FINANCIAL SERVICES
In an increasingly open network environment, financial institutions must protect the confidentiality, integrity and availability of networks, applications and data. Regulatory and industry requirements, such Gramm-Leach-Bliley, Visa CISP and to some extent HIPAA, define strict standards for network availability and security best practices – and stiff penalties for failure to meet or prove compliance with those standards. In addition, customers and employees alike demand 24/7 availability to critical financial information, and do not tolerate security breaches or unexpected interruptions in service.
Lancope's StealthWatch™ network security and monitoring system enables financial institutions to maximize network and system availability, reduce regulatory risk and improve overall employee productivity. Traditional network management and security point solutions each address only part of this challenge. For example, network perimeter security solutions are effective at stopping known, well-defined exploits, but are largely ineffective against automated worms, "zero-day" attacks, P2P file-sharing applications and internal misuse – which a recent Gartner and CERT report estimates are responsible for more than two-thirds of security incidents that cause loss.
StealthWatch utilizes innovative Network Behavior Analysis (NBA) and Response technology to help network operations and security managers to recognize threats that other technologies miss – before they disrupt the network or expose confidential records. By integrating native flow capture plus Cisco NetFlow and sFlow data from existing network infrastructure into a single, high-performance system, StealthWatch delivers immediate visibility into network operations anywhere across the enterprise. This unmatched ability to profile and analyze network traffic patterns and host behavior gives organizations the ability to preempt, find, and fix network management issues and security threats before they become crises.
With advanced alerting based on each individual manager's unique job responsibilities and advanced graphical reporting, StealthWatch delivers continuous network awareness and ensures compliance with regulatory and industry requirements through:
- Detection, mitigation, and resolution of internal and external threats, such as stealthy scans, new worms and trojans that bypass firewalls and signature-based antivirus systems
- Real-time visualization, analysis and auditing of network and host activity without installing host-based agents
- Alerts based on policy violations (e.g. attempted access to critical financial servers from unauthorized network zones), with each alert customized for individual job responsibilities
- Automated discovery and profiling of new, misconfigured or unauthorized network devices
- Enhanced protection and scalability through remote collection and analysis of NetFlow and sFlow data, as well as via native packet capture StealthWatch sensors
- Historical detail to help establish effective resource planning, forensic examination and proof of regulatory compliance

