News & Events

2012
  • SUSHIL K NAHAR JOINS PALADION AS SR. VP FOR ITS SECURITY CONSULTING BUSINESS

      BENGALURU, MAY 05, 2012: Paladion, the experts in Information Risk Management, has recently appointed Sushil Kumar Nahar as Sr. Vice President & Business Head for its Consulting Services and Solutions division. Sushil has over 24 years' of rich techno-functional experience in IT Services, Quality Management, Enterprise Systems Management, Governance, Risk & Compliance (GRC) Consulting, ITIL, CMMI and Operational Excellence.

      Sushil will be responsible for accelerating Paladion's Consulting business across the globe and drive Operational Excellence within the organization. His charter is to develop Converged and Collaborative platform for IT Governance & Strategy, Program Management, Enterprise Risk and Regulatory Compliance Management, Data Life Cycle Management, Identify and Access Management, Business Resiliency and IT Operations & Services, in alignment with Paladion's Strategic initiatives. Sushil will lead Paladion's consulting service offerings to deliver value based and customer centric services and solutions across the world.

      'Sushil's insights and experience in the fields of Strategic IT consulting and operational excellence will help Paladion achieve its aggressive growth plans and enhance customer value proposition,' said Rajat Mohanty, CEO, Paladion Networks. 'His addition in Paladion Leadership team will further help us to formulate and execute a winning proposition in the market,' he added.

      Prior to joining Paladion, Sushil was Practice Partner in Wipro Consulting Services and played an integral role in establishing Information Security Consulting practice. 'Paladion is an agile and adaptive organization. There is immense opportunity to take Paladion to accelerated growth and provide customers value proposition through world class Consulting Services and Solutions. My priority is to integrate highly skilled and motivated consulting workforce with Global delivery network to plan, build and execute solutions which are important to customers,' said Sushil.

  • PALADION LAUNCHES APPSEC TOOLS FOR MOBILE ENTHUSIASTS

      BENGALURU, APRIL 19, 2012: Paladion has recently launched Application Security tools for mobile enthusiasts. The tools, 'InsecureBank' and 'Automation Script' has been hosted and are available at free of cost in www.paladion.net.

      Paladion's Vulnerable Andriod application named "InsecureBank" is made for security enthusiasts and developers to learn the android insecurities by testing this vulnerable application. The server component is written in python. Some key vulnerabilities that can be learnt using this application are:

      • Information Sniffing due to Unencrypted Transport medium
      • Sensitive information disclosure via Property Files
      • Sensitive information disclosure via SD card storage
      • Sensitive information disclosure via SQLite DB
      • Sensitive information disclosure via Device and Application Logs

      In addition, Paladion's Mobile Security Team has developed an automation script which is helpful in quick static analysis of Android Vulnerabilities. The script is a batch file, which prompts the user to provide the path of the android application code to be analysed. The script has detection parameters pre-configured in it which run over the android application code. The result is a list of text files - one each for different vulnerability. These text files are the primary source of vulnerability identification. Sometimes it may not directly flag off vulnerability but may act as the pointer from where to start with. This script is very useful in case of bigger applications.

      List of key Checks that that the Script would be testing for:
      • Code to check for presence of HTML Sensitive Information
      • Code to check for insecure usage of SharedPreferences
      • Code to check for possible TapJacking attack
      • Code to check usage of external storage card for storing information
      • Code to check for possible scripting javscript injection

      The tools can be downloaded at: http://www.paladion.net/paladionlabs.html

  • PALADION PARTNERS WITH RECOVERY PLANNER

      UAE, APRIL 17, 2012, Dubai, Paladion Networks, the leading Information Risk Management services and solutions provider in the region, recently partnered with USA based RecoveryPlanner.com, worldleading business continuity, disaster recovery, compliance and emergency management software provider.

      Business Continuity Management and IT Recovery Planning continues to be a top priority for the CXOs in the region. A tried and tested Business Continuity Management Solution like RecoveryPlanner significantly reduces the time required to plan, implement and test a business continuity plan. "We are seeing significant revenue growth in our BCP & IT-DR practices due to increased awareness among the CXOs and operational and compliance pressure from regulators. Our solutions based on the RecoveryPlanner platform are enabling us to reduce operational overheads and implementation timeframes for our customers to a great extent," said Rohit Kumar, Head - Sales & Operation, Middle- East, Paladion.

      Commenting further on the partnership, Dan Delventhal, VP - Business Development, RecoveryPlanner.com said, "Recovery Planner has a unique opportunity to showcase the software capabilities to regional customers, leveraging Paladion's leadership position in Business Continuity and Risk Management Services in the region. We are working on a number of implementations in the region and the customers are highly satisfied with our software backed by Paladion's expertise in Business Continuity Planning".

      Paladion, one of the fastest growing technology companies in Asia, has designed and implemented Business Continuity Management Systems and IT-Disaster Recovery infrastructure for large enterprises in GCC which includes leading banks, financial service providers, retail chains and manufacturing entities. Today Paladion has to its credit, the largest number of customers certified in BS25999, the global standard for benchmarking organization Business Continuity Preparedness.

      "We have implemented RecoveryPlanner to a number of enterprise customers in the region including a multinational bank. Our customers are witnessing up to 80% reduction in manpower requirements and operational expenses for BCM maintenance and are able to establish a tested and fine-tuned disaster response process," said Firosh Ummer, Executive Vice President, GRC services, Paladion Networks. "Further, by leveraging the automation capabilities of Recovery Planner, up to 50% reduction in initial time investment for Business Continuity Planning and implementation can be achieved," he added.

  • PALADION INVITED TO SPEAK AT OWASP APPSEC APAC 2012

      BENGALURU, APRIL 10, 2012: Paladion has been invited to speak at the prestigious OWASP AppSec APAC 2012 conference, scheduled to be held in Sydney from 11-14 April. The topic to be covered by Paladion is on 'Advanced Mobile Application Code Review Techniques'.

      Paladion, the experts in Information Risk Management, has been testing and assessing Mobile Applications for over 4 years now. It has been performing Security Assessments for applications such as Mobile Banking applications, M-Commerce applications, Mobile Payment systems, etc. across platforms. The invitation further establishes Paladion's strength in the mobile application security domain.

      Recently, Paladion has extended its Mobile Application Testing capabilities for all kinds of smartphones and Tablet PCs and across platforms like Android, Apple iOS (iPhone/iPAD), Blackberry, Symbian, Windows Mobile etc.

      The topic 'Advanced Mobile Application Code Review Techniques' will throw light on how Mobile experts blend their techniques in order to accelerate code reviews and will highlight the benefits of blended techniques in comparison with those of simple scanning or manual testing. It will also talk on how to reduce the time taken for review and obtain a ready-to-use checklist.

      Know about OWASP AppSec APAC 2012 conference at https://www.owasp.org/index.php/AppSecAsiaPac2012

      To know more about Paladion Plynt Mobile Application Certification Criteria please visit: http://www.plynt.com/criteria/mobile-application-criteria/

  • PALADION HELPED QIB TO ACHIEVE PCI DSS CERTIFICATION

      QATAR, MARCH 28, 2012, Doha, Bangalore based Paladion Networks, the leading Information Risk Management provider in the region, successfully helped Qatar Islamic Bank to achieve PCI DSS certification. QIB has been recently awarded with PCI DSS standards for its entire range of payment card affiliated services across all its branches and channels (ATM, POS, Internet banking, SMS banking etc). Paladion also assessed QIB core centres and offices where these services were being run from.

      PCI DSS compliance is required by all merchants and service providers that store, process, or transmit cardholder data and applies to all payment channels, including retail, mail/telephone orders, and ecommerce. With this certification, QIB has become the second bank in Qatar to achieve this milestone which clearly distinguishes it from competitors.

      To ensure that its customers receive secured services, QIB has invested ample time and resources and assured a smooth implementation process. Paladion has assisted QIB right from the beginning till the certification was achieved and had taken end-to-end ownership to make QIB PCI DSS compliant.

      However, the road to this success was not easy since QIB has a wide range of services and multiple operating locations. Paladion spent adequate time and effort towards ensuring a comprehensive assessment of each one of them as QIB has invested in a wide range of technologies to provide these services. As part of the assessment, each technology had to be assessed for compliance to PCI DSS since the PCI DSS standard is very comprehensive and covers a wide range of processes, people and technologies. It takes a lot of effort and investments for an entity to comply.

      With its years of experience and expertise and pool of Qualified Security Assessors (QSA), Paladion worked closely with QIB to ensure practical and cost effective solution. "This is possible only because of the years of expertise of providing Information Security related services and a well qualifies work force that we have," said Rajat Mohanty, CEO, Paladion Networks. "These are qualities to reckon with and we find ourselves picking up from where other companies have failed to deliver," he added.

  • PALADION RECEIVES GLOBAL EXCELLENCE AWARD FOR PHISHING INTELLIGENCE REPORT

      BENGALURU, March 5, 2012: Paladion announced today that Info Security Products Guide, the industry's leading information security research and advisory guide, has named Phishing Intelligence Report - H1 2011, a winner of the 2012 Global Excellence Awards in Best Whitepapers, Technology Write-Ups and IT Blogs category. The security industry celebrated its 8th Annual 2012 Global Excellence Awards in San Francisco by honouring excellence in every facet of the industry including products, people behind the successes and best companies.

      More than 50 judges from a broad spectrum of industry voices from around the world participated and their average scores determined the 2012 Global Excellence Awards Finalists and Winners. Winners were announced during the awards dinner and presentation on February 29, 2012 in San Francisco attended by the finalists, judges and industry peers.

      This report on phishing is a reflection of current trends as seen through the eyes of Paladion Security Operations Center (SOC) for the region. The document provides an insight to all phishing attacks that were detected and responded to by Paladion SOC from different perspectives – the current trends in launching attacks, user's response to phishing baits and what Banks can do to minimize phishing related frauds. Paladion's Phishing Intelligence-H1 2011 report was selected as the winner based on the quality of data, clarity of analysis and innovative presentation. It competed with other five finalists shortlisted form over 200 entries including, NCP engineering, Inc. for Debunking the Myths of SSL VPN Security, NETGEAR, Inc. for The Dirty Secret Behind the UTM, Radware for Radware Security Incidents Report, 1H2011 Special Focus: Multi-Layer Attack Threats, Solutionary for Endpoint Security and the iPad, Solutionary for The Advanced Persistent Threat.

      Commenting on the occasion, Vinod Vasudevan, COO, Paladion Networks said, "Info Security Products Guide's recognition of our Phishing Intelligence Report further validates the innovation in our anti-phishing services and the experience that supports it."

  • PALADION WINS 'POSITIVE' RATING IN GARTNER MARKETSCOPE, FOR CONSECUTIVE FOURTH YEAR

      BENGALURU, FEBRUARY 9, 2012: Paladion Networks has once again won a 'Positive Player' rating in the prestigious Gartner MarketScope for Managed Security Services in Asia/Pacific, 201, for consecutively second year in a row. Paladion is one of the seventeen vendors evaluated in the Report. The analysts for this year was Andrew Walls and Rob McMillan.

      It's the fourth consecutive year that Paladion is featured in the prestigious list. In 2008 and 2009, the company was ranked as a 'Promising Player'. In 2010, Paladion moved up the ladder to become a 'Positive Player' and convincingly held its position in 2011 as well.

      Out of 87 vendors for MSS that were contacted by Gartner across the globe, 17 companies from Asia/Pacific region were qualified to participate in the research. In the report Gartner rates Paladion's professional services staff as highly skilled and considers excellent customer support as its strength. Paladion's Managed Security Services include remote, subscription-based monitoring and/or management of firewalls,IDS and IPS, Log collation and analysis, Security governance, Identity management services, Vulnerability scanning and assessment etc. "To be featured in Gartner MarketScope as a Positive player is a significant achievement. And the fact that we have won it for consecutive two years, makes us even more responsible towards our customers,' said Rajat Mohanty, CEO, Paladion Networks.

  • PALADION EXPANDS ITS MSS OPERATION IN SOUTH EAST ASIA (SEA)

      BENGALURU, FEBRUARY 24, 2012: As part of its strategic growth plan and to enhance its presence in the region, Paladion Networks has recently expanded its Managed Security Services (MSS) operation across South East Asia (SEA). The expansion happened both in terms of geography as well as service wise.

      Along with its local partners, Paladion has set up full-fledged operational Security Operation Centres (SOC) in Malaysia, Indonesia and Vietnam to deliver SOC services across the region. In a bid to offer better and more effective threat identification services, Paladion has also upgraded its MSS services for detection of Botnets, Rogue IPs, Trojans and Malware.

      Today more and more threats are happening due to these factors and Advance Persistence Threat has become a global menace. With this advanced detection services Paladion is now all set to provide its customer better protection and business security against APT.

  • PALADION LAUNCHES PLYNT MOBILE APPLICATION CERTIFICATION PROGRAM

      BENGALURU, MARCH 27, 2012: Paladion recently launched "Plynt Mobile Application Certification" Program. The awarding of Plynt Certificate establishes that a web application has adequate measures to guard against remote adversaries and protect against a wide range of threats.

      Paladion, the experts in Information Risk Management, has been testing and assessing Mobile Applications for over 4 years now. It has been performing Security Assessments for applications such as Mobile Banking applications, M-Commerce applications, Mobile Payment systems, etc. across platforms. Recently, Paladion has extended its Mobile Application Testing capabilities for all kinds of smartphones and Tablet PCs and across platforms like Android, Apple iOS (iPhone/iPAD), Blackberry, Symbian, Windows Mobile etc.

      The Mobile Application Security Testing services offered by Paladion are of two types, – Mobile Application Penetration Test and Mobile Application Source Code Review. Paladion also conducts Mobile Application Code Reviews ranging from iPhone Application Code Assessments to Android Coding Assessments. "Paladion Mobile Application Certification Criteria is derived from the rich experience that Paladion has in this domain. It is also standards driven. We have been working with large enterprise customers in enabling secure roll out of their mobile application platforms. Our expertise includes application code assessments for all key platforms including iPhone, Android," said Vinod Vasudevan, COO, Paladion Networks. "Paladion's Mobile Security experts continuously build up their skills and are up to date with the cutting edge research carried out in the Mobile Application Security domain," he added. The team regularly contributes to the security community by publishing their work in various forums and magazines.

  • PALADION WINS INC. INDIA 500 AWARD

      BENGALURU, MARCH 26, 2012: Paladion Networks has recently won the Inc. India 500 award. Promoted by Inc. India, the Indian edition of Inc., the leading US magazine focusing on entrepreneurship and growth, the listing consists of India's 500 fastest growing mid-size enterprises.

      The rankings are based on the "Net sales CAGR" of last 4 years and certain subjective parameters like Digital Presence, Leadership Credibility etc. As part of its process, Inc. India uses some of trusted database sources like Capital Line and CMIE to get authentic information about the companies.

      3,500 companies across 35 sectors, one each for public listed and privately held companies, had participated this year. The final Inc. India 500 consists of 200 listed companies, 200 unlisted public companies and 100 privately held businesses.

      "We are honoured to be recognized amongst the fastest-growing companies in the country. Our continued focus and dedicated effort for securing information assets of our customer has enabled this growth," said Rajat Mohanty, CEO, Paladion Networks. "I would like to acknowledge and thank all our customers on this occasion for their trust in Paladion. And this recognition gives us further impetus to enhance our value to customers," he added further.

2011
  • PALADION WINS DELOITTE FAST 50 AWARD, FOR CONSECUTIVE SIXTH YEAR

      Bengaluru, November 23, 2011: Paladion Networks has once again won the prestigious Deloitte Fast 50 India 2011 award, sixth year in a row. With a growth of 102%, Paladion is ranked 34th this year. It's a unique distinction to be recognized amongst the fastest growing companies in India for consecutive 6 years, a feat achieved by no other company so far in the history of Deloitte Fast 50 India program, which recently announced the winners for its seventh edition.

      The Deloitte Technology Fast 50 India program annually recognizes the 50 fastest-growing technology companies in India, based on percentage revenue growth over the last three financial years. The program has been instituted by Deloitte Touche Tohmatsu India Private Limited (DTTIPL). The award has become a benchmark in the industry.

      Commenting on the occasion, Rajat Mohanty, CEO, Paladion Networks said, "I appreciate and extend my sincere gratitude to all our customers and partners for their unprecedented support, without which this wouldn't have been possible."

      Such assessment and selection of companies by DTTIPL helps technology companies establish credibility in the global community, reach out to the businesses and customers with more conviction and further the revenue growth.

  • VERITY WINS SILICON INDIA '10 MOST PROMISING COOL PRODUCTS' AWARDS

      Bengaluru, August 25, 2011: Verity, Paladion's advanced website malware protection product has been awarded as one of the "10 Most Promising Cool Products" for 2011. The evaluation was carried out by Silicon India, the premier technology magazine in India.

      Verity is one of Paladion's leading edge offering that provides full assurance to the user's customer safety while browsing websites. Verity is designed to effectively thwart malware threats. An advanced malware protection system, Verity monitors websites for embedded malware content and application level changes that can potentially harm end-user's computers.

      As an added advantage it also offers manual verification of alerts that are generated to take corrective measures to contain impact. Many of the largest Banks and ecommerce sites have been using verity to gain better customer confidence. Verity has been developed internally by Paladion's product development team and has 24x7 online and onsite support infrastructure for its clients.

  • PHISHING THREATS IN INDIA DOUBLES DURING THE FIRST HALF OF 2011

      Bengaluru, August 11, 2011: Paladion Labs, the research innovation engine within Paladion, today released its report on 'Phishing Threat Intelligence' for H1 2011. This report on phishing is a reflection of current trends as seen through the eyes of Paladion Security Operations Center (SOC) for the region.

      "Though financially motivated attacks continue to grow unabated across the globe, Phishing attacks targeting banks and other financial organizations have seen a slight decline in the global scenario. But the same doesn't hold true for India and to an extent ME, the first half of this year has witnessed an alarming increase in number of phishing threats arising from sophisticated attacks and branded as Advanced Persistent Threats" said Vinod Vasudevan, COO & Co-Founder, Paladion Networks. "This document provides an insight to all phishing attacks that were detected and responded to by Paladion SOC from different perspectives – the current trends in launching attacks, user's response to phishing baits and what Banks can do to minimize phishing related frauds," he informed.

      Based on the insights gained through analysis of phishing attacks, it is clear that the traditional approach of phishing site detection and take down cannot be the only solution. Financial institutions are in the process of rolling out controls that incorporates stronger authentication, better transaction monitoring and more innovative processes in the backend to contain the impact of phishing attacks.

      Some Key Findings of the Report
      • The United States continues to host the highest number of phishing attacks
      • Average life of phishing site varied from 5-19 hours
      • Phishers most active during the holiday season
      • Nearly 80% of phishing sites get less than 10 victims

  • PALADION INVITED TO SPEAK AT THE PRESTIGIOUS HP PROTECT 2011

      Bengaluru, August 12, 2011: Paladion Networks has been invited to present a paper on fraud risks in Banks in the forthcoming HP Protect 2011 event, to be held in Washington D.C. between 11-14 September.

      The session, 'New Age Risks in Banking: Beat the Fraud' will primarily focus on how banks in Asia and the Middle East have customized ArcSight ESM to detect advanced cyber attacks from hacker syndicates. It will also highlight the best practices for developing custom connectors for banking applications and how to build rules and reports that enables early detection.

      Paladion will be represented by Vinod Vasudevan, COO & Co-Founder. Vinod co-founded Paladion and has 16 years of experience in technology and information risk management. He assists banks and financial institutions in designing and implementation their security strategies. Vinod is the lead author of two books, including Application Security in the ISO 27001 Environment. He regularly represents in leading global forums on information security.

      "HP Protect" is one of the most prestigious events to be associated with. It is one of the best platforms where Paladion can interact with information security stakeholders from across the world," said Vinod. "We are very excited and looking forward towards the event," he concluded.

      Protect 2011 is the single largest summit of security and compliance professionals, experts, architects and gurus under one roof. Now in its seventh year and with 1,500 participants, Protect 2011 is bigger than ever and revved up with new, exciting information and networking opportunities. This year's conference is supercharged by ArcSight, TippingPoint and Fortify.

  • PHISHING TREND ON THE RISE IN OMAN

      ABU DHABI, June 03, 2011: Muscat, Oman, Due to the development of the ICT sector, cyber security incidents in Oman is on the rise over the last few years. There have been more than 20,000 attempted cyber attacks in 2010 in Oman, and the figures have already crossed 2,000 in the first quarter of 2011.

      Considering the spike of cyber crimes increasing in the country, Paladion has documented the dominating phishing trends in Oman in order to provide all ICT stakeholders a clear picture to fight the menace. Prepared through expert evaluation & region specific experience in global phishing trends, Paladion SOC team has given a snapshot of the trends seen from 2010 till date in the Sultanate of Oman as well as entire Middle East.

      The data shows, for the year 2010, although some banks in ME experienced phishing attacks, banks in Oman were not targetted. Whereas, the picture for 2011 is exact shows banks in Oman have experienced a big jump in attacks [from 5 for the whole year of 2010 to 35 in less than 5 months]. NBO has been targetted in most of these attacks. The bank's counterparts in the country have not been targetted similarly.

      In the graph below, the monthly incident count for each of these regions is shown. Across all the regions, we have seen a jump in the number of attacks in the months of April and May. This trend is seen in Oman, and these attacks seem to be targetting only NBO.

      Talking on the objective of the report, Suveer Kalra, President & Head, Global Sales & Marketing, Paladion Networks said, "ME has been a very important region for us and we are continuously dedicated to support the countries belonging to this region towards fighting technology frauds and cyber crimes. As part of our efforts we have prepared this report to highlight the current trends in phishing attcks in ME and Oman and help our customers to deal with the threats."

  • PALADION HELPED QNB TO ACHIEVE BS 25999 CERTIFICATION

      QATAR, SEPTEMBER 9, 2011, Doha, Bangalore based Paladion Networks, the leading Information Risk Management Provider in the region, helped Qatar National Bank to achieve BS 25999 certification successfully. QNB has been recently awarded with BS 25999 standards for Business Continuity Management (BCM) practice for its entire Qatar operations.

      BS 25999-2:2007 standard is a globally accepted standard for the Business Continuity Management System (BCMS) developed as a British Standard by the BSI and accredited by the United Kingdom Accreditation Service (UKAS). Having successfully cleared the certification audit, QNB was awarded the certificate recently by Jaspal Panesar, Deputy Director, Trade & Investment, British Embassy, Qatar.

      The certification will benefit QNB's customers who can be assured that the bank has the capability to continue operations even in case of a disaster. It will also provide additional international credibility for the bank as it continues its strategic international growth.

      Paladion has been helping large corporate globally to manage their information risks efficiently, cost-effectively and successfully for over a decade. It is the fastest growing information security company in Asia (as ranked in Deloitte Technology Fast 500 Asia Pacific 2006, 2007, 2008, 2009 & 2010). With a global footprint across 15 countries and decade of experience in the information security domain, Paladion today is actively managing security for over 600 customers. It provides security assurance, compliance, governance, monitoring and management services to large and medium sized organizations.

      Please visit www.paladion.net for more information.

  • FRAUD PROOFING YOUR BANKING OPERATION

      Bengaluru, Jan 20, 2011 - Despite continuing efforts and investments by banks to mitigate financial risks, fraud is evidently a growing problem. The recent fraud incident at a leading MNC bank's branch, reportedly committed by a relationship manager confirms that it's time we stop waiting for a whistle-blower to raise the alarm and instead, go for an automated process to detect frauds instantly.

      While every related stakeholders are busy in their own ways to find out the lapses in the systems and procedures, the poor customers only concern is, "How safe is to keep my money in the Bank…as this can happen in any Bank?" Unfortunately, nobody seems to be discussing on the imperative need for the Banks to have a holistic Fraud Risk Management solution in place.

      Keeping pace with the need of the Industry, Paladion Networks, the largest pure-play Information Security Company in Asia pacific has introduced a more comprehensive and 'organization-wide' version of "Banking Fraud Risk Management" and is offering both professional services and solution deployment in this space. In the solution space Paladion has partnered with many analyst recommended global solution providers in financial crime, Risk and Compliance.

      Before discussing about the typical functionalities that a holistic fraud risk management system should have, it is important to know about the expectations of the customer. A customer will always expect that the Bank should stop or challenge online transactions which have fraudulent patterns and proactively inform them about any anomaly in their transaction behaviors.

      It is also important to inform them about current threats and safety measures that need to be taken by the customers and in case a fraud happens, help them quickly find out the culprit. The HNI customer in any Bank would definitely appreciate if they are informed regularly about the anomaly in their transaction profile.

      An integrated system in a Bank to detect anomalies in transaction behavior profile of an employee would definitely help in preventing perpetration of in-house frauds. In case a fraud happens, such systems should also correlate the employee's action with the fraud and find out the nexus.

      Essentially, a holistic Fraud Risk Management solution take s care of fraud risks within the enterprise rather than in a channel and must have the following important functionalities.

      • The capability to maintain a single profile of the user across all channels and detect fraud emanating from any channel
      • Ability to correlate different actions which can lead to a fraud scenarios and then alert.
      • The capability of multidimensional profiling i.e. profiling any entity viz customer, POS, ATM, Branch, Dealer, Relationship Manager, Loans, treasuries etc on the basis of certain statistical parameters
      • The ability to de risk the transaction before it is committed. This tantamount to real/near real time detection and prevention
      • A hybrid approach that includes rule, anomaly detection and predictive modeling for fraud detection
      • The ability to integrate with existing authentication systems, thus enabling Risk based authentication
      • Modular Implementation
      • Robust work flow and Case Management system for Investigation and Enterprise view
      • Ease of integration with the Core Banking Application
      • Efficient response time (say 10 ms)
  • PALADION LAUNCHES ALL-IN-ONE CYBERCAFÉ MONITORING DEVICE

      BANGALORE,JANUARY 11: Interception and monitoring of network traffic in a cybercafé is occasionally required by law enforcement agencies. However enabling such monitoring of traffic is usually difficult as it requires either reconfiguration of the cybercafé network or putting in network taps and multiple hardware/ software in the cybercafé.

      Paladion has launched a unique product, iCybermon, to address these challenges of cybercafé monitoring. With innovative technologies, Paladion has integrated all features of interception, network configuration, pacaket analysis and reporting in a single low price hardware device. The device can work at line speed and capture high bandwidth traffic in cybercafé. It can be installed in few minutes into any cybercafé network by law enforcement personnel without any skills on networking or interception technologies. This highly portable and leightweight device can be carried without suspicious to locations that require monitoring.

      Once installed the iCybermon system can capture all packets and silently monitor for suspicious traffic. . It can analyse various protocols and reconstruct user sessions. It is capable of decoding and reconstruct WLAN Internet traffic in real time such as Email (POP3, SMTP, IMAP), Webmail (Gmail, Yahoo Mail, Windows Live Hotmail etc.), Instant Messaging/Chat (MSN/Windows Live Messenger, Yahoo Messenger, IRC, ICQ, QQ, UT Chat Room, Google Talk), FTP, P2P, TELNET, HTTP (URL, Content, Download/Upload) etc. It can also decrypt SSL traffic if installed in MITM configuration.

      The system sends the analysed and filtered data to remote servers of law enforcement agencies. Their personnel can view the data remotely as well as update configuration and filter criteria remotely without any need for physical access. The system is built for high availability and reliability and has encrypted storage to prevent any authorized access.

      iCybermon is the most effective solution in market today to monitor suspicious activities in cybercafé environment in cost effective and transparent manner for law enforcement agencies.

  • PALADION ASSISTS DUBAI CUSTOMS BECOME THE FIRST CUSTOMS ADMINISTRATION IN THE WORLD TO ACHIEVE ISO 27001 CERTIFICATION

      Sharjah, UAE, March 2nd, 2011: Dubai Customs (www.dxbcustoms.gov.ae), yet again makes a historical achievement of becoming the world's first customs administration to be certified for ISO 27001. Dubai Customs is also considered to be the first Govt. department to achieve the standard on such a wide scale. This unique feat was enabled by Paladion Networks, a leading Information security provider.

      The 2nd largest revenue generating customs administration in the world - Dubai Customs, has more than 3000 employees spread across 21 locations. The certificate covered all the internal departments and customs centers. This streamlining of processes will facilitate smoother functioning, skilful management and enhanced customer relations for the Govt. body.

      In order to reinforce its information security culture and provide safe business procedure for their customers, Dubai Customs needed to comply with 133 controls of the ISO 27001 standard. The compliance includes stored E-information, information exchanged via IT methods, and also provides guidelines for the different customs practices including the hardcopies of data and information at all the departments and customs centers. This achievement clearly demonstrates the commitment of Dubai Customs towards adopting new tools and technologies for business enhancement and customer gratification. In Paladion they found an able partner with profound expertise in implementing the security and compliance. Incidentally, Paladion is also a certified QSA (Qualified Security Assessor) and ASV (Approved Scanning Vendor) for the PCI-DSS standards.

  • GENERAL CIVIL AVIATION AUTHORITY (GCAA) FRIST TO ACHIEVE INTEGRATED MANAGEMENT SYSTEM CERTIFICATION

      DUBAI, April, 2011: GCAA (www.gcaa.ae), has a new historical achievement of being the first aviation authority in the world to achieve Integrated Management System certification under the prestigious ISO 27001 and ISO 20000 Standards. This achievement has to be credited to GCAA's focus in adopting and implementing best practices related to the business systems to ensure safety of Civil Aviation in U.A.E.

      Headquartered in Abu Dhabi, GCAA, rated "Category 1" by U.S. Department of Transportation's Federal Aviation Administration, is also one of the most technologically advanced organization of its kind. Achieving ISO 27001 and ISO 20000 certifications as an Integrated Management System is a proof of GCAA's commitment towards achieving its strategic vision of secure civil aviation while encouraging industrialization and profitability in the field. Integrated Management System certification based on ISO 27001 & 20000 will ensure streamlined processes, better management and safer air travel.

      An Integrated Management System provides unified framework to manage operations in adherence to multiple global standards, increasing efficiency and removing redundancies amongst the standards. By harmonizing the requirements of security and quality of service delivery under ISO 27001 and ISO 20000, GCAA will simply the documentation, audits, management reviews that are required for certification maintenance. And it will also help in bringing sharper focus to the goals of security and service management as envisaged in the dual standards.

  • PALADION'S MANAGEISMS RECEIVES NETWORK PRODUCTS GUIDE 2011 PRODUCT INNOVATION AWARD

      BANGALORE, May, 2011: Paladion announced today that Network Products Guide, industry's leading information technology research and advisory guide has named ManageISMS a winner of the 2011 Product Innovation Awards. This annually venerated award recognizes and honours vendors, large and small, from all over the world with innovative and ground-breaking products that are bringing essential and incremental changes and are setting the bar higher for others in all areas of information technology.

      ManageISMS is a web based product to establish and maintain ISO 27001 in a hassle free easy manner. This unique tool automates the entire lifecycle of ISO 27001 certification. It reduces time, effort and cost through its centralized management approach of all ISO 27001 activities including risk assessment risk treatment audit and compliance. To read more about this product innovation,

      please visit

      www.networkproductsguide.com or www.paladiononline.com  
2010
  • OMANTEL BECOMES THE FIRST TELECOM COMPANY IN GCC TO HAVE THEIR MPLS CORE SERVICE CERTIFIED TO ISO 27001 STANDARDS

      MUSCAT, JANUARY 10, 2010: Muscat, Oman, Oman Telecommunications Company "Omantel", (MSM: OTEL), the Sultanate's telecom giant and one of the top listed companies on the Muscat Securities Market, today has the distinguished achievement of being the first telecommunication company in GCC to have their MPLS Core services certified under the internationally renowned ISO 27001 Standards. ISO 27001 is an international standard for protecting the confidentiality, integrity and availability of data. This achievement is credited to OMANTEL's focus in adopting and implementing global standards and best practices to ensure effectiveness, efficiency, confidentiality and integrity of data transmitted through its MPLS infrastructure.

      The ISMS was developed and implemented by Omantel in partnership with Fireware, the leading IT Security organisation in Oman and Paladion Networks, Globally acclaimed Information Risk Management Firm. The certification was awarded by TUV SUD, one of the leading certification bodies.

      MPLS provides an integrated network that can simultaneously handle multiple types of network traffic including voice, data and video. The ISMS at Omantel is designed and implemented to protect customer data and to ensure MPLS service availability, thereby meeting operational objectives and customer commitments.

      The project was initiated by meticulous and careful planning by Omantel and Paladion -Fireware beginning with, the MPLS system study and risk assessment followed by risk treatment plan, developing security policies and procedures, training and implementation of these policies. The above activities were thoroughly scrutinized by TUV SUD as external auditors spread across two stage audit.

      While speaking on the occasion, the CEO of Omantel, Dr. Amer bin Awadh Al-Rawas explained, "We are glad to announce that we are the first telecommunication company in GCC to achieve the ISO 27001 standard for MPLS service. This would help us demonstrate the commitment of OMANTEL in providing the reliable and secure services to our customers.

      Mr. Mohammed Issa Al Zadjali, Chairman of Fireware LLC said, The ISO 27001 certification achieved, is a step forward in showing Omantel's vision and commitment in implementing & managing the best security practices. Omantel's ISO 27001 Certification will provide assurance regarding the management focus on securing critical and sensitive information assets of the organization, to all its stakeholders".

      Mr. Mohammed Moqueet ur Rab, Manager-Information security at Omantel who was instrumental in the successful delivery with the IT team at Omantel added "Paladion brought in their global experience and award winning process models to make this challenging certification process an easy one for us. We have been able to accomplish the 27001 certification in less than 5 months time with the assistance of the Paladion & Fireware. The ISMS framework designed was Paladion's unique approach and methodology and the certification for MPLS core service involved multiple departments spread across entire Oman, which in itself is a noteworthy achievement".

      Adding on to this, Mr. Firosh Ummer, Executive Vice President, GRC services, Paladion Networks said "With this ISO 27001 certification, Omantel would be able to counter various threat levels linked to their MPLS setup and would tremendously improve the rate of response & preparedness of their team."

  • PALADION LAUNCHES WORLD'S SMALLEST WIFI INTERCEPTOR WITH ADVANCED FEATURES

      BANGALORE,JANUARY 11: In the Milipol 2010 at Qatar, Paladion unveils iWLAN interceptor, the latest in its portfolio of interception devices. iWLAN interceptor (iWLAN) is the world's smallest Wifi interception device with comprehensive features for forensic investigation by law enforcement agencies. This handheld device with 7 inch screen has fully built-in wifi interception software and accessories and requires no additional equipment. Being extremely lightweight and small, it can be easily and secretly carried by forensic professional to any place that requires wifi monitoring. Forensic professionals can avoid any notice while carrying this handheld, which is designed as a PDA/ mobile phone.

      On this occasion, Rajat Mohanty- CEO Paladion said, "After two years of development, we are proud to introduce the iWLAN, a pathbreaking miniature wifi interceptor ideal for covert operations by law enforcement agencies. It helps them in their drive to prevent crime and gather intelligence on unlawful activities."

      iWLAN has capability to capture multiple channels for 802.11 a/b/g with full packet capture and decoding functionality. It can analyse various protocols and reconstruct user sessions. The system provides for an intuitive and touch screen enabled GUI for viewing of the data and for operating the software. It is capable of decoding and reconstruct WLAN Internet traffic in real time such as Email (POP3, SMTP, IMAP), Webmail (Gmail, Yahoo Mail, Windows Live Hotmail etc.), Instant Messaging/Chat (MSN/Windows Live Messenger, Yahoo Messenger, IRC, ICQ, QQ, UT Chat Room, Google Talk), FTP, P2P, TELNET, HTTP (URL, Content, Download/Upload) etc. iWLAN can decrypt WEP encryption and auto detect various wireless access points. The system also stores the original raw data along with analysed and reconstructed data. The stored data can be searched using free text search and Boolean operations. It has features for easy portability of data and for taking backup.

      iWLAN is the most reliable solution in market today to monitor illegal Wireless LAN Internet activities or transactions in most secret manner for law enforcement agencies.

  • PALADION RATED POSITIVE IN GARTNER'S MARKETSCOPE FOR ASIA/ PACIFIC
      p>BANGALORE,OCTOBER 10: Paladion today announced that the company has been included in Gartner's "MarketScope for Managed Security Services in the Asia/Pacific Region". Paladion is one of 17 vendors evaluated on the report. It is the third consecutive year that Paladion is featured in the prestigious list, but this time they have moved up in stature in rating as a "Positive" player in the category. Earlier in 2008 & 2009 Paladion was featured as a "promising" player. Paladion's elevation in rating was after meticulous evaluation by Gartner on customer experience, product/ offer innovation and financial viability among other parameters.

      In the report Gartner rates Paladion's professional services staff as highly skilled and considers excellent customer support as its strength. Paladion's Managed Security Services include remote, subscription-based monitoring and/or management of firewalls,IDS and IPS, Log collation and analysis, Security governance, Identity management services, Vulnerability scanning and assessment etc.

      Paladion's MSS is backed by a strong professional service practice focused on security risk assessment and management. Paladion offers remote management and monitoring, as well as a co-sourced approach, with Paladion staff stationed at customer sites, working with customer staff.

      "Positive rating in Gartner's MarketScope 2010 is a significant achievement." Said Mr RajatMohanty, CEO of Paladion Networks. He attributed this achievement to Paladion's focus on outstanding customer services and continuous product innovation.

  • RELIANCE GROUP CISO JOINS BANGALORE BASED INFORMATION SECURITY COMPANY, PALADION

      BANGALORE, May, 2010: Durga Prasad Dube, former Chief Information Security Officer (CISO) of Reliance Group, has joined specialised information security provider, Paladion Networks as Executive Director Mr Dube would commence his new tenure from 18th of May 2010. He has played a pivotal role in developing and maintaining a strong and resilient Information security framework for Reliance, a conglomerate comprising of various businesses having different IT maturity levels and diverse regulatory and compliance requirements.

      Mr Dube will head Paladion's new strategic initiative of Banking Risk Management. This new business unit is an endeavour to cover the banking risks in its entirety by aligning conventional IT risk practises with business processes and objectives. His wide experience spanning over two decades in senior positions in RBI (www.rbi.org.in), IDRBT (www.idrbt.ac.in), Wipro (www.wipro.com) and Reliance (www.ril.com) would come handy in this new and challenging assignment.

      "Dube's insight and experience with information and cyber security is unmatched in the banking industry," said Rajat Mohanty, Paladion's CEO, in a written statement. "Our banking customers have expressed increased level of interest in holistic IT security to address business risks, and we are thrilled to have Mr. Durga Prasad Dube in the Paladion Leadership team to help us understand, formulate and execute a winning proposition within this market."

  • PALADION ASSISTS DUBAI CUSTOMS BECOME THE FIRST CUSTOMS ADMINISTRATION IN THE WORLD TO ACHIEVE ISO 27001 CERTIFICATION
      p>Sharjah, UAE, March 2nd, 2010: Dubai Customs (www.dxbcustoms.gov.ae), yet again makes a historical achievement of becoming the world's first customs administration to be certified for ISO 27001. Dubai Customs is also considered to be the first Govt. department to achieve the standard on such a wide scale. This unique feat was enabled by Paladion Networks, a leading Information security provider.

      The 2nd largest revenue generating customs administration in the world - Dubai Customs, has more than 3000 employees spread across 21 locations. The certificate covered all the internal departments and customs centers. This streamlining of processes will facilitate smoother functioning, skilful management and enhanced customer relations for the Govt. body.

      In order to reinforce its information security culture and provide safe business procedure for their customers, Dubai Customs needed to comply with 133 controls of the ISO 27001 standard. The compliance includes stored E-information, information exchanged via IT methods, and also provides guidelines for the different customs practices including the hardcopies of data and information at all the departments and customs centers. This achievement clearly demonstrates the commitment of Dubai Customs towards adopting new tools and technologies for business enhancement and customer gratification. In Paladion they found an able partner with profound expertise in implementing the security and compliance. Incidentally, Paladion is also a certified QSA (Qualified Security Assessor) and ASV (Approved Scanning Vendor) for the PCI-DSS standards.

  • GENERAL CIVIL AVIATION AUTHORITY (GCAA) FRIST TO ACHIEVE INTEGRATED MANAGEMENT SYSTEM CERTIFICATION

      DUBAI, April, 2010: GCAA (www.gcaa.ae), has a new historical achievement of being the first aviation authority in the world to achieve Integrated Management System certification under the prestigious ISO 27001 and ISO 20000 Standards. This achievement has to be credited to GCAA's focus in adopting and implementing best practices related to the business systems to ensure safety of Civil Aviation in U.A.E.

      Headquartered in Abu Dhabi, GCAA, rated "Category 1" by U.S. Department of Transportation's Federal Aviation Administration, is also one of the most technologically advanced organization of its kind. Achieving ISO 27001 and ISO 20000 certifications as an Integrated Management System is a proof of GCAA's commitment towards achieving its strategic vision of secure civil aviation while encouraging industrialization and profitability in the field. Integrated Management System certification based on ISO 27001 & 20000 will ensure streamlined processes, better management and safer air travel.

      An Integrated Management System provides unified framework to manage operations in adherence to multiple global standards, increasing efficiency and removing redundancies amongst the standards. By harmonizing the requirements of security and quality of service delivery under ISO 27001 and ISO 20000, GCAA will simply the documentation, audits, management reviews that are required for certification maintenance. And it will also help in bringing sharper focus to the goals of security and service management as envisaged in the dual standards.

2009
  • DELOITTE FAST 50 INDIA FEATURES PALADION 5 YEARS IN A ROW

      Deloitte ranked Paladion as the 19th on the Deloitte Technology Fast 50 India 2009, a ranking of the 50 fastest growing technology companies in India. Paladion has been featured in Deloitte for the 5th consecutive year. The rankings are based on the percentage of revenue growth over three years. Paladion grew a phenomenal 261% during this period.

      Paladion's CEO, Rajat Mohanty credits many factors, including quality services and strong customer focus for the company's 261% revenue growth over the past three years. He said, "We are honored to announce that this is the fourth consecutive year we have been featured in this esteemed list. Over the past four years, Paladion has consistently climbed up the ladder by gaining recognition by various prestigious organizations such as Red Herring and Asian Banker for its quality services. Deloitte Technology Fast 50 India is a list of the fastest growing technology companies in India and Paladion feels privileged to be a part of it."

      Paladion was also a winner in the Deloitte Technology Fast 50 program in the years 2006, 2007, and 2008.