Cyber Security – AvantOne Managed Cloud Services Mon, 29 Jan 2024 23:17:39 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 /wp-content/uploads/2024/01/cropped-icon-32x32.png Cyber Security – AvantOne 32 32 The Internet Jurisdiction Risk of International Data Centers and the Cloud /nproject/the-internet-jurisdiction-risk-of-international-data-centers-and-the-cloud/ Fri, 19 Aug 2022 07:45:12 +0000 https://www.avantone.net/?post_type=nproject&p=643

Overview

CTOs in Fintech Industries are currently eager to adopt cloud-computing technologies and services into their infrastructure. However, with these cloud services comes an issue surrounding the jurisdiction under which they operate.
Our case study presents certain suggestions through which these complex issues may be dealt with across different jurisdictions.

Problem

Data centers belonging to a single cloud provider, like AWS Cloud, are usually located around the globe to support a worldwide customer base. Now, different countries have different data protection laws, and these multi-national data center distributions create a conflict of law and certain additional issues.
For instance, there are strict limitations to the mobility of data generated from EU jurisdictions to other jurisdictions. Subcontracting makes this scenario even worse, as when a CSP (communications service providers) leverages the services of another CSP, confusion arises on the exact jurisdiction to be applied. This serves as a major roadblock in case legal action from a user is warranted.

Solution

There’s no universal solution to mitigating risks with CSP jurisdiction, and this is unsurprisingly due to different countries running under different laws.
Nonetheless, some measures have been identified to work in your favor.
The more common scenario is CSPs and even regulators focusing on the content of service-level agreements (SLAs). Firstly, CSPs have tried to expressly state the jurisdiction under which they fall, while regulators introduced standardization guidelines to the formulation of these SLAs.
Mutual Legal Assistance Treaties (MLATs) between countries also allow for easy transfer of sensitive data between them. One case we could look at is the MLAT between India and Poland. A CSP like Equinix can be forced to transfer data between these countries without issues around jurisdiction arising.
Apparently, only legal agreements can mitigate the risks surrounding cloud service jurisdictions.

Results

The whole scenario around CSP jurisdiction is as complex as it gets. Conflict of law exists due to the geo-location of data centers and there are particularly suffocating rules on the control and transfer of data.
Nonetheless, there are solutions for online fintech owners that wish to adopt cloud infrastructure through CSPs. Your best bets are to choose a CSP that clearly states jurisdiction in its SLA, make sure this jurisdiction protects you against data breaches, and verify that MLATs exist between countries where your CSP’s data centers are located.

]]>
Disaster Recovery Plan for Business Continuity at a Fintech Corporation /nproject/disaster-recovery-plan-for-business-continuity-at-a-fintech-corporation/ Fri, 29 Jul 2022 15:17:00 +0000 https://www.avantone.net/?post_type=nproject&p=650

Overview

Disasters are part of the ugly side of nature; we don’t want them to happen but there seems to be no way to avoid or prevent them when they do. What you can control as a CEO or business owner, however, is your insurance or backup plan against these disasters.
In our case study, we present you with how Canadian Fintech company formulated its disaster recovery plan during the setup of newly purchased Nutanix systems.

Problem

The Fintech company faced the challenge of a new web-based financial product. All the purchase, setup, and deployment needed to be completed within 8 weeks.
This financial product was an application system that managed the transfer of payments between businesses(B2B). Nutanix was selected after an encounter at VMWorld, as it served as a 3-tier solution that was easier to manage than company’s currently deployed server infrastructure.
Upon purchase, how did the Fintech company shape its web app framework for business continuity in case of a disaster?

Solution

14 Nutanix all-flash servers were purchased, half (7) were deployed at Fintech company’s Q9 company base to manage workloads, and the other half (7) were stationed on standby at a separate facility. This is the company’s second data center.
The Fintech company also used only its Nutanix systems to run mission-critical workloads. Its previously deployed traditional systems were used as business systems to manage payroll and accounting activities.

Results

All this means is that the company’s disaster recovery framework assured it of continued core business operation even with the failure of primary financial management systems. Nutanix systems also brought about lower costs, reduced downtime, and simpler server management.
Overall, Fintech companies can learn a thing or two about formulating disaster recovery plans. All that is important is standby systems at separate locations and using backed-up systems to run core Fintech company workloads.

]]>
Increasing Vpn Security In A Multinational Environment With Military Grade Encryption /nproject/increasing-vpn-security-in-a-multinational-environment-with-military-grade-encryption/ Fri, 29 Jul 2022 07:14:31 +0000 https://www.avantone.net/?post_type=nproject&p=637

Overview

A Fintech company with remote operations needs secured solutions to facilitate business communications and the transfer of data between employees. VPNs are solutions that help with this need for security while also reducing the costs of communication.
However, what happens when your deployed VPN holds certain vulnerabilities with security? How do you get rid of these vulnerabilities, improve security, and also limit your costs on advanced infrastructure deployment?
Our case study focuses on how Acme Widget improved its VPN environment by working with a GIAC-authorised professional.

Problem

Acme Widget established a headquarter in North America in 2001, with the primary aim of operations being to provide financial, legal, tax planning, and treasury support to the Italian headquarter and for North American operations. 30 staff members were hired, office renovations began, and members were required to work from home.
This remote work environment created a problem relating to the secure access to emails and departmental files on the existing office server. The existing RAS server couldn’t accommodate 30 remote users. To fix this, a Windows 2000 VPN with 25 PPTP ports was set up at the office, and firewalls were deployed at each user’s home to assure security.
A GIAC professional was hired to run an assessment on the new VPN deployment and an issue was found with VPN termination points within the framework. Terminations behind the firewall and on the domain controller posed major threats to sensitive user account details, financial information, and server integrity.

Solution

A new VPN that was rid of these was the obvious solution and our GIAC professional identified one that additionally reduced costs by offering a managed server solution; Cisco VPN.
The new military-grade Cisco VPN implemented IPsec instead of PPTP ports and this allowed for improved activity transparency through accurate traffic logs. Computer-level authentication was also added to user-level authentication, ensuring greater security all-round.

Results

The initiative of Acme Widget to hire the services of a GIAC professional saved it from massive losses that would have occurred through a vulnerable VPN deployment. This improvement in VPN was also achieved on a limited budget, over a short period, and covering large multinational locations.
The terms “multinational locations”, “financial information”, and “user authentication” point to how useful a secured VPN deployment is to Fintech companies.

]]>