Securing Email in an Ever Changing Threat Landscape Barracuda Networks January 2017
Natural Disasters Compliance Ransomware
Email-Borne Threats in the News... Email security is no longer just about preventing excessive spam and viruses – the attacks are real, they are sophisticated, and they are costly. Nearly every day there is a new story about malware – and a lot of it is ransomware, which can cost you dearly. 3
Barracuda Essentials
Barracuda Essentials for Email Security Cloud-based, multi-layer email security and archiving for Exchange, G Suite, etc. Compatible with on-premises and hybrid configurations Built on proven Barracuda SaaS solutions Low cost, per user licensing Single SKU for simple quoting/bundling Centralized management Includes 90 Day PST Enterprise Comprehensive security and archiving solution Exchange, G Suite, etc. Centralized administration through Barracuda Cloud Control Per User Licensing
Why Multi-Layer Protection? End User Education Stop email threats at the perimeter Ensure email policy enforcement Protect confidential information from leaving Prevent internal threats and outbreaks Stay ahead of evolving threats Activate ”human firewall” as defense layer ATD/Sandboxing Static Analysis Multi-Opined AV Link Protection Reputation Management & Content Inspection Spam Scoring Bayesian Analysis Image Analysis Intent Analysis Fingerprint Analysis Custom Policy Virus Scanning Recipient Verification Connection Management Sender Authentication IP Analysis Rate Control Network DDoS Protection
Barracuda Email Security Service Easy-to-Use, Cloud-Based Email Security Industry-leading spam and virus defense for email Email Continuity Service for emergency failover End-Users training & exercises Protection from data loss and reputation damage Advanced, granular policy management Real-time threat protection
Advanced Threat Protection Critical Element Advanced Threat Detection (ATD) Remote “Detonates” in sandbox to detect malware Machine learning for fast and accurate results Scans 900+ artifact attributes <1sec Link Protection Redirects suspicious URLs to sandbox Detects “typosquatting” (deliberate mis-spellings) Included in ESS and Essentials Micro-Service is Key 3 scan layers (AV/Static/Dynamic) Reduces scan/decision time Shares database across products Barracuda ATD All Barracuda NG Firewalls using the ATD features improve the central ATD hash database in the cloud. This way, if a signature is already known, the file will be processed without any further delay. 8
Encryption and Data Loss Protection Protect sensitive data with integrated Encryption and DLP Optional encryption for secure message transmission Pre-defined patterns or terms to block, quarantine, or encrypt outbound messages
Email Continuity Email Continuity Service Failover to cloud-based email service to continue mail operations Allow users to send and receive emails via emergency mailbox Provides cost effective DR for Exchange and Office 365
Integrated End User Training Link Protection ensures typosquatted links go to warning page Links to training exercises to create a “human firewall” Delivers security platform with detection, prevention, AND education
Customer Example Tommy Kanger – Dir. Information Technology Property & Casualty Insurance Company Took over as IT Director in 2014 Inherited outdated infrastructure Standardized on Office 365 Office 365 Email Security (EOP) Good at First First 6 months everything was good Later had significant CEO spoofing and spear phishing scares Didn’t have resources to “micro manage” EOP Turned to Barracuda Essentials for Office 365 Success with Barracuda Backup Enabled Email Security Service + Advanced Threat Detection Since activating; SPAM numbers, threat levels “dramatically down” “We presently use the ATD feature of the Barracuda Email Security Service and are loving it.” Took over as IT Director at beginning 2014 When arrived system dated. Previous director was not an early adopter. Was also hodge/podge. Diversified across different vendors av/backup/etc. Met with Exec team to modernize and based on cost/trouble with Exchange…decided to go to O365 Everything was good for about 6 months with EOP…things were fine but as time progressed noticed more and more things slipped through. Being Financial Services had some scares from CEO Spoofing, Spear Phishing, etc. Did some research to find what could supplement native MSFT features. When modernized implemented Barracuda Backup. Had previous experience with Barracuda and trusted the product. Did a demo and almost instantly saw a difference. Wasn’t overly expensive. Since activating SPAM numbers, threat levels dramatically down. No complaints, everything works as expected, good support. Loves that doesn’t have to micromanage security, can just set it and forget it. Wanted to focus attention on other things than managing spam policies. Uses archiving as rainy day insurance policy and can quickly find emails when needed. E3 for executives, E1 for rest of staff Deployed Essentials w/Compliance in March 2016
Barracuda Cloud Archiving Service Cloud-based archiving from Office 365 for Compliance and eDiscovery 100% Cloud-based (no HW/SW) Hosted in secure Barracuda Cloud eDiscovery search, hold, and export Import historical data (Exchange/Office 365) Role-based administration Full-featured mobile app Works with Exchange and Office 365, including hybrid deployment
Easy Access via Outlook Familiar interface From inside and outside organization Available offline No more PSTs You can also access your archived email via Outlook, where it appears as just another mailbox that you can search and use just like your standard mailbox. And direct access to this archive makes PSTs unnecessary, simplifying IT management and eDiscovery. This archive can also be available if you have no network connection.
Easy Access for Mobile Workers Access any email …Ever sent to/by you …By/to anyone …Across mobile platforms …Fast! Even if mail server is down If your organization uses Barracuda Message Archiver, you can avoid mobile access frustrations. The Message Archiver mobile app provides fully-indexed, rapid access to any email that ever hit or left your mailbox from your Android or iOS device quickly and easily, even if the email was deleted and/or you can’t reach your standard email server. The mobile app brings complete access to your entire email history to your fingertips whenever needed.
Easy eDiscovery and Compliance Role-based access and search Role-based AD/LDAP access for auditors String-based searches on user-selected email fields Detailed audit logs of all operations Policy-driven alerts and retention rules Compliance through policy definitions Global policies Granular policies Legal holds Another area where Message Archiver adds value is in legal needs, such as eDiscovery (finding and providing information in response to a legal action) and compliance (maintaining information to meet the requirements of regulations). Message Archiver supports 3 different roles – admin, auditor and user, and allows them to create, save, and share searches, apply litigation holds and export information that can be shared with 3rd parties (e.g. external auditor, legal counsel, etc.). Access is moderated by AD/LDAP integration. Message Archiver also enables admins to set proactive policies that will monitor activity and take some action when certain conditions are met, e.g., alert the admin or auditor every certain keywords are found (e.g. personal information, adult language, etc.), or apply granular retention rules to ensure optimal storage of messages.
Customer Example Multi-state Eyeglasses & Optometrist Retailer 35 states/157 locations/650+ users Standardized on Office 365 Office 365 Compliance Did Not Satisfy Requirements In-Place preservation did not prevent deletion Needed cloud-based email archiving Solution – Barracuda Cloud Archiving Service Easily generated audit logs for compliance Non-intrusive, “set it and forget it” operation
Centralized Management Cloud-based management console Enables administrators to manage Barracuda Essentials from a single console. Check the health of all connected devices, Run reports that are generated by gathering data from all the services Assign roles with varied permissions to different types of users.
Adoption Across Industries Enterprise Consumer SLED Finance & Health
Next Steps Consider Free 30 Trial... https://www.barracuda.com/essentials Talk to your Barracuda Account Exec/Reseller Learn more at https://campus.barracuda.com
Q&A