GuidePoint Security Placed on CRN MSP 500 List for Excellence in Managed IT Services

GuidePoint Security recently made their debut on CRN’s elite 2017 Managed Service Provider 500 (MSP) list in the Managed Security 100 category.

The prestigious annual list is comprised of organizations that have demonstrated excellence in their Managed IT services and North American solution providers with cutting-edge approaches to delivering managed services. Their offerings help companies navigate the complex and ever-changing landscape of IT, improve operational efficiencies, and maximize their return on IT investments.

“GuidePoint’s vSOC Managed Security Services have experienced tremendous growth over the past two years and our inclusion on this list validates that the market is taking notice,” noted Justin Morehouse, GuidePoint Security’s Co-founder and Principal.

“We pride ourselves on our World Class customer satisfaction rating and believe that we are truly advancing the industry through our innovative approach to partnering with our customers to achieve their mission,” Morehouse said.

He cited GuidePoint’s exclusive managed services, Virtual Security Operations Center (vSOC) as one the best examples of the team’s coordinated efforts to level the playing field in terms of providing a customized solution that fits all budgets and organizational sizes, while identifying threats and vulnerabilities and creating a safer cyber environment.

“Managed service providers play an increasingly important role in the day-to-day operations of businesses across North America,” said Robert Faletra, CEO of The Channel Company. “MSPs help organizations streamline their spending, effectively allocate limited resources, and benefit from advanced expertise in the latest technologies. We congratulate the service providers on CRN’s 2017 MSP500 list, who have continually succeeded in meeting their customers’ changing needs and help them get the most out of their IT investments.”

CRN’s MSP 500 list shines a light on the most forward-thinking and innovative of these key organizations.

The list is divided into three categories: the MSP Pioneer 250, recognizing companies with business models weighted toward managed services and largely focused on the SMB market; the MSP Elite 150, recognizing large, data center-focused MSPs with a strong mix of on-premise and off-premise services; and the Managed Security 100, recognizing MSPs focused primarily on off-premise, cloud-based security services.

CRN® is a brand of The Channel Company.

The MSP500 list is featured in the February 2017 issue of CRN and online at

©2017. The Channel Company, LLC. CRN is a registered trademark of The Channel Company, LLC. All rights reserved.

GuidePoint Security showcases vSOC technology at RSA 2017

Forward thinking security professionals recognize that the current progression and magnitude of cyber threats is insurmountable for the understaffed security industry to effectively tackle.

There is, however, a solution.

Join GuidePoint Security for an informative Virtual Security Operations Center (vSOC) presentation at RSA 2017. During the vSOC presentation, you’ll learn about how GuidePoint’s managed security services can assist you with identifying threats and vulnerabilities through detection, response, and recovering from validated incidents.

Presentation Location: CrowdStrike Booth #2345, South Hall
Presentation Days/Times: Tuesday, 12:30 p.m. and Wednesday and Thursday, 11:30 a.m.

GuidePoint Security’s vSOC analysts and incident responders, supported by CrowdStrike Falcon Host, offer best-in-breed endpoint protection. Together, they offer one of the most comprehensive around-the-clock endpoint and security monitoring solutions on the market – all with the efficiency and scalability of cloud-based security management.

GuidePoint’s vSOC ingests Falcon Host platform data into the vSOC Detect monitoring platform, powered by Splunk. By monitoring endpoints and correlating endpoint data against other security-related information, vSOC analysts actively hunt for and discover new and emerging threats.

If you can’t make the presentation in the exhibit hall, our team will offer free, private demonstrations of our vSOC. All you have to do is sign up, and a GuidePoint representative will be in touch to set up a time to meet with you during the RSA Conference. Register now for your exclusive vSOC demo.

Not attending RSA or don’t have time to visit with us? You can register for our webinar, Stay Ahead of Adversaries Using Next-Gen Endpoint Security, on March 9th.

GuidePoint’s Expertise Supports Your Organization’s GSA HACS Contract Needs

Imagine this: Your network is compromised with outbound connections sending data to foreign countries, and your information security team has no idea.

That’s exactly what GuidePoint Security’s analysts and incident responders discovered while actively cyber hunting for a new client in our Virtual Security Operations Center (vSOC).

Our professionals discovered open connections to more than 30 foreign countries, even though the client had no foreign interests or customers. Using Splunk’s Enterprise Security application, our team put its geolocation capabilities to work and created a map to illustrate all the foreign locations that successfully received this data.

When we alerted the client to the connections, we used the map to show the extent of the compromise. The client agreed to implement egress rules on its firewalls to limit destinations for data transfers, as well as country-blocking technologies in its perimeter security appliances to deny connections to foreign countries. By working with GuidePoint, the client narrowed the scope of who has access to its enterprise network and improved its overall security posture.

This real-world example of cyber hunting for data exfiltration is one of the many ways GuidePoint can support your organization with your General Services Administration (GSA) Highly Adaptive Cybersecurity Services (HACS) contract needs.

GSA recently awarded GuidePoint all four HACS Special Items Numbers (SINs), including, 132-45C: Cyber Hunt. The others SINs include: 132-45A: Penetration Testing; 132-45B: Incident Response; and 132-45D: Risk and Vulnerability Assessment.

With these SINs, GuidePoint’s subject matter experts can help your organization with all of your information security needs. As a federal or state/local government client, your organization will have:

  • Access to pool of technically evaluated cybersecurity vendors
  • Rapid ordering and deployment of services
  • Reduction in open market ordering and contract duplication
  • Cybersecurity/acquisition support resources from GSA

For more information about how GuidePoint has helped clients, download the full text of our SINs Use Cases.

For additional information and pricing on our IT professional and cybersecurity services, visit

Automation Tools Help with Real-Time Incident Response and Protection

Free webinar: Real-world examples of how to keep your environment secure from attacks, accelerate remediation

If you’re an information security professional responsible for incident response, you may feel frustrated and overburdened by all the manual processes needed to keep your environment safe.

You’re not alone.

In a recent Enterprise Strategy Group survey, more than 60 percent of information technology professionals say their organization has taken steps to automate incident response, but 91 percent say those processes are not effective or efficient.

Did you know there are resources and tools available to help facilitate some of these key processes for your organization? GuidePoint Security’s Virtual Security Operations Center (vSOC) analysts and incident responders have real-world experience using these types of tools. One such tool, Carbon Black, helps power GuidePoint’s vSOC enabling analysts and responders to hunt for incidents in real time, visualize the complete attack kill chain, and efficiently defend environments from attacks.

Here are some examples of how they have successfully used Carbon Black to stop incidents and monitor endpoints:

PowerShell Watchlist

Recently, GuidePoint analysts used Carbon Black to create a PowerShell watchlist for an unauthorized user attempt. Once alerted, analysts tracked down a malicious remote address and shut down unauthorized privileges on the host.

Environment audits

In another instance, vSOC analysts used Carbon Black to audit an environment to limit privilege account credentials. The audit alerted analysts to a possible vulnerability that could have allowed unrestricted access to a domain.

PUA/PUP activity

vSOC analysts recently used Carbon Black to create a custom watchlist for PUA/PUP activity. They found an instance that stood out from others and located an unapproved IE toolbar, which was loaded without approval on multiple workstations. The toolbar was isolated as a threat because it had the ability to monitor web-browsing behaviors.

Would you like to know more about these real-world incident response examples and how you can move from playing incident response catch-up to proactively hunting for threats?

Join GuidePoint and Carbon Black for a free, interactive webinar, “Conquering Challenges of Incident Response: Real-Time Hunting and Response,” at 2:30 p.m. Thursday, Nov. 17. The session will last about 45 minutes, with a chance to interact with the presenters, Stephen Jones, GuidePoint’s director of managed services, and Justin Scarpaci, technical solutions lead, Carbon Black.

Register online here.

About the presenters

Stephen Jones has more than 10 years of experience in information technology and cyber security. He specializes in security operations and has extensive experience working within the Department of Defense and the Intelligence Community.

Justin Scarpaci is a technical account manager on the Partner Success team at Carbon Black. In that role, he assists IR/MSSP partners with operationalizing Carbon Black as part of their service offerings. Justin served in the Marine Corps and has worked in multiple security roles for a defense contractor. He has a master’s degree in information security and forensics.

Can’t make the webinar? No worries. Go ahead and register now and we will send you a recording after the live presentation.

About GuidePoint Security

Headquartered in Herndon, Virginia, GuidePoint Security provides innovative and valuable cyber security solutions and expertise that enable organizations to successfully achieve their mission. By embracing new technologies, GuidePoint Security helps clients recognize the threats, understand the solutions, and mitigate the risks present in their evolving IT environments. Headquartered in Herndon, Virginia, GuidePoint Security is a small business, and classification is with the System for Award Management (SAM). Learn more at:

The Cyber Hunt Is On: Quickly Find New and Emerging Threats

Free webinar explains how you can respond to intrusions faster

Do your security analysts have limited time and resources? Are they bogged down searching through logs instead of actively hunting for potential intrusions on your network?

In a free webinar, “Active Cyber Hunting Revealed: How vSOC Identifies Threats in Your Environment,” security experts from GuidePoint Security and CrowdStrike will show you how you can more efficiently correlate data and begin your own cyber hunt for potential threats to your environment.

This free, educational webinar begins at  2 p.m. EDT Wednesday, Aug. 24, 2016. Register here now.

During the webinar, participants will learn how CrowdStrike Falcon can be integrated into a Virtual Security Operations Center (vSOC) for endpoint monitoring. By using Falcon Connect API to ingest host data into the vSOC monitoring platform, analysts can correlate endpoint data against SIEM security logs. The combination makes it easier to discover new and emerging threats.

Participants will learn how to do ad-hoc searches and queries, quickly conduct comprehensive investigations, identify insider threat activity, and create dashboards and reports.

Following the presentation, there will be a 15-minute question and answer session. Even if your schedule is full and you can’t tune-in live, go ahead and register now and we’ll send you a recording you can watch later.

Presenters will be Stephen Jones, GuidePoint Security’s director of managed services, and Kris Merritt, senior director of hunting operations for CrowdStrike.

Stephen has more than 10 years of experience in information technology and cybersecurity within the Department of Defense and Intelligence Community. His primary focus has been Information Assurance (IA) and Computer Network Defense (CND).

Kris leads CrowdStrike’s internal and external hunting programs. He has more than 10 years of experience in cybersecurity and network defense, mainly in leadership roles of security operations, incident response, digital forensics, signature development, indicator management, and tactical tool development within large enterprise networks.

“I look forward to presenting alongside Stephen on how CrowdStrike Falcon Host’s continuous endpoint visibility immediately enables SOCs and hunters to detect, analyze, and respond to intrusions at a time scale once only dreamed about,” Kris said. “Operating at this time scale has provided unique insights into malicious behavior where a human actor or even malware is involved.”

“CrowdStrike uses these insights, along with rich visibility on the endpoint, to rapidly refine its approach to the threat, Kris explained. “I’m excited about our partnership with a company like GuidePoint who is eager to use the best technology to provide the best service to their customers.”

For more information about GuidePoint and how security experts like Stephen can help you make the most of vSOC services, visit For more information about CrowdStrike and to connect with Kris and his team, visit

Don’t forget to register for this free, interactive webinar here.

About GuidePoint Security

GuidePoint Security LLC provides innovative and valuable cybersecurity solutions and expertise that enable organizations to successfully achieve their mission. By embracing new technologies, GuidePoint Security helps clients recognize the threats, understand the solutions, and mitigate the risks present in their evolving IT environments. Headquartered in Herndon, Virginia, GuidePoint Security is a small business, and classification can be found with the System for Award Management (SAM). Learn more at:

GuidePoint Security’s vSOC and Prelert’s AD Strike Back Against DROWN

In a recent blog article titled, Star Wars X – Attack of the DROWNs: Machine Learning-based Anomaly Detection Detects the DROWN SSLv2 Vulnerability, Prelert announced the ability to detect Decrypting RSA with Obsolete and Weakened eNcryption (DROWN) attacks using machine-based learning through the Prelert Anomaly Detective (AD) tool. The widespread nature of the vulnerabilities related to DROWN means that it is highly likely there are still many vulnerable servers in the wild that could benefit from the watchful eye of Prelert AD operated by the trained network defenders of a managed security service like GuidePoint Security’s Virtual Security Operations Center (vSOC). vSOC leverages the power of Prelert’s AD to enhance the native detection capabilities of our Splunk-centric monitoring platform. The DROWN use case, in addition to many other co-developed use cases, provides vSOC with finely tuned anomaly detection that enables us to quickly identify, validate, and report critical security incidents to our customers. Stay tuned to the GuidePoint vSOC blog for other joint efforts and collaborative projects all focused on the protection of enterprise networks and data through advanced monitoring and hunting techniques.

About GuidePoint Security

GuidePoint Security LLC provides customized, innovative and valuable information security solutions and proven cyber security expertise that enable commercial and federal organizations to successfully achieve their security and business goals. By embracing new technologies, GuidePoint Security helps clients recognize the threats, understand the solutions, and mitigate the risks present in their evolving IT environments. Headquartered in Herndon, Virginia, GuidePoint Security is a small business, and classification can be found with the System for Award Management (SAM). Learn more at:

vSOC: Not Your Father’s Security Operations Center

GuidePoint’s vSOC Disrupts the Market with Numerous Differentiators

Basic CMYK
GuidePoint Security’s Virtual Security Operations Center (vSOC) is shaking up the Managed Security Services Provider (MSSP) market by offering an unrivaled enterprise security monitoring service brimming with differentiators. vSOC has taken the concepts of the traditional enterprise Security Operations Center (SOC), virtualized them and embedded them in the Amazon Web Services (AWS) cloud. Our cloud-based architecture allows us to leverage dynamic scaling of compute and storage resources to build a robust and flexible monitoring infrastructure.

Flexibility and Customization

GuidePoint has purposefully built the vSOC offering to be agile and customizable. vSOC strives to be a minimally invasive supplement to your existing security operations while providing maximum return on investment (ROI) and value to the security of your enterprise. Our flexibility and configurability options ensure a custom fit that provides the services and support you need without paying for things you don’t.

Cloud-based Implementation

vSOC is a cloud-based enterprise security solution architected and implemented in Amazon Web Services (AWS). AWS provides a robust and secure cloud environment with state-of-the-art compute and storage resources, encryption and automation capabilities. vSOC can dynamically provision and grow customer resources as needed, transparently and effortlessly, to ensure consistent levels of operation and performance.

Splunk Enterprise

vSOC’s enterprise monitoring solution leverages the extensibility and analytical power of Splunk to provide unparalleled security monitoring and event correlation. GuidePoint has enhanced and extended the native capabilities of Splunk Enterprise with the addition of integrated applications to provide vSOC analysts with comprehensive security dashboards and workflows that reduce the mean time to detection, resulting in quicker notification and remediation of security incidents. Additionally, GPS has enriched Splunk’s native correlation capabilities through strategic partnerships with global threat intelligence aggregators and providers.

Volume-Based Pricing

Our pricing model addresses the common feeling of being “nickel and dimed” by your MSSP every time a new information system or log source is added to the network. vSOC uses volume-based pricing to provide maximum flexibility to the customer to provision and remove network resources as needed. Our volume tiers directly correlate to the amount of log data vSOC will ingest in a 24-hour period.

Ownership of Data

Regardless of whether your security logs are in your security tools or the vSOC monitoring platform, the data is yours and you should have access to it. vSOC’s monitoring platform has been purposefully built without proprietary data formats or unnecessary restrictions on the customer’s ability to access their own data at any time. All vSOC customers are provided with accounts to their Splunk implementations so they can create their own searches, view dashboards and reports, and interact with the data any way they see fit.

Virtual Team of Experienced Security Professionals

vSOC not only leverages the well-trained cyber security analysts dedicated to our customers, but also has access to the breadth and depth of technical expertise throughout the entire company. GuidePoint’s staff of highly-trained and experienced professionals can be utilized by the vSOC analysts to consult on difficult security matters or to provide insight into challenging incidents. Our virtual team of experienced security professionals ensure that no customer is ever without an answer or solution to even the most challenging security incident or event.

More Than a Security Operations Center

vSOC customers, as part of the GuidePoint family, have access to other security services and support without having to seek out other potentially unknown and untrusted vendors. GuidePoint’s reputation as “Trusted Advisors” to our customers means we have the ethics and experience needed to consult on a wide range of security matters. From making recommendations for best of breed security tools, security services and much more, GuidePoint can help.

About GuidePoint Security

GuidePoint Security, LLC provides customized, innovative and valuable information security solutions and proven cyber security expertise that enable commercial and federal organizations to successfully achieve their security and business goals. By embracing new technologies, GuidePoint Security helps clients recognize the threats, understand the solutions, and mitigate the risks present in their evolving IT environments. Headquartered in Herndon, Virginia, and with offices in Georgia, Massachusetts, Michigan, Minnesota, Missouri, Florida, Texas, and North Carolina, GuidePoint Security is a small business, and classification can be found with the System for Award Management (SAM). Learn more at: