Mexico. Comstor, a business unit of Westcon-Comstor and one of the main wholesalers of Cisco technology, offers 7 recommendations to improve the security of Endpoints to its customers because these are considered as one of the main points of risk for invasions in networks.
There have never been so many options in cybersecurity solutions as there are so many invasions and attacks as now. According to specialists, this scenario reveals an overload of IT security teams with a large number of tools and interfaces, to manage what makes them vulnerable to the strategies adopted.
In a recent report released by Forrester called "Mastering the Endpoint" it was found that, on average, companies use 10 different types of tools and use at least five different interfaces for the analysis and solution of incidents. Above all, endpoints, which are one of the main structures used by cybercriminals to invade corporate networks.
Solutions specific to that component already add up to an average of 10% of the total IT security budget according to another Forrester study titled "The Forrester Wave: Endpoint Security Suites Q4 2016."
The main challenge for IT leaders is precisely to find the right tools to protect an increasingly complex area of attack, since breaches multiply rapidly in companies and both employees and officials are among the preferred targets for hackers.
Forrester's 2016 study showed that 48% of the attacks suffered happen on the corporate server, which becomes one of the main targets of external attacks, followed by corporate devices with 42% and employee devices with 40%. These numbers tend to grow as the area of attack is increasing due to the increase in the devices of officials linked to the corporate network.
This scenario encouraged the creation and offer of new products and services with different approaches to those that had been used until then for Endpoints, leaving aside the focus of antiviruses and firewalls for actions more focused on detection and response on users' devices.
Here are some suggestions for improving endpoint security:
1. A scalable and adaptable security structure.
In a scenario that is constantly in motion, the option to adopt several layers of security can be quite effective. Meanwhile, to get the most out of all these layers it is necessary to make an integration between them, using a flexible and adaptable digital security structure, in this way there will be communication between the implemented defense layers potentiating their action, and the extensible structure, will allow to incorporate new layers according to the needs of the business, in addition to attention and safety requirements in constant evolution.
2. Resources for threat detection and integrated responses to daily routines.
In order for professionals to be attentive and respond quickly to threats, a solution is necessary that allows the integration of detection and response resources to daily activities, since it is an action of utmost importance related to the security of the Endpoints. By enabling that integration, administrators will be able to act quickly when an incident occurs.
3. Work towards the reduction of false positives.
The simple fact of reducing false positives offers certain advantages such as allowing more concentration on important defense tasks, that classification can be made by the tools themselves that share the threat intelligence once they manage to validate or refute a potential threat automatically. In this way, administrators do not need to do that task manually and can act more quickly in case of potential threats, in the same way, automatically highlighting the incidents of higher priority, helps to organize a workflow focused on resolution.
4. Share threat information in real time.
A combination of external sources and information collected in the environment itself, are quite effective strategies when it comes to defense intelligence. In this way, the platforms used must share in real time and automatically, information between the different layers of defense, without needing the joint collaboration of professionals who are operating between the different interfaces.
5. Immediately put into practice what has been learned.
After sharing threats in real time, platforms must immediately share with the other security systems in the environment the information learned with the previous threat or infection.
6. Make use of Machine Learning.
Using advanced Machine Learning, in conjunction with the Cloud, will allow growth, as it will be possible to compare suspicious executable statistics with thousands of other known threats, making it possible to discover new hidden threats in a fraction of seconds.
7. Consolidation of agents and processes.
The option to choose a consolidated approach, bringing together in a single administration display the different systems, tools and reports, contributes to the significant reduction of the number of manual processes simplifying workflows. In a practical example, instead of spending hours dealing with multiple interfaces, it's better to train collaborators to control the various layers of endpoint security from automated resources.
Finally, it is important to remember that, for organizations, the effects of attacks are devastating and can impact financially, compromise the reputation and competitiveness of the company, so attention to the security of endpoints should be considered critical for the business.


