CBC knew that with growing cyber attacks across the UK the security incidents situation has moved over the years from “if” to “when”. While CBC had security in place with a growing threat – were their defences good enough?
CBC had been making steps forward over the past five years with a focus on information governance and improved vulnerability management (utilising an in-house team and Nessus) CBC had also procured a SIEM system in 2012/13 which provided a log of some systems within CBC.
It was clear that the existing SIEM system provided only a small part, not the whole, of the required security management regime.
When reviewing several high profile incidents they discovered that it was clear the issues were greatly compounded by the late discovery of the issue. It was clear that the existing SIEM system provided only a small part, not the whole, of the required security management regime. It was clear CBC needed a new approach to cyber security to protect against the growing threat.
Central Bedfordshire reviewed their options. It was clear that their software was not delivering the required results and internally they lacked the bandwidth to give the task the focus it needed. Although CBC was security aware, job posts did not exist to focus solely on cyber security. They understood that there would be a need for both new tools and for multiple posts to provide the coverage needed for an appropriate security service.
They reviewed the sector to see what other solutions were available. While there were lots of different software tools and different managed security providers available, the majority of them were unsuitable for the unique requirements of a council.
CBC spoke with ECLIPSE Security and Governance about the Managed Security Service offering to enhance their security. ECLIPSE Security and Governance had been working with CBC since 2014 regarding Information Governance, PSN and N3 compliance, security by design for new architecture, and governance aspects of moving to the cloud. ECLIPSE Security and Governance work had always been high quality and CBC saw them as a trusted partner.
“ECLIPSE Security and Governance have the right mix of skills and tools to ensure we have an appropriate level of cyber security.”
Emel Morris, CIO, Central Bedfordshire Council
ECLIPSE Security and Governance had spent three years assessing the requirements of local government cyber security in developing their Managed Security Service. ECLIPSE Security and Governance’s Managed Security Service offers a best of breed Unified Security Management solution. ECLIPSE Security and Governance has reviewed and trialled available security technology to identify which is the most appropriate for the business requirements and threat environment in local authorities. The ECLIPSE Security and Governance Managed Security Service uses this technology, which its specialist security operatives utilise to maximise the protection/ benefit to the Council.
Delivery of the Managed Security Service
ECLIPSE Security and Governance commissioned to provide the ECLIPSE Security and Governance Managed Security Service to CBC in April 2018.The same month the sensors were deployed in the two main data centres, and the service commenced.
“We quickly derived more benefit from the ECLIPSE Security and Governance service than we got from the pure SIEM system we had deployed for several years”.
Bernard Sykes, Operations and Networks manager at Central Bedfordshire Council
A phased delivery plan was agreed; CBC a data centre technical refresh programme underway, and it was decided to introduce “security by design” for the new infrastructure, rather than reengineer legacy systems that were due for replacement. This process has progressed well, and most of the estate is currently within the scope of the
Managed Security Service
The real benefits have been obtained from the system to date, including the tuning of the councils remote working systems. The ECLIPSE Security and Governance service has collated information from firewalls, Okta, Mobile Iron and F5 service to gain a holistic view of the situation, and the identification and correction of compliance issues. The Threat and Vulnerability Management System is providing real time information regarding vulnerabilities within the estate, this is collated with real time threat feeds from Open Threat eXchange, asset information, and security events to provide holistic and contextualised security information.
The result of the deployment of the ECLIPSE Security and Governance service to date has been the suppression of vulnerabilities and incidents, and although ECLIPSE Security and Governance detects many security events per day, only events of real consequence are reported to CBC – this is typically less than 10 per day, and this is decreasing as the security posture improves.
ECLIPSE Security and Governance continues to work as trusted partners of Central Bedfordshire providing the Managed Security Service and other critical information governance guidance.
Emel Morris, CIO, Central Bedfordshire Council commented about the partnership.
“The world of cyber security is a complex one, with an increased number of cyber-attacks and threats every day. ECLIPSE Security and Governance have the right mix of skills and tools to ensure we have an appropriate level of cyber security. Using ECLIPSE Security and Governance’s Managed Security Service we believe that our citizen's data is safer. The service has meant we have more visibility of potential or actual issues and can work proactively to contain and prevent them from causing harm".