Global Report: More than 90% of Business Leaders Say Cloud is a Business Priority in the COVID-19 Shutdown

1,077 respondents across 9 countries are relying more on cloud technologies and seeing more cybersecurity attacks, according to Zogby Analytics Research    

Infoblox Inc., the leader in Secure Cloud-Managed Network Services, and Zogby Analytics unveil research into the ongoing IT challenges posed by the COVID-19 shutdown. Half a year into the shutdown, companies are still playing catch up to optimize their remote work experience. Based on 1,077 responses from the US, the UK, Germany, the Netherlands, Spain, China, Japan, Australia, and Singapore, key survey findings show that: 

  • The borderless enterprise is here to stay. More than 90% of decision-makers consider digital transformation and cloud-managed services a priority. The percentage of companies with a majority of employees working remotely more than tripled from 21% before the shutdown to 70% after. 40% of companies, twice the pre-COVID-19 rate, are permanently keeping a majority of workers remote.
  • Organizations are still building out their IT infrastructure and security controls to optimize remote work. Organizations say distributing sanctioned devices (35%), building network infrastructure (35%), and securing the network (29%) are top IT challenges when transitioning to remote work. 
  • Threat mitigation and network visibility remain the top security concerns for the remote work environment. 68% say better threat detection and or mitigation technologies would enable more remote work for their organizations. Specifically, respondents are looking for better visibility into devices on the corporate network (65%), cloud applications workers are using (61%), and compromised devices (46%). 
  • Security incidents are rising. Half of the surveyed businesses are seeing more cyber-attacks—with the biggest jumps in China and Australia—while just a quarter are seeing fewer.
  • Companies are reversing policies to allow the use of personal applications to foster collaboration. 63% of companies are allowing workers to connect with each other using applications like WhatsApp, Zoom, and Houseparty. 
  • Companies are using cloud security tools, particularly from the DDI family (DNS, DHCP, IP Address Management), to secure the borderless enterprise. 59% of companies plan on making additional investments in DNS to secure their expanded networks.

“When the COVID-19 shutdown started, organizations rushed to enable remote work overnight,” said Kanaiya Vasani, Executive Vice President, Products and Corporate Development at Infoblox. “Their top priority was making sure workers could connect to enterprise applications from their homes—sometimes through unsecured personal devices.”

“While most organizations can now accommodate the basics of remote work, this report highlights the need for more security controls,” Vasani added. “To meet that need, a majority of surveyed companies are turning to DNS to rapidly stand up a foundational layer of security for employees working from home. “Using a hybrid DNS security solution like BloxOne Threat Defense, enterprises can create a ubiquitous layer of visibility and security across their expanded infrastructure.”

Fortinet Research Demonstrates Enterprises Must Adapt to Address Telework Security Challenges Long-term

“The COVID-19 pandemic will have lasting effects on how organizations invest in cybersecurity. In fact, over 90% of enterprises plan to invest more to secure telework over the next two years. Given a dramatically expanded digital attack surface, thewaves of cyber threats targeting remote workers, and the ongoing cyber skills gap, organizations need to carefully consider what technologies and approaches are needed to secure their telework strategies long-term,” said John Maddison, EVP of Products and CMO at Fortinet. “They have an opportunity to maximize their investments with cybersecurity platforms designed to provide comprehensive visibility and protection across the entire digital infrastructure, including networked, application, multi-cloud, and mobile environments. This ongoing shift to remote work will also require more than just technology; cybersecurity training and awareness should also remain key priorities.”

The Sudden Shift to Telework Was Challenging for Most Organizations

  • As the COVID-19 pandemic spread rapidly in the first half of 2020, many organizations were required to shift to telework practically overnight as teams around the globe were asked to stay home. Nearly two-thirds of the firms surveyed had to rapidly transition over half of their workforce to telework. In addition, most respondents said the rapid change presented a challenge to their organization, with 83% citing it as moderately, very, or extremely challenging. Only 3% were not at all challenged.
  • In addition, the evolving remote work environment, increased reliance on personal device usage, and overall influx of workers outside the corporate network opened an opportunity for unprecedented cyber threat activity. From opportunistic phishers to scheming nation-state actors, cyber adversaries found multiple ways to exploit the global pandemic for their benefit at enormous scale as evidenced by a recent FortiGuard Labs Global Threat Landscape Report. Threats included phishing and business email compromise schemes, nation-state backed campaigns, and ransomware attacks. In fact, 60% of organizations revealed an increase in cybersecurity breach attempts during the transition to remote work, while 34% reported actual breaches in their networks.
  • With a spike in employees remotely connecting to the corporate network, an increase in breach attempts and overall cyber attacks, organizations cited the most challenging aspects of this transition as ensuring secure connections, business continuity, and access to business-critical applications.
  • At the time of the survey enterprises had already invested in key technologies as a result of the pandemic. Nearly half of organizations invested further in VPN and cloud security, while nearly 40% invested further in skilled IT professionals or network access control (NAC).

There is Still Room for Improvement: Almost All Enterprises Will Invest More in Secure Telework

Given the number of attempted breaches and overall waves of cyber threats targeting remote workers, organizations need to carefully consider what technologies and approaches are needed to secure telework moving forward. Defense strategies need to be adjusted to fully account for the extension of the network perimeter into the home.

  • As of June this year, a long-term shift to telework is anticipated, with nearly 30% of organizations expecting more than half of their employees to continue working remotely full time after the pandemic.
  • Almost all organizations expect to invest more to secure telework long-term, with nearly 60% of enterprises spending more than $250,000 in secure telework investments in the next 24 months.
  • Moving forward, the majority of enterprises surveyed intend to make unplanned upgrades to their existing systems to secure telework. Many also plan to add new technologies not previously in place.
  • Only 40% of organizations had a business continuity plan in place prior to the pandemic. Yet, as a result of the pandemic and the rapid shift to remote work, 32% invested further in this area.

While organizations have made improvements in securing their remote workforces since the beginning of the pandemic, survey data reveals several areas that could be considered opportunities for improving secure remote connectivity. These areas include:

  • Multi-factor Authentication (MFA) – The survey revealed that 65% of organizations had VPN solutions in place pre-pandemic, but only 37% of organizations had multi-factor authentication (MFA). While VPNs play an important role in ensuring secure connectivity, they are simply one part of securing access. Therefore, if not already in place, it is recommended that organizations consider integrating MFA into their remote security plans.

  • Endpoint Security and Network Access Control (NAC) – 76% and 72% of organizations plan to either upgrade or adopt NAC or endpoint detection and response (EDR) solutions respectively. As employees work remotely, organizations face challenges to control the influx of non-trusted devices on their networks to enable remote work, creating new security challenges overnight. By adopting NAC solutions, IT teams get increased visibility and control over the users and devices on their network. EDR solutions deliver advanced, real-time threat protection for endpoints both pre- and post-infection.
  • Software-defined Wide-area Networking (SD-WAN) for the Home: 64% of organizations plan to either upgrade or adopt SD-WAN, but specifically for the home office. The critical advantage of extending secure SD-WAN functionality to individual teleworkers, especially super users, is that they can enjoy on-demand remote access as well as dynamically scalable performance regardless of their local network availability.

  • Secure Access Service Edge (SASE) – 17% of organizations made investments in SASE prior to the pandemic, and 16% invested in SASE as a result of the pandemic. Still, 58% plan to invest in SASE to some degree going forward. Although SASE is an emerging enterprise strategy, it is increasingly seen as an opportunity to combine network and security functions with WAN capabilities to support the dynamic, secure access needs of today’s organizations.
  • Skilled Security Professionals – At the start of the pandemic, only 55% of organizations had enough skilled IT workers in place to support the shift to remote work. And while 73% of organizations stated their intention to invest further in skilled IT workers in the next 24 months, the historical lack of skilled IT security professionals could present a challenge.

FortiGuard Labs Reports Cyber Adversaries Are Exploiting the Global Pandemic at Enormous Scale

“The first six months of 2020 witnessed an unprecedented cyber threat landscape. The dramatic scale and rapid evolution of attack methods demonstrate the nimbleness of adversaries to quickly shift their strategies to maximize the current events centered around the COVID-19 pandemic across the globe,” says Derek Manky, Chief, Security Insights & Global Threat Alliances, FortiGuard Labs. There has never been a clearer picture than now, of why organizations need to adjust their defense strategies going forward to fully take into account the network perimeter extending into the home. It is critical for organizations to take measures to protect their remote workers and help them secure their devices and home networks for the long term. It is also wise to consider adopting the same strategy for cyber viruses that we are adopting in the real world. Cyber social distancing is all about recognizing risks and keeping our distance.”

Seizing the Opportunity in Global Events: Attackers have used subjects in the news as social engineering lures before, but this moved to the next level in the first half of 2020. From opportunistic phishers to scheming nation-state actors, cyber adversaries found multiple ways to exploit the global pandemic for their benefit at enormous scale. This included phishing and business email compromise schemes, nation-state-backed campaigns and ransomware attacks. They worked to maximize the global nature of a pandemic that affected everyone around the world combined with an immediately expanded digital attack surface. These trends were seen with other newsworthy items and demonstrate how quickly attackers can move to take advantage of major developments with broad social impact at a global level.

The Perimeter Gets More Personal: The increase in remote work created a dramatic inverse of corporate networks almost overnight, which cyber adversaries immediately started to leverage as an opportunity. In the first half of 2020, exploit attempts against several consumer-grade routers and IoT devices were at the top of the list for IPS detections. In addition, Mirai and Gh0st dominated the most prevalent botnet detections, driven by an apparent growing interest of attackers targeting old and new vulnerabilities in IoT products. These trends are noteworthy because it demonstrates how the network perimeter has extended to the home with cybercriminals seeking to gain a foothold in enterprise networks by exploiting devices that remote workers might use to connect to their organizations’ networks.

Browsers Are Targets Too: For attackers the shift to remote work was an unprecedented opportunity to target unsuspecting individuals in multiple ways. For example, web-based malware used in phishing campaigns and other scams outranked the more traditional email delivery vector earlier this year. In fact, a malware family that includes all variants of web-based phishing lures and scams ranked at the top for malware in January and February and only dropped out of the top five in June. This may demonstrate the attempt of cybercriminals to target their attacks when individuals are the most vulnerable and gullible—browsing the web at home. Web browsers, not just devices, are also prime targets for cybercriminals, perhaps more than usual, as cybercriminals continue to target remote workers.

Ransomware Not Running Away: Well-known threats such as ransomware have not diminished during the last six months. COVID-19-themed messages and attachments were used as lures in a number of different ransomware campaigns. Other ransomware was discovered rewriting the computer’s master boot record (MBR) before encrypting the data. In addition, there was an increase in ransomware incidents where adversaries not only locked a victim organization’s data but stole it as well and used the threat of widescale release as additional leverage to try and extort a ransom payment. The trend significantly heightens the risks of organizations losing invaluable information or other sensitive data in future ransomware attacks. Globally, no industry was spared from ransomware activity and data shows that the five most heavily targeted sectors for ransomware attacks are telco, MSSPs, education, government, and technology. Unfortunately, the rise of ransomware being sold as a service (RaaS) and the evolution of certain variants indicates that the situation with ransomware is not going away.

OT Threats After Stuxnet: June marked the 10th anniversary of Stuxnet, which was instrumental in the evolution of threats to, and security of, operational technology. Now, many years later, OT networks remain a target for cyber adversaries. The EKANS ransomware from earlier this year shows how adversaries continue to broaden the focus of ransomware attacks to include OT environments. Also, the Ramsay espionage framework, designed for the collection and exfiltration of sensitive files within air-gapped or highly restricted networks, is an example of threat actors looking for fresh ways to infiltrate these types of networks. The prevalence of threats targeting supervisory control and data acquisition (SCADA) systems and other types of industrial control systems (ICS) is less in volume than those affecting IT, but that does not diminish the importance of this trend.

Mapping Exploitation Trends: A review of the CVE List shows the number of published vulnerabilities added has risen over the last few years, sparking discussion over the prioritization of patching. Even though 2020 looks to be on pace to break the number of published vulnerabilities in a single year, vulnerabilities from this year also have the lowest rate of exploitation ever recorded in the 20-year history of the CVE List. Meanwhile, vulnerabilities from 2018 claimed the highest exploitation prevalence at 65%, and more than a quarter of organizations registered attempts to exploit 15-year-old CVEs. For cyber adversaries, exploit development at scale and distribution via legitimate and malicious hacking tools continues to take time.

The Urgency to Secure the Network Perimeter Extending Into the Home

With the increase in connectivity, devices, and ongoing need for remote work, the digital attack surface is expanding. With the corporate network perimeter extending to the home, attackers are looking for the weakest link and fresh attack opportunities. Organizations need to prepare by taking concrete steps to protect their users, devices and information in ways similar to the corporate network. Threat intelligence and research organizations can help by providing broad insight as the threat landscape evolves as well as in-depth analysis of attack methods, actors, and new tactics to help supplement the cyber knowledge of organizations. The need for secure teleworker solutions to enable secure access to critical resources while scaling to meet the demands of the entire workforce has never been greater. Only a cybersecurity platform designed to provide comprehensive visibility and protection across the entire digital attack surface–including networked, application, multi-cloud, or mobile environments–is able to secure today’s rapidly evolving networks.

Report Overview
This latest Global Threat Threat Landscape Report is a view representing the collective intelligence of FortiGuard Labs, drawn from Fortinet’s vast array of sensors collecting billions of threat events observed around the world during the first half of 2020. It covers global and regional perspectives as well as research into three central and complementary aspects of that landscape: exploits, malware, and botnets.

Airport International Group Charts Course for Success through COVID-19 Crisis with Nutanix

Implementation of Xi Frame has ensured business continuity and rapidly empowered a newly formed remote workforce

Nutanix (NASDAQ: NTNX), a leader in enterprise cloud computing, today announced that Airport International Group – a Jordanian consortium of local and international investors with proven experience in airport rehabilitation, enhancement, operation and management – has implemented Xi Frame to maintain business continuity through the turmoil and uncertainty brought on by the COVID-19 pandemic. The Desktop-as-a-Service (DaaS) solution has facilitated set up of virtual training rooms for seamless delivery of extensive training on the newly implemented Airport Management System. It has also provided employees with secure access to specialized applications via shared desktops. As importantly, the solution has enabled the establishment of a virtual control room, giving the Operations Team secure, remote access to mission critical airport IT systems.

In 2007, Airport International Group was appointed by the Government of Jordan to manage the rehabilitation, expansion and operation of Queen Alia International Airport (QAIA), which serves as a pillar of the national economy and the local aviation, transport and tourism sectors. Under Airport International Group’s management, QAIA has successfully expanded, recorded significant growth in passenger numbers and received several Airports Council International (ACI) awards. Today, Airport International Group employs approximately 450 professionals and utilizes the latest technologies and innovations to ensure that the over 50 airlines and millions of annual passengers who rely on QAIA are assured truly world-class experiences.

With the COVID-19 pandemic necessitating the move to remote working, Airport International Group’s IT Team was keen to ensure that around-the-clock access to key services via shared desktops could be provided to employees (teams of technicians and skilled workers) in a secure and reliable manner. As a long-standing Nutanix customer, Airport International Group was quick to identify Nutanix Xi Frame as a perfect fit for its requirement.

Mr. Waseem Al Rousan, IT Director at Airport International Group, said, “Unlike other organizations that suddenly found themselves scrambling to deploy new cloud applications for their remote workers, we could offer our employees access to the same applications they were familiar with. This enabled us to maximize utilization of our existing IT infrastructure and eliminated unnecessary costs and learning curves. Providing employees with the secure access to applications using Xi Frame requires us to simply provide them with login credentials and a link – it’s that easy! Moreover, from an IT perspective, we have been impressed with the ease of deployment, intuitive and powerful web-based management interface, and the guaranteed availability that the solution offers.”

“The ease of use of Xi Frame meant we could easily and rapidly accommodate the business continuity requirements of each department in this challenging time. Moreover, rather than having to deal with the costs, complexities and inevitable slew of helpdesk requests typically associated with corporate VPNs, we could offer our new remote workers the most convenient, secure and intuitive access to the tools and applications they needed to stay productive,” said Mr. Al Rousan.

The timing of the deployment proved especially fortuitous as Airport International Group was in the midst of a mission-critical, multi-million dollar undertaking to migrate its Airport Management System (AMS), which controls everything, from the gates and immigrations services to check-in counters.

At the time when the Government of Jordan announced lock-down measures, consultants and implementation engineers were suddenly unable to travel to Amman. The team’s planned user acceptance and training programs for the new AMS solution looked to be in jeopardy. Using Xi Frame, in just a few hours, Airport International Group set up a fully equipped virtual training lab with 12 remotely accessible workstations. The team then simply provided users with an access link and login credentials, granting them instant, secure access to live training sessions. “We conducted four weeks of extensive training in this manner. The experience was seamless and our employees loved the ability to attend sessions from any location, and via any device,” said Mr. Al Rousan.

With members of the Operations Team also having to work remotely, Airport International Group decided to establish a virtual control room which enabled them to remotely access critical systems including the AMS, Airport Operations Data Base (AODB), Airport Resource Management System (RMS) in a secure manner. “Rigorous vulnerability testing gave us confidence that Nutanix’s solution could match our highest security expectations,” continued Mr. Al Rousan.

The feedback from users has been overwhelmingly positive and Mr. Al Rousan noted that the efforts of his team have been duly recognized by C-level executives and his counterparts in other departments. However, not ones to rest on their laurels, Mr. Al Rousan and his team are keen to build on their success. They are now exploring further use cases for Xi Frame which include enhanced support for BYOD (Bring Your Own Device) and robust ways to respond to unplanned business requirements. “This project has created a shift in mindset across our organization and there is a clear appetite to explore further VDI use cases. With its extremely dedicated on-ground support and range of market leading solutions, Nutanix has proven to be a reliable long-term technology partner. Over the last three years, we have become more and more invested into Nutanix and we will continue to strengthen our business relationship with them,” commented Mr. Al Rousan.

“Airport International Group like many organizations across the Middle East are dealing with the reality of needing to set up all their employees to work remotely, while still maintaining access to the same tools and applications they require to be productive. Through Xi Frame, we are proud to have been able to deliver an automated, fully managed cloud hosted service solution with ‘do-it-yourself’ simplicity that simplifies the continuous integration and continuous delivery of the digital workspace. We look forward to expanding our collaboration with Airport International Group in the near future,” concluded Aaron White, Regional Sales Director, Middle East at Nutanix.

Russian Helicopters to present upgraded Mi-171Sh at ARMY-2020 for the first time

The Russian Helicopters holding company (part of Rostec) will for the first time present upgraded Mi-171SH “Storm” military transport helicopter at the International Military-Technical Forum ARMY-2020. The helicopter, featuring enhanced protection and unique strike capabilities, was manufactured at the Ulan-Ude Aviation Plant.

The first flying prototype of the helicopter will be demonstrated at the forum. The presentation will also include the IBKV-17VP “glass cockpit” avionics suite and model of the new target sight system.

“Upgraded Mi-171Sh provides superior level of protection for both the crew and transported troops, thanks to titanium and kevlar armor protection, and the vehicle’s strike capabilities have been expanded to include guided missile weapons, noted the Director General of the Russian Helicopters, Andrey Boginsky.Mi-171SH is prepared for the most demanding combat and climatic conditions, which is why we named it “Storm” for our foreign customers. The name symbolizes its readiness to fight the elements, and on the other hand speaks of the helicopter’s flexible assault capabilities.” 

Mi-171Sh “Storm” is equipped with upgraded engines, new rotor system with an improved profile composite main rotor and X-shaped tail rotor, as well as latest version of the President-S on-board aircraft defense system. The armoring effectively protects the crew and the most parts of the helicopter, as well as the troop compartment. Two sliding doors on the sides and a ramp enable ultra-fast troop deployment.

In addition, the helicopter comes with improved armament, including 12.7 mm caliber machine guns and mdoern guided missile weapons with the OPS-24N-1L target sight system, which allows to engage against various ground and air targets.

JSC “Russian Helicopters”, a part of Rostec State Corporation, is a leading player in the global helicopter industry, the sole Russian designer and manufacturer of helicopters. The Holding Company was established in 2007 and is headquartered in Moscow. We operate five helicopter assembly plants, two design bureaus, component production and maintenance enterprises, aircraft repair plants and one helicopter service company providing after-sales support in Russia and abroad. The customers of the Holding Company are the Ministry of Defense, the Ministry of Home Affairs, EMERCOM of Russia, and other state customers, Gazpromavia, UTair Aviation company, large Russian and foreign companies.

State Corporation Rostec is one of the largest industrial companies in Russia. It unites more than 800 scientific and industrial organizations in 60 regions of the country. Its key areas of activity are transport engineering, electronics, medical technology, chemistry and innovative materials. Rostec holdings form three clusters: electronics, weapons and aviation. The corporation’s portfolio includes such well-known brands as AvtoVAZ, KAMAZ, Kalashnikov, Russian Helicopters, Uralvagonzavod and others. Rostec is active in the implementation of all 12 national projects. The company is a key provider of Smart City technology, it is engaged in the digitalization of public administration, industry and social sectors, and it is developing plans for the development of 5G wireless technologies, an Industrial Internet of Things, big data and blockchain systems. Rostec partners with leading world manufacturers such as Boeing, Airbus, Daimler, Pirelli and Renault. The corporation’s products are delivered to more than 100 countries worldwide. Almost a third of the company’s revenue comes from the export of high-tech products.

Ensuring Reliable Network Connectivity with High Availability Load Balancing

By: Adil Baghir, Technology Consultant Lead, Middle East & Africa at A10 Networks

The load balancer market is expected to grow to US$ 5billion by 2023, and trends such as mobile broadband, multi-cloud and hybrid cloud, virtualisation, remote working, and bring your own device (BYOD) have helped to fuel this growth. The result is that tremendous pressure is being placed on IT departments to ensure high availability for mission-critical applications such as ERP, communication and collaboration systems, and virtual desktop infrastructure (VDI).

The need for high availability

High availability, which is the ability of a system or system component to be continuously operational for a desirably long period of time, can help IT departments implement an architecture that uses redundancy and fault tolerance to enable continuous operation and fast disaster recovery. This is true for every element of the data centre—from high availability for applications to high availability for the load balancer or application delivery controller (ADC) that manages network traffic within and across the data centres in an environment.

High availability begins with identifying and eliminating single points of failure in the infrastructure that might trigger a service interruption—for example, by deploying redundant components to provide fault tolerance in the event that one of the devices fails. Load balancing, whether provided through a standalone device or as a feature of an ADC, facilitates this process by performing health checks on servers, detecting potential failures, and redirecting traffic as needed to ensure uninterrupted service.

While ensuring fault tolerance for servers is obviously critical, a high availability architecture must also consider the load balancing layer itself. If this becomes unable to perform its function effectively, the servers below run the risk of overflow, potentially compromising their own health as well as application performance and application availability. This makes redundancy just as important for the load balancer or ADC as for any other component in the data centre.

As with a high availability server cluster, there are several ways in which load balancers or ADCs can be deployed to provide high availability, including:

  • Active-standby – The most common configuration, the active-standby model includes a fully redundant instance of each ADC which is brought online only in the event that its primary node fails. Each active ADC can be configured differently, though each active-standby pair will share the same configuration.
  • Active-active – In this model, multiple similarly configured ADCs are deployed for routine use. In the event that one node fails, its traffic is taken over by one or more of the remaining nodes and load balanced as needed to ensure consistent service. This approach assumes that there will be sufficient capacity available across the cluster for it to function even when one ADC is unavailable.
  • N+1 – Providing redundancy at a lower cost than active-standby, an N+1 configuration includes one or more extra ADCs that can be brought online in the event that any of the primary ADCs fails.

In each case, rapid failover enables fault tolerance and disaster recovery for the load balancing function so that application performance and application availability are not affected by the failure. Failover and traffic management is typically managed through a version of the Virtual Router Redundancy Protocol redundancy standard.

Key high availability features for load balancing or ADC

In addition to ensuring high availability for your ADC, you should also make sure that your ADC provides high availability for the applications whose traffic it manages. In the event that a server fails, the ADC can reroute traffic to another available server in the cluster. Key features that enable this function include:

  • Load balancing methods – There are several methods that can be used for server selection, including round robin, least connections, weighted round robin, weighted least connections, fastest response, and more. Your ADC should offer all these options to allow the most suitable configuration for your environment and priorities.
  • Health monitoring – To ensure rapid failover with little or no downtime, server health should be continuously assessed based on a number of indicators, including:
    • Time series of total bytes in and out from each server
    • Time series of traffic rates (in Mbps) in and out from each server
    • Percent of error traffic over range
    • Number of good SSL connections
    • Average application server latency by service
    • Client-side latency SRTT, max, min, and average as a time series
    • Custom health checks such as measuring the response time for specific SQL database queries

Why this is so critical?

As enterprises become further dependent on the Internet to get business done, the threat of downtime can become a competitive disadvantage. Direct financial losses are substantial and a primary reason why businesses need to establish a high availability solution. Apart from the direct cost of downtime we also see business continuity, in terms of reputation and data loss, as another factor encouraging businesses to ensure high availability is implemented. Firstly, reputation will improve as the business and brand is known for its reliability versus its competitors. Secondly, reducing risk of data loss is essential as due to the severe penalties incurred under the terms of the GDPR. A highly available infrastructure also mitigates the negative impact of outages to revenue and productivity.

Phishing in a Pandemic: How to Combat Social Engineering Attacks

By Aamir Lakhani, Global Security Strategist and Lead Researcher for FortiGuard Labs.

Over the past few months, threat intelligence teams around the world have been tracking a significant increase in phishing attacks. These attacks coincide with a temporary drop in more traditional attacks, indicating that attackers, like workers, are modifying their efforts in order to accommodate changes due to the pandemic. In fact, our recent Global Threat Landscape Report details this and more.

More people are now working from home, and they are connecting back into the office from their home networks, and quite often, using their personal computers. Attackers are looking to target these users’ devices as a way into the corporate network or cloud. They attempt to lure unsuspecting victims into going to malicious sites, clicking on malicious links, or providing personal information via email or over the phone. They do this by impersonating legitimate organizations, such as the Centers for Disease Control and the World Health Organization, and offering fake informational updates, discounted masks and other supplies, and even promises of accelerated access to vaccines. Similar attacks target healthcare workers, political movements, or even the recently unemployed using the same sort of tactics.

Of course, such tactics are not new. We regularly see spikes in social engineering tactics around major events and catastrophes. Criminals respond to hurricanes and other natural disasters by pretending to be relief organizations, and major sporting events such as the World Cup where they lure victims with promises of discounted tickets or free streaming services.

Social Engineering Works

The reason that social engineering – an attack strategy that uses psychology to target victims – is so prevalent, is because it works. According to Verizon’s 2019 Data Breach Investigations Report (DBIR), nearly one-third of all data breaches involved phishing in one way or another. Cybercriminals are opportunistic, and they constantly prey on the only vulnerability that cannot be patched – humans.

It is a perpetual bombardment, every minute of the day, 24x7x365. And the odds are in the favor of the attacker, because they only need one unsuspecting person to click on a malicious link or attachment to open up the gates into the corporate network. And the truth is, nobody is immune – from entry-level employees, contractors, and interns at one end, on up to the C-Suite at the other. Business partners can also be indirect targets, mining them to obtain information to soften up targets. And for those of us now connecting to the office through our home networks, even our children are potential targets. Even seasoned security professionals get caught off-guard, in part because attack tactics have become more sophisticated. 

The goal, of course, is to gain access to our networks and sensitive information, either to steal it, corrupt it, or hold it for ransom. Most often, however, spear phishing is just the tip of the attack, and can easily go unnoticed by a victim who has been compromised. 

Training Alone is Not Enough

Of course, cybersecurity awareness has grown – up to 95% of employees now receive phishing training so they can learn to spot suspicious emails. This is important progress, as most breaches start with a phishing email followed by an unsuspecting employee who opens a malicious file or clicks on a bad link. Despite this training push, however, the number of employees that can tell the difference between a legitimate email and a malicious one remains frighteningly low. That’s because cybercriminals are experts at the art of masquerading, manipulating, influencing, and devising lures to trick targets into divulging sensitive data, and/or giving them access to our networks and/or facilities. 

There are two challenges at play here: employees are not taking cybersecurity seriously, and cyberattacks are getting even more sophisticated. For example, there are still far too many employees who never change their passwords, and two-thirds who still do not use a password management tool. At the same time, years of training people to identify phishing emails, avoid clicking on suspicious links, and follow best practices with their passwords have not panned out the way InfoSec professionals would have liked. 

The thing is, people know they need to use complex passwords, but they still use obvious choices that hackers can easily guess or discover by simply browsing a target’s social media sites, such as their pet’s name, the name or birthday of their child, or the year they graduated from college. 

The problem is not awareness – it is rooted in human behavior. Safe password practices – using long passwords with non-sensical characters and numbers, for example – take extra effort to implement. And when it comes right down to it, employees have shown that, for whatever reason, the extra effort is not worth their time and energy. 

Security 101: It’s All About People, Products, and Process 

The first step is to help employees feel like they are part of the security team. Helping them understand the repercussions of a security event, and how it can personally affect them, is a good place to start. Seeing connections such as these – between safe cybersecurity practices and the positive impact they feel they are making when everyone is engaged and responsible – should lead to direct improvements in how people behave when they are confronted with suspicious cyber behavior or questionable email or websites.

Next, give employees the tools they need to succeed. For example, in most organizations there is typically no easy way for employees to manage a multiplicity of complex passwords. If they choose to use a password management program, one which generates and manages complex passwords, it is only because of their own initiative. 

And finally, change the process by taking as much of the risk out of their hands as possible. Organizations need to update email security gatewayswith sandboxing and content disarm and reconstruction (CDR) tools to eliminate malicious attachments and links. They need to use web application firewalls to secure access to websites and identify and disable malicious links or embedded code or deploy cloud-based solutions and endpoint detection and response (EDR) tools so users are protected both on- and off-premise. They also need to add proactive access controls to ensure that connections originating from compromised home networks and personal devices can’t be used as a conduit for an attack.

Final Thoughts on Fulfilling Security Responsibilities

Regardless of the details, the most important key to improving an organization’s risk profile is still getting employees involved, one way or another, in accepting and fulfilling their security responsibilities. With training, the right tools, and effective processes, including support from top-tier company leaders, security teams can help everyone take cybersecurity seriously — and take a serious bite out of cybercrime.

Kodak Alaris to Host Webinar ‘Covid 19: Impact, Trends, and The Way Forward’

Kodak Alaris has announced that it will host a series of dynamic webinars from August through to October 2020 for organizations in the Middle East, Turkey, Africa and Russia (METAR) region. The first of the five free webinars, entitled ‘Covid 19: Impact, Trends, and The Way Forward’ will take place on Wednesday, August 26, 2020 at 3:00pm Gulf Standard Time (GST). Experts from the company will discuss the effects of the pandemic in the business sector and educate regional organizations on how to leverage everything from Work from Home (WFH) technologies,  Artificial Intelligence (AI) and Robotic Process Automation (RPA) to Cloud Computing in order to drive business continuity in these uncertain times.

Speaking about the webinars, Naji Kazak, General Manager, METAR at Kodak Alaris says, “2020 has highlighted the importance of business continuity and resilience. Now more than ever, it’s vital for businesses to focus on digital transformation. Imagine being able to utilise key technologies to improve efficiency, minimise costs, transform business processes, and streamline remote team collaboration, all whilst improving customer engagement. As a leading provider of information capture solutions that simplify business processes, Kodak Alaris through its webinars aims to show organizations just how to do that.”

In the first 1-hour webinar Kodak Alaris will break down:

  • How COVID-19 has changed the business landscape
  • Predicted work trends post-pandemic
  • Digital transformation strategies to streamline business continuity and collaboration whilst working remotely
  • How to leverage RPA and AI and Cloud Computing for optimal results
  • Ways to maximise efficiency, simplify collaboration, and cut costs simultaneously

There will be a Q&A at the end of the webinar. The schedule of the webinars is as follows:

COVID-19: Impact, Trends, and The Way Forward

Wednesday, August 26, 2020, 03:00 PM GST

Delivering a Better Patient Experience at Lower Cost

Wednesday, September 09, 2020, 03:00 PM GST

Helping Government Agencies Serve Citizens

Wednesday, September 23, 2020, 03:00 PM GST

BFSI – Automate Business Processes to Improve Customer Experience and Enhance Compliance

Wednesday, October 07, 2020, 03:00 PM GST

Coping with the Diversity of Data in the Retail and Logistics Markets

Wednesday, October 21, 2020, 03:00 PM GST

To register for the webinars, please click on the following link

eufy security shines at the Transformational Leadership awards 2020

Smart Home and security products from eufy security shines at the Transformational Leadership awards 2020

Anker Innovations’ eufy Security is delighted to receive the Innovative Home Security Technology of the Year award from tahawultech.com held virtually to celebrate the top technology leaders that have illustrated remarkable vision by helping enterprises and stakeholders navigate their way during the current period of uncertainty.

Faraz Mehdi

Faraz Mehdi, Regional Sales Head at Anker Innovations MEA said, “We are delighted to receive the Innovative Home Security Technology of the Year specially as eufy Security products have proven to be a hero brand by being the eyes on the ground for many families and businesses during the pandemic, including front liners who were separated from their families and away from their home over long periods of time.”

As travellers were stranded in different parts of the world, having eufy Security at home meant they could keep an eye on stranded properties, speak with elderly relatives or stay connected with colleagues at the office with a two-way communication as well as give instructions to staff when needed.

According to Syed Sameer, Senior Sales & Operation Manager of GCC, Eufy Security Smart Security changes the perception of security as you can monitor from anywhere and trigger alarm for unwanted intrusion instead of being tied down to a big screen in a room. Users can also use Design Motion alert as needed since we are living in an era of Digital Connect and Apps by using smart integration like Alexa, Google assistant & Apple home kit. It will enable the flexibility of voice command.

The eufy Security range includes 365 days of Battery life, weather proof (IP67), Encrypted Local storage for outdoor cameras, Pet & Human Alerts for indoor cameras and house entrance monitoring through video doorbells.

Eufy security products store, process, and calculate user data locally using military grade encryption and does not upload user data to the server, allowing users to control their own data.

The development of artificial intelligence has provided a wider space for technology and products. It uses deep learning algorithms to identify people and faces to remove false positives, and further optimizes the algorithm to identify vehicles, animals, and express delivery. Users can choose to configure preferences themselves.

Anker Innovations is known globally for new age connected, functional devices, security solutions and unique and innovative consumer products in smart home appliances.

 

Anker Innovations’ eufy Security receives Innovative Home Security Technology of the Year award

Smart Home and security products from eufy security shines at the Transformational Leadership awards 2020

Anker Innovations’ eufy Security is delighted to receive the Innovative Home Security Technology of the Year award from tahawultech.com held virtually to celebrate the top technology leaders that have illustrated remarkable vision by helping enterprises and stakeholders navigate their way during the current period of uncertainty.

Faraz Mehdi, Regional Sales Head at Anker Innovations MEA said, “We are delighted to receive the Innovative Home Security Technology of the Year specially as eufy Security products have proven to be a hero brand by being the eyes on the ground for many families and businesses during the pandemic, including front liners who were separated from their families and away from their home over long periods of time.”

Faraz Mehdi

As travellers were stranded in different parts of the world, having eufy Security at home meant they could keep an eye on stranded properties, speak with elderly relatives or stay connected with colleagues at the office with a two-way communication as well as give instructions to staff when needed.

According to Syed Sameer, Senior Sales & Operation Manager of GCC, Eufy Security Smart Security changes the perception of security as you can monitor from anywhere and trigger alarm for unwanted intrusion instead of being tied down to a big screen in a room. Users can also use Design Motion alert as needed since we are living in an era of Digital Connect and Apps by using smart integration like Alexa, Google assistant & Apple home kit. It will enable the flexibility of voice command.

The eufy Security range includes 365 days of Battery life, weather proof (IP67), Encrypted Local storage for outdoor cameras, Pet & Human Alerts for indoor cameras and house entrance monitoring through video doorbells.

Eufy security products store, process, and calculate user data locally using military grade encryption and does not upload user data to the server, allowing users to control their own data.

The development of artificial intelligence has provided a wider space for technology and products. It uses deep learning algorithms to identify people and faces to remove false positives, and further optimizes the algorithm to identify vehicles, animals, and express delivery. Users can choose to configure preferences themselves.

Anker Innovations is known globally for new age connected, functional devices, security solutions and unique and innovative consumer products in smart home appliances.