Businesses using a PAM solution benefit greatly in fortifying their security foundation – reducing risk, and minimizing both insider and external threats – but also in meeting strict compliance requirements and upholding industry regulations with precision. The swift and effective incident response capability of PAM is crucial, providing real-time monitoring and session recording to detect and address any anomalies as soon as they occur. Key features based on least privilege principles exemplify the strength of PAM software in safeguarding critical systems and sensitive data in the dynamic landscape of cybersecurity.
Patch management is a critical aspect of maintaining the security and functionality of your IT systems. Here are the key reasons why it is essential:
- Security: Patches often address vulnerabilities that could be exploited by cybercriminals. Regularly applying patches helps protect your systems from malware, ransomware, and other security threats.
- Performance: Updates and patches can improve the performance and stability of your software and systems, ensuring they run smoothly and efficiently.
- Compliance: Many industries have regulations that require organizations to maintain up-to-date software. Proper patch management helps you stay compliant with these standards and avoid potential fines.
- Feature Enhancements: Patches can also introduce new features and improvements, enhancing the functionality of your applications and systems.
- Minimizing Downtime: By proactively managing patches, you can prevent unexpected system failures and reduce downtime, ensuring business continuity.
In summary, effective patch management is vital for safeguarding your systems, enhancing performance, ensuring compliance, and maintaining operational efficiency.
Azure Site Recovery or ‘ASR’.
Off-site backups are great for that rainy day or your time of need don’t get us wrong and we’d never recommend getting shut of these! But, with Azure Site Recovery you can have a ‘replica’ environment on stand-by for that rainy day that is ready to failover almost instantly! This beats the recovery time of a restore that can face many variables such as what internet speed you have, how quick the device you are recovering to and from is and many more factors.
ASR negates recovery times and even negates what you’re recovering to! If you run a single server operation or your other servers don’t have the capacity to accommodate one of your other servers, you’re basically dead in the water until the physical hardware is repaired or expanded to accommodate the recovery, all this is time and money lost.
If you run business critical systems that are integral to your operation, we’d recommend replicating these services into Azure so you can be back operational before you know it!
Speak to one of the team for more information on how we can help your business.
Remote Working – Forti-EMS
As working from home is becoming more and more common, this leaves major gaps in security. Most companies build there protection in and around there offices, but what if half your work force work on the road or from home?
What is protecting your user while they innocently log in to public networks?
We offer many solutions to this issue, but our favourite would be Forti-EMS.
Forti-EMS is multi-layered server that can either be hosted on-premise or in the cloud, this server constantly polls software installed on the end-user device. This product allows for the protection you’d expect inside the office to be extended to the device no matter the location.
The Tier-1 version (ZTNA) includes the following;
- Web Filtering – Block malicious websites or known threats no matter where you are!
- ZTNA – Zero trust network access, users must meet a posture check before been able to authenticate to your network!
- Vulnerability Assessment – Devices are routinely scanned for known vulnerabilities and can be auto-patched from within Forti-EMS against the latest CVE’s. This also works hand in hand with ZTNA, for example a device could appear to have multiple vulnerabilities detected, with ZTNA we can ensure this device cannot join the business network until these issues are patched. The EMS doesn’t only detect the vulnerabilities, it can also auto-patch 99% of them for you!
For maximum security, we’d recommend pairing Tier-1 with our SentinelOne EDR for maximum coverage.
Tier-2 Version (EPP / ATP) – includes all of the above plus;
- Inline Ransomware Protection
- Application Firewall
- Removable Media Control
- Automated Endpoint Quarantine
- Next Generation Anti-Virus (AI)
- FortiSandbox / cloud, Integration
Not only does this protect your user from anywhere, this software client also provisions and auto-updates your users VPN connection to the business!
This server also seamlessly integrates into your Next-generation FortiNet Firewall, for a single-pane of glass approach.
Feel free to get in touch for a demo or to find out more information!
14th December 2023
Server/s are centralized computer systems that are specifically built to serve a purpose, whether it be a computerised filing cabinet for all your files, a platform for your software to run on or just a server to manage all your printers. Servers allow better visibility, management, security & compliance for your business.
Whether your business needs multiple servers for your server farm or just a singular server, we are experts in server deployment and migration. We will architect any server to specifically meet your needs whether it be a Domain controller, file & Print Server to a SQL & Remote desktop server for your ERP or bespoke software we can provide it all. We don’t just provide the bare metal, we’ll also ensure you are licensed correctly to use the equipment and ensure you have the relevant care-packs for business continuity.
Feel free to get in touch to see how we can help your business.
Mutli-Factor Authentication,
You have probably seen or even have multi factor setup already for some of your personal services such as your online banking. This may be a text to your phone or use of a biometric such as face recognition or a thumb print scanner.
Multifactor is a must in cyber security as there are factors outside of your control such as website breaches that can expose passwords you have used for legitimate websites! Phishing websites that emulate real legitimate websites but re-route your credentials to a perpetrator. You may also store your passwords in your browser which could become hijacked on a website!
These vulnerabilities and attacks are becoming more prevalent these days. Having a second line of defence is key to keeping you and your business secure.
We recommend MFA is enforced on all services across the board including your Office 365 Account, VPN Services, public websites & anything that will support it!
We have different methods to implement MFA to align with your business needs, whether it be using the Built-in 365 MFA or a third party we have got you covered. We also are able to perform single sign-on (SSO) so your identity is in one location not spread across multi-vendors with multiple logins!
We also can provide FIDO keys such as ‘YubiKeys’ which are the most Phish-resistant tool on the market at current!
Speak with us for more information on securing your accounts.
We supply managed WiFi for your entire organisation whether it be for a office space, production environment or warehouse, indoor or outdoor. We can provide everything from a heat-map for the most efficient installation and coverage, to the structured cabling to the physical access point mounting.
We can configure the Access points in a multitude of ways to give you ‘Guest WiFi’ access that’s completely segregated from your company network to allow 3rd parties access to the internet without compromising your security. We can segregate iOT devices and mobile phones with a ‘QOS’ to ensure that these devices aren’t eating your bandwidth. There and endless configurations available and we can tailor this to meet your needs.
We also offer a range of microwave links that allow you to connect buildings together where a wire isn’t possible, for more information on this please speak to one of the team.
Feel free to get in touch for more information or a no obligation audit / quote.
(All new Kit supplied is Wifi6 Certified)
Microsoft Azure,
Microsoft Azure is more than just an identity service and is broken down into three categories.
- IaaS, or infrastructure as a service, is on-demand access to cloud-hosted physical and virtual servers, storage and networking – the backend IT infrastructure for running applications and workloads in the cloud.
- PaaS, or platform as a service, is on-demand access to a complete, ready-to-use, cloud-hosted platform for developing, running, maintaining and managing applications.
- SaaS, or software as a service, is on-demand access to ready-to-use, cloud-hosted application software.
Here at Goldfield we have the experience to move your environment exclusively into Microsoft Azure (IaaS) on a Pay-as-you-go Model, this is most suited to larger corporations. We find the best approach is a hybrid existence between Azure & On-Premise.
If you are wanting to go completely serverless Microsoft Azure has multiple options, Such as AAD (Azure Active Directory) that can be paired with Intune & Auto-Pilot to keep the manageability, visibility of a server on-premise. This is an ideal solution for multi-branch or remote work forces as if you’ve got an internet connection, you’re on your company network.
Each use case is different and all options have some limitations, so if you are thinking of moving to hosted, please feel free to give us a call for a consultation.
Telephony / VOIP
BT announced back in 2015 they will shut off the ISDN and PSTN services completely in 2025, Yes, that means everyone, businesses and home users. And it’s not just your phone services you will need to think about. It’s everything else that currently uses the old analogue phone network, all your non-voice services connected to things like alarms, EPOS machines, door entry systems, CCTV, and faxes. Get in touch to learn how we can help your business move across to a complete VOIP system.
Countdown for the ISDN Switchoff
Cyber Security – NGFW (Next-Generation Firewall)
Goldfield have gained accreditation and partnership with FortiNet & CheckPoint to be able to provide the market leading firewalls to it’s customers.
What is a NGFW?
Next Generation Firewalls are firewalls that utilize features ordinary firewalls are unable to do. The main feature is ‘SSL’ or ‘DPI’ which allows the Firewall to unencrypt traffic, scan it and then re-package the data once scanned and sent it onto it’s destination on the fly as a man-in-the-middle. This is a huge feature as you’ve probably noticed while browsing the web, most websites these days are ‘Secure’ and use HTTPS.
The Firewalls we supply & Configure have a multitude of features available and can be configured in many different scenario’s. (Edge Firewalls, ISFW Firewalls & Cloud Deployments)
Some of the key features are;
- Anti-Virus
- Web & DNS Filtering
- IPS (Intrusion Prevention)
- Application Control
- DoS Protection
There are many more features, feel free to get in touch to see how we could help secure your network.
See below the Web protection filter blocking a website on the fly.