Monday, October 19, 2015

High Performance, Low Latency, Hyper-Converged Computing


Recently 360is implemented several systems for clients who needed very high performance, within a stated budget, and had limited physical space and power to work with. For these clients we designed hyper-converged compute/storage units built from non-proprietary, commercial off the shelf components, supportable by their in-house IT team. Thanks to recent advances in storage technology it is now possible to obtain very high performance for a fraction of the cost of a traditional Server + SAN approach. Better still, these systems aren't subject to the vendor’s ideas of life-span (often artificially foreshortened), and can remain operational for 5, 10, or more years if required. You the customer, remains in control.
  • 70GB/sec streaming transfers, 4M IOPS, 4U of space, 5TB to 250TB raw capacity, 2.5PB per rack
  • 2GB/sec streaming transfers, 480TB raw capacity, 4U of space. 4.8PB per rack
  • 75% less power for a given performance level
  • 3X to 6X the performance when compared to similarly priced Server + SAN
  • On-site spares for instant access to replacement parts, forever
  • Scale-out capability with clustered filesystems like Lustre, GlusterFS, and Ceph
  • No chance the vendor can make the systems obsolete
If you are challenged to provide performance, either on-premise or in the cloud, then a hyper-converged system may be for you, and will certainly have a longer lifetime without vendor or service lock-in. For a fixed cost, a properly designed hyper-converged system will always deliver significantly more performance than Server/SAN systems. Let us know your constraints and we can give you an immediate indication of whether hyper-converged is for you.

About 360is
Our scientific approach to performance analysis and engineering has been proven in previous engagements. We work with top 5 Investment Banks, Telcos, and technology vendors. If you have an IT performance problem that is impacting your business, contact us to arrange a no-obligation meeting with one of our consultants.

Wednesday, September 23, 2015

Countering The Social Engineering Threat

An increased number of clients are experiencing social engineering attacks either directly against their finances and information assets, or the IT infrastructure upon which those assets depend for confidentiality and security.

Once only immediately saleable commodities such as credit card numbers were targeted. Now criminals are seeking medical records, credit history files, general personal identity information, significant cash funds, and online social media account information for purposes as diverse as blackmail, defamation, and identity or insurance fraud.

Highly targeted attacks often focus on uncovering commercial negotiating positions, cost-to-manufacture for orders, and in identifying holders of intellectual property or purchasing authority within an organisation. Those defending against such attacks now need to consider far more than simple monetary loss.

360is have prepared a short briefing for those tasked with defending their organisation and users from social engineering attacks including Phishing, Pharming, Vishing and SMishing. It is intended as an introduction to the technical, procedural, and human elements of a successful social engineering defence.

If you would like assistance in implementing any of the measures described in the document, or in understanding your own organisations vulnerability to social engineering attack, get in touch.

Download "Countering The Social Engineering Threat" here.

Thursday, June 11, 2015

City Security Magazine, How To Avoid Leaks


Leaks are news, whether they are about Governments, Corporations, or individuals. City Security Magazine, the print and digital magazine that promotes security issues across the UK, carries an article from 360is on how to reduce your chances of becoming the next SONY, NSA, US State Department, or celebrity to suffer a breach of Information Security and have private and confidential information leaked to the public domain.

360is are able to assist in improving your organisation’s Information Security posture, and in implementing the advice given in the article. While it may be impossible to guarantee that your confidential information will stay that way, you can significantly reduce the chances of the kind of widespread leak experienced by the US State Department, the NSA, or SONY.
To speak to one of our consultants, visit our contact page and request a meeting.

Wednesday, April 08, 2015

Meet 360is At InfoSecurity Europe 2015


Three Sixty Information Security Ltd will be at InfoSecurity Europe, Olympia, London, 2nd to 4th June 2015. We'll be meeting clients, partners, and friends among the 12000 expected visitors and 330 stands at the show this year.

If you want to discuss the results of a penetration test, arrange a confidential meeting about a  breach, or just need advice on how your organisation should handle the latest bug disclosures, get in touch. We will have technical consultants at the show.


Thursday, February 05, 2015

How do we validate a supplier has ISO 27001?

(c) Scott Adams
Most of the questions we get from our clients about ISO 27001, the standard for Information Security Management Systems, are about how they can implement this standard and possibly achieve certification.  We covered some of that in our previous blog.

The "other" question we get asked less often is "how do we validate a supplier or partner that claims to follow ISO27001 or claims to have been certified now or in the past?"
You may be surprised by the answer.


There is no such thing as a complete, current list of ISO 27001 certified companies.

That's right, it is impossible to obtain a definitive list of companies with ISO certification.

The creation of such a central list has been attempted in the past more than once, and for several ISO standards (notably ISO 9000) but such lists have always been incomplete and prone to going out of date. Part of the reason for this is that there is a competitive market between certification companies, they don't want to share their list of clients, or even indicate how many clients in total they might have, or how many might have once held certification which has since expired. Companies go out of business, get acquired, divested of, and restructured, and all these things mean that an ISO certificate issued in the past, may not count for much in the present unless the certified company has kept up with its maintenance audits (surveillance audits as we call them in ISO-speak).

Your best hope is to speak to the certification body the certificate holder used. For example, BSI allows you to query a certificate number against their database of clients to see if it was issued or is current here. Not all certification bodies have such an online service, and if you don't know who issued the certificate then you are out of luck.

360is is able to perform due diligence against your suppliers and partners to determine the strength of their information security, whether or not they have undergone any formal certification. If their technology, processes, or procedures do not provide adequate protection for your sensitive data, we are able to describe and implement improvements. If you are faced with meeting strict information security compliance targets yourself, we can help your formulate an appropriate response and program of improvements to meet expectations. Talk to one of our consultants.