Managed Network & Server Security
24/7 Monitored and Managed Security Services
Steadfast Networks provides a fully managed suite of security services, such as firewalls, VPNs, intrusion detection systems (IDS), vulnerability scanning, log management, email filtering, and overall security consulting/management. We have the experienced security professionals in place to figure out exactly what you need and to assure your network and data are kept as secure as possible, as well as the 24/7 staffing to keep a personal eye on all the logs, alerts, and alarms generated. These security services along with the physical security of the data center itself allow us to fully assist our customers in meeting industry and federal requirements such as PCI DSS, HIPAA, SOX, GLBA, and FISMA.
Our managed security services are backed by a 24/7/365 SSAE16 (update to SAS70) audited Security Operations Center (SOC) and fully managed 24/7/365. The attackers never rest, and you're not expected to be a security expert. We understand that, which is why we're constantly and continuously monitoring the status of your security 24/7/365. If you ever do have a security issue of any kind simply call us and we'll be able to walk you through your options and get the issue resolved for you immediately right over the phone.
Why Security is Important
In today's online and digital business, security has become a major concern, because of both the increase in attacks and types of attacks and the increase in legislation and regulation. Not only are there more compromised computers than ever before, but there is also more network connectivity available. Combined, that equates to a much greater danger in attacks, and this has been noticed by various industries and the government, resulting in increased regulation. By not being up-to-date with network security, you are risking your entire business. Not only are you risking your own reputation by having a site/service compromised, customer data released, and secrets being revealed, but you're also risking the costs and fines associated with such a lack of security. As an example, if you process any credit cards or hold credit card data, you are responsible for being PCI DSS complaint and if you are not, you risk being fined and having your ability to accept credit cards revoked. The cost associated with the typical PCI DSS compliance violation has been calculated at approximately $300 per customer, counting just the fines, legal, and accounting costs. Would your company be able to easily survive those fees, as well as the damage to your reputation? Probably not, as a majority of the companies levied with PCI fines have declared bankruptcy within the following 6 months. Don't let the complexity of security keep you from being safe and securing the well being of your company; let us handle that for you for only a couple hundred dollars a month.
Services Offered
To purchase these services, please contact our sales department by emailing us at sales@steadfast.net or calling us at 312-602-2689 option 2.
Managed Firewall
Just having a firewall in place will not keep you secure and will not establish regulatory compliance. In order for this firewall to be useful, you need to put the proper firewall rules in place, monitor the attempted intrusions, keep those firewall rules up-to-date, and audit the rules/functionality of the firewall. This can require a lot of work and knowledge, which is why an end-to-end fully managed solution can make a lot of sense. For only $49.95 a month, we can provide you with a managed firewall (can be used to protect multiple servers, up to 10 Mbit/sec), 24/7 monitoring and support, regular auditing, and complete setup/consulting services. Please contact us if you're interested in a dedicated firewall or more in-depth firewall solution.
DDoS Protection
Distributed Denial of Service (DDoS) attacks, an attempt to make a machine or network resource unavailable to its intended users, are becoming more and more common as the Internet and connectivity speeds continue to increase. Due to this distributed nature of the attack, often coming from thousands and thousands of systems and changing in primary characteristics, typical filtering methods (iptables, hardware firewalls, ACLs, and similar) are often not useful against DDoS attacks, requiring complicated signature or heuristic based filtering. By default, we provide a basic level of DDoS protection to all of our customers, monitoring and null routing, but also over Advanced DDoS Protection options.
Intrusion Detection System (IDS)
In addition to standard firewall services, we can provide a more in-depth analysis of your network traffic. This will help protect you against known security issues and vulnerabilities in the software you're using. These types of issues cannot be prevented with a standard firewall, as you still need traffic passed to your email, SQL, and web services. These ports cannot simply be blocked or limited as a whole, yet the services can still have security vulnerabilities. Just as with a firewall, the rules in an IDS/IPS require constant monitoring/updating to assure that all of the malicious traffic is being caught while you're not getting any false positives, and that can require going through thousands of lines of alerts each and every day. By using our managed services, you can always be assured you're being protected from all of the latest attacks and vulnerabilities, the rules and logs are constantly being monitored and audited, and you will be promptly alerted of any problems. IDS/IPS services can be added to the above Managed Firewall/VPN service for an additional $249.95 a month.
Vulnerability Scanning
Vulnerability scanning is required to be PCI DSS compliant, but it is also a good general rule for security analysis. In addition, just doing these scans once a month, as most services provide, still leave you open to vulnerabilities for as many as 30 days. We provide weekly scanning for $20 per month per device to assure that as soon as a security update is released you're notified and aware that these updates need to be applied. Combined with our managed hosting services, we can even assure that these updates are applied to your system as promptly as possible, leaving little to no window for those vulnerabilities to be exploited.
Log Management
One of the most overlooked aspects of PCI compliance is the required daily log audits. Are you able to easily consolidate all of your logs? Do you know what logs you're required to monitor? Are you fully aware of the security threats you're even looking for? When you find suspicious activity what do you do? It can be like looking for a needle in a haystack and cost you or your team hours of work each and every day. Our team of experts has both the automated tools and experience to know exactly what they're looking for and how to resolve those issues. Log management services start at $20 a month per device and is included with our fully managed dedicated servers.
Email Security
To save both your own time and internal resources, we also offer full email virus scanning and spam protection. These are some of our most affordable services and are offered at a rate of only $5 a month per protected domain as long as you have any of our other hosting or managed service products. We can offer 99.9% spam blocking with less than one false positive out of every 1 million emails across a fully redundant email filtering system. You can expect enterprise grade filtering services for a fraction of the price of other solutions.
Managed VPN
A key to a secure remote environment is assuring communications are secure and encrypted over a Virtual Private Network (VPN). Our managed VPN services allow you to easily setup a SSL, IPsec, Site-to-Site, and Two Factor authentication for as little as $1 a month per user. OpenVPN access is provided over our internal network with all dedicated servers at no additional charge.
Security/Compliance Consulting
If you don't know what you need, we'll help figure it out for you. If you specifically need to be PCI DSS, HIPAA, SOX, GLBA, or FISMA compliant we can walk you through those requirements and guide you through the entire process. Being a data center operator, we can provide a nearly complete solution ourselves with physical security measures and network security, but there are still measures you need to take inside your company to be compliant, such as secured wireless networks in your office and background checks of employees. With our cooperation, you can go through the compliance tests with no trouble and without a worry. A full security plan, review, and audit can be completed for as little as $5,000, but we are also more than happy to work with you on smaller projects and specific security concerns at a much lower cost.
To purchase these services, please contact our sales department by emailing us at sales@steadfast.net or calling us at 312-602-2689 option 2.
Related Laws and Regulations
- Payment Card Industry Data Security Standard (PCI DSS) - Defined by the Payment Card Industry Security Standards Council, the PCI DSS standard was created to help payment card industry organizations that process card payments prevent credit card fraud through increased controls around data and its exposure to compromise. The standard applies to all organizations that hold, process, or exchange cardholder information from any card branded with the logo of one of the card brands.
- Health Insurance Portability and Accountability Act (HIPAA) - US Public Law 104-191-AUG. 21, 1996 requires the establishment of national standards for electronic health care transactions for providers, health insurance plans, and employers and the security and privacy of the related health data. The standards are meant to improve the efficiency and effectiveness of the nation's health care system by encouraging the widespread use of electronic data interchange in the U.S. health care system, while maintaining the privacy and security of that data.
- Sarbanes-Oxley Act (SOX) - US Public Law 107-204-JULY 30, 2002 set new and enhanced standards for all US public company boards, management and public accounting firms, prompted by the Enron, WorldCom, Tyco, and similar accounting scandals. It requires management to assess the effectiveness of internal controls, obtain external validation of those controls, and provide assurances that financial/accounting processes are protected from unauthorized usage.
- Gramm-Leach-Bliley Act (GLBA) - US Public Law 106-102-NOV. 12,1999 compliance is mandatory for all financial institutions; whether a financial institution discloses nonpublic information or not, there must be a policy in place to protect the information from foreseeable threats in security and data integrity. The Safeguards Rule of the law requires financial institutions to develop a written information security plan that describes how the company is prepared for, and plans to continue to protect clients' nonpublic personal information.
- Federal Information Security Management Act (FISMA) - 44 USC ยง 3541recognizes the importance of information security to the economic and national security interests of the United States. The act requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source.
In short, PCI DSS compliance is required for all companies taking and/or storing credit card data, HIPAA compliance is required for all companies taking and/or storing private health care data, SOX compliance is required for all public US companies, GLBA compliance is required for all financial institutions, and FISMA compliance is required for all government agencies and contractors. These are certainly not all the laws and regulations pertaining to network security, but they are the primary ones. As you can see, these laws and regulations cover the vast majority of businesses, and if you need help understanding what you're required to do in regards to these regulations, just give us a call at 312-602-2689 option 2 or email sales@steadfast.net.


