- Network security can be a financial “black hole” for many companies in the Kingdom.
- IT departments are always trying to enhance network security, but corporate management has a hard time seeing the value of a bigger IT security budget — unless the company’s network resources are breached.
These days controlling data leaving the corporate network is as important as preventing undesirable connections to the network. Many companies pay for increasing amounts of bandwidth to cope with perceived user needs, when in fact a significant amount of bandwidth is being consumed for purposes unrelated to business objectives. And in regards to corporate data, rooms filled with filing cabinets are being replaced by digital storage. Keeping track of who should be able to access which digital files can be a burden. Yet not controlling and tracking access would surely result in leaks of confidential information, which could harm a business and its clients. “The Global State of Information Security,” by PricewaterhouseCoopers found that 33 percent of information security attacks originated from internal employees, while 28 percent came from ex-employees and partners.
So companies must deal with a host of criminals, including spammers, hackers and phishers attacking the network from outside. Plus, they must block disgruntled, abusive and corrupt employees trying to take advantage of the network from within. Long gone are the days of anti-virus software being the main network security concern. Now companies have cabled together multiple network security appliances, hoping that each box will do its job properly and not interfere with the others. It’s a nightmare to maintain them all individually, especially in the Kingdom, where there’s a shortage of Saudi network administrators.
According to Nirav Mahida, manager, Marketing Communications, Cyberoam — Elitecore, small and mid-sized Saudi companies are increasingly turning to Unified Threat Management (UTM) security appliances from Cyberoam in order to simplify and strengthen their network security, while controlling costs and optimizing IT resources.
A Unified Threat Management (UTM) security appliance includes multiple security features integrated into one device. With multiple security features on a single platform, such an appliance effectively counters network threats and performs a comprehensive suite of security functions. The UTM appliance generally contains the ability to handle network firewalling, network Intrusion Detection and Prevention (IDP), and gateway anti-virus and anti-spam. Additionally, the appliance is managed through just one management interface and produces comprehensive reports.
Unlike IP-address based solutions, Cyberoam UTM appliances offer the only Identity-based Internet security solution that identifies the user, eliminating anonymity within network. It embeds user identity in firewall rule matching criteria, eliminating IP addresses as intermediate components to identify and control the user. This offers a clear view of usage and proactive controls over security breaches. Also, this delivers complete security in dynamic IP environments such as DHCP and Wi-Fi, where the user cannot be identified through IP addresses.
Cyberoam’s value was noted by research analysts Gartner, Inc. In Gartner’s July 2009 Magic Quadrant analysis for SMB Multifunction Firewalls, Cyberoam, a division of Elitecore Technologies, was positioned as a “Visionary.” The Magic Quadrant evaluated twelve vendors based on their ability to execute and completeness of vision.
It must be emphasized that Cyberoam isn’t a fix for all network security ills. A Cyberoam UTM appliance is not “plug and play.” While less complex than other solutions that offer as much control, companies still must configure the Cyberoam UTM appliance as per their needs and integrate it properly within the corporate network architecture to get the best network security value. The appliance also must be monitored regularly and fine-tuned to meet changing threats and control requirements. Such procedures may be handled by businesses with their own IT staff or may be turned over to Elitecore’s valued-added reseller in Saudi Arabia, Sariya Company Ltd. ().
There has been some criticism that the Cyberoam UTM appliance, or any UTM appliance, presents a single point of failure. The more functions these appliances offer, the more risky that becomes. Some companies do manage this issue by having an appliance on standby. UTM supporters counter this argument by highlighting the fact that separate appliances managing each different aspect of network access and security simply represent multiple points of failure. If any of them fail, it could bring a company’s network down. At least in the UTM model, companies only have to be concerned with one box, not several.

