incident response Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/incident-response/ Breaking news about the market for products, systems and services for the U.S. intelligence community Mon, 04 May 2026 22:03:10 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg incident response Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/incident-response/ 32 32 59882712 Owl launches incident response data diode https://intelligencecommunitynews.com/owl-launches-incident-response-data-diode/?utm_source=rss&utm_medium=rss&utm_campaign=owl-launches-incident-response-data-diode Mon, 04 May 2026 22:03:10 +0000 https://intelligencecommunitynews.com/?p=44485 On May 4, Owl Cyber Defense announced the launch of its Incident Response Diode (IRD), the industry’s first pocket-sized protocol...

The post Owl launches incident response data diode appeared first on Intelligence Community News.

]]>
On May 4, Owl Cyber Defense announced the launch of its Incident Response Diode (IRD), the industry’s first pocket-sized protocol filtering diode (PFD) for incident response and forensics teams. The Owl IRD was developed to help users securely move evidence from compromised endpoints into trusted analysis environments without adding risk. Owl IRD will be made available to select customers for field testing.

When an endpoint is compromised, responders must race against the clock to pull critical data before systems are wiped, reimaged or attacked again. But risky connections and legacy technology may spread malware, break chain of custody, and trigger costly enclave rebuilds. The Owl IRD solves this with hardware-enforced, protocol-aware one-way transfer per U.S. Government PFD requirements. As a PFD, the Owl IRD enhances the unidirectional nature of a simple diode with protocol filtering at the FPGA level — delivering a secure, repeatable evidence path that reduces reinfection risk and preserves forensic integrity. The Owl IRD extends Owl’s PFD suite to the endpoint, complementing Owl Talon’s always-on network flows with purpose-built incident response capabilities, from endpoint triage to evidence intake and one-way mission data collection. High-stakes collections become a consistent, defensible workflow.

“Every incident responder knows the uncomfortable tradeoffs they face when collecting evidence from a live, compromised system,” said Tim Fahl, chief technology officer at Owl Cyber Defense. “Their options are to rush ahead with tools that put their clean environments at risk, or slow everything down trying to engineer safer workarounds in the middle of a crisis. The Owl IRD eliminates that tradeoff by putting protocol-aware, hardware-enforced, one-way protection directly into the responder’s go-bag, so teams can confidently collect what they need without opening new paths for the adversary.”

Source: Owl

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post Owl launches incident response data diode appeared first on Intelligence Community News.

]]>
44485
Forcepoint to acquire Deep Secure https://intelligencecommunitynews.com/forcepoint-to-acquire-deep-secure/?utm_source=rss&utm_medium=rss&utm_campaign=forcepoint-to-acquire-deep-secure Wed, 16 Jun 2021 13:02:54 +0000 https://intelligencecommunitynews.com/?p=29681 On June 15, Austin, TX-based Forcepoint announced the company has signed a definitive agreement to acquire UK-based Deep Secure. Deep...

The post Forcepoint to acquire Deep Secure appeared first on Intelligence Community News.

]]>
On June 15, Austin, TX-based Forcepoint announced the company has signed a definitive agreement to acquire UK-based Deep Secure. Deep Secure’s cybersecurity products and services protect organizations from cyberattacks delivered via malware and help prevent unwanted data loss.

Underlying the planned acquisition of Deep Secure are expansion opportunities that will enable Forcepoint to extend the capabilities of its industry-leading Cross Domain Solutions portfolio to deliver enhanced efficacy for securing the critical data and missions of governments in the U.S. and beyond. Cross domain solutions enable secure sharing and access to critical mission and operational data between security levels across the government and critical infrastructure, providing enhanced security and functionality for high-consequence missions around the world.

“Forcepoint has been the global Cross Domain Solutions market leader for more than 20 years. We’ve maintained this leadership position by working closely with government, commercial clients and technology partners to ensure our solutions continue to deliver the most robust security and usability possible, while supporting our customers’ current and future mission requirements,” said Sean Berg, president of global governments and critical infrastructure at Forcepoint.

“The addition of Deep Secure’s innovative Threat Removal Platform and hardware security to our Forcepoint Cross Domain Solutions portfolio further extends the depth of our defense-grade capabilities to governments and critical infrastructure organizations around the world, who continue to be under siege from nation-state and other attackers looking for financial gain or to ultimately disrupt societies and economies at scale. We look forward to completing the transaction and subsequent integration of the Deep Secure team and technology into Forcepoint following required regulatory reviews in the coming weeks,” Berg continued.

Deep Secure addresses a substantial problem for organizations — the safe exchange of information with trusted and untrusted sources. Deep Secure’s Threat Removal platform takes a zero trust approach to data, assuming all of the original data is infected and prohibits that data from reaching its destination. Instead, information is extracted from the original data, verified as safe using hardware-based verification, and then new data is built to carry the information safely to its destination. Malicious or unrecognized data hidden in the document is eradicated.

Deep Secure’s Threat Removal platform helps eliminate the threat from a number of the most common attack vectors, including email and web downloads, and is ideal for organizations requiring the highest levels of assurance. Unlike traditional Content, Disarm & Reconstruction (CDR) products, Deep Secure’s Threat Removal platform is not reliant on detection and has been proven to be highly effective, with optimized user experience, flexible deployment and proven ROI.

“There’s already significant alignment between Forcepoint and Deep Secure based on our respective footprints in the defense and intelligence sectors as well as our shared mission in taking a data-first and zero trust approach to security that protects the digital crown jewels at all costs – which is critical for business integrity today,” said Dan Turner, CEO of Deep Secure. “The economics of removing the Malware threat in the information flows are truly compelling and by extending the Threat Removal approach into cross domain solutions on-premises, hybrid or in the cloud enables enterprise organizations to experience defense-grade cybersecurity solutions at an exceptional value.”

Subject to regulatory review and customary closing conditions, the transaction is expected to close in August 2021.

Source: Forcepoint

The post Forcepoint to acquire Deep Secure appeared first on Intelligence Community News.

]]>
29681
Honeywell launches new cybersecurity service https://intelligencecommunitynews.com/honeywell-launches-new-cybersecurity-service/?utm_source=rss&utm_medium=rss&utm_campaign=honeywell-launches-new-cybersecurity-service Thu, 10 Jun 2021 12:17:22 +0000 https://intelligencecommunitynews.com/?p=29628 On June 9, Atlanta, GA-based Honeywell announced the introduction of the Honeywell Advanced Monitoring and Incident Response (AMIR) service. The...

The post Honeywell launches new cybersecurity service appeared first on Intelligence Community News.

]]>
On June 9, Atlanta, GA-based Honeywell announced the introduction of the Honeywell Advanced Monitoring and Incident Response (AMIR) service. The service provides 24/7 operational technology (OT) cybersecurity detection and rapid response for current and emerging cyber threats.

AMIR is a cost-effective, easy to deploy, scalable cybersecurity service that is tailored to help IT and OT security teams that may struggle to keep up with the continuing evolution of today’s cyber-attacks that target industrial control systems (ICS) and operational technology networks due to a lack of expertise or budget constraints.

AMIR is part of Honeywell Forge Managed Security Services (MSS), an end-to-end security as a service solution that helps protect OT environments, control systems and operations. In comparison, other third-party MSS providers and in-house solutions may rely either on basic monitoring that doesn’t employ a proactive approach to securing critical OT assets and operations or on IT security operation centers that lack OT domain knowledge and expertise in different industrial protocols and assets.

“Honeywell’s Advanced Monitoring and Incident Response solution provides a combination of advanced cybersecurity software, experts, and playbooks with remediation guidance in order to better detect, prevent, analyze, evaluate and coordinate the response to cybersecurity threats occurring within OT environments,” said Jeff Zindel, vice president and general manager, Honeywell Connected Enterprise Cybersecurity. “Staffed by cybersecurity experts with specific OT experience, AMIR offers a tremendous resource to complement any existing IT/OT cybersecurity program and help ease the burden of cybersecurity challenges.”

AMIR continuously monitors OT environments by “hunting” for anomalous behavior, including both known and emerging cybersecurity threats. It analyzes indicators of compromise and alerts operators to potential problems before significant damage can occur. Through the use of proprietary technology, AMIR collects, correlates, prioritizes and analyzes security events and log data from multiple sources, providing a comprehensive approach to better minimize cyber risk and support cybersecurity compliance.

Source: Honeywell

The post Honeywell launches new cybersecurity service appeared first on Intelligence Community News.

]]>
29628
Seize the “Top of the Pyramid” https://intelligencecommunitynews.com/seize-the-top-of-the-pyramid/?utm_source=rss&utm_medium=rss&utm_campaign=seize-the-top-of-the-pyramid Wed, 11 Nov 2020 21:26:39 +0000 https://intelligencecommunitynews.com/?p=27977 From IC Insider Siren By John Randles, CEO of Siren Cybersecurity threats represent the single greatest menace to governments and...

The post Seize the “Top of the Pyramid” appeared first on Intelligence Community News.

]]>
From IC Insider Siren

By John Randles, CEO of Siren

Cybersecurity threats represent the single greatest menace to governments and organizations today. To an extent this threat has been magnified due to COVID-19, as more of us are working from home on less stringent network environments. An organization’s ability to protect its data from its adversaries is critical to their survival. It takes little imagination to consider the catastrophic effect of a nation losing their passcodes to their enemy during a conflict. News media headlines are riddled with stories from data breaches to hostile malware – often orchestrated by state-sponsored nefarious organizations. As institutions struggle to fight these never-ending attacks, they must seek ways to mitigate and address these threats. An active cyber defense is often addressed by:

  • Continuous improvement and adaptation
  • Unique analytic capabilities
  • Investigative tools
  • Tailored agile cyber threat intelligence.

The Pyramid of Pain

Organizations address these threats through the Pyramid of Pain, a maturity model that spans from simple, frequent attacks against vulnerable endpoints through sophisticated attacks. As security analysts move from the bottom to the top of the Pyramid, their job becomes progressively more difficult. For example, while endpoint protection is the most frequent point of attack, it represents the lowest level of sophistication.

However, the most difficult levels for most organizations remain the top three categories. More importantly, these three categories require organizations to hire and retain security analysts with specific skill sets that need to be continuously sharpened and honed. Organizations must be able to uniquely adapt to different types of threats that are seen and observed or respond to an incident that may have been missed.

In addition to maintaining highly skilled individuals, organizations must be able to develop a tailored process and incorporate their own specific datasets. Indicators needed to be analyzed are often hidden across various system logs. For example, a hotel chain might have a rewards program that is subject to a fraud ring. The fraud may be a larger effort to hide more egregious behavior such as credit card theft or identity theft of their top-level clientele.

Incident Response

When compromise events occur, analysts must be able to update threat observables in real-time, visually updating the scope as new indicators are added to the intrusion set: enabling scalable collaboration, real-time situational awareness, and clear communication.

Historically, organizations have turned their attention to a Security Information and Event Management (SIEM) tool to solve these challenges. However, there are complementary technologies such as Siren to aid the Threat Analytics phase of problem solving. This tool empowers organizations to effectively deploy an enterprise-wide cyber threat intelligence and threat hunting capability.

Security analysts find themselves copying and pasting specific alerts or IPs and try to pivot through different dashboards and various search functions – ending up creating long, complex search queries. These end up being difficult to repeat and maintain. Siren enables analysts to search all the data in a single pane of glass, moving from one index to another through intuitive graphs or relational navigators – without complex query languages. The solution rapidly ingests any kind of telemetry data analysts want to throw at it.

Link Analysis with the Network Graph

Security analysts fall victim to eye and mental fatigue searching and manipulating the data. Through Siren’s Knowledge Graph, analysts are able to quickly expand, investigate, and drive insights in an intuitive link and node user interface. Imagine starting an investigation by graphing adversary behaviour and discovering a specific malware sample and its relationship to different infrastructures or mechanisms of operations – in the form of a picture. No logs. No endless commands. A clear, easy-to-understand network graph. In addition, through Siren’s Web Services, analysts can enrich their data on-the-fly. The knowledge graph can bring together, for example,  OSINT sources, IDS alerts, CVE Data, Mitre Attack classification etc. to bring as much data as possible to bear on a particular threat.

Threat Hunting

Threat hunting comes down to being able to understand more discreet, nuanced behaviours observed on the network and associating them to discovered indications of an adversary.

Siren’s flexible data model allows security analysts to rapidly ingest discreet datasets on the fly and extend Siren’s existing data model without impacting other analysts’ work. With Siren’s data model, you’re not constrained to a specific set of indicators to start an investigation from certain classes of logs that you might use to scope. When the security analyst build’s the data model, he or she can effectively explore a living presentation of the data, no matter where the investigation starts.

Should I Ascend the Pyramid?

To answer this question , there are seven questions every Chief Information Security Officer should ask themselves:

  • Do I really need to be at the “Top of the Pyramid” – Threat Hunting?
  • Are advanced adversaries likely to overcome my automated cyber defence?
  • Does my organisation make more than $300M/year?
  • Do we work with PII or other valuable data?
  • Do we work in a sensitive sector or have sensitive customers?
  • Do we expect a targeted attack?
  • Do we expect personalized malware?

Siren’s Security Analytics solution offers a full breadth of capabilities security professionals demand when working at the ‘Top of the Pyramid’.

Regardless of your environment, Siren offers several different integration options. Siren quickly leverages Elasticsearch and integrates with most SQL databases, datalakes and Siems such as Splunk. Siren holds a rich set of capabilities and a wide spectrum of hooks that can seamlessly integrate into any organizations’ framework. The intuitive user interface provides a rapid time-to-value for any security analyst.

Indicator Feeds, Telemetry Events, and Alerts

As security analysts work to understand how to make sense of their logs, they often copy and paste values from one point solution into another. Through the use of Siren’s Set to Set Navigation, analysts seamlessly pivot from one dashboard into another, giving them a powerful context navigation tool that makes exploring logs effortless. Switching between network segments provides analysts complete insight into logs that were once difficult to search and impossible to manage. For example, if an analyst receives an alert on Network A, they can quickly understand the relationship between that source and the destination alert, and other log sources that have traffic related to the nodes they are investigating.

With Siren, moving from one dashboard to another does not require any special search syntax or special search language to master. While this challenge may seem trivial, it plagues most security analysts today.

In Summary

Siren offers a spectrum of capabilities that fully support cyber threat hunting. From exploring adversaries attempting to breach networks to creative account takeover attempts, Siren’s robust data model and a rich library of visualizations make it a perfect extension to any Security Operation Center’s portfolio of solutions.

About Siren

Siren provides the leading Investigative Intelligence platform to some of the world’s largest and most complex organizations for Investigative Intelligence on their data. Rooted in academic R&D in information retrieval, distributed computing and knowledge representation, the Siren platform provides integrated investigative intelligence combining previously disconnected capability of search, business intelligence, link analysis and big data operational logging and alerting.

Among Siren awards are Technology Innovation of the Year and the Irish Startup of the Year (Ireland’s National Tech Excellence awards). In 2020, Siren was named as a Gartner Cool Vendor in an Analytics and Data Science Report. For more information, visit www.siren.io.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Seize the “Top of the Pyramid” appeared first on Intelligence Community News.

]]>
27977