International Asset Management Company
Strengthening Cyber Defenses: A Case Study of Developing a Cyber Program for an International Asset Management Company
Financial services companies are prime targets for cybercriminals due to the valuable data they store. Recognizing this threat and their vulnerability to cyber attacks, an international asset management company partnered with Port53 to take action, identify security gaps, and implement effective measures for protection. Initially, the company deployed Cisco Umbrella as a first line of defense, which provided DNS and IP layer security. Leveraging Umbrella’s DNS allows them to gain visibility into their threat landscape, enhance network resiliency, and ensure reliability. Umbrella also blocks access to malicious websites, preventing malware infections and containing threats before they cause significant harm. With the company wanting to continue their security journey, Port53 advised on how the proper cybersecurity framework can help build a roadmap to address gaps in policies, processes, and infrastructure. They determined that the NIST Cybersecurity Framework (CSF) best fit their needs and took advantage of a platform called TrustMAPP, which automated implementing and managing their cyber posture and strategy to align them with the NIST CSF. The application of TrustMAPP has a similar approach to scrum, agile software development. Instead of an annual compliance check, TrustMAPP continuously identifies and prioritizes areas requiring improvement. Progress is monitored in real-time using the TrustMAPP platform and addressed through “remediation sprints,” enabling the company to stay current on their cybersecurity status. An early project identified during this program was for Port53 to help implement multi-factor authentication (MFA) for employee access. Cisco Duo protects financial services companies against cyber attacks by limiting unauthorized access and defeating credential theft. Duo’s solution granted the client enhanced visibility and control over system and data access, ensuring compliance with regulatory requirements. Port53’s Customer Success Manager closely collaborated with the company throughout this process to instill confidence in their security journey. A tailored environment was created to suit their specific needs, bolstering the overall strength of their security approach. Since then, the company has integrated Port53’s continuous penetration testing and 24x7 Managed Detection and Response programs into their cybersecurity regimen, taking advantage of all available specialized cyber services