Bank-Al-Habib
Bank-Al-Habib is one of the reputed financial organization in Pakistan since 1991. Bank-Al-Habib has a network of 505 branches (inclusive of sub-branches) and offshore banking units in Bahrain, Turkey, and EPZ. After Microsoft brought its Forefront Threat Management Gateway (TMG) to a dead-end in 2012, it was a time for Bank-Al-Habib to find a reasonable alternative of TMG to make sure the protection of their organization remains intact.
After a successful Proof of Concept, the Project was awarded to ISA (COMSTAR).
During the installation of SOPHOS XG Next-Generation Firewall, many tasks were achieved
The Configuration of two SOPHOS XG-650 Appliances in Active-Active mode with Load Balancing, Authentication of Users Via Active Directory, Implementing current profiling setup as maintained by Microsoft TMG. Blocking and restricting malicious URL through Web Profiling and through Single IP Host, blocking websites, blocking web application such as Skype and WhatsApp. Identification of Malicious IPs generating denied traffic, block downloading Zip (Password Protected & Encrypted) files, blocking all the extensions and only allowing file extension such as doc, ppt, pdf, xls. Category wise blocking such as Social Media, Online Storage and etc. Safe Search on Google, Bing, and Yahoo. Integration of Sophos with IBM Qradar SIEM 7.2.4 for Syslog and SSL VPN configuration. Access to some of the internal services that run in Bank-Al-Habib such as Money Gram and LESCO/FTP was achieved.
All the above task was achieved through Network Protection and Web Protection
Pakistan International Airlines
Pakistan International Airlines commonly known as PIA is the national flag carrier of Pakistan. Pakistan International Airlines were using Kaspersky for their endpoint protection but it was lacking in certain features such as User-Based Policies, Malicious Traffic Detection, Data Loss Prevention DLP, Cloud-based management (SaaS), complete synchronization with Microsoft Active Directory and Synchronized security (Endpoint + Network).
We offered our technical services to Pakistan International Airlines and purposed a Sophos Endpoint Protection solution which can integrate a range of innovative technologies to secure their Windows, Mac, and Linux systems against malware and advanced threats such as targeted attacks. Sophos Endpoint Protection includes next-gen features like Malicious Traffic Detection and the Sophos System Protector. By correlating suspicious behaviors with threat intelligence from Sophos Labs, Sophos Endpoint Protection identifies attacks that have never been seen before and protects users from every angle.
Sophos Endpoint Protection has within it a whole bunch of different components or sensors. It’s capable of scanning a file and seeing what its code does before it runs. It has a Host Intrusion Prevention System (HIPS) that looks for bad behaviors as the software is running. And it can detect malicious websites and exploit kits by looking for things like malicious javascript containing exploits.
Pakistan International Airlines chose Sophos Endpoint Protection for securing their 3200 Internet Gateway, servers and workstations altogether. Sophos Endpoint Protection Installation and migration from Kaspersky Antivirus went smoothly without a glitch.
SMI University
SMI University is a university in Karachi, Pakistan. SMIU .Their professional were looking for a solution that can provide best Wi-Fi coverage for more than 1500 Students and Faculty members, also securing their network while not affecting the performance and speed. We proposed a solution for Wi-Fi coverage and best effective security solution which does not compromise performance and speed and it was achievable by SOPHOS. Our design solution was accepted by Sindh Madressatul Islam University.
SOPHOS SG UTM was installed at the campus for achieving the following tasks such as, creating users with reading and write and read-only access, load balancing between multiple uplinks, uplink monitoring and quality of services on uplinks. Network address translation (NAT), static routing, Inter VLAN routing between departments along with DHCP and DNS services which were provided through Sophos. For securing and controlling their web traffic we used web protection for blocking websites, blocking web application such as Facebook application and Snap Chat. Identification of Malicious IPs generating denied traffic, block downloading Zip (Password Protected & Encrypted) files. Category wise blocking such as Social Media, Nudity and etc. also Safe Search on Google, Bing, and Yahoo was enable.
After the installation of Sophos SG UTM, their network is completely secure from different security threats and running efficiently, uninterrupted since today.
Atlas Honda
Atlas Honda (Pakistan) Limited is a joint venture between Honda Motor Company Limited, Japan and the Atlas Group, Pakistan. The company was incorporated on November 4, 1992, and a joint venture agreement was signed on August 5, 1993. The company is listed on Karachi, Lahore and Islamabad Stock Exchanges.
Atlas Honda Pakistan was in search of a solution that can provide best Wi-Fi coverage for their factory located in Karachi, the security was also the biggest concern for Atlas Honda IT team. They wanted to have a solution which can secure their organization vital data traffic while not affecting the performance and speed. We proposed a solution for Wi-Fi coverage and best effective security solution which does not compromise performance and speed and it was achievable by SOPHOS. Our design solution was accepted by Atlas Honda Pakistan.
Atlas Honda Pakistan is very vigilant about their network security and were securing their network with Juniper (Edge Firewall) and Microsoft Forefront Threat Management Gateway. We provide a one box solution Sophos SG UTM for replacing both of these devices. Since
After assessing all the features of SOPHOS UTM it was approved by Atlas Honda and was installed on a gateway mode at their factory for achieving the following tasks such as: creating users with reading and write and read-only access, load balancing between multiple uplinks, uplink monitoring and quality of services on uplinks. Network address translation (NAT), static routing, Inter VLAN routing between departments along with DHCP and DNS services which were provided through Sophos. For securing and controlling their web traffic we used web protection for blocking websites, blocking web application such as Facebook application and Snap Chat. Identification of Malicious IPs generating denied traffic, block downloading Zip (Password Protected & Encrypted) files. Category wise blocking such as Social Media, Nudity and etc. also Safe Search on Google, Bing, and Yahoo was enable.
After the installation of Sophos UTM and replacing Juniper (Edge Firewall) and Microsoft Forefront Threat Management Gateway> their network is completely secure from different security threats and running efficiently, uninterrupted since deployment. Now they planning the same SOPHOS UTM solution for their other factory’s located in Pakistan.
Hilal Foods
Hilal Foods Pvt. Ltd is one of the leading confectionery and food manufacturing companies of Pakistan and exporting to more than 20 countries around the world. Since inception in 1957, Hilal Foods is manufacturing high-quality products with a focus on continuous improvement and Research and Development.
Hilal Foods was running Kaspersky for a long time but now there were looking for a solution that could protect their network against advanced malware and threats. We purposed Sophos Cloud Endpoint Advanced Protection solution to Hilal Foods which could provide these following benefits;
Protects users from new zero-day threats
Provides anti-malware, HIPS, malicious traffic detection and more
Web, application, device and data control for comprehensive policy enforcement
Simple, centralized management
Flexible deployment, with a choice of cloud-based or on-premises management
Optional mobile device management and security
Self-Service Portal: Users can log in to the self-service portal to customize their security status and notifications.
Decloaking Malware: Sophos Endpoint works on the device and in conjunction with the firewall to detect and isolate compromised devices. Synchronized Security gives you additional context providing information from the network.
Behavioral Analytics: Determines suspicious behaviors, allowing for the detection of malware specifically designed to evade traditional solutions.
Integrated Endpoint and Network: Instant and automatic communication between the Endpoint and Network alerts the suspected system of exactly what the firewall is detecting, allowing the endpoint protection agent immediate use of that information to discover the process behind the threat.
Sophos Cloud Endpoint Advanced Protection has within it a whole bunch of different components or sensors. It’s capable of scanning a file and seeing what its code does before it runs. It has a Host Intrusion Prevention System (HIPS) that looks for bad behaviors as the software is running. And it can detect malicious websites and exploit kits by looking for things like malicious javascript containing exploits.
Sophos Cloud Endpoint Advanced Protection is easy to install and manage, with a small footprint, unlike comparable products from competitors such as Kaspersky, Symantec, and McAfee.
Now Hilal Foods is using Sophos Cloud Endpoint Advanced Protection to secure their network devices including Windows, Mac, and Linux systems against malware and advanced threats such as targeted attacks with features like Malicious Traffic Detection and the Sophos System Protector and managing all their products from a single interface.
Provincial Assembly of the Punjab
The Government of Punjab, a provincial government in the federal structure of Pakistan, is based in Lahore, the capital of Punjab Province
Being as an assembly of the biggest province as per population, Punjab assembly network team were very concerned about the robustness of their network security – protection from real-time threats such as malware, ransomware, spyware and different viruses.
We have provided them a one box solution through SOPHOS XG-310 Firewall to secure their network from different network threats that exist today. Through Enterprise guard subscription their network was secured as it covers:-
Intrusion Prevention (IPS)
ATP and Security Heartbeat
Remote Ethernet Device (RED) VPN
Clientless VPN
Web Protection and Control
Application Protection and Control
Web and App Traffic Shaping
After the installation of SOPHOS XG Firewall, their network is completely secure from different security threats and running effectively.
Cedar College Karachi
Cedar College Karachi is an exhilarating new A Level school with an exceptional breadth and depth of curriculum. Located in Karachi, Cedar College is a pioneer in educational innovation and seeks to change the academic experience in its totality.
The services we provided included Wi-Fi solution, Layer 2 and Layer 3 Switching solution and the best solution to secure their network – was achieved by SOPHOS.
During the installation of Sophos SG UTM, many tasks were achieved as, creating users with reading and write and read-only access, load balancing between multiple uplinks, uplink monitoring and quality of services on uplinks. Network address translation (NAT), static routing, Inter VLAN routing between departments along with DHCP and DNS services which were provided through Sophos. For securing and controlling their web traffic we used web protection for blocking websites, blocking web application such as Facebook application and Snap Chat. Identification of Malicious IPs generating denied traffic, block downloading Zip (Password Protected & Encrypted) files. Category wise blocking such as Social Media, Nudity and etc. also Safe Search on Google, Bing, and Yahoo was enable.
All the above task was achieved through Network Services, Network Protection, and Web Protection.
The Urban Unit
The Urban Unit was established in 2006, as a Project Management Unit (PMU) of the Planning and Development Department under the Government of Punjab. In 2012, the company underwent significant transformation and was converted into an independent private sector company.
Network security team of The Urban Unit wanted to secure their network from different threats and also needed to have uninterrupted services for the SSL VPN user of their organization connecting to their head office from different remote locations.
SOPHOS XG-135 firewall with Enterprise guard subscription was able to secure their network from different threats while SOPHOS Clientless VPN has provided them secure SSL VPN as it provides Sophos unique encrypted HTML5 self-service portal with support for RDP, HTTP, HTTPS, SSH, Telnet, and VNC.
After implementing SOPHOS XG-135 firewall on their network it is completely secure from different security threats and running efficiently, and uninterrupted since deployment.