Earthwave is offering a service to build and deliver a security operations center in under a year Earthwave, a managed security services provider, is pioneering a much faster way for large companies and service providers to create a security operations center that meets a high standard for security.It’s called SOC-in-a-Box, a product Earthwave began offering after helping companies on a piecemeal basis build security operations centers, said Carlo Minassian, who founded the Sydney-based company 12 years ago and is its CEO.Financial services, telecommunication operators and government agencies all need extensive monitoring of their networks as hackers seek to steal data and disrupt operations. SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe That monitoring requires installing a security information and event management (SIEM) product, which tries to pick out anomalies in network traffic. It also requires physically building a SOC, meeting a variety of industry and government standards as well as hiring the right people to run it. Perhaps not surprisingly, many projects failed or ran way over budget, Minassian said. “We saw this consistently happening especially in the last four or five years. As the SIEM market is heating up, more and more people are buying it, and we are seeing more and more failed projects.”Earthwave decided to start offering a SOC as a complete package. Companies typically can spend three to five years building, certifying and staffing a SOC on their own built from scratch, but Earthwave has cut that time down to a year, Minassian said. Clients can use whatever technology they want, with Earthwave making sure it works right, or even contract with Earthwave to run it. Earthwave builds to specifications such as Information Technology Infrastructure Library (ITIL), ISO/IEC 27001, the payment card industry’s PCI/DSS, the Australia Security Intelligence Organisation’s T4 physical security standard and Australia’s Defence Signals Directorate’s “Highly Protected” classification, among others. Since Earthwave has already obtained the various certifications, its customers know their SOCs will pass as well, Minassian said.Two SOCs run by Earthwave for its customers have bulletproof glass, wire meshing in concrete slabs and special cabinets for servers to prevent unauthorized access. Separate air conditioning ducts separate from the main building serve the SOC to prevent intruders from gaining access. Armed guards will respond to an incident in the centers in under 15 minutes.On the software side, Earthwave uses ArcSight, now owned by HP, for security event monitoring. Earthwave’s developers have built a customized portal that collates information from the various security products employed by its clients. It also has developed its own intellectual property built around ArcSight in the form of 400 information “feeds” which detect certain defined security risks. One scenario a feed would detect is if a person is physically at work but is logging onto a sensitive company system from somewhere else, Minassian said. Minassian also spearheaded the Threat Intelligence Alliance, a program started five years ago that collects information on Internet threats from other vendors, such as URL blacklists and botnet command-and-control servers. That intelligence is incorporated into its network monitoring systems.About half of Earthwave’s clients are Australian government agencies, with the others in areas such as financial services and telecommunications. For example, Earthwave is responsible for network monitoring for about 95 percent of the critical infrastructure used for delivering clean water and energy in the state of New South Wales, Minassian said. So far Earthwave’s managed services are focused solely on Australia due to data-handling requirements dictated by the security specifications it builds to, Minassian said. But the company has done consulting for other large companies outside of Australia.Earthwave’s business has come into its own as of late, but its early days were hard: Minassian, an ethnic Armenian who immigrated to Australia from Iran in 1985, said he worked for free for years as it struggled to stay in business. Now, it has changed: He said last year he rebuffed more than a dozen acquisition offers from defense companies, venture capital firms and other vendors.He won’t sell — yet. “I’m having too much fun,” Minassian said.Send news tips and comments to jeremy_kirk@idg.com Related content feature Mastercard preps for the post-quantum cybersecurity threat A cryptographically relevant quantum computer will put everyday online transactions at risk. Mastercard is preparing for such an eventuality — today. By Poornima Apte Sep 22, 2023 6 mins CIO 100 CIO 100 CIO 100 feature 9 famous analytics and AI disasters Insights from data and machine learning algorithms can be invaluable, but mistakes can cost you reputation, revenue, or even lives. These high-profile analytics and AI blunders illustrate what can go wrong. By Thor Olavsrud Sep 22, 2023 13 mins Technology Industry Generative AI Machine Learning feature Top 15 data management platforms available today Data management platforms (DMPs) help organizations collect and manage data from a wide array of sources — and are becoming increasingly important for customer-centric sales and marketing campaigns. By Peter Wayner Sep 22, 2023 10 mins Marketing Software Data Management opinion Four questions for a casino InfoSec director By Beth Kormanik Sep 21, 2023 3 mins Media and Entertainment Industry Events Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe