Skip to main content



L-R Fergal Meehan, Chief Commercial Officer at Paradyn, pictured at Lough Eske, Co. Donegal, with Sean Dunnion, Project Leader Information Systems at Donegal County Council

L-R Fergal Meehan, Chief Commercial Officer at Paradyn, pictured at Lough Eske, Co. Donegal, with Sean Dunnion, Project Leader Information Systems at Donegal County Council

Paradyn, one of Ireland’s leading cybersecurity service providers, has announced that it is backing up critical data for Donegal County Council with Vault365, an all-in-one backup, ransomware, and data protection solution.

Donegal County Council needed to effectively back up and secure its Microsoft Office365 data to ensure compliance and eliminate the setup and maintenance of its own hardware, storage, and infrastructure. Paradyn deployed the Vault365 solution which runs in the cloud and backs up information to its own highly secure off-site data centre. The remotely stored data is immutable and cannot be compromised by potential cyberattacks on the organisation’s estate.

Paradyn’s solution is protecting sensitive information for Donegal’s 166,000 citizens. It’s also enhancing the user experience for those who engage with the council’s vital services as public information is backed up, reliable, and up-to-date.

Ongoing monitoring and management by Paradyn of the Office365 estate gives peace of mind to Donegal County Council that its critical assets are protected. The council also has access to a self-service portal, meaning it has full control and visibility of the solution. The solution is flexible and scalable in line with organisational growth in the future.

Paradyn is securely backing up 900 Microsoft Office365 accounts for the council across applications including Teams, SharePoint and OneDrive. As Microsoft only stores data for up to 90 days, the Vault365 solution ensures business continuity and is increasing employee productivity as data can be quickly recovered in the event of an incident. The new solution is based on a cost per user model, which is resulting in significant cost savings for the council.

Sean Dunnion, Project Leader Information Systems at Donegal County Council, said: “With Paradyn’s extensive expertise securing organisations in the public sector and local government, they were the natural fit to support on this next phase of our journey. This Vault365 solution has futureproofed our data protection and backup capabilities, and provides peace of mind that sensitive information is secure.

“Crucially, it’s helping to enhance the services we provide to citizens throughout Donegal as the solution gives us full control of our Office365 estate, while ensuring minimal downtime should an incident occur. Ultimately, the technology is built with growth in mind and will enable us to scale as needed.”

Fergal Meehan, Chief Commercial Officer, Paradyn, said“It’s a common misconception that Microsoft backs up customer data, which is why it’s essential for organisations to proactively protect their critical information. Vault365 eliminates the risk of losing access and control over this data, underpinned by the expert knowledge of our experienced specialists. Hackers will typically target on-site backups and having critical data stored securely in an off-site location provides an extra layer of protection.

“The council deals with citizens’ sensitive information and provides crucial public services to the people of Donegal, and this solution enables the council to meet these needs now and into the future.”

Click here to discuss your backup requirements in more detail.




Paradyn appoints Fergal Meehan as Chief Commercial Officer

Fergal Meehan, appointed CCO of Paradyn

Paradyn, one of Ireland’s leading cybersecurity service providers, is today announcing the appointment of Fergal Meehan to the position of Chief Commercial Officer (CCO). Fergal brings over two decades of experience in the technology industry to the role, with key focuses on cybersecurity and customer experience.

Prior to this appointment, Fergal held the role of Head of Public Sector Relations with Paradyn, where he worked closely with public sector customers to develop bespoke services tailored to their unique needs. As the CCO in the field of cybersecurity, Fergal will be responsible for developing and executing commercial strategies that drive revenue growth and market expansion for Paradyn.

Furthermore, Fergal will shape and evolve Paradyn’s offering for new and existing customers across its full suite of cyber security, backup, and networking solutions. With extensive experience in the technology and cybersecurity industry, Fergal possesses a deep understanding of the market landscape, customer needs, and emerging trends.

He will also enhance the offering from Vault365, an all-in-one backup, anti-ransomware, and data protection solution leveraging on premise and cloud for airgap and disaster recovery. In addition, Fergal will be tasked with developing and building out cross-skilled sales and technical teams to deliver these innovative services which, in turn, will help to drive value for customers.
Fergal’s career journey started in 2000 and he has gained a strong professional and educational background with major technology providers such as Cisco, Microsoft, Checkpoint and Palo Alto, with a focus on cybersecurity. He has also gained hands-on experience by working with these tech companies across security and network consultancy roles.

Fergal is a strategic thinker, data-driven decision-maker, and a passionate leader who motivates teams to deliver results. His communication skills allow him to connect with customers and partners, build long-term relationships, and create compelling value propositions that resonate with the target market.

Fergal Meehan, Chief Commercial Officer, Paradyn: “As CCO, my aim is to drive the human element of what we do and really understand our customers’ unique requirements. I believe I can bring the best of both worlds to the role, leveraging my technical background and experience in customer-focused roles to develop and deliver innovative solutions to solve customers’ business problems. I also plan to draw on my deep knowledge of the public sector to drive increased value for customers in this area.

Click here to get in touch with Fergal or any of our Paradyn team.

Paradyn achieves ISO 27001:2017 certification

Paradyn, one of Ireland’s leading cybersecurity service providers, today announced that it has achieved ISO 27001:2017 certification for its Information Technology, Security Techniques and Information Security Management System (ISMS). The certification and extensive audit process were performed by National Standards Authority Ireland (NSAI).

Established by the International Organisation for Standardization (ISO), ISO 27001 is an information security standard that outlines the requirements for an information security management system (ISMS). Achieving ISO 27001 certification demonstrates that an organisation has implemented a systematic approach to managing sensitive information and has implemented the necessary controls to protect against risks.

The benefits of achieving ISO 27001 certification are numerous and include improved risk management, increased customer trust, better data protection, and enhanced business continuity.

    • Improved Risk Management

One of the primary benefits of achieving ISO 27001 certification is improved risk management. The standard requires organisations to identify, assess, and prioritize the risks to their sensitive information and to implement appropriate controls to manage those risks. By following this systematic approach, organisations can better understand their exposure to information security risks and can make informed decisions about how to manage those risks. This leads to improved risk management practices, reducing the likelihood of a data breach or other information security incident.

    • Increased Customer Trust

Achieving ISO 2701 certification can also increase customer trust in an organisation. Customers want to know that their sensitive information is being protected and that the organisations they do business with are taking the necessary steps to secure that information. By achieving ISO 27001 certification, an organisation is demonstrating its commitment to information security and its willingness to undergo independent assessment to validate its information security practices. This builds trust with customers and can provide a competitive advantage in the marketplace.

    • Better Data Protection

ISO 27001 requires organisations to implement a number of information security controls to protect sensitive information. These controls cover a wide range of areas, including access control, cryptography, network security, incident management, and data backup and recovery. By implementing these controls, organisations can better protect their sensitive information from theft, loss, or unauthorized access. This leads to improved data protection and reduces the risk of a data breach or other information security incident.

    • Enhanced Business Continuity

Achieving ISO 27001 certification also enhances an organisation’s business continuity. The standard requires organisations to implement a business continuity management system (BCMS) that includes a plan for responding to and recovering from disruptive events, such as a natural disaster or cyber attack. By having a BCMS in place, organisations can ensure that they are prepared to continue operating in the event of a disruptive event, reducing the impact on their business operations and minimizing downtime.

    • Cost Savings

Another benefit of achieving ISO 27001 certification is cost savings. The standard requires organisations to implement a systematic approach to information security, which can lead to the consolidation of information security efforts and the elimination of redundant or ineffective controls. This can result in cost savings for the organisation, as it reduces the need for multiple information security solutions and simplifies the management of information security.

    • Improved Compliance

Finally, achieving ISO 27001 certification can also improve an organisation’s compliance with various laws and regulations related to information security. The standard covers a wide range of information security requirements, many of which are also required by other laws and regulations, such as the General Data Protection Regulation (GDPR) in the European Union. By achieving ISO 27001 certification, organisations can demonstrate their compliance with these requirements and can avoid the time and expense of preparing for multiple compliance assessments.

In conclusion, with Paradyn achieving ISO 27001 they have shown a standard required to implement a systematic approach to information security, which leads to a more effective and efficient information security program.


About Paradyn:

At Paradyn, we build strategic partnerships with our clients. Our clients benefit through our security-first approach from best-practice consultancy of their entire IT estate right through to implementation, monitoring and ongoing support. Our team of highly trained network and security consultants deliver best-in-class advice and support so our customers can reduce cyber risk and focus on delivering their core business activities.

Best practice cybersecurity for an evolving business landscape

Cillian McCarthy, chief executive officer, Paradyn: the company provides organisations with a 360-degree assessment of the gaps in their IT infrastructure, systems and processes

CIS Controls provide actionable steps to optimise cybersecurity for organisations of all sizes

As cyberthreats become increasingly sophisticated in a hybrid-working world, organisations cannot afford to be complacent about their cybersecurity strategies. CIS Controls are the globally accepted benchmark for cyber defence, providing specific and actionable ways to stop today’s most pervasive and dangerous attacks.

This recommended set of steps helps to optimise your cybersecurity landscape, ensures compliance and gives more control over your organisation’s systems. The controls are regularly monitored and updated to keep pace with the rapidly changing cybersecurity ecosystem.

Proactive approach to cybersecurity challenges

By using a highly proactive and collaborative approach, Paradyn is helping organisations of all sizes to implement these actions in order to protect their customers and the way they interact with stakeholders.

Paradyn provides organisations with a 360-degree assessment of the gaps in their IT infrastructure, systems and processes, reviewing the entire estate against the 170+ CIS Controls. Its security experts then recommend a tailored implementation and remediation plan.

From malware, email and web security to employee awareness training and penetration testing, the controls help to protect organisations against cyberattacks while aiding regulatory compliance with measures such as GDPR.

CIS Controls can also help to inform management objectives, prioritising areas that need attention and creating better ways of working and engaging with employees and stakeholders.

As security challenges evolve, so do the best practices to meet them. CIS Controls enable organisations to deal with new challenges and act as a guide to benchmark against peers. They can also provide a holistic framework to secure existing and planned business assets and resources, no matter how complex.

Click here to discuss your cybersecurity requirements in more detail.

IT security is first priority when preparing for risk

Fergal Meehan, head of government relations, Paradyn

Paradyn’s methodology uses a traffic-light system to explain to the business how vulnerable it is to cyber attacks


Organisations today are increasingly aware of the threat from cyber criminals. How they respond to it, however, is changing, with a growing emphasis on risk management.

As IT has grown to become central to the operations of every organisation a threat has grown with it: not only are cyber attacks increasingly common, in today’s hyper-connected world, the consequences of a successful one are worse than ever. In response to this, ever more sophisticated security solutions are being deployed, including the use of active threat hunting and artificial intelligence.

Beyond the technology there has also been a wider transformation. Increasingly businesses are looking to assess their readiness from the perspective of managing risk – and turning to specialist managed service providers to assess the risks to which they are exposed in order to prepare for them.

Of course, risk cannot be measured if the IT estate itself is not understood, so making sense of what systems an organisation uses is an essential first step.

“What we do is gap analysis, CIS and NIST, analysing the business from an IT perspective,” Fergal Meehan, head of government relations at managed security specialists Paradyn, said.

Paradyn’s methodology uses a traffic-light system to explain to the business how vulnerable it is, and where its weaknesses lie.

“If there’s something like a phone system, for instance, it will be a red, amber or green, and we then ascertain what the risk is to the business if it is amber or red. That’s very important for explaining it to management,” he said.

Working with public sector clients, Meehan found these organisations were leaning more than ever into taking security seriously and were now ahead of some areas of the private sector.

“Procurement can be an issue. Public bodies tend to know what they want, but the procurement process can be difficult,” he said.

“Certainly, we’ve seen a lot of growth in awareness of security.”

First and last line of defence

With IT security, the mantra has long been that attacks are not so much a case of ‘if’ as of ‘when’. With that in mind, information security itself, important as it is, is not the only method of managing and mitigating risk.

Meehan said that alongside traditional security measures, any serious risk mitigation strategy will take backups very seriously indeed as getting an organisation back up and running after a problem or breach is one of the most crucial tasks.

“A lot of the time it comes down to backups. You can have all of the systems and hardware in place, but at the end of the day the key defence is the backup,” he said.

This does not mean that security is less important, and Meehan advocates a ‘zero trust’ model that starts at the device. It is a case of acknowledging the reality of the growing threat and ever-widening attack surface.

“There is no such thing as being risk free, so what’s the next best thing? Well, to have good, good backups. Ransomware is one of the best-known threats

Backups themselves can be, and often are, a target too, and so they need to be unalterable. If they are not, then attackers can encrypt them meaning a business will not be able to get up and running again after an attack.

“[We do] off-site backups, which links into the space around disaster recovery. We airgap the backups, creating immutability. This means you have a read-only version of the backups, so they themselves are protected from the threat of ransomware,” he said.

Working with a managed service provider, businesses can set recovery time objectives and recovery point objectives, as well as a comprehensive service level agreement. After this, however, they should not just sit back and relax. In order to ensure that they actually work when they are called upon, back-ups need to be tested.

“It’s important that you do your tests, and if you don’t have the expertise in house your service provider can do it for you. You do get customers who prefer to do it themselves as it means they don’t have their eggs in one basket: they have the backup as a managed service but they do their own testing in-house,” Meehan said.

Of course, one reason to have a managed service provider perform regular testing might be because an organisation has no internal IT team. Another, however, might be that the IT team is already overworked just keeping the lights on, and this is precisely when the risk of a breach will be at its highest.

“Even those that have IT departments are so stretched these days, particularly with cybersecurity,” Meehan said.

Click here to discuss your backup requirements in more detail.

Paradyn delivers cloud back-up to over 20,000 Microsoft365 accounts

Cybersecurity expert implements watertight back-up solution for Microsoft365 data


Company data is one of the most crucial elements of any business, but are you keeping yours secure enough? Data is facing ever-evolving threats such as deletion, corruption and ransomware attacks, and companies need to ensure that it is secured, compliant and quickly recoverable.

Do you know that backing up your Microsoft365 (M365) cloud data is your responsibility? Paradyn can help you to protect your entire M365 environment across Exchange Online, SharePoint Online, OneDrive for Business and Microsoft Teams, with a cloud solution including automated back-ups and full data restoration.

Innovative back-up technology

Data hosted at Paradyn’s secure Irish-based data centres together with innovative Veeam back-up technology ensures no downtime for customers in the event of an incident, enables speedy disaster recovery, and eliminates data loss. All customers have access to a self-service portal where they can carry out information recovery and restores, in cases of accidental or malicious deletion. Paradyn can also restore any data that has been deleted.

Without back-up for Office 365, you have limited access to and control of your own data. You can fall victim to retention policy gaps, data loss dangers and open yourself up to serious internal and external security risks, as well as regulatory exposure. Paradyn’s solution can help to protect your critical data and ensure business continuity.

Paradyn is one of Ireland’s leading cybersecurity service providers, with a security-first approach to implementation, monitoring and ongoing support. Its team of highly trained network and security consultants deliver best-in-class advice and support, enabling customers to reduce their cyber risk and focus on delivering their core business activities.

Click here to discuss your backup requirements in more detail.

Compliance is key in the world of data

Paul Casey, chief operations officer at Paradyn: ‘We need to make sure and constantly verify that we’re still allowing the right people access to the right areas and no more and no less than that.’


Four years have passed since GDPR came into play and from it both challenges and the knowledge facing privacy are increasing

It’s easy to forget the panic surrounding GDPR before its introduction in May 2018, which forced organisations to treat data with the seriousness and care it deserves.

Four years later, its influence has been greatly felt in how businesses deal with data and their responsibilities, much to the point where data breaches and fines regularly appear in the news.

“What it’s done is it put the concept of personal information to the forefront of every business owner’s mind,” Paul Casey, chief operations officer at Paradyn, said. “You should be thinking about it early in the process; it should be in the initial planning phases.”

“There’s probably more of a focus on data protection with cases appearing in the news. At least once a month, there’s some new headline and that is solidifying that this is the standard and it’s here to stay.”

Casey brings up an interesting point that while GDPR has been around since 2018, the pandemic happening two years later changed the landscape.

With all workers moving off-premises and many likely staying that way into the future, either as fully remote or a hybrid model, data protection is now more complex than before. Now the onus is on protecting data in different locations like the cloud.

“If they’re working from home, there’s so much between where they are and your organisation’s data,” he said. “You have to make sure you can verify it’s the right person from the right location getting to the data and not somebody else in-between.”

It’s why practices like zero trust – which requires all users to be authenticated, authorised and continuously validated for security before being granted or keeping access to data, no matter where they are in an organisation’s network – are becoming so popular. The boundaries separating organisations and access have disappeared completely.

“A lot of organisations are putting in the components of a zero-trust architecture without having that as a strategic end goal,” he said. “They did that to cover the risk of employees at home, verifying that it’s still that person.”

“We need to make sure we put those divisions in place and the previous IT infrastructure idea of the corporate networks being your castle where everyone inside is safe and trusted and everyone outside are the bad guys, that’s long gone.

“We need to consider people behind the walls as much as those outside it are working for the bad guys and we need to make sure and constantly verify that we’re still allowing the right people access to the right areas and no more and no less than that.”

Focusing on ensuring all of these things are covered is more difficult when considering the global skills shortage in cybersecurity. Having a dedicated team in-house is a luxury only major multinationals can afford, so for most organisations, outsourcing security is the only way.

It’s why services like Paradyn SOC and SIEM are growing in popularity, but as Casey mentions, many don’t know where to start.

The good news is that there are cybersecurity frameworks to base your protections on, such as ISO 27001. They can help break down your responsibilities and requirements into more manageable chunks so you can assess where your blind spots are.

“When you look at it from a holistic, big picture side, it gives an IT manager or director of IT a roadmap on what to do,” he said. “It’s all measured out, there are milestones, KPIs, and they can show that the organisation’s security posture is going in the right direction.”

“If you’re not operating on one of these frameworks, it ends up being piecemeal and you won’t be aware of the gaps in these projects you’re running.”

The benefit of that framework and measuring it is that you have something tangible to show those at board level about the effects of your security measures. By presenting it in a way that they understand, it makes it easier to show how vital security is to the organisation.

There is further scope for encouragement with the EU organisation ENISA (the European Union Agency for Cybersecurity), which is trialling certification for cloud products ensuring that they’re up to a certain standard.

Similar to the standard ISO 27001 provides, it will give further confidence that organisations are treating data with the protection and care it deserves and is expected to come into play in 2023.

“It’s good to see this evolution because they’ve seen we’re missing a spot there,” Casey said. “They said, what can we do to validate and express confidence in these cloud environments, where all of our data is held at the moment?”

“If you look at cybersecurity budgets – and it isn’t necessarily an IT function, it’s an organisational function – there’s a big portion of that which relies on IT doing what it needs to do to protect where the data is.”

“They’ve almost all come together in a line to emphasise organisations’ responsibilities to protect the data. Whether it’s on-premise or in the cloud, paper or digital, personal data or additional bits, you protect it with the same best practices.”

Click here to discuss your GDPR requirements in more detail.

Taking Security to the next level with visibility a key element

Fergal Meehan – Head of Government relations at Paradyn


As attack surfaces evolve and change thanks to a new way of working, new security frameworks like SASE are rising to the challenge.

With the development of the past few years, as remote working is now part and parcel of many businesses, tracking everything you need to protect is a greater challenge than ever. With the average worker using multiple devices to log into the same accounts, there’s a greater impetus to track what’s on the network.

That means the attack surface for the average company is now more expansive than ever and requires the approach to education, technology and policies to be updated and expanded. Not to mention other concerns as highlighted by Fergal Meehan, head of Government relations at Paradyn.

“The tools and technology are out there, but it’s knowing how to position it, remediate concerns and figure it out in a cost-effective manner,” he said.

It’s why security frameworks like SASE (Secure Access Service Edge), which was originally coined by Gartner in 2019, are coming to the fore. In layman’s terms, SASE brings all security and connectivity tools and technology together into one single cloud-delivered solution.

Tools like DNS security, machine learning, data analytics and cloud-driven firewalls are all built into the same system, allowing you to connect users and deliver technology solutions that keep them secure.

Meehan sums up the benefits as allowing flexibility, reducing costs and enabling new digital business scenarios. In short, IT managers can adapt and tailor it around the everyday demands that a business and its departments have.

“We’re in an era where every business unit in an organisation survives on IT,” he added. “SASE works off the zero trust model and brings elements like full-content inspection, allowing you to integrate with your SASE solution.”

The critical component throughout all of this is visibility. As Meehan mentions, you can have all the technology solutions in the world, but if you don’t know what you’re protecting or see what’s covered, they’re not going to be effective.

Zero trust is where this process starts and creating an itinerary of devices connected to the network, your IT architecture, and similar assets is the first step to knowing what to protect.

With SASE, you can see everything with full identity awareness. Regardless of where a person is logging in, you have the relevant information needed for your business to stay safe, including what applications they’re using.

That visibility also brings an unintended benefit that is important to good security posture: reporting. Whether it’s daily, weekly, bi-weekly, monthly or in-between, having reports gives your company an extra level of awareness that can only benefit them in the long run.

This heightened awareness is beneficial, but it’s only good if you have the necessary measures to mitigate an attack, something companies can tend to forget about until a zero-day exploit happens.

“The technology is there to monitor so you’re aware of your inventory and where it’s at with updates, but it’s getting that reporting back down to the desk of the person responsible,” he said.

“Once you normalise that, it brings another checkpoint where you can decide to move from quarterly patch management to bi-weekly because these updates made you aware of what’s required.”

While protection is important, giving the business the necessary breathing space to operate in is also required.

For most IT managers, the challenge is finding the middle ground between protection and accessibility, and the good news is that more tasks like patch management are automated, taking away much of the regular heavy lifting.

Having all these security measures is pointless unless you have a suitable mitigation strategy, with back-ups being a key element of this strategy. Paradyn itself practice this through its service Vault365, which leverages the cloud to back up an organisation’s Office 365 infrastructure. As long as you’re aware that you need to protect the data in the cloud, you will have peace of mind.

Taking such measures isn’t just for convenience; it also meets compliance and data protection requirements. Showing your work goes a long way to reassuring auditors, stakeholders and customers that you’re handling data responsibly.

“At the end of the day, it’s to get to a point where all you need is an executive report saying these tasks are successfully completed, that you’re now in this state, and you can tick these boxes around compliance and data protection,” Meehan said.

Click here to discuss your security requirements in more detail.

Paradyn invests €500,000 in new Vault365 backup service

Cillian McCarthy, CEO, Paradyn and Pat Downing, Commercial Director, Vault365

Vault365 is a brand-new backup solution for data stored on premise and in cloud applications, including Microsoft 365

Paradyn, one of Ireland’s leading cybersecurity service providers, is today announcing it has invested €500,000 in the launch of Vault365, a brand-new all-in-one backup, ransomware and data protection solution for data stored on premise and in cloud applications, including Microsoft 365. The solution has been designed to enable the fastest data restore in the industry.

The company forecasts revenues of €750,000 in 2023 following the launch and is creating five new jobs over the next 18 months. Initially available for Irish-based customers, Vault365 plans to roll out their backup services in the UK within the next six months.

As Office 365 will only retain data for up to 90 days, Vault365 securely backs up and eliminates the risk of data loss on Exchange Online, SharePoint Online, OneDrive for Business and Microsoft Teams. The easily-managed solution, which includes a Backup-as-a-Service (BaaS) option, also protects physical servers, virtual servers, cloud and Software-as-a-Service (SaaS) applications such as Salesforce. Businesses can leverage powerful search tools, fast and flexible recovery, and export options to perform eDiscovery across their entire backup environment.

All data is securely hosted at Vault365’s Irish-based data centres. This ensures local access to data if needed and minimal downtime in the event of an incident, with speedy disaster recovery enabled. Should any incident occur, including a ransomware attack, customers can quickly recover data with the fastest data restore in the industry. Customers also have control over their own data with secure and easy-to-use portal access.

Vault365 is hiring in the areas of sales and support to meet customer demand for increased data backup and security in an ever-evolving IT landscape. The company will be engaging with customers across private and public sectors.

Businesses can avail of a 30-day free trial of backup for Office365 following the launch of the new service.

Cillian McCarthy, CEO, Paradyn: “Proactively protecting data has never been more important in a world where security risks are higher than ever. We are one of a few Irish companies offering this service, which we’re launching to meet customers’ increasing backup and security needs for their mission critical data, regardless of where it is.. There is a common misconception that backup is included with Microsoft, and a solution like this is crucial for businesses to avoid irreparable loss or theft of their Office 365 data.

“Our engineers are experts in their fields, and Vault365 enables business continuity which, in turn, offers peace of mind to customers. We are also excited to make the solution available to our UK customers within the next six months. With Vault365, data is always protected and accessible in today’s uncertain technology landscape.”

Click here to discuss your backup requirements in more detail.

First things first in security

Paradyn COO – Paul Casey

Cyber crime as a service is the new reality, and businesses need to fight back with better defences. They can start by getting back to basics.

Remote working. Previously unknown exploits. Phishing. Smishing. Ransomware. Compliance. It’s a cliché to call the internet the Wild West, perhaps even an insult to the denizens of the old West, but the reality is that businesses today are under extreme pressure to ward off cyber attacks.

Businesses know this, but the question is: do they know how to respond to it?

“There is, I think, a recognition that the threat landscape has changed,” Paul Casey, chief operations officer at network IT and service management solutions company Paradyn, said. Legislation has had an impact, of course, notably the EU’s general data protection regulation (GDPR), which has lit a fire under companies that hold or process customers’ personal data.

“Following on from the likes of GDPR there is a lot more compliance among medium and small enterprises. Of course, large pharma, banking and governments were already used to a level of compliance,” he said.

Casey said that one of the important aspects of GDPR was that companies had to not only do the right thing, but demonstrate good faith. Insurers, too, want to see the right policies in place, otherwise they may adjust rates or even remove cover. “Even from an insurance perspective, businesses are looking to demonstrate that they’ve done the right thing,” he said.

Clearly, then, the pressure is on. There are methodologies out there, though, that can help, notably from the Centre for Internet Security (CIS) and National Institute of Standards and Technology (NIST), adherence to which can give businesses confidence that they are doing things right.

“Were doing a lot with CIS controls. There’s another one, NIST, and there’s also ISO 27001. They all work in similar ways: what they do is allow an organisation to examine and understand everything they do.” Casey said that adherence to these standards led to what he called ‘security hygiene’. “Cyber security hygiene is like personal hygiene: you will be more prone to infection if you are not looking after hygiene,” he said.

Despite the whirlwind of change, businesses have a responsibility to themselves and to their customers, one that is increasingly present in law. “The boundaries have all moved, but the fact is you still have to control things. You need to find out where you’re doing well and where you’re not and work from there,” he said. “That’s where the frameworks come in.”

The goal is a different way of thinking about security, one that means stepping back from saying ‘right, I need another box with lights on it’ and instead looking at the data, systems and network that run a business. ‘It’s really not about putting another box in,” he said.

In fact, businesses often trip up on basic measures including things such as patching and updates. The threat from this seemingly trivial fault is very real indeed and businesses may find they are entirely exposed as a result, especially as so-called ‘zero day’, or novel, exploits are on the rise. “The Chrome browser has had 12 zero day exploits this year alone,” said Casey.

In any case, businesses need to get the basics right before they can move on to more complex measures. As a result, auditing processes is at the top of Paradyn’s list of crucial steps to take in the fight to protect its clients from online criminals.

“If your processes aren’t right, if your users aren’t being trained, and your users on-boarded and off-boarded correctly, then there is a problem. These are things that organisations need to think about and it requires a formalised approach,” he said.

Casey said he is not arguing there is no requirement for new technology, however.

“There are next generation tools with the capability to mitigate against new threats, but if those tools are not implemented in the right way you’re not going to get maximum benefits or, if it’s particularly badly done, you’re leaving yourself open,” he said.

Paradyn also helps to produce reports for internal teams or for businesses own cyber security teams, helping to ease the burden on often already stretched IT staff. “Keeping on top of everything that is changing – the Windows 11 rollout, all of your ongoing projects – is a difficult job as it stands,” Casey said.

But keeping on top of things is essential. A recent report in trade newspaper Computing indicated that it is not only legitimate businesses that are leaning on service providers: strange as it sounds, hackers are now offering criminal gangs ‘exploit as a service’. As a result, the only possible response is to seek external help to fight off the growing threat.

“There’s a massive demand for security services,” Casey said. Little wonder.

Click here to discuss your cybersecurity requirements in more detail.