Cybersecurity Solutions features explained
for IT and Infrastructure
Every feature we track for Cybersecurity Solutions products, with a description of what each one means.
Access Control & Identity Management
Mechanisms for ensuring only authorized individuals and devices can access sensitive systems and data.
- API Security
- Applies security controls to APIs used by internal and third-party services.
- Access Audit Logs
- Full logging of all authentication and authorization events.
- Adaptive Authentication
- Adjusts authentication requirements based on risk factors (location, device, etc).
- Directory Integration
- Seamless integration with Active Directory, LDAP, or similar directory services.
- Multi-Factor Authentication (MFA)
- Requires multiple forms of verification before granting access.
- OAuth2/OpenID Support
- Supports modern federated authentication protocols.
- Privileged Access Management (PAM)
- Manages and monitors access of users with elevated privileges.
- Role-Based Access Control (RBAC)
- Restricts system access based on users' roles within the organization.
- Self-Service Password Reset
- Allows users to securely reset their passwords without administrator intervention.
- Single Sign-On (SSO)
- Allows users to authenticate once for access to multiple systems.
- User Enrollment Speed
- Average time to enroll a new user into the security system.
Cloud Security
Protects brokerage assets, data, and applications hosted on public, private, and hybrid clouds.
- API Security Controls
- Secures APIs between cloud, on-prem, and third-party integrations.
- Cloud Access Security Broker (CASB)
- Monitors and secures the use of cloud services.
- Cloud Encryption Support
- Ensures data is encrypted in all cloud environments.
- Cloud Security Posture Management (CSPM)
- Automates risk and compliance management for cloud environments.
- Cloud Workload Protection
- Secures applications and services running in the cloud.
- Configuration Drift Detection
- Monitors changes in cloud security settings.
- Identity and Access Management (IAM) Integration
- Integrates cloud security controls with user identity systems.
- Log Integration with SIEM
- Ensures cloud platform logs flow into enterprise SIEM.
- Malware Scanning for Cloud Storage
- Detects and blocks malicious files in cloud storage.
- Secure Cloud Backup
- Ensures cloud backups are protected and encrypted.
- User Activity Monitoring
- Audits and reports on user actions in the cloud.
Compliance & Regulatory Support
Helps brokerage firms achieve and maintain compliance with applicable laws, regulations, and security frameworks.
- Audit Log Integrity
- Ensures audit logs are tamper-proof and verifiable.
- Automated Compliance Audits
- Automates checks against regulatory requirements (e.g., GDPR, FINRA, SEC, SOX).
- Automated Evidence Collection
- Gathers and stores evidence required for audits.
- Compliance Gap Analysis
- Detects missing controls or processes relative to compliance requirements.
- Customizable Reporting
- Reports can be tailored for specific regulations or business management.
- Data Privacy Controls
- Implements technical controls to protect personally identifiable information.
- Incident Response Documentation
- Captures standard documentation to demonstrate incident response procedures.
- Number of Supported Frameworks
- Number of industry or regulatory frameworks directly supported out of the box.
- Preconfigured Policy Templates
- Provides templates for standard industry policies and controls.
- Risk Assessment Tools
- Enables regular assessment and documentation of information security risk.
- Role-Based Compliance Tracking
- Tracks compliance status for specific users and departments.
Data Security & Encryption
Mechanisms to protect stored and transmitted data within brokerage IT environments.
- Cloud Encryption Integration
- Supports encryption for data stored in public and private clouds.
- Data Loss Prevention (DLP)
- Prevents unauthorized sharing or transfer of sensitive information.
- Data Retention Policy Support
- Implements automated policies for retaining and deleting sensitive data.
- Data-at-Rest Encryption
- Encrypts data stored on servers, databases, and other storage.
- Data-in-Transit Encryption
- Ensures encryption of data moving between systems.
- Database Activity Monitoring
- Audits and alerts on suspicious database activities.
- Encrypted Backup
- Ensures backups are encrypted to protect against data breaches.
- File Integrity Monitoring
- Detects unauthorized changes to critical files.
- Granular Access Controls
- Allows fine-grained control over access to specific files and datasets.
- Key Management
- Secure generation, storage, and rotation of encryption keys.
- Tokenization
- Replaces sensitive data with non-sensitive equivalents during processing.
Endpoint Protection
Security measures implemented on computers, mobile devices, and servers to protect against malware, unauthorized access, and other threats.
- Antivirus/Antimalware
- Detects and removes malicious software.
- Application Control
- Restricts which applications can be run on endpoints.
- Automated Response Actions
- Performs predefined security actions upon threat detection.
- BYOD Support
- Supports protection for employee-owned devices.
- Behavioral Analysis
- Detects threats by analyzing abnormal endpoint behaviors.
- Centralized Management Console
- Unified interface for managing endpoint security policies and incidents.
- Device Control
- Controls access to removable devices (USB, external drives, etc).
- Device Encryption
- Encrypts data stored on endpoint devices.
- Endpoint Detection and Response (EDR)
- Provides advanced monitoring, detection, and analysis of endpoint threats.
- Number of Supported Endpoints
- Maximum number of devices supported under a single deployment.
- Patch Management
- Automates deployment of security updates to devices.
- Remote Wipe Capability
- Allows remote erasure of lost or stolen devices.
Incident Response & Forensics
Capabilities for detecting, investigating, and responding to security incidents in real time.
- Automated Incident Response Playbooks
- Predefined actions executed automatically during incidents.
- Chain of Custody Tracking
- Tracks all access and handling of digital evidence.
- Collaboration Tools
- Facilitates coordinated response among security teams.
- Compliance Integration
- Assures response actions comply with legal/regulatory requirements.
- Forensic Data Collection
- Captures data required for in-depth investigations.
- Incident Timeline Generation
- Automatically builds a chronological timeline of incident events.
- Post-Incident Reporting
- Comprehensive summaries of incident and response actions.
- Response Time (Median)
- Median time taken to respond to an incident.
- Retrospective Detection
- Analyzes past data for previously missed indicators of compromise.
- Root Cause Analysis
- Ability to determine the source and method of compromise.
- Threat Containment
- Isolates affected systems to prevent threat spread.
Network Security
Tools and mechanisms designed to protect internal and external networks from unauthorized access and threats.
- Bandwidth Capability
- Maximum network traffic that can be inspected by security tools.
- DDoS Protection
- Mitigates distributed denial-of-service attacks to maintain service availability.
- Firewall Protection
- Prevents unauthorized access to or from a private network.
- Intrusion Detection System (IDS)
- Monitors network traffic for suspicious activity and known threats.
- Intrusion Prevention System (IPS)
- Proactively blocks detected threats in real time based on established rules.
- Network Segmentation
- Segments networks to limit lateral movement of threats.
- Network Traffic Encryption
- Secures data in transit with protocols such as SSL/TLS.
- Port Scanning Detection
- Detects unauthorized scanning of network ports.
- Real-Time Monitoring
- Active monitoring of network traffic for quick incident response.
- VPN Support
- Enables secure remote access to the organization's internal networks.
- Zero Trust Network Access
- Applies a 'never trust, always verify' policy to all devices and users.
SIEM & Log Management
Security Information and Event Management (SIEM) platforms gather, correlate, and analyze log data from across the brokerage IT environment.
- Anomaly Detection
- Detects abnormal log patterns indicating security issues.
- Automated Alerting
- Triggers alerts when suspicious events are detected.
- Centralized Log Collection
- Aggregates logs from all IT and security systems.
- Compliance Reporting
- Predefined reports to meet regulatory needs.
- Customizable Dashboards
- Configurable dashboards for monitoring and visualization.
- Forensic Investigation Tools
- Supports detailed analysis of historical security incidents.
- Incident Response Integration
- Triggers and tracks incident response activities from within SIEM.
- Log Ingestion Rate
- Maximum amount of log data the SIEM can process per second.
- Log Source Support
- Number of device/application types supported for log integration.
- Long-Term Log Retention
- Stores logs for regulatory and forensic requirements.
- Real-Time Correlation
- Correlates events across multiple sources in real time.
Threat Intelligence & Analysis
Capabilities for gathering, analyzing, and acting upon threat intelligence relevant to the financial sector.
- Advanced Persistent Threat (APT) Detection
- Recognizes highly sophisticated long-term attacks.
- Anomaly Detection Engine
- Identifies unusual patterns indicative of emerging threats.
- Automated Incident Scoring
- Provides risk scoring of detected incidents to prioritize response.
- Automated Threat Detection
- Identifies and flags threats using advanced analytics and AI.
- Machine Learning Integration
- Uses machine learning models to improve detection and analysis.
- Malware Sandbox
- Isolates and analyzes suspicious files and scripts.
- Phishing Detection
- Identifies and blocks phishing attempts targeting users and systems.
- Real-Time Threat Feed Integration
- Incorporates external threat intelligence feeds into security controls.
- Threat Intelligence Sharing
- Supports sharing threat data with peer institutions and industry groups.
- Threat Research Portal
- Provides portal access to latest threat intelligence and research.
- Volume of Threat Indicators Processed
- Maximum number of threat indicators processed by the system per day.
Usability & Integration
Ensures security solutions are user-friendly and can integrate with existing IT systems in a brokerage environment.
- API Integration
- Supports integration with trading platforms, order management, and other IT systems.
- Custom Reporting
- Enables the creation of customizable reports for management and compliance.
- Customizable Alerts
- Fine-tune alerts to reduce noise and highlight critical issues.
- Deployment Flexibility
- Available as on-premises, cloud, or hybrid deployment.
- Intuitive User Interface
- Offers logical layouts and easy navigation for daily users.
- Multi-Language Support
- User interface and documentation available in multiple languages.
- Onboarding Time
- Typical time required to deploy and fully onboard the solution.
- Role-Based Dashboards
- Dashboards tailored for various user roles (admin, compliance, technical support, etc).
- Scalability
- Ability to support expansion in number of users or systems.
- Support for Automation
- Enables automation of routine tasks and workflows.
- Third-Party Integration Support
- Ability to integrate with external security tools or business applications.
Vulnerability Management
Processes for identifying, prioritizing, and remediating vulnerabilities in brokerage IT systems.
- Asset Discovery
- Identifies all devices and software within the brokerage's environment.
- Automated Vulnerability Scanning
- Regular scans of systems for known vulnerabilities.
- Criticality Scoring
- Rates vulnerabilities by impact and exploitability.
- External Attack Surface Monitoring
- Scans public-facing infrastructure for exposure risks.
- Frequency of Scans
- How often automated scans are performed.
- Integration with Ticketing Systems
- Connects vulnerability management with IT service desk systems.
- Patch Management Integration
- Links vulnerability discovery to patch management workflows.
- Remediation Tracking
- Tracks status and progress of vulnerability fixes.
- Reporting and Alerts
- Provides detailed reports and real-time alerts on vulnerabilities.
- Web Application Scanning
- Identifies vulnerabilities in web applications and portals.
- Zero-Day Vulnerability Detection
- Detects previously unknown (zero-day) vulnerabilities.