Speak to an expert : Live Chat exa online chat

Knowledge HubTMeducation

Protecting Our Customers’ Cyber Security

The NCSC and their international partners have recently published an advisory on state-sanctioned Russian cybercriminals’ targeting of UK networks and their equipment.

In light of this, we’d like to outline the steps we take to keep customers safe and secure.

Cybersecurity is a game of cat and mouse between systems operators and threat actors. Identifying risks ahead of attackers and resolving them promptly is the key to staying secure. Our processes aren’t a reaction to the news; they’ve been in place for months and have processed hundreds of potential threats in that time.

Identifying risks

To protect our infrastructure and customers, Exa monitors security advisories and performs regular vulnerability scanning of not only our own network but also our clients’.

Our systems automatically process and triage the findings, providing us with a view of what’s changed and actionable data to follow up on. This includes information like the IPs, ports and protocols associated with the risk, CVE identifiers and CVSS scores, and an audit trail of when the issues first/last appeared.

When the device at risk is one of our managed devices, we’ll also look at changes you’ve requested via our firewall management requests system. We maintain a robust history of requests and changes, which allows us to build a full view of the issue over time.

Resolving issues

If your network has appeared in our reporting, we’ll get in contact with you to relay all the information you need to determine the next steps.

For our managed service customers, this process is as easy as possible. Exa will propose a mitigation and a date that we’ll make the change alongside our vulnerability report. From that point, there are three outcomes:

  • If you agree with our mitigation plans, we’ll fix the issue right away.

  • If you have a specific use case in mind, want to accept the risk, or believe it’s a false positive, we’ll record your response and act accordingly.

  • If we don’t hear back from you before our proposed date, we will implement the fix on your behalf. This is done in order to ensure the safety of your organisation.

You’ll always be kept in the loop with any changes we make and are happy to discuss or answer any questions you might have throughout the process. Any updates will be recorded alongside our vulnerability data for future reference.

Secure by design

Processes

Keeping customers safe is a core part of our mission. We organise ourselves so the secure outcome is the default – security that depends on siloed, uphill effort is incidental and prone to fail. Exa holds Cyber Essentials and ISO 27001 certification; the standard’s principles are built into all of our policies and we undergo regular auditing by an external body to ensure compliance.

Our firewall change and vulnerability reporting workflows are geared towards this:

  • Recording requests for firewall changes in a structured and automated way means they’re consistent and auditable by default, and not just because someone remembered to record the details. We’ll double-check requests that we judge to be potentially dangerous.

  • Every member of our customer operations team is trained on this process, ensuring new issues are addressed quickly and without dependence on any given member of staff. Each stage of the process can be actioned by a different person, ensuring we don’t have blindspots or delays.

  • Automatic remediation ensures that the default action we take is the safe one.

Our vulnerability reporting protects our own infrastructure as well. We designed the process to work for anyone’s infrastructure, regardless of whether it’s owned by Exa or our customers. Not distinguishing between owners means any improvement we make automatically reaches everyone covered by the process.

ExaCube

So far we’ve discussed finding cybersecurity issues after they appear. Better still is for them never to appear in the first place. As well as our processes, we integrate “secure by default” principles into everything we build – most recently, ExaCube. The hacking campaign discussed in the NCSC‘s advisory is opportunistic. Cybercriminals are going after low-hanging fruit like lax firewall rules, weak passwords and vulnerable out-of-date software versions. ExaCube is designed around the opposite.

In addition to firewall rules customers have requested, we maintain our own stringent list of firewall rules required to secure and ensure proper functioning of an ExaCube. Almost nothing is accessible by default, and where ports are open, access is restricted to a specific subset of IP addresses inside our network.

ExaCubes don’t permit any form of internet-facing password authentication. When we provision a device, our automated setup tools disable password-based remote sign-in entirely and require public-key authentication in its place – so there are no passwords that could be guessed or brute-forced.

We have designed a bespoke fleet management system that allows us to continually monitor and upgrade ExaCubes and the software running on them. Software updates and security fixes are proactively applied, keeping your device secure over time – and before it appears in a vulnerability report.

Beyond hardware security, SurfProtect customers benefit from automatic blocking of dangerous malware-related domains, powered by NCSC PDNS and over 20 years of web filtering expertise. This includes Evolution and Evolution+, which are available on ExaCube and perform content filtering directly on the device.

We’re here to help

If you’ve received one of our vulnerability notifications and aren’t sure what it means, or you simply have a question about how we keep your equipment safe, our support team is always happy to help. You can contact us via 0345 145 1234 or helpdesk@exa.net.uk.

Suggested Next Read

draytek Vigor 2862 router

Related Knowledge Hub™ Articles

ISPA Testing

The Exa Foundation

Contact us

Sales

Sales

Office hours

Monday: 8:30am – 5pm
Tuesday: 8:30am – 5pm
Wednesday: 8:30am – 5pm
Thursday: 8:30am – 5pm
Friday: 8:30am – 5pm
Saturday: Closed
Sunday: Closed

Technical Support

Contact us

Email: helpdesk@exa.net.uk
Phone: 0345 145 1234

Office hours

Monday: 8am – 6pm
Tuesday: 8am – 6pm
Wednesday: 8am – 6pm
Thursday: 8am – 6pm
Friday: 8am – 6pm
Saturday: 10am – 4pm
Sunday: 10am – 4pm