Showing posts with label business. Show all posts
Showing posts with label business. Show all posts

March 27, 2022

Do Businesses Need Zero Trust?

 

Zero trust security is essential for all businesses with a digital presence. It is a strategic approach that verifies every user and device has access after confirming who they say they are. Many cloud environments host critical enterprise apps and data, so they are vulnerable to attackers wishing to steal or hold for ransom sensitive and private data. Zero trust reduces the attack surface area and can limit the severity and impact of an attack if credentials become compromised or firewalls are breached.

Each user must undergo an evaluation when requesting access to the network and this is based on the user type, their location, and other features that can help identify a user. Zero trust then grants access for a certain time period and only allows users to access what they should. These mechanisms can significantly reduce risk and enhance security control while increasing visibility and productivity, and making better use of your IT resources.

As many employees continue to work from home, businesses have relied on single sign-on to allow their users to gain access to a multitude of hosted services. However, this verification method should be combined with multi-factor authentication to enhance an enterprise’s security process. This makes the end-user experience much less smooth though. By using zero trust mechanisms, artificial intelligence and machine learning algorithms learn what constitutes as “normal” user behaviour and allows businesses to detect unusual activity that deviates from regular patterns, blocking access until the user can be verified.

Zero Trust Authentication Mechanisms and Tools

The effectiveness of zero trust requires continuous analytics and monitoring that allows a business’s IT professionals to investigate suspicious access requests rather than monitor each and every request individually. This is a huge benefit to most organisations as a recent 2021 study found 60% of business’s claim a lack of cybersecurity professionals is placing their operations at risk. By safely automating the security process with zero trust mechanisms, you are reducing the burden on human resources and allow IT professionals to focus on innovation instead. Zero trust also optimises your current security processes by introducing a centralised monitoring system that can provide valuable insights into user behaviour and generate reliable streams of data.

Zero trust also allows shared responsibility for security between cloud vendors and the organisation which can further enhance your business’s safeguards. Furthermore, by properly implementing a zero trust strategy, your enterprise can ensure it is deploying a robust ‘least privilege’ mechanism so suppliers, vendors, partners, and customers are not gaining access to applications, infrastructure, and data that they should not otherwise be able to access. This is employed by zero trust’s foundation of “always verify” every user, no matter what.

By enforcing these access controls from anywhere the user connects from, the business no longer requires employees to ensure their devices are patched and their networks aren’t compromised. Many employees may be IT illiterate or fail to follow basic IT hygiene, but that is no longer an issue when zero trust is enforced.

Are Businesses Implementing Cloud Solutions Correctly?

 

Cloud has become a business enabler that can deliver value and help an enterprise reach its goals as the technology and its capabilities have matured in recent years. These technologies have improve their IT organisations, helped customer experiences, and overall refined the business they are implemented in by creating more agile, sustainable, modern, and secure IT operations. Cloud solutions are also enabling the next generation of IT innovation by helping to release 5G, edge, IoT, and artificial intelligence technologies.

Before implementing a cloud solution to your organisation, you will need to determine the right placement of workloads and applications – which data should be held on-premises and what is OK or more secure to have stored in the cloud? You must also accurately predict how much it will cost to implement and operate both now and in the future. Finally, business leaders must establish the correct security position to ensure applications and data remain safe and protected no matter where they are located.

These considerations are part of a wider cloud enterprise strategy that you must ensure you are thoroughly crafting rather than implementing cloud “just because”. Assess your business needs and identify relevant use cases for these cloud solutions that better your current operations. Can using cloud technologies help you enter new markets? Can cloud applications improve agility, innovation, ways of working or your business’s reputation? Ensure the move to cloud drives optimal outcomes  [PDF] such as increasing speed, improving business value, or reducing costs securely.

Enterprise Cloud Solutions Diagram

Enterprises should ensure they are taking a “design to cost” approach that will allow them to optimised resources, consumption, and manage contractual obligations. IT leaders must define what good looks like to them in their organisation so that success can be quantified in discernible metrics and monitored carefully. Question how these cloud solutions are enabling better business outcomes, value, and employee experiences. Take a holistic approach and verify the right governance, technology, strategy, and talent are in place to take advantage of the technology and make the transition a success.

Organisations that take a more practical path to cloud adoption will see better results and support from their peers and businesses as they scale. Implementing the right strategy will ensure a more successful transition and a more optimised use of the cloud solutions.

March 26, 2022

Email Compromise More Prevalent Than Ransomware

 

While ransomware remains one of the most talked about cyber issues targeting enterprises, business email compromise (BEC) has remained the largest source of financial losses according to the FBI’s Internet Crime Center (IC3) – with losses totalling $2.4 billion in 2021. When grouped with ransomware and cryptocurrency theft, BEC and these other crimes led to Americans losing $6.9 billion last year compared to $4.2 billion in 2020. Complaints about cybercrime losses are up 7%.

Initially, BEC scams spoofed or hacked a business email account of someone with senior ranking in the organisation and then instructed someone more junior to transfer funds to the scammer’s bank account. Many of these scams seemed to target real estate companies. Today, scammers are using virtual meeting platforms to spoof credentials and hack emails and then initiate fraudulent money transfers which are immediately transferred to cryptocurrency wallets and then rapidly dispersed. This makes the investigation and recovery efforts much more difficult.

Ransomware Attacks - Directory CLI

During these virtual meetings, fraudsters are using pictures of the company’s CEO with no audio, or deep faking the audio, and sometimes even the video, using AI while the scammers claim there is some issue with their connection. Despite ransomware attacks grabbing the most headlines, these attacks amounted to losses of around $50 million in comparison to BEC losses of $2.4 billion. However, there has been an increase in “high-impact” ransomware attacks on critical infrastructure operators in 2021 based on data provided by the FBI, NSA, and agencies in the UK and Australia. ‘Ransomware-as-a-service’ is also trending as hackers provide negotiation services and brokers to gangs.

The healthcare, financial services, and IT sectors were the most frequently targeted for ransomware attacks last year according to IC3 and it expects a larger number of complaints this year, but doesn’t recommend paying ransoms. New US legislation requires critical infrastructure operators to report hacks and ransomware attacks to CISA instead of the FBI.

It has been estimated that cyber criminals have washed over $8 billion of cryptocurrency last year, typically using mixers or tumbler software to split the large sums and blend it with other transactions before forwarding the amounts to new addresses.