Threat Vigilance – Continuous Risk Management Through Information Security
Threats are numerous and constant. We are all one breach away from being featured on the evening news or thrust into emergency mode. CVP goes beyond compliance, providing cybersecurity solutions that are focused on continuous risk management through information security.
CVP provides a uniform and evolutionary approach to address an organization’s critical security needs that emphasizes a risk-based approach. Using a proactive security management approach, we reduce overall risk while improving your security posture.
- Our deep federal security program experience helps us quickly recognize and stop any “bleeding,” while we build, deploy, and improve the program, resulting in threat vigilance for a range of organizations
- Have a mature program? We build on your organization’s success by adapting and applying the latest industry best practices
- Our techniques mean we hunt threats, prevent attacks, and respond to security incidents more efficiently with fewer personnel
Beyond mere compliance with the federal security requirements that flow out of FISMA provisions, Executive Directives, and NIST frameworks, we identify and fill program gaps to create a comprehensive risk management program to give you peace of mind across your mission-essential program portfolio.
Innovation: Threat Intelligence Lab (TIL)
CVP’s Threat Intelligence Lab offers a sustainable, customizable solution that serves two purposes: for threat analysis and response, and a training ground for security analysts and IT professionals. Using the Lab helps prioritize security operations, sharpens forensic and analytical capabilities, and strengthens the use of data and security resources. Threat analysis is the first line of defense in cybersecurity.
The Lab creates a small virtualized network that simulates desktops and servers within virtual machines. CVP deploys the Lab on a stand-alone workstation or laptop. This local implementation ensures practical deployment regarding a client’s security policies, reduces dependence on costly commercial licenses, and does not require remote-hosting. In this quarantined environment, CVP analysts open suspect files or links to observe what happens. The Lab may use a dedicated line for accessing the public Internet and connecting to untrusted sources without putting a client’s assets or data at risk – an essential capability to forensically analyze potentially malicious code. We can then formulate and test specific, risk-based response strategies before an actual attack.
CVP’s security team first developed the Lab as an environment for training cybersecurity specialists. Modern digital defense techniques require hands-on experience with malware and the software that defends digital networks and devices under control conditions. The CVP team soon realized that they could apply the TIL in clients’ environments for malware forensics and incident response.
See the video above to understand how our analysts use the TIL.
Protecting Enterprise Systems from Cyber Threats
CVP manages the security operations center (SOC) of a food inspection agency that has a workforce of over of 11,000 employees and contractors that operates nationwide. Because three quarters of the workforce is mobile working on-site inspections across the country, CVP handles security operations and incident handling with an integrated, multidisciplinary team that does not disrupt critical public health-related business operations. We hunt threats, prevent attacks, and respond to security incidents with tools and processes aligned with federal policies and guidelines. Each month, we analyze thousands of security events and respond to 30 declared incidents a month on average. Our plan safeguards operations, stops unauthorized access, protects against malware, prevents data loss, ensures availability, and eases network management. Our SOC team has better situational awareness and can use event and threat information to better assess and mitigate the risk.
Restructuring an Enterprise Security Program
CVP helped a federal financial management agency restructure its cybersecurity program. CVP started a vulnerability scanning program customized to the agency’s environment and made it into a defined, repeatable, and scheduled operation. We defined the agency’s set of common controls and introduced system owners and stakeholders to the integration of enterprise controls into previously insular security plans. We worked collaboratively to structure a mitigation tracking plan; define standards; map a common set of fields, terms, and methods; and distribute templates for consolidated use by the organization.