Most security offerings in this market are assembled from products. A provider resells an endpoint agent, perhaps manages a firewall, and describes the result as managed security. The client receives licences, a dashboard they will not look at, and an arrangement in which alerts are generated continuously and examined by nobody.
That is not a criticism of the products, which are frequently excellent. It is an observation about what is actually being sold, which is tooling rather than defence, and about the assumption underneath it, which is that a business with the right products installed is a business that is protected.
The Siyaxhuma security practice is built on the opposite assumption. This piece sets out what it covers and how the parts relate to each other, because the coherence between them is the part that matters.
Endpoint detection and response
The endpoint is where most intrusions become visible, and modern endpoint detection differs from traditional antivirus in a way that is worth stating precisely. Antivirus identifies files it recognises as malicious. Endpoint detection observes behaviour, which allows it to identify an attack that uses no malicious file at all, and a substantial proportion of current intrusions use tools already present on the operating system rather than introducing anything that could be recognised.
The second half of the term matters as much as the first. Detection without response produces alerts. Response means the ability to isolate a compromised device from the network within moments of a determination being made, which requires both the capability and somebody authorised and available to use it.
Firewall management
A firewall is not a product that is installed, it is a configuration that is maintained. Rule bases accumulate over years, each rule added for a reason that made sense at the time, and the reasons expire long before the rules do. The result in most environments is a rule base substantially more permissive than anybody intends, containing entries that no current member of staff can explain.
Managed firewall work means periodic review of the rule base against what the business actually requires, verification that logging is enabled and that the logs are going somewhere they will be examined, and keeping firmware current, which is a security control in its own right given how frequently vulnerabilities in perimeter devices are exploited.
Vulnerability assessment
Vulnerability assessment is the continuous, unglamorous discipline of knowing what is unpatched, what is misconfigured and what is exposed, across an estate that changes every week. It is distinct from penetration testing, and the distinction is worth being clear about because the two are often conflated in sales conversations.
Assessment is broad and regular, and it establishes the current state of the whole estate. Testing is deep and periodic, and it establishes what somebody could actually do with that state. A business needs both, and a business that has only had a penetration test is holding a photograph of a moment that has already passed.
Backup and disaster recovery, under attack conditions
Backup belongs in a security practice rather than alongside it, because ransomware has made recovery a security control rather than an operational one. The relevant questions are therefore security questions.
Whether the backup can be reached from the production network, because modern ransomware operators locate and destroy backups deliberately before triggering encryption, and a backup accessible with the credentials the attacker now holds is not a backup. Whether the storage is immutable, meaning it cannot be modified or deleted even by an account with full administrative rights. And whether a restoration has actually been performed and timed, because the number that matters during an incident is how long recovery takes, and a business that has never measured it is guessing at the most consequential figure in its continuity planning.
Penetration testing
Testing establishes what an attacker could actually achieve, which is a different question from what vulnerabilities exist. A finding that looks minor in an assessment may be the first step in a chain that ends in full control of the environment, and a finding that scores highly may be practically unexploitable in your specific configuration. Only testing distinguishes between them.
The part that matters commercially is what happens after the report. A test delivered by a firm that only tests ends with findings handed to a client who must then arrange remediation with somebody else, and a meaningful proportion of those findings are still open a year later. Because we hold the remediation capability as well, findings move into work rather than into a document, and the fix is verified by the people who found the problem.
The people behind it
This practice is delivered by specialists with more than twenty five years in information security, holding certification in offensive security and formal accreditation with the platform vendors whose technology underpins the endpoint and firewall components. They work alongside our engineering team rather than at arms length, which is why findings and remediation move between them without a commercial boundary in the middle.
We are deliberate about this because security is a field where overstated capability is discovered at the worst possible moment. Ask us who specifically would be doing the technical work, what they are certified in, and what happens at two in the morning. Those questions are worth putting to any provider you are considering, and the answers are usually informative.
If you would like to know how your environment would hold up rather than whether it satisfies a standard, that begins with an assessment. Get in touch with Siyaxhuma.