Home Blog Page 160

How Strong Cybersecurity Boosts Your Share Price

cybersecurity investment

Since the onset of the National Cybersecurity Awareness Month (NCSAM) for the U.S. starting October 1, on the theme “Do Your Part. #BeCyberSmart,” there has been a renewed interest in the space, thanks to the efforts by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cyber Security Alliance (NCSA). This week NCSAM emphasizes “If You Connect It, Protect It,” concurring a thought similar to the Hypponen Theory coined by Mikko Hypponen, a world-class cyber criminality expert and the Chief Research Officer of F-Secure. Taking it ahead, and to better elaborate the benefits of establishing a security-by-design architecture, BitSight, the Standard in Security Ratings, and Solactive, a German index engineering firm, have released research demonstrating how a company’s cybersecurity posture can become an indicator of business growth. According to the research, well-performing BitSight-rated companies outperform their respective benchmarks by 1% to 2% annually, and for certain sectors, such as U.S. Technology, several of these companies outperform the benchmark by 7% per year.

Good Cybersecurity Derives Better Investment

The research also highlighted that even investors are concerned about the cybersecurity posture of the company. Research by Solactive of BitSight also ascertained that there has been a shift in the approach for investors when it comes to cybersecurity. It notified that that share prices on average fall 7.27% in a two-week period after a publicly disclosed breach. In fact, cybersecurity was the #1 ESG risk for investors. It was also found that cybersecurity has remained the #3 threat to portfolio companies’ strategic success in the next three to five years.

Steve Harvey, Chief Executive Officer, BitSight, said, “BitSight is powering a new era, where cyber risk is integrated into every market decision and strong, measurable cybersecurity performance is a market differentiator.  This unprecedented research based on BitSight’s unique data will not only affect investors’ views on cybersecurity, but also the way that C-suite and security professionals manage and measure cybersecurity performance inside of their organizations.

In its recent analysis report “Global Cybersecurity 2020 Forecast” Canalys revealed that cybersecurity spending across the globe is estimated to grow between 2.5% ($43.1 billion) and 5.6% ($41.9 billion) in 2020, depending on the economic impact.

Organizations are investing to enhance their endpoint security, network security, web, and email security; data security, vulnerability detection, and security analytics — to boost their security defenses in the wake of present remote working conditions.

While network security remains the largest segment in cybersecurity spending at 36%, the research stated that the endpoint security segment will witness high growth rates due to remote working practices.

“AI has done a good job in securing the dynamic workforce”

PII for social engineering attacks

EC-Council is conducting its 2020 Global CISO Forum virtual event, October 5 – 7. The Global CISO Forum (GCF) is an annual event that sees a confluence of the highest-level executives from across industries and countries who discuss the most pressing issues in information security. Delivering a presentation titled “Securing the Future of Work with Cyber AI,” Marcus Fowler, Director of Strategic Threat, Darktrace, said the future of work is unpredictable and uncertain. He spoke about the rapid adoption of digital collaboration, the dynamic workforce, and the shifting threat landscape – which now extends to remote workers. Highlighting attacks like ransomware, crypto mining, SaaS account attacks, and banking Trojans, Fowler said that even bad actors work after hours and there is no longer a concept of fixed work hours (it’s now fluid work hours). Cybercriminals are now thriving on all the disruption and change around us. So, organizations must rethink their approach to security and rely on new technologies like Cyber AI to achieve much-needed adaptability and resilience.

By Brian Pereira, Principal Editor, CISO MAG

“Digital collaboration has exploded in the last six months. We are using many platforms for collaboration, and these platforms have vulnerabilities,” said Fowler. “The switch to work from home has caused us to lose visibility of users, etc. We ask ourselves if we have enough visibility to feel secure. There are gaps in security outside the corporate network. And there are things happening within the corporate network. (Prior to COVID) things were done to ensure business survival and business acceleration. But has security kept step today?”

He then spoke about the rampant and menacing threats that escalated in the past months, notably ransomware, crypto mining, insider threats, and SaaS account hijacks.

“They are going after sensitive IPs, sensitive communications, and information. And they are doing this to expedite payment, and how much they can ask for. There is lateral movement, crypto mining, and insider threats. We also see external data transfer, and what’s moving out of the corporate network on unofficial or unapproved cloud services or file-sharing services. There’s also SaaS account hijacks, due to an increase in SaaS dependency. Attackers are using brute force,” said Fowler.

Fowler mentioned key changes observed in recent months:

  • Digital transformation projects are being accelerated.
  • Fluid working environments and hours are here to stay.
  • Fragmented, staggered return to offices.
  • Employees may bring malware and vulnerabilities with them or inadvertently used unapproved technology.
  • Low-lying cyber-criminals thriving on disruption and change.

“Darktrace has gone from a time when we were thinking and talking about digital assets and digital environment to including that dynamic workforce — protecting them no matter where they are or what platform they are on and having that security and visibility and ensuring that that team is informed,” said Fowler.  “All the blueprints are constantly changing. So, you need a security technology that is going to adapt and be agile with your changes and decisions in terms of workforce and applications. And it needs to be hybrid and for a mix of industries.”

How AI Adapted

The technology he was referring to is Cyber AI, which proved to be highly agile and adaptable. For some companies, the changes were happening in hours and not even days. So, the technology had to adapt really fast to changing models.

“We did see that AI did a very good job in adapting to extreme changes in work from home. We used an unsupervised learning approach, which does not require an external training data set,” said Fowler.

Watching his presentation, it was interesting to learn how Darktrace’s AI Immune System is doing the “heavy lifting” for security analysts and augmenting humans who are burdened with threat fatigue and false positives. Fowler spoke about the Darktrace AI Immune System using deep learning towards autonomous response, stopping ransomware in seconds.

“Darktrace has gone from a time when we were thinking about digital assets and digital environment to including that dynamic workforce — protecting them no matter where they are or what platform they are on and having that security and visibility and ensuring that that team is informed,” he said.


Listen to the CISO MAG podcasts to catch the advice and best practices from security leaders.  Click here 


Cyber AI for the Dynamic Workforce

To secure the dynamic workforce, the AI solution should be able to provide full visibility and autonomously stop – and augment human teams, making up for the skills shortage. One example is Cyber AI for email. It should be able to detect spear-phishing attacks, for instance.

Fowler said the solution should provide these abilities:

  • Visibility into endpoints, email, and SaaS environments.
  • Contextual understanding across the entire digital organization.
  • Detects the full range of threats – from account takeover and malicious insiders, to critical misconfigurations.
  • Autonomously investigates and responds to attacks – wherever they are.

Fighting Back: Autonomous Response

Teams of security analysts are now complemented by the AI analyst, who moves past alert fatigue, a trait seen in humans. It can also mitigate false positives. It can prioritize triaged events. It will keep security teams informed so that they can take evasive action.

Some of the benefits of an autonomous solution are:

  • Autonomous response, surgical interruption of attacks
  • Reacts faster than human teams
  • No impact on normal, legitimate activity – business as usual
  • Improves functionality of other tools in a SOC
  • Frees up human teams to focus on what matters
  • Responds to a threat every three seconds

“So, this is really a war of the machines. And you can’t bring a human to a machine fight!” concluded Fowler.

About Global CISO Forum

Global CISO ForumGlobal CISO Forum is an annual event that sees a confluence of the highest-level executives from across industries and countries who discuss the most pressing issues in information security. Now in its tenth year, the 2020 Global CISO Forum promises to be the best yet with an exciting mix of industries, formats, and interactive presentations.

In celebration of our 10 years of CISO events, EC-Council is giving its brand-new Risk Management Approach and Practices e-book to all attendees of the Global CISO Forum! Risk is at the heart of what a CISO does and EC-Council wants to create as many risk-smart executives to protect the world’s assets as possible.

EC-Council’s Global CISO Forum is an invite-only, closed-door event gathering.


CISO MAG is Content Editorial Sponsor for the Global CISO Forum.

Online Celebrity Searches Could Potentially Trigger Cyber Risks

Media Industry

Users rely on the internet to find information about their favorite celebrities, which makes them vulnerable to various cyber risks. Cybercriminals are capitalizing on users’ interest by spreading malware via search results. To highlight the same, McAfee’s Annual Threat Report revealed the names of some of the top celebrities in the U.S. and India whose search links lead to malware or malicious sites.

According to McAfee, actress Anna Kendrick is the most dangerous celebrity to search online followed by veteran female leads, talk show hosts, and musicians like Blake Lively, Taylor Swift, and Jimmy Kimmel.

2020 Top 10 Celebrities in the U.S. include:

The survey also highlighted that Indians have been active online searching the internet for a wide variety of entertainment, owing to the COVID-19 lockdown. McAfee identified the top 10 popular celebrities generating the riskiest search results online in India. Football sensation Cristiano Ronaldo has topped the list, including other famous film personalities like Shahrukh Khan, Anushka Sharma, Sara Ali Khan, Sonakshi Sinha, Arijit Singh, etc. 

2020 Top 10 Dangerous Celebrities to Search Online in India:

How to Stay Safe Online?

McAfee recommended certain security steps for safe online behavior, which include:

  • Users looking for popular coming-of-age films from the last decade, as well as updates on their favorite celebrities, should be cautious and only click on links to reliable sources. The safest thing to do is to wait for official releases and leverage legitimate TV and movie streaming platforms, instead of visiting third-party websites that could contain malware.
  • It is important to only use legitimate music streaming platforms, even if they come at a cost. Many illegal downloads are riddled with malware or adware disguised as mp3 files.
  • Safeguard yourself from cybercriminals with a comprehensive security solution. This can help protect you from malware, phishing attacks, and other threats.
  • Kids are fans of celebrities too, so ensure that limits are set for your child on their devices and use parental control software to help minimize exposure to potentially malicious or inappropriate websites.

“Cybercriminals use consumers’ fascination with celebrity culture to drive unsuspecting fans to malicious websites that install malware on their devices, potentially putting personal information and log-in details in the wrong hands. Consumers are searching the web for free online entertainment now more than ever, and as cybercriminals continue to implement deceptive practices such as fake sites claiming to offer free content, it is crucial that fans stay vigilant about protecting their digital lives and think twice before clicking,” said Baker Nanduru, VP of McAfee’s Consumer Endpoint Segment.

Second Largest GDPR Fine! H&M Fined €35.2 Mn for Violating Employees’ Data

GDPR fines in 2020

Popular fashion retailer Hennes & Mauritz Online Shop A.B. & Co KG (H&M) was fined €35.2 (US$41.1 million) by the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) for violating the General Data Protection Regulation (GDPR). In an official release, HmbBfDI stated the management of the H&M Service Center in Nuremberg unauthorizedly monitored its employees’ personal information.

H&M Violations

H&M’s data privacy violations included extensive use of its staff data, including their holiday experiences, medical symptoms, and diagnoses for illnesses. The HmbBfDI’s investigation also found that some managers of H&M also acquired employees’ private details like their informal chats, including family issues and religious beliefs by illegally recording their conversations at the workplace. It also found that the company used this private data to evaluate employees’ work performance. Besides, the illicitly obtained data became accessible company-wide for several hours in October 2019 due to misconfiguration.

“In addition to a meticulous evaluation of individual work performance, the data collected in this way was used, among other things, to obtain a detailed profile of employees for measures and decisions regarding their employment. The combination of collecting details about their private lives and the recording of their activities led to a particularly intensive encroachment on employees’ civil rights,” the HmbBfDI said.

Prof. Dr. Johannes Caspar, Hamburg’s Commissioner for Data Protection and Freedom of Information, said, “This case documents a serious disregard for employee data protection at the H&M site in Nuremberg. The amount of the fine imposed is therefore adequate and effective to deter companies from violating the privacy of their employees. Management’s efforts to compensate those affected on site and to restore confidence in the company as an employer have to be seen expressly positively. The transparent information provided by those responsible and the guarantee of financial compensation certainly show the intention to give the employees the respect and appreciation they deserve as dependent workers in their daily work for their company.”

The H&M management apologized to its staff and agreed to compensate the affected employees. This is the second largest GDPR fine imposed on a single company. Last year, the French data regulator, CNIL, fined Google €50 Mn (around US$57 million) for breaching the GDPR.

Also Read: Four Biggest GDPR Fines of 2020

Disclaimer:  The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.  CISO MAG is merely passing on what has been discovered and reported by the source mentioned in the article.

Biggest Malware Collaboration! Researchers Find 11 Banking Trojans Sharing Resources

Trojans, RAT, remote access trojan, Snip3 Crypter-as-a-Service

Security researchers from ESET discovered the biggest collaboration of various banking malware creators across Latin America. The researchers found eleven different banking Trojan families that have been sharing their malware capabilities, distribution channels, and incorporating new tactics, techniques, and procedures (TTPs).

The discovered Trojan families include Amavaldo, Casbaneiro, Grandoreiro, Guildma, Krachulka, Lokorrito, Mekotio, Mispadu, Numando, Vadokrist, and Zumanek. The researchers stated that all these malware families are using the same encryption algorithms, obfuscation techniques, same uncommon third-party libraries, and similar domain generation algorithms to connect to C2 servers.

“The operators of these banking Trojans appear to be in contact with one another. We first spotted this when examining algorithms used for string encryption. Most Latin American banking Trojans use very simple, custom encryption schemes that are generally unknown in the broader programming community, and yet we see the same algorithm being used in six different families. These common features do not end with the binaries’ contents. By examining the distribution chains, we find usage of the same obfuscation methods or packers applied to different scripts,” ESET researchers said.

How a Latin American Banking Trojan Works

  • A typical Latin American banking Trojan collects information on the victim’s device, including system name, username, unique identifiers, and in some cases verifies whether security software is installed or not.
  • The compromised data is sent to a URL distinct from the C&C server.
  • The Trojan attacks by displaying a fake pop-up window crafted specifically to lure the users into clicking on the window.
  • The malware then tries to make it as hard for the victim to get rid of the window by blocking input anywhere else, keeping the window always on top, disabling hotkeys, disabling Task Manager, and blocking mouse manipulation.

“Given so many common features, one might be inclined to think that the authors of these banking Trojans share the fake pop-up windows too, since they are designed to attack customers of the same banks. In fact, the opposite seems to be the case. This is likely the one thing they do by themselves. We have analyzed around 600 of the most recent of these fake windows and it seems they are unique to each family,” the researchers added.

CISA Warns Potential Cyberattacks from State Actors Amid Geo-Political Tensions

IoT Connections to Reach 83 Billion by 2024: Report, CISA alerts critical infrastructure, CISA – FBI holiday season alert

Amid the brewing geopolitical tensions in the U.S. and with the Presidential election being just around the corner, CISA has issued an alert for all operatives of critical infrastructure to look out for possible cyberattacks in the upcoming months. In a broader light of keeping the organizations and businesses safe from this foul play of certain state actors involved, CISA has provided information on specific tactics, techniques, and procedures (TTPs) employed by them.

The Chinese Threat

To the world, China has been on the defensive ever since the U.S. claimed that China was running a cyber espionage campaign against it through Huawei’s 5G contract. However, through many other incidents like the “Taidoor malware attack” and the “Zhenhua data leak,” China’s offensive tactics are being identified and portrayed globally.

CISA notes that “Made in China 2025,” is a 10-year plan outlining China’s top-level policy priority. In pursuit of these national interests, China can target critical infrastructures in the national and economic sectors of the U.S. These critical infrastructure sectors include new energy vehicles, next-generation information technology (IT), biotechnology, new materials, aerospace, maritime engineering, and high-tech ships; railway, robotics, power equipment, and agricultural machinery.

Additionally, there are several Department of Justice (DOJ) indictments over the past few years that provide enough evidence suggesting how Chinese threat actors are continuously targeting the U.S. to exfiltrate its intellectual property (IP) from both public and private domains. Their targets also include western companies with operations inside China.

Commonly Known TTPs of Chinese Threat Actors

The following table denotes the Pre-Att&ck TTPs that are commonly used by Chinese threat actors before launching an attack:

Technique Description
Acquire and/or Use 3rd Party Software Services [T1330] Staging and launching attacks from software as a service solution (SaaS) that cannot be easily tied back to the APT.
Compromise 3rd Party Infrastructure to Support Delivery [T1334] Compromising infrastructure owned by other parties to facilitate attacks (instead of directly purchasing infrastructure).
Domain Registration Hijacking [T1326] Changing the registration of a domain name without the permission of its original registrant and then using the legitimate domain as a launch point for malicious purposes.
Acquire Open-Source Intelligence (OSINT) Data Sets and Information [T1247] Gathering data and information from publicly available sources, including public-facing websites of the target organization.
Conduct Active Scanning [T1254] Gathering information on target systems by scanning the systems for vulnerabilities. Adversaries are likely using tools such as Shodan to identify vulnerable devices connected to the internet.
Analyze Architecture and Configuration Posture [T1288] Analyzing technical scan results to identify architectural flaws, misconfigurations, or improper security controls in victim networks.

 

As per CISA, these TTPs and associated IOCs are difficult to detect and hence need to be carefully monitored. Many state-sponsored APT groups like APT3, APT10, APT19, APT40 and APT41 are said to be actively employing these pre-attack techniques.

In the Enterprise Att&ck TTPs, Chinese threat actors are seen using commonly available security testing tools and frameworks such as:

  • Cobalt Strike and Beacon
  • Mimikatz
  • PoisonIvy
  • PowerShell Empire
  • China Chopper Web Shell and more.

Mitigation Steps

On studying the TTPs and IOCs at large, CISA suggested a few mitigation steps that are noted below:

  • Adopt heightened security awareness and vigilance.
  • Establish and keep indent response plans ready.
  • Concentrate on patch and configuration management. Keep all systems and networks updated.
  • Exercise access control. Disable unwanted access, ports, protocols, and services. Minimize the operational landscape.
  • Install network and email traffic monitoring solutions to restrict malicious break-in from these nodes.

Marty Edwards, VP of OT Security, Director of ICS-CERT and Co-Chair of the Control Systems Interagency Working Group, said, “Today’s CISA alert about possible state-sponsored attacks against the country’s most sensitive and valuable critical infrastructure is what the cybersecurity community has been warning about for some time. For years, we have seen steady momentum of new, targeted attacks against the US that seek to compromise the systems we rely on to function as a modern society. With Covid-19, our reliance on critical infrastructure – from railways to energy to agriculture to pharmaceuticals — has gone into hyperdrive. This dependence is extremely lucrative to cybercriminals looking to wreak havoc.”

 

Egregor: A Spin-off of Sekhmet Ransomware

Ransomware attacks, LockBit Ransomware

Researchers from cybersecurity firm Appgate uncovered a new ransomware variant “Egregor” targeting organizations globally to encrypt files that hold sensitive information. The researchers stated that Egregor seems to be derived from the Sekhmet malware family. The threat group uses code obfuscation and packed payloads to escape security detection. The researchers also found Egregor’s news website hosted on the dark web, which is used for leaking stolen data and other malicious activities.

After encrypting sensitive files, the ransomware group asked companies for ransom. Egregor’s ransom note specifically states that if the ransom is not paid by the company within 3 days, and aside from leaking part of the stolen data, they will distribute the files via mass media where the company’s partners and clients will know that the company was attacked. However, if the company agrees to pay the ransom, the hackers provide recommendations for securing the company’s network after decrypting all the files.

“The Egregor payload can only be decrypted if the correct key is provided in the process’ command line, which means that the file cannot be analyzed, either manually or using a sandbox, if the exact same command line that the attackers used to run the ransomware isn’t provided,” Appgate stated.

Egregor’s “hall of shame” lists 13 different companies, including the global logistics company GEFCO, which also fell prey to a cyberattack recently.  

121.4 Mn Ransomware Attacks Recorded in H1 of 2020

A  survey from cybersecurity firm SonicWall revealed that the opportunistic use of COVID-19 pandemic by cybercriminals has resulted in the rise of ransomware and IoT malware attacks globally. The survey “2020 SonicWall Cyber Threat Report” found that ransomware continues to be the most concerning threat to enterprises and the preferred attack method, with 121.4 million attacks (20% increase) reported globally in the first half of 2020. The threat researchers recorded 79.9 million ransomware attacks (109% increase) in the U.S. and 5.9 million ransomware attacks (6% decline) in the U.K.

Only 1 in 4 Organizations Keep Payment Data Secure

Cardholder payment data

Even though COVID-19 has brought its fair share of limelight on cybersecurity, cardholder payment data continues to be far from secure. According to new research by Verizon, only one in four organizations keep cardholder payment data secure. This is even after the fact that cardholder payment data is among the hot favorite for cybercriminals, with 9 out of 10 data breaches being financially motivated. In fact, 99% of security incidents analyzed by the recent 2020 Data Breach Investigation Report were focused on acquiring payment data for criminal use.

The Verizon Business 2020 Payment Security Report pointed out that a lack of long-term payment security strategy and execution is among the key reasons why payment data is handled so precariously. Several companies are struggling to retain qualified CISOs or security managers, and this is another reason for this alarming trend that puts a dent on sustained compliance within the Payment Card Industry Data Security Standard (PCI DSS).

The report highlighted that only 27.9% of global organizations maintained full compliance with PCI DSS. Even here there has been a decline in compliance with a 27.5%-point drop since compliance peaked in 2016.

“Unfortunately, we see many businesses lacking the resources and commitment from senior business leaders to support long-term data security and compliance initiatives. This is unacceptable,” said Sampath Sowmyanarayan, President, Global Enterprise, Verizon Business. “The recent coronavirus pandemic has driven consumers away from the traditional use of cash to contactless methods of payment with payment cards as well as mobile devices. This has generated more electronic payment data and consumers trust businesses to safeguard their information. Payment security has to be seen as an on-going business priority by all companies that handle any payment data, they have a fundamental responsibility to their customers, suppliers and consumers.”

The report also underscored that even security testing has taken a backseat for several companies where just a little over half the surveyed organizations successfully test security systems and processes as well as unmonitored system access. Here, only two-thirds of all businesses track and monitor access to business-critical systems adequately, while only 7 out of 10 financial institutions (70.6%) maintain essential perimeter security controls.

“This report is a welcome wake-up call to organizations that strong leadership is required to address failures to adequately manage payment security,” said Maxine Holt, Senior Research Director at Omdia.

Father of the Internet, Vinton Cerf Calls for Balanced Regulation of the Internet

Internet Regulation, Vinton Cerf, Vice President and Chief Internet Evangelist, Google

Delivering the keynote in the Future Stream at CYBERSEC Global Forum 2020 last week, Vinton Cerf, Vice President and Chief Internet Evangelist, Google, said the Internet impacts many lives and offers several opportunities. It has evolved rapidly and kept up with change. But there is also a dark side to the Internet. He mentioned common threats and spoke about the Internet being misused for cross-border warfare. To curb this, a government can take extreme steps like surveillance, censorship or blocking websites. He called for a balanced response towards protecting citizens from harm through the Internet.

Cerf, popularly known as one of the “Fathers of the Internet,” contributes to global policy development and the continued spread of the Internet. He is the co-designer of the TCP/IP protocols and the architecture of the Internet. Cerf has served in executive positions at MCI, the Corporation for National Research Initiatives and the Defense Advanced Research Projects Agency and on the faculty of Stanford University. He served as chairman of the board of the Internet Corporation for Assigned Names and Numbers (ICANN) from 2000-2007 and has been a Visiting Scientist at the Jet Propulsion Laboratory since 1998. Cerf was also the founding president of the Internet Society (ISOC) from 1992-1995.

AUDIO: Listening time: 11 mins 47 sec

Excerpts from his presentation follow:

QUOTE

It is important for us to remember that the Internet has become a … part of many lives, and it is vital that we keep it open. A place where information can be shared, discovered, and where information can be generated. We are in a situation now, in some parts of the world, where that openness is under some threat. Governments must take a balanced response to the harms affecting its citizens.

One thing for sure is that the Internet has shown a remarkable ability to adapt and evolve to the changing situation of our world — as we depend increasingly on digital technology, the internet has managed to keep up.

But I am sorry to say that this platform, which is so enabling, also enables some fairly bad behaviors. We see misinformation and disinformation, the spread of malware, denial of service attacks, hacking, fraud, bullying, social divisiveness — there are a variety of bad things that happen in the online environment because it is such a powerful tool. And people are going to use those tools to do harm.

On cross-border cyber warfare…

Most governments are concerned about the safety and security of their citizens, and they see this abusive behavior and they feel like they need to respond to it because their citizens are harmed. To make matters worse, harm can come across the country borders. The Internet is insensitive to the boundaries of countries.

An attacker could be in one country and the victim could be in another country. So, we must think how we are going to cooperate across those international boundaries in order to protect our citizens from harm. That’s going to require serious cooperation across international boundaries in order to come up with common norms and practices that will help countries protect their citizens.

Balanced response

I think we need to achieve a balanced response to these harms.

It is possible to go to an extreme and to try to protect people by suppressing the information, by censoring information, by limiting access to various websites. While that makes sense for certain conditions, it certainly should not make sense for every condition.

It is very important to keep the Internet open to allow people to explore its content and to generate/share content they believe is important to other people.

It seems to me that what we seek is attention between protecting people’s safety — using surveillance and other kinds of techniques and protecting their privacy.

In theory, these should not have to conflict. Protecting privacy is important but there are some people who will argue that protection of privacy leads to harm — because some people whose privacy is protected will seek to do harm in a way that is private.

So, we have to find some middle ground where it is possible to give strong protections to people’s privacy while at the same time, figuring out how law enforcement, especially across international boundaries, can be affected while preserving the important freedoms that we find enshrined in the universal declaration of human rights.

UNQUOTE

VMware Adds New Edge to its SASE Capabilities

VMware future ready workforce

Legacy networking and security approaches lack the automation, cloud-scale, and intrinsic security needed to connect and protect apps, data, and users across a globally distributed supply chain. Thus, there is an urgent need for converging cloud networking, cloud security, and zero-trust network access with best in class web security to deliver flexibility, agility, and scalability for enterprises of all sizes. In response to this, VMware announced its Future Ready Workforce solutions that not only provide exceptional workforce experiences and end-to-end Zero Trust security controls but also simplified management.

VMware’s Future Ready Workforce solutions combine its Secure Access Service Edge (SASE), digital workspace, and endpoint security capabilities to help IT teams manage and optimize more secure access to any app, on any cloud, and from any device while providing a simple, high performant, and a safer user experience for the distributed workforce.

SASE: An Emerging Solution for Unified Network and Security in the Cloud

The SASE platform offered by VMware is a cloud-first offering that delivers application quality assurance, intrinsic security, and operational simplicity that is ideal for organizations that are supporting a work from anywhere workforce. At the core, it provides the following features:

  • Comprehensive SD-WAN VMware has been positioned as a leader in the Gartner 2020 Magic Quadrant for WAN Edge Infrastructure. Its global SD-WAN network has expanded to more than 2,700 cloud service nodes across 130 points of presence (POPs). The new VMware Edge Network Intelligence gives IT teams added visibility and telemetry into the end-user experience as applications are accessed from anywhere, and application traffic traverses many different networks. The Dell EMC SD-WAN Solution powered by VMware now also includes a built-in LTE to support mobile clinics / temporary sites as well as higher reliability for work from home.
  • Zero Trust Network Access (ZTNA)VMware Secure Access is a ZTNA service that combines VMware Workspace ONE and VMware SD-WAN into a single, cloud-hosted offering that enables more secure, optimized, and high-performance access for remote and mobile users.
  • Cloud & Web SecurityVMware is partnering with leading companies to provide customers flexibility and choice in meeting their cloud and web security requirements.
    • The new VMware Cloud Web Security service will integrate Menlo Security’s secure web gateway (SWG), cloud access service broker (CASB), Data Loss Prevention, sandbox, and remote browser isolation capabilities natively into the VMware SASE solution. VMware Cloud Web Security will be offered to businesses of all sizes as a ready to use solution.
    • VMware and Zscaler announced an expanded strategic relationship to enable enterprises to combine VMware SD-WAN and VMware Secure Access with Zscaler Internet Access into a best of breed SASE solution.
  • Integrated Next-Gen Firewall as a Service – The VMware NSX Firewall is a Layer 7 firewall that will be integrated into the VMware SASE Platform for cloud-delivered firewall as a service in both single-tenanted and multi-tenanted deployment options. This will complement the firewall capabilities of the existing VMware SD-WAN solution today.

Rajiv Ramaswami, Chief Operating Officer, Products and Cloud Services, VMware said, “Organizations are navigating one of the most significant disruptions of our generation. These challenges will accelerate a shift to cloud-centric strategies, like SASE, that address the requirements of enabling people to work from anywhere. The VMware Future Ready Workforce solutions help businesses enable their people to work from anywhere with intrinsic security, delightful end-user experiences, and lower operational complexity.”

A Vision for the Future of Work

The pandemic has likely changed the future of work forever. According to VMware research, 42% of global employees surveyed said the ability to work remotely is a prerequisite to their job, not just a perk. 90% said that it is the responsibility of the employer to ensure employees have appropriate access to digital tools to enable remote work. However, enabling a distributed workforce is fraught with challenges ranging from remote employee on-boarding, visibility and compliance, security, employee safety, and more.

To address these challenges, VMware Workspace Security has unified the endpoint management and endpoint security platform enabling its customers the power to leverage the potential of big data and provide comprehensive endpoint visibility as well as actionable insights in conjunction with data-driven prevention technology through a single dashboard. VMware’s new Workspace ONE and Workspace Security offerings are also introduced to better secure work-related devices that are easy to deploy, manage, and scale including:

  • VMware Workspace Security Remote – Combines unified endpoint management (UEM), endpoint security, and remote IT support into an integrated solution. It enables broader compliance and help to operationalize security updates. Workspace Security Remote brings the two teams, technologies, and consoles closer together to enhance overall device health, provide Zero Trust access, and efficiently automate threat response.
  • VMware Workspace Security VDI – This new age solution goes beyond legacy solutions. It integrates Carbon Black technology directly into the VMware vSphere Hypervisor and VMtools to deliver an agentless approach with improved anti-tamper capabilities, audit, and remediation, and uses behavioral detection to protect against ransomware and file-less malware.

VMware Workspace Security Remote and VMware Workspace Security VDI have already been made available. However, VMware Edge Network Intelligence is expected to be available latest by October 30, 2020. VMware Cloud Web Security is expected to be available in VMware’s Fiscal Q1 FY22, and NSX Firewall as a Service for the VMware SASE Platform is expected to be available in FY22.