protection involve rules that actually block the social engineering around the Salesforce Identity Confirmation feature in addition to the malware.


“Just as Barracuda Networks was the first major appliance vendor to target the attacks against Adobe Reader users in 2007, we are proud to be the first to specifically target the attacks against salesforce.com users in 2008,” said Pao. “The tactical response of Barracuda Central combined with the Barracuda Spam Firewall's 12 defense layers allows us to continue to supply the best spam protection at the best value in the industry.”



About the Barracuda Spam Firewall
The Barracuda Spam Firewall is available in seven models and supports up to 30,000 active users with no per user licensing fees. Its architecture leverages 12 defense layers: denial of service and security protection, rate control, IP analysis, sender authentication, recipient verification, virus protection, policy (user-specified rules), Fingerprint Analysis, Intent Analysis, Image Analysis, Bayesian Analysis, and a Spam Rules Scoring engine. In addition, the entire Barracuda Spam Firewall line features simultaneous inbound and outbound email filtering with the inclusion of sophisticated outbound email filtering techniques, such as rate controls, domain restrictions, user authentication (SASL), keyword and attachment blocking, dual layer virus blocking, and remote user support for outbound email filtering. The Barracuda Spam Firewall’s layered approach minimizes the processing of each email, which yields the performance required to process millions of messages per day.  Or read more in Gartner, Inc.'s Magic Quadrant

About Barracuda Networks Inc.
Barracuda Networks Inc. is the worldwide leader in email and Web security appliances. Barracuda Networks also provides world-class IM protection, application server load balancing and message archiving appliances. More than 50,000 companies, including Coca-Cola, FedEx, Harvard University, IBM, L'Oreal, NASA and Europcar, are protecting their networks with Barracuda Networks solutions. Barracuda Networks' success is due to its ability to deliver easy to use, comprehensive solutions that solve the most serious issues facing customer networks without unnecessary add-ons, maintenance, lengthy installations or per user license fees. Barracuda Networks is privately held with its headquarters in Campbell, Calif. Barracuda Networks has offices in eight international locations and distributors in more than 80 countries worldwide.

For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/products-security.php

About Us

Sencilo Solutions is a Florida-based integrator specializing in storage, security and networking solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, NetApp, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Miami, Tampa, St. Petersburg, Orlando, Hialeah, Fort Lauderdale, Tallahassee, Cape Coral, and Pembroke Pines.

Key words:  Barracuda Networks Security RSA Encryption Cisco Decru Neoscale EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant SSL SonicWall Secure Computing Firewall VPN Endpoint enVision Data Loss Prevention Encryption and Key Management


ICANN and overbearing governments are gearing up for a major expansion of the attack surface of the DNS. - January 7, 2008

The use of domain names in most phishing is relatively crude, You see a lot of names like www.somefreewebsite.com/~ingrid/www.bankofamerica.com/.... There's no SSL, and the tricky part of the domain name is off to the right. A user would really have to ignore the domain name and focus on the body of the page, which is where the real phishing expertise comes in.But a potentially lucrative minefield for phishing domains may open up through a series of developments currently underway. One of them is the move by some governments to develop alternative root servers. The other is the development of internationalized domain names, especially top-level domains. In at least one case the two are combined.

The alternative root server is a strange concept to most people, says Brian McCarthy President of Sencilo Solutions. The root servers are the DNS servers that control the root of the DNS. They control the top of the hierarchy or the bottom (root) of the tree, depending on the metaphor you want to use. So eWEEK controls the eweek.com domain; VeriSign controls the .com domain; and the root, the level above .com and also known as "." is controlled by the IANA (the Internet Assigned Numbers Authority).

This Wikipedia article includes a list of alternative roots that exist and the non-standard zones they include. For instance, the home page for OpenNIC is http://opennic.glue/. You might be wondering at that ".glue" top-level domain, and if you click on it you'll get an error. That's because OpenNIC is an alternative root with a completely different name space. Your DNS, probably derivative of your ISP's DNS, doesn't point into the OpenNIC name space. Organizations like OpenNIC sometimes exist in order to escape the control of ICANN. Free to put up any TLD they wish, they have .geek for example.

But OpenNIC does exist on the public Internet; it's not a private network. If your DNS is set up for it, it's possible to see these as well as the real Internet. In fact, UnifiedRoot goes this extra mile, by setting up your systems to see the public DNS as well as their own, on which they sell new TLDs to whoever wants them.

These groups don't worry me. Who's going to use them anyway? I get worried when I see whole countries, like Russia, trying to set up separate roots. In the case of Russia, the government wants more control over the Cyrillic portion of the Internet. They can never have real control as long as the root zone is in the hands of the IANA. Call me a western hegemonist, but I just don't trust the Russian government with a root zone.

Compounding the Russian issue is the ongoing development of IDNs (Internationalized Domain Names), which are domain names that support non-Latin character sets, including the Cyrillic used in Russia. Work on this has been in standards bodies coordinated by ICANN for years and some are in use. Work on Internationalized TLDs is also underway, and here's where the phishing angle becomes really clear. .ru the Russian TLD, translates in Cyrillic to .py, the TLD for Paraguay. It's not hard to see a Cyrillic phishing domain in the Paraguayan .py being used to fool Russian users.

This specific example isn't the real point. I have a general concern about these expansions of the DNS in ways that seem destined to provide massive new opportunities for abuse. The limitations of freedom for the people of Russia and China, which is also interested in both developments. Internationalized domain names are not inherently objectionable, of course, and it would be great if they could be made to work securely. Unfortunately, I see most of the news being about new browser exploits and scams.  It's companies like Infoblox that keep things running.  Read more about this in the 2H2007 Gartner, Inc.'s Magic Quadrant.

For more information please call (407) 265-6293 or visit us at: http://www.sencilo.com/products-security.phpAbout Us

Sencilo Solutions is a Florida-based integrator specializing in storage, security and networking solutions. Sencilo delivers a comprehensive portfolio of products from best-of-breed hardware and software from multiple manufacturers including VMware, EMC, NetApp, Juniper Networks, Hitachi, Symantec, Barracuda Networks, and HP. Its technical expertise is known throughout the storage and security industry. Clients include leading corporations, major financial institutions, top universities, government facilities, as well as small to medium size businesses. Sencilo's professional services include consulting, integration, project management, installation, maintenance and knowledge transfer.

Sencilo has offices throughout Florida including: Jacksonville, Miami, Tampa, St. Petersburg, Orlando, Hialeah, Fort Lauderdale, Tallahassee, Cape Coral, and Pembroke Pines.

Key words:  Barracuda Networks Security RSA Encryption Cisco Decru Neoscale EMC NetApp HP IBM Quantum Compliance VTL Data Domain vs Gartner Magic Quadrant SSL SonicWall Secure Computing Firewall VPN Endpoint




headerbottomrounded