Strengthen Microsoft Office 365 with Sophos Cloud and Reflexion Many organizations are embracing cloud technology and moving from complex, rigid on-premise infrastructure and software to the simplicity and flexibility of a Microsoft Office 365 environment. Of course, one of the main barriers to cloud adoption is concern over security. Microsoft does provide robust security for customer data held within its Office 365 services in the cloud. However, this security doesn t extend outside of the Office 365 environment to help you protect your users, workstations, servers, or mobile data. Microsoft Office 365 doesn t provide solutions such as a secure web gateway to protect and control your end users internet access or a firewall to secure your organization s perimeter.
Still, the attraction of Office 365 is clear. Why set up your own Exchange Server or manage and maintain Microsoft Office software when Microsoft can take care of all of that for you? Certain Office 365 plans include Exchange Online, and moving email infrastructure from on-premise to Exchange Online can certainly help you manage the costs of your environment. At first glance, moving to Exchange Online will also appear to simplify your email setup. Many of the technologies you ve been using for years to support your email infrastructure on-premise, such as security, archiving, and continuity, now appear to be included in Office 365. However, in your conventional on-premise network you supplemented your Microsoft infrastructure with solutions from vendors such as Sophos and Reflexion to reduce the risks of security threats, support your compliance objectives, and guard against email outages. In your new cloud and Office 365 world, many of the risks you originally planned to eliminate with your on-premise security, archiving, and continuity remain. Sophos Cloud provides integrated security for endpoint, mobile, and web, offering you the perfect complement to Office 365. Sophos recently announced that it has acquired Reflexion Networks, a leader in cloud-based email security, archiving, email encryption, and business continuity services. Together, Sophos and Reflexion deliver enterprisegrade security in an affordable and simple-to-manage combination that helps you effectively mitigate these risks in Microsoft Office 365. What is Microsoft Office 365? Microsoft Office 365 is a cloud-based set of subscription software and service products. Depending on the package chosen, it includes Microsoft Office applications such as Word and Excel along with Exchange Online-hosted email services, Skype for Business, and other business applications. What data security features are included in Microsoft Office 365? Microsoft Office 365 uses a range of security technologies including anti-malware and encryption techniques to protect customer data within the Microsoft Office 365 environment. Exchange Online uses anti-spam and anti-malware engines to filter customer email for spam and viruses. Does Microsoft Office 365 provide a complete security solution? Microsoft provides robust security for customer data held in its Office 365 services in the cloud. However, it does not secure an organization s users, workstations, servers, or mobile data. Microsoft Office 365 does not provide a secure web gateway to protect and control end-user internet access or a firewall to secure the organization perimeter. Exchange Online filters mail for spam and viruses but lacks critical archiving and continuity features you may have deployed on-premise. A Sophos Whitepaper September 2015 2
How can Sophos Cloud help customers achieve a complete security solution for their Microsoft Office 365 environment? Sophos Cloud does for end user, server, mobile, and web security what Office 365 does for business applications. It allows you to deliver and manage your security via the cloud. The alternative, traditional approach of on-premise management requires you to build and maintain infrastructure to manage security across your environment. Now, with the acquisition of Reflexion Networks, Sophos complements your Office 365 deployment with cloud-based email security, archiving, email encryption, and business continuity services. What is Sophos Cloud? Sophos Cloud is the only unified solution that integrates endpoint protection for both Windows and Mac, while providing server lockdown, a secure web gateway, and mobile device management. Designed to give you an intuitive user experience, Sophos Cloud is simple to deploy, manage, and maintain. And since we host the management console in the cloud there is no need to install a management server, so you ll be up and running in minutes. Windows, Mac, and mobile device security in a single, integrated console. User-centric approach to pricing, policy, and reporting. Server protection that secures your IT infrastructure. Enterprise-grade secure web gateway for advanced web protection and reporting. Proven Protection Technology Sophos Cloud is based on the same proven technology that protects over 100 million devices worldwide. Security policies follow the user across devices, platforms, and locations. Stop malware with multiple layers of protection: web exploit detection, malicious traffic detection, HIPS, buffer overflow protection, and more. Reduce your attack surface by monitoring or restricting access to removable devices. Keep protection current with automatic updates and real-time lookups of suspicious files over any internet connection. A Sophos Whitepaper September 2015 3
Enterprise-Grade Secure Web Gateway The web is one of the most common infection vectors for organizations. Sophos Cloud Web Gateway protects your users with our enterprise-grade, secure web gateway. Enjoy unmatched security, visibility, and control for all your PCs, Macs, and mobile devices, no matter how or where they access the web. Advanced web protection from the latest zero-day threats. Global protection through an extensive network of enforcement data centers. Simple but powerful policy controls for websites and apps. Extensive analytics and reporting powered by the cloud. High-Performance Server Protection Sophos Cloud is the only solution offering cloud-managed server protection integrated with advanced anti-malware, HIPS, and server application whitelisting/lockdown. By simply clicking a button, you can lock down your servers in a safe state. Sophos Cloud automatically recognizes your server applications and adapts the configurations and management settings. Server application whitelisting with one-click lockdown. Server Authority automatically establishes and manages trusted changes. Integrated, advanced anti-malware, HIPS, and whitelisting. Automatically adapts to the server environments with scan exclusions. Simple Mobile Device Management Mobile device management in Sophos Cloud enables mobility for your users, keeping them productive and your corporate data secure while on the move. Reduces the risk of data breaches with remote wipe and anti-theft technologies. Enforces compliance with corporate policy: Sets password requirements, prohibits jailbreaking, and controls access to corporate email. Easily manages device inventory and policy from the same console you use for your workstations. A Sophos Whitepaper September 2015 4
Intuitive Cloud Management Sophos Cloud lets you manage security simply and effectively using an integrated, cloud-based management console. Gain clear visibility into all of your users devices and their protection status. Deploy user-based policies that follow your users throughout all of their devices. Get started immediately, with no training required; built-in best practices provide effective security settings by default. Sync with Active Directory for quick deployment and ongoing user and group management. Advanced Email Security, Archiving, and Continuity from Reflexion Networks And now, with the acquisition of Reflexion Networks, you can add cloud-based email security, archiving, email encryption, and business continuity services to your Sophos Cloud solutions. Reflexion works both standalone and in conjunction with Sophos Cloud. Eventually, Reflexion will be fully integrated into Sophos Cloud to create a unified solution for end user, server, mobile, web, and email security in a single cloud-managed console. Diagram: How Sophos Cloud secures your business and complements your Office 365 deployment A Sophos Whitepaper September 2015 5
What Is Reflexion? Reflexion is a range of enterprise-grade cloud-based email security, archiving, email encryption, and business continuity services. They re easy to implement, contain unique features, and are a great value. The services are: Reflexion Email Continuity Services Reflexion Archiving, Discovery, and Recovery Reflexion Total Control Email Security Reflexion Email Encryption Services How do Reflexion s services complement your Microsoft Office 365 services? 1. Reflexion Email Continuity Services Email has become a critical business application in most organizations. Organizations with on-premise Exchange invest in redundant infrastructure to ensure email availability. Microsoft Office 365 has redundant infrastructure; however, it is all part of one Microsoft solution that becomes a single point of failure for your messaging environment should it experience an outage. Reflexion Email Continuity Services provides cloud-level redundancy to ensure email continuity in Office 365 environments. When Office 365 suffers an email outage, users can log in to a webmail interface that can be used to send and receive email in real time, ensuring that business can continue as normal. 2. Reflexion Archiving, Discovery, and Recovery Again, on-premise, organizations invest in security and backup systems to protect against data loss, corruption, and malicious activity. With Office 365 alone, you lose an independent, verifiable copy or backup of your data and the ability to restore it in the case of data loss. Reflexion Archiving, Discovery, and Recovery (RADAR) provides a completely independent copy of your data that can be queried and searched, providing a truly compliant archive that avoids the loopholes that can lead to the accidental or malicious deletion of email. Examples of these loopholes include: Office 365 email is archived on a schedule, opening the door for a user to delete messages in the period between receipt and the scheduled push to the archive. If you delete an O365 mailbox, the archive is also deleted. Important functions must be configured manually; for instance, legal hold. Users are allowed to log in and delete archived email. A Microsoft service upgrade could damage data. On discovery, there is no way of verifying the data or recovering it. Microsoft will pay for the damage in terms of their SLA, but this may not compensate for the data that has been damaged. A Sophos Whitepaper September 2015 6
Reflexion Archiving, Discovery, and Recovery is fully integrated into Reflexion Total Control (RTC). It seamlessly stores all email historical, internal, new, inbound, and outbound. There are no setup or ingestion fees, and RADAR offers unlimited storage and unlimited historical data, with the option to apply a monthly retention policy: for instance, 7 years and 2 months. Additionally, if a user accidentally deletes a message and empties the Deleted Items folder, RADAR can recover individual messages, an entire mailbox, or the entire archive in a few clicks. 3. Reflexion Total Control (RTC) Email Security Reflexion is an ideal solution for protecting Office 365 email from spam and malware. Because it is also delivered and managed via the cloud, there s nothing to install or maintain. Reflexion also provides a number of unique features. Reflexion RTC provides the configurability that end users need, from making decisions on which senders to whitelist or blacklist, with granular spam controls (flag, quarantine, vaporize, etc.). There s subject filtering, and filtering via permitted languages and countries for those hard-to-detect spam problems. RTC also provides an in-message control panel that can reduce spam-related support tickets by more than 90 percent. The control panel enables end users to simply click a link to block future incoming messages from a particular sender or domain. 4. Reflexion Email Encryption Services While Office 365 offers business-class email and cloud-hosted applications, it simply doesn t offer effective email encryption. The cumbersome setup, painful login process, and inconvenient mobile interface provide an inadequate email encryption experience for your users. The most complicated and costly aspect of email encryption is key management. With Reflexion it s easy; all key management is automated through the industry s largest email encryption directory. This global community connects your organization to tens of millions of members, and this increases by approximately 100,000 members per week. The global directory safeguards against expired keys and certificates by providing centralized distribution among all members. You ll get the industry s only bi-directional transparent email encryption. When one Reflexion encryption user sends encrypted email to another Reflexion encryption customer, the message is sent and received transparently no passwords and no extra steps are required for the sender or recipient. With transparent email encryption, employees spend less time tinkering with security and more time doing work that really matters. Reflexion removes the hassle and frustration of secure email. No other solution is this easy. A Sophos Whitepaper September 2015 7
Microsoft Office 365 with Sophos Cloud and Reflexion Summary Microsoft Office 365 provides your users with the freedom to work in the office or on the go. It offers you the freedom to run your entire email infrastructure in the Microsoft cloud. While this is attractive, moving to Office 365 does not solve all your security challenges. Businesses must consider some of the risks that remain after migrating to Office 365. With Office 365, businesses need complementary security services to ensure their environment remains secure and available. Sophos Cloud achieves for end user, server, mobile, and web security what Office 365 offers for business applications providing effective Sophos security with cloud simplicity. Now, Sophos and Reflexion together deliver enterprise-grade cloud security in one affordable and simple-to-manage solution to help you mitigate these risks in your Microsoft Office 365 environment. Learn more about Sophos Cloud Contact Pugh today 01974 200 201 sales@pugh.co.uk More than 100 million users in 150 countries rely on Sophos as the best protection against complex threats and data loss. Sophos is committed to providing complete security solutions that are simple to deploy, manage, and use that deliver the industry's lowest total cost of ownership. Sophos offers award winning encryption, endpoint security, web, email, mobile, server and network security backed by SophosLabs a global network of threat intelligence centers. Read more at www.sophos.com/products. United Kingdom and Worldwide Sales Tel: +44 (0)8447 671131 Email: sales@sophos.com North American Sales Toll Free: 1-866-866-2802 Email: nasales@sophos.com Oxford, UK Boston, USA Copyright 2015. Sophos Ltd. All rights reserved. Registered in England and Wales No. 2096520, The Pentagon, Abingdon Science Park, Abingdon, OX14 3YP, UK Sophos is the registered trademark of Sophos Ltd. All other product and company names mentioned are trademarks or registered trademarks of their respective owners. 2015-07-30 WP-NA (MP) Australia and New Zealand Sales Tel: +61 2 9409 9100 Email: sales@sophos.com.au Asia Sales Tel: +65 62244168 Email: salesasia@sophos.com