Datanet » Technologies and IT solutions » Cyber Security
INFORMATION SECURITY
Cybersecurity is critical for every organization, and managing risk requires treating the security model as a whole: visibility and control across the entire lifecycle of an attack — before it happens, while it unfolds, and after containment, through incident investigation and measures that prevent recurrence.
Today’s attack surface extends far beyond the traditional perimeter: networks, endpoints and mobile devices, data centers, virtual and hybrid environments, cloud applications, user identities and access. An integrated security architecture built on Zero Trust principles protects the entire IT ecosystem, at a time when threats are evolving rapidly — increasingly powered by artificial intelligence in the hands of attackers.
Datanet's cybersecurity experience
Datanet Systems is the first Cisco Preferred Partner in Romania across all competency areas — including Security — the highest status granted under the new Cisco 360 Partner Program. Our teams design, implement, and operate complete security architectures for medium and large companies and public sector organizations, delivering turnkey, pre-tested, fully integrated solutions. The Datanet portfolio includes products and services from Cisco, CrowdStrike, CyberArk, Cymulate, F5, Fortinet, Meraki, Netscout, Palo Alto Networks, SentinelOne, SolarWinds, and Splunk.
For organizations with limited in-house security expertise, Datanet provides IT security infrastructure as a service and Security Operations Center (SOC) services.
NOC & SOC: complete visibility from a single source
Many security incidents first appear as operational anomalies — performance degradation, unusual traffic. That is why Datanet combines, uniquely on the local market, Network Operations and Security Operations: our NOC services for IT infrastructure monitoring provide 24/7 monitoring of availability and performance, with on-site intervention anywhere in Romania, while SOC services cover threat detection and response. The two can be contracted together or independently.
Datanet’s cybersecurity portfolio
MORE DETAILS
IAAS, NOC & SOC SERVICES
NEXT GENERATION FIREWALL & IPS
WEB APPLICATION FIREWALL
ADVANCED MALWARE PROTECTION
EMAIL SECURITY
ACCESS AND POLICY MANAGEMENT
SECURE REMOTE ACCESS & DNS SECURITY
MULTI-FACTOR AUTHENTICATION
SECURITY INFORMATION & EVENT MANAGEMENT
ENDPOINT SECURITY
IDENTIY RISK MANAGEMENT
CYBERATTACK SIMULATION
PRIVILEGED ACCESS MANAGEMENT
MOBILE DEVICE MANAGEMENT
IAAS, NOC & SOC SERVICES
IAAS, NOC & SOC SERVICES
IT Security IaaS — Security infrastructure as a service
State-of-the-art security products, dedicated exclusively to your company and integrated into a coherent architecture — configured, monitored, and kept up to date by Datanet’s experts, at a significantly lower cost than managing security in-house.
Security Operations Center (SOC)
24/7 or 8/5 cybersecurity monitoring, backed by Datanet’s local expertise and the extended resources of the Soitron Group, present across several European countries: we collect and analyze logs from security systems and servers, and when an incident is identified you receive notifications with priority, analysis, and remediation guidance — with a 2-hour response time for severe security incidents. Optionally, active attacker blocking through integration with your infrastructure.
Network Operations Center (NOC)
Proactive 24/7 monitoring of the availability and performance of your entire IT infrastructure, Incident and Problem Management (RCA), on-site intervention within a maximum of 4 hours anywhere in Romania (SLA-backed for eligible locations and advanced support packages), and a single point of contact with three-tier expertise (L1–L3). Many security incidents first surface as operational anomalies — NOC and SOC can be contracted together for complete visibility.
More details: Security infrastructure as a service · Datanet NOC services
NEXT GENERATION FIREWALL & IPS
NEXT-GENERATION FIREWALL & IPS
Cisco Next-Generation Firewall:
- Provides advanced protection against computer vulnerabilities and breaches;
- Allows the creation of security zones and access policies between areas;
- Offers monitoring, analysis and blocking of traffic at application level (Facebook, WhatsApp, Twitter) and categories of domains (social media, gambling, drugs, etc.);
- Facilitates the automatic application of security policies throughout the organization;
- Allows integration with Active Directory to link security policies with defined user categories.
Cisco Intrusion Prevention System:
- Conducts real-time traffic inspection and blocks it when an IPS signature that signals a known threat is detected ;
- Benefits from constant updates of the IPS signature base to stop the most recently launched attacks;
- Provides real-time recommendations based on existing network traffic for the IPS inspection algorithm to dynamically adapt to existing infrastructure.
WEB APPLICATION FIREWALL
WEB APPLICATION FIREWALL
F5 Advanced Web Application Firewall (WAF):
- Protects organizations against attempts to steal accounts and login passwords;
- Provides protection against software robots that attempt to gain unauthorized access by automatically filling in the fields on web pages with bogus login data;
- Dynamically encrypts connection data;
- Automatically blocks DoS (Denial of Service) attacks at levels 3, 4, and 7, analyzing traffic profiles generated by Web applications.
ADVANCED MALWARE PROTECTION
ADVANCED MALWARE PROTECTION
Cisco Advanced Malware Protection (AMP):
- Performs a continuous analysis of the files that enter the network with advanced traceability capabilities (also presenting retrospective analyzes);
- Provides file and archive protection, with the possibility of analyzing them in the Cisco sandbox environment;
- Dynamically scans all executable files.
Cisco Advanced Malware Protection (AMP) for Endpoints:
- Identifies malware files/code and blocks them before infection;
- Integrates anti-malware functionality to inspect files on devices running Windows, Linux, Android and iOS;
- In case of “Zero-Day” attacks, it offers the possibility to send files for inspection in the Cisco sandbox environment;
- It works in parallel with the antivirus solution installed on the terminal device but is powered by Tetra, another antivirus engine, that also includes the retrospective file analysis function.
EMAIL SECURITY
EMAIL SECURITY
Cisco Email Security Appliance (ESA):
- Detects and blocks real-time threats/malware distributed via email;
- Blocks emails with potentially risky links or block access to newly infected sites;
- Provides protection against spam, anti-virus and phishing attacks, as well as filtering content from email messages;
- Provides an additional file-level scanning solution by integrating with AMP for Endpoints.
ACCESS AND POLICY MANAGEMENT
ACCESS AND POLICY MANAGEMENT
Cisco Identity Services Engine (ISE):
- Provides network access control for users connected to wired, wireless or remote (VPN) networks;
- Allows authentication of users/devices in accordance with the individual access rights defined by the authorization policies;
- It simplifies the identification of devices connected to the network and their classification according to the supplier, type and model, the tec operating system. (profiling);
- Verifies that the devices connected to the network comply with the compliance policy (defined either in the ISE or in the MDM solution);
- Allows the creation of “Guest” portals or networks for visitors;
- Provides authentication, authorization and accounting (AAA) services to simplify administrators’ access to network equipment.
SECURE REMOTE ACCESS & DNS SECURITY
SECURE REMOTE ACCESS & DNS SECURITY
Secure Mobility Client – Cisco AnyConnect Apex:
- Provides remote access to resources through the company’s internal network;
- Simplifies and enhances the mobile user experience;
- Dynamically adapts to VPN services, depending on the latency requirements of the applications;
- Provides a wide range of endpoint security services, from a single unified agent;
- Access to next-generation encryption technologies through the IKEv2 VPN protocol suite;
- Provides access to Network Visibility Module, to monitor the usage of end applications, if there is an integration with Identity Services Engine.
Domain Name System (DNS) Security – Cisco Umbrella Insights:
- It ensures the protection of mobile users at the DNS level by blocking their access to dangerous web content;
- It blocks the traffic at the level of the web categories;
- Facilitates the application of user-customized security policies by integrating with Active Directory;
- Ensures the visibility of the IP address of the computer that generated the DNS request, by installing Umbrella VM. Moreover, by integrating the VM with Active Directory, the identity of the user connected to the respective station can be established;
- In case of accessing a domain with an uncertain status (neither bad nor safe), it allows traffic through a proxy for real-time scanning – files in transit are checked with Advanced Malware Protection;
- Possibility of storing logs in Amazon Web Services.
MULTI-FACTOR AUTHENTICATION
MULTI-FACTOR AUTHENTICATION
Adaptive Multi-Factor Authentication – Cisco Duo:
- Provides dual authentication (device and person) for remote connections through AnyConnect VPN and Windows Logon;
- Possibility to add double authentication to client applications.
SECURITY INFORMATION & EVENT MANAGEMENT
SECURITY INFORMATION AND EVENT ANALYSIS
Benefits:
- Provides log storage, correlation and normalization capabilities;
- Alerts the personnel responsible for IT security incidents;
- It reacts automatically when events occur.
ENDPOINT SECURITY
CROWDSTRIKE
Este cea mai avansată soluție nativă cloud din industrie pentru protecția dispozitivelor IT terminale, a sarcinilor de lucru în cloud, a identității și a datelor.
Soluția include:
- Securitate pentru terminale și pentru identitate
- Securitate și operațiuni IT
- Threat intelligence
- Securitate în cloud.
Principalele beneficii:
- Agent suplu, fără impact asupra utilizatorului și a punctelor finale – mai puțin de 1% încărcare CPU
- Agil, cu implementare simplă și rapidă, simplu de utilizat
- Asigură expertiză încorporată: experți in identificarea amenintărilor informatice, protecție și remediere ca serviciu gestionat, informări despre amenințări
- Soluție de ultima generație, oferă securitate pentru companii si organizații pentru cele mai critice elemente din următorul val digital – securitatea dispozitivelor terminale, securitate în cloud, model zero-trust.
IDENTIY RISK MANAGEMENT
ILLUSIVE NETWORKS – managementul riscului de identitate
Illusive Networks livrează o soluție de apărare activă la atacurile cibernetice prin crearea unui mediu ostil pentru atacatori. Aceasta apărare activă este alcătuită din trei componente: Attack Surface Manager (ASM), Active Detection System (ADS) și Attack Intelligence System (AIS).
ASM, denumit și Illusive Spotlight, micșorează preventiv suprafața de atac cibernetic, efectuând analize și remedieri continue și automate pentru a identifica și elimina informațiile care nu sunt necesare despre identități, conexiuni și cai de acces din sistemele informatice.
ADS, denumit și Illusive Shadow, transformă PC-urile existente într-o rețea de capcane informatice (deceptions) pentru a detecta în mod determinist mișcarea laterală a atacatorului. După reducerea cu ASM a suprafeței reale de atac, ADS extinde suprafața de atac vizibilă atacatorului cu o serie de capcane care duc la detectarea atacatorului la încercarea acestuia de a le accesa. Astfel, Illusive Shadow face aproape imposibil ca un atacator să se miște lateral cu succes fără a fi detectat. Spre deosebire de alte tehnologii similare care utilizează agenți / honeypots, Illusive nu folosește agenți, așa că nu poate fi detectată de atacator. Soluția oferă trei tipuri de deceptions – de endpoint, de user și de fisier (MsDocx/Excel). Atunci când un atacator încearcă sa acceseze oricare din aceste variante, se generează o alertă care permite izolarea și remedierea rapidă a sistemului informatic atacat.
AIS oferă date de telemetrie despre activitățile atacatorului, la detecția unui atac sau la cerere, pentru a accelera investigarea și remedierea. Produsul oferă capturi de ecran reale ale activității atacatorului pe măsură ce aceasta are loc și o cronologie a tuturor evenimentelor și proceselor implicate. Vizualizarea activităților pe o linie temporală oferă o perspectivă nu numai asupra activităților, ci și asupra intenției atacatorilor. Datele detaliate furnizate la cerere reduc de obicei timpul de investigare cu 60% – 90%.
Beneficii principale ale soluției:
- Remediază automat riscurile de acces neautorizat eliminând conexiunile si conturile care nu sunt necesare,
- Funcționează atât în cloud cât și on-premises,
- Nu folosește agenți, nu se poate dezactiva, are un impact foarte redus asupra performanței sistemelor pe care le protejează,
- Este ușor și rapid de implementat, nu necesită schimbarea politicilor de securitate și reconfigurarea echipamentelor firewall,
- Se integrează cu majoritatea soluțiilor Endpoint Detection and Response (EDR), permițând reacția rapidă la atacurile cibernetice detectate.
CYBERATTACK SIMULATION
CYMULATE
Este o platformă de testare a securității, livrată ca Software as a Service, care asigură validarea continuă a securității prin lansarea de simulări cuprinzătoare de atacuri informatice pentru a descoperi vulnerabilitățile de securitate.
Beneficii principale:
- Ușor de implementat
- Simplu de utilizat, lansează scenarii de testare extinse, cu un singur clic
- Oferă instrucțiuni clare de remediere pentru a trata configurațiile greșite și pentru a închide vulnerabilitățile de securitate
- Automatizează evaluările de asigurare a securității unice pentru mediul dvs
- Oferă vizibilitate și remediere completă a căii de atac APT kill chain
- Sigur de utilizat în mediul de producție în timpul orelor de lucru
- Furnizează scoruri de securitate, permițând luarea de decizii obiective, bazate pe date
- Oferă informații imediate, acționabile, continuu sau la cerere pentru echipa tehnică:
- Unde esti cel mai vulnerabil?
- Care ar trebui să fie prioritatea ta principală?
- Cum îți poți reduce scorul de expunere?
- Oferă informații imediate, acționabile, pentru echipa executivă:
- Performanța în timp,
- Scorul de expunere de bază și cel curent (CVSS, NIST),
- Evaluare comparativă cu alte entități din domeniul economic din care faceți parte.
PRIVILEGED ACCESS MANAGEMENT
CYBERARK
Este cea mai completă platformă de securizare a identităților de utilizatori, de dispozitive si de aplicații.
De oriunde în lume, din orice locație, utilizatorii vor cere acces la aplicații și sisteme situate în sediile companiei sau în cloud. Și nu vor fi doar identități de persoane, tendința generală actuală către automatizare și transformare digitală crește cerințele sistemelor autonome de a obține acces securizat.
Numărul de identități folosite pentru a accesa sistemele informatice actuale, extrem de variate, a explodat. Acest lucru aduce cu sine o proliferare de privilegii și drepturi care se vor dovedi dificil de înțeles și de gestionat. Sistemele automate vor continua să aibă nevoie de acces securizat fără a le fi redusă viteza. Provocarea adresată de CyberArk este de a menține o abordare unificată a securității și de a proteja acest acces.
Fără un perimetru clar definit de apărat, breșele cibernetice sunt inevitabile. Dar daunele nu sunt. Companiile care adoptă o abordare centrată pe privilegii pentru a securiza identitățile sunt într-o poziție mai bună pentru a se proteja de o gamă largă de atacuri.
Beneficii principale ale soluției:
- Previne furtul de credențiale: protejează toate credențialele privilegiate pentru identitățile umane și non-umane.
- Izolează amenințările: adoptă un model Zero Trust pentru a preveni mișcarea laterală și verticală a atacatorilor.
- Aplică cel mai mic privilegiu: introduce controale just-in-time, acordând acces temporar numai atunci când este necesar.
Soluția include:
- Privileged Access Manager: izolează amenințările și previne compromiterea privilegiilor prin gestionarea conturilor, credențialelor și sesiunilor și prin remedierea activităților riscante.
- Cloud Entitlements Manager: remediază permisiunile neutilizate și configurate greșit pentru a vă apăra în mod proactiv de amenințări interne și externe.
- Endpoint Privilege Manager: aplică cel mai mic privilegiu, controlează aplicațiile și previne furtul de acreditări pe desktop-uri Windows și Mac și pe serverele Windows pentru a limita atacurile.
- Autentificare multifactor: validează identitățile folosind un mod passwordless cu inteligență artificială conștientă de riscurile de securitate.
- Vendor Privileged Access Manager: Conectează în siguranță furnizorii de la distanță la organizația dvs. cu autentificare biometrică bazată pe cloud prin intermediul telefoanelor inteligente.
MOBILE DEVICE MANAGEMENT
MOBILE DEVICE MANAGEMENT
Meraki Systems Manager Enterprise:
- Provides centralized management of mobile devices and workstations (Windows and macOS) from a single control point;
- Allows the creation and centralized implementation of compliance settings for mobile devices (password requirements, mandatory security code on the device, blocking access to the room, data limit on SIM cards);
- Integrates the geolocation functions of the devices, for better control;
- Simplifies the installation/uninstallation of mobile applications through a centralized interface;
- It blocks access to different mobile applications, according to the rules in place.
