When you think of security information and event management (SIEM) tools, you typically think of vast enterprises that have thousands of devices logging millions of events every day. In such cases, a SIEM might be the only way to truly gain visibility into such a large network. But smaller companies can benefit from a SIEM tool, too—especially if the IT department is small and overworked. TriGeo Network Security offers a tool for the SMB market that’s like having a security expert on staff.
There are quite a few good security information and event management (SIEM) tools for the enterprise that capture event information from device logs, correlate the events, alert the experts who can act on troublesome activities and store millions of pieces of data for forensic analysis . The enterprise level products are capable of handling thousands of network devices and millions of events on a daily basis. Security specialists in a company’s security operation center (SOC) monitor the SIEM on a 24/7 basis.
But what if your network is relatively small and you don’t even have a million events in a year? What if your entire IT department is only a handful of people and your company has no such thing as a SOC? Small and medium-sized companies could really benefit from a tool like SIEM—just as the big enterprises do. This is the market that TriGeo Network Security Inc. addresses with its TriGeo Security Information Manager (SIM) product.
TriGeo SIM is a SIEM appliance that has been purpose-built for companies with 5,000 or fewer employees. It sits in the center of all the other devices on your network and collects logs from these devices. The appliance is able to do log analysis and event correlation in memory, which means the insight from this analysis is as close to real-time events as possible. When a security event is detected, the TriGeo SIM allows for an automated active response that can mitigate an activity that is still in progress.
Here’s an example situation from a TriGeo customer – a small local bank. At 10:00 PM, someone at the closed bank made several failed attempts to login into the network. The TriGeo SIM pieced together the fact there were multiple user login failures, from a single IP address, in a short amount of time, after regular business hours, and alerted the bank’s IT administrator via cell phone. He was able to connect to the network and direct the bank’s security cameras toward the location of the device with the login attempts. There sat the janitor, still trying to gain entry to the network through a desktop PC. The TriGeo SIM sent a command to disconnect the PC from the network, thereby stopping the janitor’s actions before he was able to breach the network.
TriGeo SIM doesn’t require someone to monitor the console all the time. The tool allows you to leverage correlation, automated active response, and notification so you can walk away and get other work done while TriGeo watches your back. This is especially good for smaller companies with IT people who must wear numerous hats. What’s more, the correlation engine puts information into the proper context, and alerts are in plain English, so you don’t need to be a security analyst to understand the security events.
TriGeo SIM ships with over 700 correlations in the box, with more than 100 fully enabled upon installation. Many of the correlations are designed for specific businesses; for example, local banks or credit unions. These correlations are unique to situations that might arise in the financial industry. TriGeo customers even share their own home grown correlation rules through an active user community. There are more than 300 reports out of the box, with templates for all the major regulations like HIPAA, PCI, SOX, GLBA and so on. TriGeo has thoughtfully packaged this product to make it easy to get up and running within just a few hours.
In many smaller companies, one person may have administrative privileges to do just about all the IT tasks. In this case, you might think a miscreant administrator would be able to circumvent TriGeo’s logging and analysis to steal sensitive data or commit other harmful acts. Not so. Even an administrator with privileges cannot manipulate the source logs or make changes to an audit trail. Thus, anything he does within the console is fully audited and reported upon.
One thing that is unique to TriGeo SIEM is that it can work all the way out to the endpoint. This allows you to monitor and act upon activities at the desktop; for example, a user attempting to download sensitive data to a USB thumb drive. TriGeo SIEM can detect such an action while it is happening and disable the USB port without intervention.
You don’t have to be a big company with an extensive network to benefit from a SIEM tool. Every network administrator would like better visibility into what’s happening on his network, along with automated notifications and responses to events. TriGeo SIM can address the specific issues of the mid-market organization without charging an enterprise-level price for the solution.
Linda Musthaler is a Principal Analyst with Essential Solutions Corporation. You can write to her at mailto:LMusthaler@essential-iws.com.
About Essential Solutions Corp: Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.




