<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/endpoint-security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Endpoint-security ]]></title>
                <link>https://www.itpro.com/tag/endpoint-security</link>
        <description><![CDATA[ All the latest endpoint-security content from the ITPro team ]]></description>
                                    <lastBuildDate>Tue, 02 Sep 2025 14:35:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Blackpoint Cyber and NinjaOne partner to bolster MSP cybersecurity ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/blackpoint-cyber-and-ninjaone-partner-to-bolster-msp-cybersecurity</link>
                                                                            <description>
                            <![CDATA[ The collaboration combines Blackpoint Cyber’s MDR expertise with NinjaOne’s automated endpoint management platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UP7UDyxxbN5WDTQxe8ni9d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Sep 2025 14:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:description>                                                            <media:text><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:text>
                                <media:title type="plain"><![CDATA[A glowing shield formed from glowing points and lines in an abstract landscape to represent security controls.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Lq6brmg8jRUNyRnyv5SBxe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed detection and response (MDR) provider Blackpoint Cyber has announced a new partnership with NinjaOne.</p><p>The collaboration aims to enhance and streamline cybersecurity for MSPs as they continue to navigate an evolving threat landscape.</p><p>By combining Blackpoint’s MDR expertise with NinjaOne’s endpoint management platform, the move promises to simplify security and deliver improved response times through rapid threat detection. For MSPs, that means greater visibility, security, and control across every endpoint in their IT estate.</p><p>In an announcement, Blackpoint Cyber CEO Gagan Singh said the partnership is built on a shared commitment to helping IT teams tackle modern security threats.</p><p>“By aligning our expertise in threat detection and response with NinjaOne’s leadership in endpoint management, we’re laying the foundation for a smarter, more unified approach to cyber security—one that reduces complexity while strengthening resilience,” he explained.</p><p>Founded in 2014 by former NSA cybersecurity expert Jon Murchison, Blackpoint Cyber specializes in MDR services for MSPs and security teams, backed by an around-the-clock, human-led Security Operations Center (SOC) for continuous monitoring and threat response.</p><p>NinjaOne provides a cloud-native automated endpoint management platform that works to provide visibility, security, and control across all customer endpoints, simplifying management, patching, and environments at scale.</p><p>The pair’s collaboration targets SMBs and MSPs as they expand their digital footprints and face increasingly sophisticated security threats in the era of AI.</p><p>According to a <a href="https://www.mastercard.com/us/en/news-and-trends/stories/2025/small-business-cybersecurity-study.html"><u>forthcoming survey</u></a> from payment giant Mastercard, which quizzed more than 5,000 SMB owners across four continents, almost half of its respondents said their business had been hit by a cyber attack, with one in five of those impacted either filing for bankruptcy or closing their doors for good.</p><p>“In the face of increasingly sophisticated and dynamic cyber security threats, MSPs require robust, enterprise-grade solutions that support rapid threat detection, response orchestration, and enforcement of a consistent security posture across distributed environments,” commented Erzan Uygur, NinjaOne’s vice president of strategy and operations. </p><p>“Blackpoint Cyber shares our customer-first mindset, and together we are delivering a modern security experience built on proactivity, adaptability, and reliability.”</p><h3 class="article-body__section" id="section-more-from-channelpro"><span>MORE FROM CHANNELPRO</span></h3><ul><li><a href="https://www.itpro.com/business/acquisition/okta-acquires-axiom-security-to-enhance-privileged-access-management">Okta acquires Axiom Security to enhance privileged access management</a></li><li><a href="https://www.itpro.com/business/leadership/ninjaone-appoints-industry-veteran-paul-redding-to-lead-msp-partnerships">NinjaOne appoints industry veteran Paul Redding to lead MSP partnerships</a></li><li><a href="https://www.itpro.com/software/development/hexaware-partners-with-replit-to-take-secure-vibe-coding-to-the-enterprise">Hexaware partners with Replit to take secure 'vibe coding' to the enterprise</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WithSecure Elements EPP and EDR review: Endpoint protection on a plate ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/withsecure-elements-epp-and-edr-review-endpoint-protection-on-a-plate</link>
                                                                            <description>
                            <![CDATA[ An affordable cloud-managed solution with smart automated remediation services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZmxwDBoSBA7a9LgbKckLkh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m6jGbfbeH5aMmmCMVLTMxP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Dec 2023 12:00:47 +0000</pubDate>                                                                                                                                <updated>Tue, 12 Dec 2023 15:37:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m6jGbfbeH5aMmmCMVLTMxP-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The WithSecure Elements EPP and EDR interface on the ITPro background ]]></media:description>                                                            <media:text><![CDATA[The WithSecure Elements EPP and EDR interface on the ITPro background ]]></media:text>
                                <media:title type="plain"><![CDATA[The WithSecure Elements EPP and EDR interface on the ITPro background ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m6jGbfbeH5aMmmCMVLTMxP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Finnish company WithSecure offers a complete suite of security solutions all easily managed from its Elements Security Center cloud portal. Its Endpoint Protection (EPP) module provides a firm foundation and a modular approach allows you to enhance it with other WithSecure components as required.</p><p>In this review, we test EPP and take a closer look at the Endpoint Detection and Response (EDR) module. EDR takes a proactive stance on cyberattacks, providing advanced threat detection capabilities, full attack analysis, and automated responses for isolating compromised systems.</p><p><br></p><h2 id="withsecure-elements-epp-and-edr-setup-xa0">WithSecure Elements EPP and EDR: Setup </h2><p>EPP offers great platform support, too: it protects Windows and macOS workstations, Android and iOS mobiles, plus Windows and <a href="https://www.itpro.com/linux/28951/the-benefits-of-linux-servers">Linux servers</a>. And it includes patch management for Windows OSes as standard. Workstation deployment is swift; we used our portal&apos;s EPP dashboard to email a download link to users, with the agent taking three to four minutes to install and link up with the portal account.</p><p><br></p><p>Protection starts immediately. The agent grabs a predefined profile that enables essential security functions such as real-time malware scanning, a <a href="https://www.itpro.com/security/firewalls/355328/how-to-build-your-own-firewall-with-pfsense">firewall</a>, and browsing protection. Customizing profiles is simple: you clone the read-only ones provided, tweak their settings as desired, and use the devices page to assign them to multiple endpoints.</p><p>There&apos;s a lot to play with: profiles enforce web protection with a list of 32 URL categories, can stop users from interacting with the agent, and control access to all kinds of local hardware such as USB sticks, optical drives, and wireless and Bluetooth devices.</p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="C89Mj92FzceM24PFbsdQpZ" name="C89Mj92FzceM24PFbsdQpZ.jpg" caption="" alt="Endpoint protection or endpoint security interlocking gears" src="https://cdn.mos.cms.futurecdn.net/C89Mj92FzceM24PFbsdQpZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a></p></div></div><p>An EPP Premium subscription enables application controls and WithSecure&apos;s DataGuard, which uses behavioral rules to detect potential <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> activity. Rollback is a smart new feature that provides instant ransomware protection for Windows systems. It tracks apps classed as unknown and, if they exhibit any dubious behavior, it closes them down and automatically rolls back all the file and Registry changes they made.</p><p>Don&apos;t worry if the app turns out to be legit, as all changes are stored in locally protected quarantine areas and can be restored by users. It can also initially run in safe mode, where it only reports on unauthorized changes.</p><p>You can keep a close eye on the action using the security events view and set up email alerts for multiple recipients. EPP has fast reaction times: when we introduced malware to our test clients events were posted in the portal almost immediately, with alert messages winging in three or four minutes later.</p><p>EDR provides deep analysis of detected threats and uses the same agent as EPP, so adding this module later on automatically activates it for all endpoints. It features WithSecure&apos;s broad context detection (BCD), which cuts through alert avalanches by highlighting suspicious events so you can see clearly if an attack is taking place.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p7aA9ci4nXKjR9pXsMHoAN" name="Mapping the digital attack surface_thumb.png" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/p7aA9ci4nXKjR9pXsMHoAN.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn about how malicious actors target the attack surface<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370166/mapping-the-digital-attack-surface">DOWNLOAD NOW</a></p></div></div><p>BCD shows a filtered view of all detected threats. Selecting one takes you to a threat analysis page, with a process tree showing how the potential malware developed and what it interacted with. If you don&apos;t like what you see, you can isolate all affected devices with one click.</p><p>An EPP/EDR subscription also enables the new outbreak control feature. The modules team up to track device changes, and if anything occurs to critical areas such as IP addresses and reverse DNS or new <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> is detected, a stricter rule is applied automatically to affected devices.</p><p>Its high levels of automation make WithSecure a great choice for SMBs that want endpoint protection on a plate. It&apos;s simple to deploy, offers a wealth of security features, and all modules are easily managed from the Elements cloud portal.</p><p><em>This content originally appeared on ITPro&apos;s sibling magazine PC Pro. For more information and to subscribe, please visit PC Pro&apos;s </em><a href="https://subscribe.pcpro.co.uk/"><em>subscription site</em></a><em>. </em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Eset Protect Cloud Advanced review: An impressive arsenal of endpoint protection features ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/eset-protect-cloud-advanced-review-an-impressive-arsenal-of-endpoint-protection-features</link>
                                                                            <description>
                            <![CDATA[ Policy management is complex, but Eset offers an affordable and flexible cloud-hosted solution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xfobpLhyos9jijNkoWCZmn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AZCxafxg2d2ChFciyw36NW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Dec 2023 12:00:08 +0000</pubDate>                                                                                                                                <updated>Mon, 11 Dec 2023 14:54:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AZCxafxg2d2ChFciyw36NW-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Eset Protect Cloud Avanced interface]]></media:description>                                                            <media:text><![CDATA[The Eset Protect Cloud Avanced interface]]></media:text>
                                <media:title type="plain"><![CDATA[The Eset Protect Cloud Avanced interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AZCxafxg2d2ChFciyw36NW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Eset Protect is a versatile endpoint protection solution, and it can be run either on-premises or in the cloud. That said, Eset&apos;s focus is clearly on the latter, and it makes more sense for SMBs as Protect Cloud is easier to deploy and doesn&apos;t need a dedicated hosting server.</p><p>The product is available in four versions. Entry delivers a cloud console and protection services for workstations, servers, and mobiles, while the Advanced version on review adds full disk encryption and advanced protection against zero-day threats with cloud sandboxing. Mail and <a href="https://www.itpro.com/desktop-software/19337/office-365-review">MS365</a> protection appears in the Complete version but endpoint detection and response (EDR) is available only in the top-of-the-line Elite enterprise option.</p><h2 id="eset-protect-cloud-advanced-setup-xa0">Eset Protect Cloud Advanced: Setup  </h2><p>Installation is simple. After creating our cloud account, we pushed the agent to our Windows workstations and servers by downloading them from the portal or sending an email to users so they could handle it themselves. Either way, the agent took only two minutes to load and then ran a full system malware scan in the background.</p><p>Protection is instant, with the agents being assigned a default set of security profiles that enable essential functions such as real-time malware scanning, Eset&apos;s LiveGrid cloud-based reputation system, host-based intrusion prevention (HIPS), and Ransomware Shield services. Blanket protection is achieved as Eset initially places every client in a top-level computer group that has all the built-in default policies assigned to it.</p><p>Groups add extra flexibility. You can create static or dynamic ones where the latter are automatically populated with systems based on criteria such as their OS version if they&apos;re a mobile device or have a problem. In either case, you can add custom policies to each group and fine-tune their settings as required.</p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="C89Mj92FzceM24PFbsdQpZ" name="C89Mj92FzceM24PFbsdQpZ.jpg" caption="" alt="Endpoint protection or endpoint security interlocking gears" src="https://cdn.mos.cms.futurecdn.net/C89Mj92FzceM24PFbsdQpZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a></p></div></div><p>There are settings aplenty: you can customize the scanning engine, password-protect the agent, add <a href="https://www.itpro.com/security/firewalls/355328/how-to-build-your-own-firewall-with-pfsense">firewall</a> rules, activate <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing protection</a>, block botnets, and apply removable device access rules. One drawback is that there are so many policy options it took us a while to figure out what some of them do and how to set them up. There&apos;s a heap of web-browsing protection features, with filtering rules offering a choice of over 140 URL categories to block or allow. Eset&apos;s LiveGuard can also be enabled so suspicious files are sent to its cloud sandbox first to see if they harbor anything unpleasant.</p><p>The portal offers a range of dashboards, with the default non-customizable view showing the status of all protected devices and alerts. The security overview page is even more informative; it displays unresolved threat detections, scanning engine performance, and the top ten systems at most risk. Clicking on any element takes you to the relevant page for more information.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p7aA9ci4nXKjR9pXsMHoAN" name="Mapping the digital attack surface_thumb.png" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/p7aA9ci4nXKjR9pXsMHoAN.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how malicious actors target the attack surface</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370166/mapping-the-digital-attack-surface">DOWNLOAD NOW</a></p></div></div><p>Reporting services are outstanding, with a wide range of options provided for all security aspects, and 23 for <a href="https://www.itpro.com/malware/28076/what-is-malware">malware detection</a> activity alone, all of which can be run with one click. You can create your own using templates, schedule them to run regularly, and send their output to multiple email addresses.</p><p>Notification features are equally impressive, as you can choose from a list of 24 predefined alerts, add your own, and decide who to email them to. Eset doesn&apos;t hang around sending them, either; when we triggered its scanners with genuine malware and web threats, events were posted in the portal in one minute and alert emails landed two minutes later.</p><h2 id="eset-protect-cloud-advanced-is-it-worth-it-xa0">Eset Protect Cloud Advanced: Is it worth it? </h2><p>Eset Protect Cloud Advanced is good value, with a three-year subscription for 50 devices panning out at only $31 (£26) per device per year. Policy management is overly complicated, but Eset delivers an impressive arsenal of endpoint protection features backed up by great reporting and alerting tools.</p><p><em>This content originally appeared on ITPro&apos;s sibling magazine PC Pro. For more information and to subscribe, please visit PC Pro&apos;s </em><a href="https://subscribe.pcpro.co.uk/"><em>subscription site.</em></a><em> </em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The channel is helping to bake in endpoint security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-channel-is-helping-to-bake-in-endpoint-security</link>
                                                                            <description>
                            <![CDATA[ With endpoints expanding, how can the channel approach security with integrated technologies that protect every device? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aWN4Gnx9Aq56jCrsZvbcED</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ha5D2d4V5pYoYqemueYv5X-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Jul 2023 15:36:06 +0000</pubDate>                                                                                                                                <updated>Tue, 11 Jul 2023 13:29:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/QST9gbWQZLs5T4KfoM2StL.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ha5D2d4V5pYoYqemueYv5X-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of a laptop with a padlock to suggest endpoint security]]></media:description>                                                            <media:text><![CDATA[Graphic of a laptop with a padlock to suggest endpoint security]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of a laptop with a padlock to suggest endpoint security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ha5D2d4V5pYoYqemueYv5X-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security has transformed as enterprises have become more flexible organizations with widely dispersed workforces, with this shift demanding a new approach to endpoint security for channel suppliers. </p><p>There’s an effort to integrate robust <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> into a plethora of digital devices typically used across a company&apos;s processes and workers. Workers migrating to their homes and other remote sites has shifted the debate towards integrated approaches that include a core hardware component. </p><div  class="fancy-box"><div class="fancy_box-title">Industry Insight</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GjG7G9PWu8nsh3iPm6pGfL" name="GjG7G9PWu8nsh3iPm6pGfL.jpg" caption="" alt="Somebody typing at their computer with a digital padlock and other illustrations" src="https://cdn.mos.cms.futurecdn.net/GjG7G9PWu8nsh3iPm6pGfL.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/how-the-channel-can-help-secure-the-future-of-work">How the channel can help secure the future of work</a></p></div></div><p>A more holistic approach is needed to make sure comprehensive security is available for every digital device, <a href="https://h20195.www2.hp.com/v2/getpdf.aspx/4AA8-0080ENW.pdf"><u>says IDC</u></a> in a report assessing the security landscape, in partnership with HP. It highlights hardware-based “root-of-trust” technologies that can bake security in below the level of the operating system, in particular.</p><p><a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>Ransomware</u></a>, <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a>, <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, and compromised email systems are all clear and present dangers for enterprises and their digital devices in use. With multi-channel attacks also becoming more common, VARs and MSPs are pivoting to incorporating a hardware-based approach into cyber security defences. </p><p>"Customers are increasingly looking to purchase services rather than just devices, and channel partners can offer those who have concerns about hybrid workers’ security add-ons like remote management capabilities for <a href="https://www.itpro.com/technology/virtual-desktop-infrastructure-vdi/357507/top-daas-providers-amazon-vs-microsoft-vs"><u>desktop as a service (DaaS) models</u></a>,” Dr Ian Pratt, HP’s global head of security for personal systems tells <em>ITPro</em>. “Services like these, which add an extra layer of protection at the endpoint for their customers, are a great opportunity to generate a recurring revenue stream for the Managed Service Provider.”</p><p>An end-to-end approach to digital security is a clear trend in the channel marketplace. Enterprises are looking to reduce their tech stack to reduce costs and improve efficiency, and enhance digital security in a landscape business owners see as increasingly risky to their operations.</p><h2 id="built-in-endpoint-security-xa0">Built-in endpoint security </h2><p>One attack vector that’s continued to expand is firmware updates, with examples including <a href="https://www.itpro.com/security/malware/368655/researchers-uncover-mysterious-windows-rootkit-actively-exploited-2016"><u>LoJax</u></a> and MosaicRegressor. Hardware used by dispersed workforces has been under sustained attack for several years, and having firmware authentication built into the hardware is a robust response to this level of cyber attack. Channel suppliers are increasingly seeing demand for this kind of integrated security as businesses look to create a more robust and flexible cyber security envelope.</p><p>Increasing the availability of devices with built-in endpoint security for channel suppliers is a differentiator in the marketplace. Businesses have always bought best-of-breed, and when their security needs are considered, the choice available is expanding. VARs are progressively being asked to simplify the procurement of devices and, with these purchases, also support more comprehensive security. VARs&apos; relationship with vendors lets them influence how security hardware architectures should advance to meet the defensive needs of their clients.</p><p>Built-in endpoint security including HP’s Wolf Security for Business, as well as Intel’s Boot Guard and Hardware Shield protect devices by defending the BIOS. Vendors are also embracing artificial intelligence (AI), with notebook PCs from Lenovo and Asus embedding this technology to deliver built-in security that VARs can offer to businesses seeking to boost cyber security through hardware procurement.</p><p>“Advanced security tooling can work alongside network security and user authentication to protect endpoint devices by increasing visibility, prevent tampering, or malware infections utilising machine learning techniques to move beyond signature-based protection,” says Rick Hemsley, UK&I government and public sector cyber security lead, EY. “This combined approach will enhance the overall security posture of the business and provide greater protection against evolving threats.”</p><h2 id="the-channel-x2019-s-role-in-safeguarding-enterprises">The channel’s role in safeguarding enterprises</h2><p>Nearly a third (29%) of businesses attribute a data breach in hardware to an external attack, according to <a href="https://www.itpro.com/security/endpoint-security/356810/bios-security-the-next-frontier-for-endpoint-protection"><u>Forrester</u></a>. For many companies protecting their remote workers have become a priority. Deploying <a href="https://www.itpro.com/security/27098/best-vpn-services"><u>VPNs</u></a>, for example, has formed the basis of secure remote network connectivity. However, as threat actors have become more sophisticated, and workers now use multiple devices in several locations, a hardware approach to digital security is expanding to become the foundation onto which all other defenses are built.</p><p>“Hardware-based security offers better protection from manipulation and interference than its software-based counterpart because it’s more difficult to alter or attack the physical device or data entry points,” says Michela Menting, digital security research director at technology research firm ABI Research.</p><p>In addition, Chris Vaughan, VP, technical account manager, Tanium, also points out that enhanced hardware security doesn&apos;t add more complexity for users: "The good news is that while it takes a lot of work to hack hardware security devices, it doesn’t require reskilling on the employees’ part to take advantage of the added security.”</p><p>Moving forward, the channel will play a vital role in ensuring their customers have the latest hardware that defends their businesses from the expanding threat landscape enterprises see expanding.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">What is zero trust?</a></p></div></div><p>“Consider the threat landscape, security requirements, scalability, integration, performance impact, ease of deployment and management, vendor reputation and support, TCO, future-proofing and training,” says Nathan Charles, head of customer experience at cyber security specialist OryxAlign. </p><p>“Choose a hardware-based endpoint security solution that aligns with your needs, protects endpoints, and integrates well with existing infrastructure, all while being cost-effective and providing reliable support.”</p><p>For business leaders looking to enhance their digital security at the time of new hardware purchases, the built-in endpoint security options now available across channel providers are expanding.</p><p>The accepted approach to creating robust cyber security has been to protect devices with security software that runs above the operating system, with that layer increasingly vulnerable. Channel partners are now critical to create the <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero-trust</a> security all enterprises need. This level of protection must begin at the hardware level to ensure comprehensive defenses are always operational.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why zero trust strategies fail ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/five-zero-trust-pitfalls-to-avoid</link>
                                                                            <description>
                            <![CDATA[ Zero Trust is the gold standard for organizations in protecting systems from cyber attacks, but there are many common implementation pitfalls businesses must avoid ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BL5vEydYUKbCiZEKFHDJZi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/D6ZFS3xgHqChAfbizUojYN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 May 2023 07:00:24 +0000</pubDate>                                                                                                                                <updated>Fri, 05 May 2023 08:44:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sandra Vogel ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/D6ZFS3xgHqChAfbizUojYN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A shot of a woman sat at her desk in a dimly lit office, with her eyes closed and a stressed expression on her face, her hands raised to massage her temples. In the foreground, blue code is rising to either side of the frame to indicate complexity in the task that her unseen screen is showing]]></media:description>                                                            <media:text><![CDATA[A shot of a woman sat at her desk in a dimly lit office, with her eyes closed and a stressed expression on her face, her hands raised to massage her temples. In the foreground, blue code is rising to either side of the frame to indicate complexity in the task that her unseen screen is showing]]></media:text>
                                <media:title type="plain"><![CDATA[A shot of a woman sat at her desk in a dimly lit office, with her eyes closed and a stressed expression on her face, her hands raised to massage her temples. In the foreground, blue code is rising to either side of the frame to indicate complexity in the task that her unseen screen is showing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/D6ZFS3xgHqChAfbizUojYN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zero trust strategies are one in which nothing and nobody can use an organization’s digital resources without being verified. This isn’t just about verification upon entry into the system, but also when individuals are moving around within the system.</p><p>Such a strict regime is required because a cyber criminal or an automated agent might breach a system and move about freely within it if, once inside, there were no verification checks. <a href="https://www.itpro.co.uk/security/network-security/358282/what-is-zero-trust"><u>Zero trust</u></a> has, therefore, become a gold standard for <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> in today’s enterprise landscape. </p><div  class="fancy-box"><div class="fancy_box-title">More on zero trust</div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">What is zero trust?</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model">How to build a zero trust model</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/366925/four-key-benefits-zero-trust-can-bring-to-your-channel-firm">Four key benefits zero trust can bring to your channel firm</a></p></div></div><p>Implementing zero trust requires a root and branch examination of the entire technology estate. The organization needs to identify its vulnerabilities, both technological and human, and figure out <a href="https://www.itpro.co.uk/security/cyber-security/368543/six-cyber-security-holes-you-need-to-plug-now"><u>how to best plug the holes</u></a>. This should be done in the context of minimal disruption to everyday workload, and an understanding that zero trust is not a one-time fix but an evolving idea. </p><p>Implementing such a regime, however, isn’t without its potential pitfalls and pain points. It’s a time-consuming and complex process that requires input from many roles across the organization, as well as external expertise. </p><h2 id="1-failing-to-look-beyond-the-corporate-network">1. Failing to look beyond the corporate network</h2><p>When hybrid working is the norm, people will be using all manner of locations to work including their homes and public networks. Everything is part of the <a href="https://www.itpro.co.uk/security/cyber-security/369983/what-is-attack-surface-management"><u>attack surface</u></a> and the organization should trust nothing. Every endpoint is a potential vulnerability. </p><p>This also, by the way, includes devices that might sit outside the network such as printers, security cameras, and other <a href="https://www.itpro.co.uk/cloud-computing/28037/what-is-iot"><u>Internet of Things (IoT)</u></a> devices.</p><p>A thorough audit of devices will be required before work begins, with a strategy in place to protect each device and to ensure that each device is updated as regularly as needed. </p><h2 id="2-implementing-zero-trust-too-quickly">2. Implementing zero trust too quickly</h2><p>Implementing a Zero Trust approach might require significant changes to technologies and also to how people go about their daily business. Go too fast and it’s easy for mistakes to happen. Single devices or applications might slip through the net of compliance assurance at the time of implementation or later. Security hygiene – ensuring that <a href="https://www.itpro.co.uk/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>all hardware and software is up to date and patched</u></a> – is a central aspect of zero trust.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/27713/the-importance-and-benefits-of-effective-patch-management">Patch management vs vulnerability management</a></p></div></div><p>Ensuring every piece of hardware and software is known and its security can be optimized at all times takes time. It is important to allocate enough time to managing everything from the outset, and to develop processes for ensuring existing and new acquisitions are accommodated going forward. </p><h2 id="3-ignoring-the-principles-of-least-privileged-access">3. Ignoring the principles of least privileged access</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FRD22ayLuvtE64VjirP8YB" name="Why_Customer_Identity-thumb.png" caption="" alt="Whitepaper cover with image of multi generation colleagues smiling together at table" src="https://cdn.mos.cms.futurecdn.net/FRD22ayLuvtE64VjirP8YB.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Businesses at work</strong></p><p class="fancy-box__body-text"><em>Discussing the most popular apps and top performing apps of 2022, and the rise of Zero Trust security</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/collaboration/368250/businesses-at-work"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Least privileged access refers to the policy of ensuring users only have the bare minimum permission level to do what they need to do. It’s designed to keep access to resources tightly controlled and prevent the kind of sprawling access through systems that can be most helpful to bad actors. </p><p>However, it can be difficult to implement, particularly in the case of <a href="https://www.itpro.co.uk/cloud/34476/what-is-multi-cloud"><u>multi-cloud environments</u></a> in which data and apps are hosted with different providers, each with different policies and security protocols. In the end, budget, available time, and sheer workload can mean in-house teams assign wider privileges than necessary.</p><p>Using a class of software called entitlement management, or cloud infrastructure entitlement management, access to a multitude of software, systems, devices, and cloud platforms can be managed centrally. </p><h2 id="4-failing-to-focus-on-users">4. Failing to focus on users</h2><p>An organization’s employees are not the only stakeholders it’ll have to work with. There may also be contractors, suppliers, purchasers, delivery partners, and others. Presenting users with new protocols, hoops to jump through, and processes – without understanding whether these are seen as barriers – can cause resentment and foster non-compliance strategies. Users who work around security protocols are users who create risk. </p><p>High-quality user education on how to achieve compliance with security protocols is only part of the solution. People must also understand why certain behaviors are required, and be comfortable with any required actions or approaches. <a href="https://www.itpro.co.uk/security/cyber-security/370285/can-we-ever-achieve-cyber-security-buy-in"><u>Creating a ‘culture of security’ across the organization</u></a> takes time, effort, and leadership – from chief officers, senior managers, and line managers. </p><h2 id="5-assuming-zero-trust-is-bought-into-by-default">5. Assuming zero trust is bought into by default</h2><p>Every organization is different. Its technology setup will be unique. How people use technology will vary too. Where its people work will vary too, including in-office, remote or hybrid, one city, with national offices, or multinational. The variables are many and complex. While certain principles and approaches apply to zero trust, their implementation in any one organization will be unique. Simply going to a vendor and expecting them to do everything without any input is a fallacy.  </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/cyber-security/368543/six-cyber-security-holes-you-need-to-plug-now">Six cyber security holes you need to plug now</a></p></div></div><p>Organizations need to commit their own staff resource to work alongside vendors and understand that the implementation of zero trust will take time. This is and will continue to be an ongoing process.</p><p>With cyber attacks showing no signs of slowing down, and with organizations of all sizes and in all markets potentially vulnerable, securing data and networks is paramount. It’s no longer adequate to take a piecemeal approach to this challenge. A zero trust approach can help an organization implement a risk-based strategy toward data security. It isn’t without pitfalls, and organizations should be alive to these, and willing to commit the time and energy required to work them through. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Defender “obliterating” users with false password alerts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/windows/microsoft-defender-obliterating-users-with-false-password-alerts</link>
                                                                            <description>
                            <![CDATA[ Windows 11 devices have been affected by the Defender for Endpoint error, which flags SSO domains as problematic ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2dFnJbT2GAv4nD2nSMhMPU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zAYaas3CxLBLjrBvXghy8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Apr 2023 11:22:25 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Apr 2023 15:42:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zAYaas3CxLBLjrBvXghy8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo under magnifying glass, which appears in color in place of the Windows key on a standard white Microsoft keyboard]]></media:description>                                                            <media:text><![CDATA[Microsoft logo under magnifying glass, which appears in color in place of the Windows key on a standard white Microsoft keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo under magnifying glass, which appears in color in place of the Windows key on a standard white Microsoft keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zAYaas3CxLBLjrBvXghy8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>System administrators have reported an abudance of alerts from Microsoft Defender for Endpoint, with multiple sites falsely flagged as having reused passwords.  </p><p>A number of admins complained that they are receiving alerts that read “Password reuse activity was detected by Microsoft Defender for Endpoint” with no clear explanation from the software.</p><p>Users denied having reused passwords on the sites flagged by the system, while others have stated that multiple subdomains of software as a service (SaaS) platforms have been flagged as containing password reuse.</p><p>Many admins indicated that the problem could have arisen from Defender for Endpoint incorrectly flagging <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso" target="_blank"><u>single sign-on (SSO)</u></a> domains as needing attention.</p><p>“We now have 17 alerts today for Password Reuse. Everyone I have looked at is a false positive,” one user <a href="https://www.reddit.com/r/DefenderATP/comments/12s6qcc/comment/jgyz7gj/" target="_blank"><u>wrote</u></a>.</p><p>They also noted that some alerts come with “about:blank” as the supposed domain containing password reuse, and that in one case a user was accused of “password reuse over three services, listing three subdomains of the same SaaS”.</p><p>The warning message itself is seemingly absent from Microsoft documentation.</p><p>"We determined these are false positive results and we have resolved this," a Microsoft spokesperson told <em>ITPro</em>.</p><p>"No customer action is needed."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uH2UFsZsWQr9xxCirTLXZP" name="More than a number_Your risk score explained_listing.jpg" caption="" alt="The back of two colleagues looking, and pointing at, a dual screen workstation in an office" src="https://cdn.mos.cms.futurecdn.net/uH2UFsZsWQr9xxCirTLXZP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>More than a number: Your risk score explained</strong></p><p class="fancy-box__body-text"><em>Understanding risk score calculations</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/risk/370277/more-than-a-number-your-risk-score-explained"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>According to accounts from multiple commenters, the alerts appear to only be coming from Windows 11 devices and almost all relate to supposed password reuse on Microsoft domains.</p><p>“Yup same here, we are getting obliterated with alerts. The alerts are only coming from Win 11 devices,” <a href="https://www.reddit.com/r/sysadmin/comments/12s8gr9/any_one_else_all_of_sudden_getting_password_reuse/" target="_blank"><u>wrote</u></a> another.</p><p>Dozens of new commenters have appeared in a six-month-old thread covering the same issue, seeking help with inexplicable alerts that they too have received.</p><p>In a Twitter exchange on the issue, one user <a href="https://twitter.com/GlorytoSpoon/status/1646006140231098369" target="_blank"><u>suggested</u></a> that the problem could be linked to <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/protect-passwords-with-enhanced-phishing-protection/ba-p/3631881" target="_blank"><u>enhanced phishing protection</u></a> brought in by Microsoft in September 2022.</p><p>This is intended to warn users against reusing passwords.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">All this is related to SSO and OAuth and the only URI being flagged is https://t.co/oZk8RKMK00 (with various URLs)But yeah, fun trying to explain the user is not even entering a password 😬<a href="https://twitter.com/nemesis09/status/1648962153842462720">April 20, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>Microsoft Defender has incorrectly inundated users with warnings on multiple prior occasions. </p><p>In September 2022, the app <a href="https://www.itpro.com/security/cyber-security/368972/microsoft-defender-causes-mass-confusion-after-legitimate-apps-trigger-ransomware-alerts" target="_blank"><u>caused confusion after flagging software as ransomware</u></a>, including popular browsers and productivity apps such as Chrome, <a href="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms" target="_blank"><u>Slack</u></a>, and <a href="https://www.itpro.com/web-browsers/24526/what-is-microsoft-edge" target="_blank"><u>Microsoft Edge</u></a>.</p><p>Further false positives were addressed by Microsoft in January 2023, after a <a href="https://www.itpro.com/operating-systems/microsoft-windows/369873/microsoft-releases-scripts-to-restore-shortcuts-windows-defender-faulty-update" target="_blank"><u>faulty update deleted shortcuts</u></a> that had been incorrectly identified as malware. </p><p>Microsoft released <a href="https://www.itpro.com/development/programming/368567/coding-vs-programming-vs-scripting-whats-the-difference" target="_blank"><u>scripts</u></a> to fix the issue, though some administrators stated that these were imperfect and failed to fully rectify matters.</p><p>A recent update for Microsoft Defender Antivirus also led to confusion among devs, who upon updating received a warning stating that Local Security Authority (LSA) Protection - a process used to authenticate and oversee user logins - had been disabled.</p><p>Microsoft <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#3048msgdesc" target="_blank"><u>released</u></a> a workaround for the issue, though a subsequent update appears to have disabled LSA altogether on Windows 11 systems in favor of a new process titled ‘Kernel-mode Hardware-enforced Stack Protection’.</p><p><em>This article has been updated to include a statement from Microsoft.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ZeroFox to snap up LookingGlass in $26 million acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/zerofox-to-snap-up-lookingglass-in-dollar26-million-acquisition</link>
                                                                            <description>
                            <![CDATA[ Cyber security provider says LookingGlass will bolster its platform’s global attack surface intelligence capabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">w9b2JDHD4Zj7pixhjPHMvQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tx4YLGu5Htdkoj4xaBbCXC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Apr 2023 11:31:03 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Apr 2023 13:53:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tx4YLGu5Htdkoj4xaBbCXC-1280-80.jpg">
                                                            <media:credit><![CDATA[ZeroFox]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ZeroFox logo against a dark blue background]]></media:description>                                                            <media:text><![CDATA[ZeroFox logo against a dark blue background]]></media:text>
                                <media:title type="plain"><![CDATA[ZeroFox logo against a dark blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tx4YLGu5Htdkoj4xaBbCXC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Enterprise cyber security provider ZeroFox has announced it has struck a definitive agreement to acquire LookingGlass Cyber Solutions for $26 million.</p><p>Headquartered in Reston, Virginia, LookingGlass specializes in external attack surface management (EASM) and global threat intelligence that provides organizations with curated intelligence on critical assets, risks, and sectors.</p><p>These capabilities will now be integrated into ZeroFox’s External Cybersecurity Platform to enable visibility into external attack surface assets and vulnerabilities, as well as serve up improved actionable intelligence.</p><p>“The acquisition of LookingGlass is a natural extension of our strategy to provide our customers with a single end-to-end platform for protecting their external attack surface from increasingly sophisticated cyber attacks,” said James C. Foster, chairman and CEO of ZeroFox. </p><p>“We are bringing together passionate teams that have been partners for years, and proven world-class capabilities across <a href="https://www.itpro.com/security/cyber-security/369983/what-is-attack-surface-management"><u>attack surface management</u></a>, digital risk protection, <a href="https://www.itpro.com/security/cyber-security/370051/information-overload-a-key-barrier-to-effective-threat-intelligence-mandiant"><u>threat intelligence</u></a>, and breach response to continue our leadership in external cyber security.”</p><p>LookingGlass’ internet-facing surface intelligence <a href="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics"><u>data lakes</u></a> provide public sector organizations, large enterprises, and industry security alliances with extensive discovery, intelligence, and cyber defense capabilities. </p><p>The firm said these tools allow organizations to identify and assess threats in support of remediation strategies against the most sophisticated cyber attacks.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eGrnhMDULkAtUKVawtuXPT" name="The_Cyber_Asaasin_Manual_Thumbnail.png" caption="" alt="Assassin's Creed hooded figure with Outlook, Salesforce, and Google icons in circles around him" src="https://cdn.mos.cms.futurecdn.net/eGrnhMDULkAtUKVawtuXPT.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Kaseya)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The &apos;cyber aSaaSin&apos; manual</strong></p><p class="fancy-box__body-text"><em>Providing valuable insights to identify SaaS data enemies and win the battle against SaaS data threats</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-cyber-asaasin-manual"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“The mission at LookingGlass is to protect our customers by providing unmatched attack surface intelligence for global threat visibility and cyberattack disruption,” said Bryan Ware, LookingGlass CEO, who will join the ZeroFox executive team as part of the transaction. </p><p>“Joining ZeroFox allows us to expand the capabilities we provide security teams to defend against cyber criminals and nation-state actors.”</p><p>As a <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas"><u>SaaS</u></a>-based cyber security provider, ZeroFox’s wider platform combines advanced <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a> analytics, digital risk and privacy protection, and full-spectrum threat intelligence, with a portfolio of breach, incident, and takedown response capabilities to help organizations protect themselves against cyber threats.</p><p>Back in August 2022, the company began trading publicly on the Nasdaq stock market, in a move uncommon for a pure-play cyber threat intelligence company. </p><p>However, last month it was <a href="https://simplywall.st/stocks/us/software/nasdaq-zfox/zerofox-holdings/news/zerofox-holdings-nasdaqzfox-dips-11-this-week-as-increasing" target="_blank"><u>reported</u></a> that ZeroFox Holdings had dipped 11% in the wake of increasing losses, with the company seeing an overall share price decline of 75% over the last twelve months.</p><p>Despite this, the firm continues to make moves through acquisitions and partnerships. Earlier this month, it announced a new partnership with Google Cloud to detect <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> domains and warn users of dangerous URLs. </p><p>Websites marked by ZeroFox as malicious will see Google send out a warning message to its 5 billion-strong userbase advising them not to click.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The top malware and ransomware threats for April 2023 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/the-top-malware-and-ransomware-threats-for-april-2023</link>
                                                                            <description>
                            <![CDATA[ New ransomware gangs and malware abound as hackers continue to evolve their tactics ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NKveEGmf2wzVUN4mjRA3v9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wxwQh5vaMoKWvRvc4tsgMe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Apr 2023 11:53:32 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Apr 2023 07:28:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones is the News and Analysis Editor at ITPro, CloudPro, and ChannelPro. As the brands’ leader for news, he welcomes pitches on all topics, and he personally still reports breaking news on the topics of cyber security, software, and Big Tech firms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;He has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Connor is currently in his third year at ITPro, but has been a journalist for much longer, having written for the likes of Red Bull Esports and UNILAD. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wxwQh5vaMoKWvRvc4tsgMe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top malware and ransomware cause &#039;system hacked&#039; alert to appear on a computer screen]]></media:description>                                                            <media:text><![CDATA[Top malware and ransomware cause &#039;system hacked&#039; alert to appear on a computer screen]]></media:text>
                                <media:title type="plain"><![CDATA[Top malware and ransomware cause &#039;system hacked&#039; alert to appear on a computer screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wxwQh5vaMoKWvRvc4tsgMe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Alerts for new malware strains and active ransomware groups were spread widely across the security industry throughout March and the first half of April.</p><p>New strains of malware targeting organizations of all kinds were discovered, harnessing infection vectors that may not already be in their threat models.</p><p>It’s highly important that organizations stay on top of emerging threats and patch their systems against the most prevalent types of attacks. </p><p>Patching isn’t always an easy task to do, especially in large organizations, but as a bare minimum, it’s advised that active threats are protected against if a more comprehensive patch operation isn’t feasible.</p><p>Knowing what cyber security vulnerabilities and zero days to patch is one thing, but it’s equally important to pay close attention to the ways malware is evolving to bypass security detections so the workforce can be aware of what suspicious activity to look out for.</p><p>Here you’ll find a complete list of the most dangerous malware and ransomware threats of April 2023.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:5000px;"><p class="vanilla-image-block" style="padding-top:73.18%;"><img id="vs9yTRo5yQxteYSCkYk7Qi" name="onenote-GettyImages-1237632217.jpg" alt="OneNote logo on a smartphone against white background with Windows logo on it" src="https://cdn.mos.cms.futurecdn.net/vs9yTRo5yQxteYSCkYk7Qi.jpg" mos="" align="middle" fullscreen="" width="5000" height="3659" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="onenote-exploited-to-bypass-macro-attacks">OneNote exploited to bypass macro attacks</h2><p>Ever since Microsoft made the long-awaited decision to <a href="https://www.itpro.com/security/cyber-security/368513/microsoft-confirms-vba-macro-backtrack-is-only-temporary"><u>disable VBA macros</u></a> in Office documents by default last year, cyber attackers have been experimenting with inventive ways to deliver malware in a trusted way.</p><p>Microsoft OneNote is installed on Windows by default, unlike Word, Excel, and PowerPoint, and can therefore allow all Windows users to open email attachments in the OneNote format regardless of whether they have a Microsoft 365 subscription.</p><p>The combination of using a malware-laden OneNote file to seem more legitimate and the weaker detection measures the application provides against embedded malware, now makes OneNote a more reliable threat vector than Office documents.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p7aA9ci4nXKjR9pXsMHoAN" name="Mapping the digital attack surface_thumb.png" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/p7aA9ci4nXKjR9pXsMHoAN.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Mapping the digital attack surface</strong></p><p class="fancy-box__body-text">Why global organisations are struggling to manage cyber risk</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/cyber-security/370166/mapping-the-digital-attack-surface"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Zscaler’s ThreatLabz researchers found that a variety of scripts and malware have been observed running after successful phishing attacks led victims to download and open the files.</p><p><a href="https://www.itpro.com/security/trojans/355479/four-steps-to-exterminating-rats-controlling-your-computer"><u>Remote access trojans (RATs)</u></a> and information stealers have been installed following successful attacks. </p><p>Researchers also <a href="https://www.zscaler.com/blogs/security-research/onenote-growing-threat-malware-distribution" target="_blank"><u>said</u></a> that MSHTA, WSCRIPT, and CSCRIPT can be executed from within OneNote, using multi-layered obfuscation techniques to evade detection. </p><p>CHM, HTA, JS, WSF, and VBS scripts are also supported via OneNote documents.</p><p>Organizations should inform their staff about the dangers of OneNote attachments in emails. If an email seems suspicious, it should be checked by the organization’s security team before downloading any attachments.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2329px;"><p class="vanilla-image-block" style="padding-top:55.26%;"><img id="ZLh8NqNMJxu2ezah4ARbhn" name="botnet-GettyImages-1398190099.jpg" alt="Mockup of a botnet and its different stages" src="https://cdn.mos.cms.futurecdn.net/ZLh8NqNMJxu2ezah4ARbhn.jpg" mos="" align="middle" fullscreen="" width="2329" height="1287" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="emotet-returns-again-with-new-tricks">Emotet returns again with new tricks</h2><p>Trend Micro announced in March that the <a href="https://www.itpro.com/security/cyber-security/370253/new-emotet-socially-engineers-evade-detection?utm_campaign=itpro_newsletter_20230314&utm_source=itpro_uk_newsletter&refid=8FF9B2F3D90B6CB87A72F4BDCC18B32F&utm_medium=email" target="_blank"><u>Emotet botnet has returned once again</u></a> after another of its trademark periods of downtime.</p><p>Emotet was observed mimicking replies in existing email chains, increasing the perceived legitimacy of responses rather than it being a cold email from an unrecognized sender.</p><p>While OneNote is being exploited to bypass Microsoft’s VBA macro defenses, Emotet instead deploys social engineering tactics to trick victims into manually re-enabling macros, allowing malicious Office documents to execute commands, like downloading DLLs, and install malware.</p><p>The new version of Emotet also uses binary padding - crafting large files, such as 500MB Word documents, to bypass security scans.</p><p>The prevailing advice is that workers should remain mindful that attempts to re-enable VBA macros will likely lead to malicious activity and should be flagged to the security team as soon as possible.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6500px;"><p class="vanilla-image-block" style="padding-top:53.85%;"><img id="L6DSTHdion3mCrSBkWnF9C" name="malware-GettyImages-1420039900.jpg" alt="Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security" src="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C.jpg" mos="" align="middle" fullscreen="" width="6500" height="3500" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="cl0p-overtakes-lockbit-in-ransomware-rankings">Cl0p overtakes LockBit in ransomware rankings</h2><p>Cl0p’s exploitation of the <a href="https://www.itpro.com/security/data-breaches/370409/the-goanywhere-data-breach-explained"><u>vulnerability in GoAnywhere MFT</u></a> propelled it to the top of Malwarebytes’ ransomware rankings for April, overtaking LockBit by a small margin.</p><p>The group claimed to have breached more than 130 organizations in a month including Proctor and Gamble, Virgin Red, Saks Fith Avenue, and the <a href="https://www.itpro.com/security/ransomware/370329/pension-protection-fund-confirms-employee-data-exposed-goanywhere-breach"><u>UK’s Pension Protection Fund (PPF)</u></a>.</p><p>Although Cl0p operates its own namesake ransomware program, many of the GoAnywhere-related breaches are thought not to have involved ransomware.</p><p>Regardless, it overtook LockBit this month after it dominated in March with 126 attacks. For context, the second-place gang from last month, ALPHV, only registered 32 attacks.</p><p>The reliability of LockBit was questioned earlier this month by DarkTracer International, accusing it of running an inefficient website on the dark web.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">The reliability of the RaaS service operated by LockBit ransomware gang seems to have declined. They appear to have become negligent in managing the service, as fake victims and meaningless data have begun to fill the list, which is being left unattended. pic.twitter.com/mfGhH93oYh<a href="https://twitter.com/darktracer_int/status/1646125694127345664">April 12, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>LockBit responded by attempting another of its ‘pranks’, like it has done in the past with the likes of <a href="https://www.itpro.com/security/ransomware/369449/lockbit-repeats-pr-stunt-as-thales-ransomware-investigation-reveals-no-breach"><u>Mandiant and Thales</u></a>, but it ultimately backfired when its team, which doe snot speak English natively, confused DarkTracer with Cambridge, UK-based Darktrace. </p><p>This forced Darktrace to publicly deny that it had been attacked by LockBit, and the vent prompted many in the community to mock the ransomware gang’s mistake.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">Earlier today @darktracer_int stated Lockbit ransomware group was declining and becoming negligent in managing their service.Lockbit responded to them on their onion domain. pic.twitter.com/3ISlwIZtPw<a href="https://twitter.com/vxunderground/status/1646433205916925953">April 13, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>A patch for the GoAnywhere MFT vulnerability has been available since February and should be applied as a priority if it hasn’t been already to prevent further attacks from Cl0p.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FRRDLEFjuVCi2yG5QJMqoU" name="malware-getty.jpg" alt="Blue and gold mockup of motherboard with lock denoting malware and security" src="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="microsoft-signals-new-ransomware-gang-on-the-block-in-patch-tuesday">Microsoft signals new ransomware gang on the block in Patch Tuesday</h2><p>In yet another <a href="https://www.itpro.com/windows/microsoft-april-patch-tuesday-password-feature"><u>error-strewn Patch Tuesday</u></a> from Microsoft, it highlighted an actively exploited zero-day vulnerability.</p><p>Researchers identified the new ransomware gang, known as Nokoyama, exploiting the vulnerability since February.</p><p>Trend Micro’s <a href="https://www.trendmicro.com/en_us/research/22/c/nokoyawa-ransomware-possibly-related-to-hive-.html" target="_blank"><u>report</u></a> on the group linked the operation to the <a href="https://www.itpro.com/security/cyber-crime/369952/fbis-landmark-takedown-hive-ransomware-unlikely-significant-impact"><u>recently taken down Hive</u></a> group, which claimed attacks on the likes of New York Racing Association, Tata Power, and <a href="https://www.itpro.com/security/368903/altice-reportedly-hit-by-hive-ransomware-attack"><u>Altice</u></a>.</p><p>The researchers said the two groups share a number of similarities in their attack chain such as the use of Cobalt Strike and <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> emails, but noted Hive’s <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware"><u>double extortion</u></a> technique hasn’t been used by Nokoyama yet.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:8000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="o7aE2bbqGF7TeVESbqgZfb" name="malware-GettyImages-1345812496.jpg" alt="Mockup of brigtly coloured alert with code and a warning sign, reading 'malware'" src="https://cdn.mos.cms.futurecdn.net/o7aE2bbqGF7TeVESbqgZfb.jpg" mos="" align="middle" fullscreen="" width="8000" height="4500" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="fusioncore-malware-as-a-service-operation">FusionCore malware as a service operation</h2><p>Researchers at CYFIRMA detailed an emerging threat actor believed to be operating from inside Europe earlier this month.</p><p>FusionCore has been described as a ‘one-stop shop’ for malware services, with a wide range of tools on offer, plus hacker-for-hire services too.</p><p>The malware on offer has been described as “cost-effective, yet customizable”, and its ransomware affiliate scheme provides both a ransomware payload and affiliate software to manage negotiations with victims.</p><p>“FusionCore typically provides sellers with a detailed set of instructions for any service or product being sold, enabling individuals with minimal experience to carry out complex attacks,” CYFIRMA <a href="https://www.cyfirma.com/outofband/the-rise-of-fusioncore-an-emerging-cybercrime-group-from-europe/" target="_blank"><u>said</u></a>.</p><p>A number of indicators of compromise (IOCs) can be found on the researcher’s blog.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WUxCWQvnDGZ7w4W2rRGJE" name="china-hacker-security-getty.jpg" alt="Laptop with china flag on screen and code overlaid, denoting Chinese hacking" src="https://cdn.mos.cms.futurecdn.net/WUxCWQvnDGZ7w4W2rRGJE.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="chinese-hackers-targeting-products-with-no-edr-support">Chinese hackers targeting products with no EDR support</h2><p>Mandiant’s blog in March highlighted a threat actor, which it tracks as UNC3886, targeting products that aren’t supported by endpoint detection and response (EDR) products.</p><p>These include firewalls, IoT devices, hypervisors, and VPNs from Fortinet, SonicWall, Pulse Secure, and others.</p><p>Dozens of attacks have been investigated by the security firm and have involved the exploitation of zero-day vulnerabilities and the use of custom malware to both steal credentials and maintain a lasting presence in a victim’s IT environment.</p><p>Full details of the attack scenarios, their methods, and the products being targeted can be found in <a href="https://www.mandiant.com/resources/blog/fortinet-malware-ecosystem" target="_blank"><u>Mandiant’s detailed blog</u></a>.</p><p>The takeaway for admins here is that they should be communicating regularly with vendors to ensure any potential threats can be mitigated.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3840px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VUDZptndWJDCBjYxYfV9u6" name="python-code-GettyImages-1346778393.jpg" alt="Python code on a screen" src="https://cdn.mos.cms.futurecdn.net/VUDZptndWJDCBjYxYfV9u6.jpg" mos="" align="middle" fullscreen="" width="3840" height="2160" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="developers-beware-of-w4sp-copycats">Developers beware of W4SP copycats</h2><p>Sonatype said that one of the key malware trends for March this year was a continuation of malicious packages being uploaded to the PyPI registry - a destination for developers to download and use software built by the <a href="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer"><u>Python community</u></a>.</p><p>It noticed a number of packages mimicking the W4SP stealer - a popular information stealer since the middle of 2022 used to carry out <a href="https://www.itpro.com/security/cyber-security/369082/c-suite-executives-say-software-supply-chain-hacks-have-become-chief-concern"><u>software supply chain attacks</u></a>.</p><p>“These types of packages are a cause for concern as they pose a serious threat to developers who may inadvertently download and install them,” it <a href="https://blog.sonatype.com/malware-monthly-march-2023" target="_blank"><u>said</u></a>.</p><p>The packages have since been taken down, but with the ongoing attempts to poison the software supply chain, and the damage such attacks can cause - think <a href="https://www.itpro.com/security/malware/370353/3cx-ceo-state-sponsored-hackers-behind-supply-chain-malware-attack"><u>3CX as a recent example</u></a>, then developers need to be especially vigilant when downloading open-source software, ensuring that it’s safe to use.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A roadmap to Zero Trust with Cloudflare and CrowdStrike ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/370076/a-roadmap-to-zero-trust-with-cloudflare-and-crowdstrike</link>
                                                                            <description>
                            <![CDATA[ Achieve end-to-end protection across endpoints, networks, and applications ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3Q6QNe3GHw97W6Rim5XKC6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x2PxhiyBDcMwJVd3mJGTVR-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Feb 2023 17:32:27 +0000</pubDate>                                                                                                                                <updated>Mon, 13 Mar 2023 13:32:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Apps]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/x2PxhiyBDcMwJVd3mJGTVR-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Webinar screen with topic discussion and contributor photos]]></media:description>                                                            <media:text><![CDATA[Webinar screen with topic discussion and contributor photos]]></media:text>
                                <media:title type="plain"><![CDATA[Webinar screen with topic discussion and contributor photos]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x2PxhiyBDcMwJVd3mJGTVR-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Every security leader understands the challenges that cloud migration and distributed workforces pose to their corporate network and endpoints, and the importance of moving to a Zero Trust architecture. But the journey to Zero Trust can seem complex and difficult.</p><p>This recorded session shares how Cloudflare offers one uniform, composable platform to make this journey extremely simple and effective for organisations of all sizes.</p><p>Watch now to discover how joint customers of Cloudflare and CrowdStrike use both platforms to achieve end-to-end protection across endpoints, networks, and applications.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MotKo6zNeTjhW4aSt5zm36" name="" alt="Cloudflare logo" src="https://cdn.mos.cms.futurecdn.net/MotKo6zNeTjhW4aSt5zm36.png" mos="https://cdn.mos.cms.futurecdn.net/MotKo6zNeTjhW4aSt5zm36.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49963/cloudflare-uk-exp-zero-trust-abm-syndication-efpl098805?locale=1&p=false&wp=10850"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is attack surface management? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/369983/what-is-attack-surface-management</link>
                                                                            <description>
                            <![CDATA[ Instigate attack surface management to anticipate where cyber attackers might strike and avoid falling prey ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bsYBwLBsFpS17ru7PijLbv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o4sTtCMXCug5SJJav5HyzL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Feb 2023 08:00:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o4sTtCMXCug5SJJav5HyzL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cybersecurity expert examines an attack]]></media:description>                                                            <media:text><![CDATA[A cybersecurity expert examines an attack]]></media:text>
                                <media:title type="plain"><![CDATA[A cybersecurity expert examines an attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o4sTtCMXCug5SJJav5HyzL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Attack surface management (ASM) might sound like something the SAS might get involved in, but this most definitely refers to the world of networks and <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369758/the-scariest-cyber-security-horror-stories-of-2022" data-original-url="/security/cyber-security/369758/the-scariest-cyber-security-horror-stories-of-2022">The scariest cyber security horror stories of 2022</a></p></div></div><p>The attack surface is the sum of all possible entry points that a cyber criminal might use to gain unauthorised access to systems, networks or data. For a typical business, this might include devices, websites, servers, software platforms and even people. Every time the enterprise adds a server, deploys a new application, sets up a <a href="https://www.itpro.com/security/27098/best-vpn-services" target="_blank" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">virtual private network (VPN)</a> or enrols more users, the surface grows.</p><p>That’s where ASM can come in handy. Taking the perspective of the hacker into account, this process involves discovering, analysing and mitigating the vulnerabilities and potential vectors that altogether comprise the attack surface. Proper attack surface management highlights the targets and understands the level of risk associated with the attack vectors in question. </p><h2 id="what-does-attack-surface-management-involve">What does attack surface management involve?</h2><p>Attack vectors are methods that attackers use to gain access, such as <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, API exploits or zero-day vulnerabilities. The attack surface is the target against which those methods can be deployed. So <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> is an attack vector; an individual whose trust is exploited is part of the attack surface.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52558420&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>Figuratively speaking, your attack surface generally has three sides. One is the digital attack surface: that’s everything connected to your network, from apps to websites and the ports they connect through. Then there’s the physical attack surface – servers, <a href="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy" target="_blank" data-original-url="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy">mobile devices</a>, <a href="https://www.itpro.com/networking/27835/best-wi-fi-routers" target="_blank" data-original-url="https://www.itpro.com/networking/27835/best-wi-fi-routers">routers</a> and even <a href="https://www.itpro.com/hardware/367538/best-all-in-one-printers" target="_blank" data-original-url="https://www.itpro.com/hardware/367538/best-all-in-one-printers">printers</a>. Finally, the social attack surface comprises staff, contractors and so forth. You can of course further break down these divisions with greater levels of granularity, but the digital, physical and social aspects broadly cover everything.</p><h2 id="what-steps-can-my-business-take-to-shrink-its-attack-surface">What steps can my business take to shrink its attack surface? </h2><p>This is very much the hard part. Because the attack surface is always changing and evolving, managing it can seem like a Sisyphean task. </p><h3 class="article-body__section" id="section-1-minimise-complexity"><span>1. Minimise complexity</span></h3><p>As a business expands, its IT environment tends to accumulate legacy endpoints and applications – prime targets for attackers. Security processes grow in complexity too, creating more potential for exploitable mistakes. Cut out <a href="https://www.itpro.com/business-strategy/digital-transformation/369535/how-to-manage-a-blend-of-legacy-and-modern-it" target="_blank" data-original-url="https://www.itpro.com/business-strategy/digital-transformation/369535/how-to-manage-a-blend-of-legacy-and-modern-it">legacy assets</a> wherever you can, and segment your network to limit the potential for intrusions.</p><h3 class="article-body__section" id="section-2-know-your-vulnerabilities"><span>2. Know your vulnerabilities</span></h3><p>Static vulnerability scanning is valuable, but real attackers are more cunning and resourceful than any automated test. Schedule <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" target="_blank" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">regular penetration testing</a>, and include “red team” exercises to obtain a realistic, adversary’s-eye view of your vulnerabilities.</p><h3 class="article-body__section" id="section-3-raise-awareness"><span>3. Raise awareness</span></h3><p>Many compromises start at the social attack surface. Promote awareness of threats, from the shop floor to the boardroom – and support it with upstream security controls. Don’t play the blame game, but embrace <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" target="_blank" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust</a> principles to make it as hard as possible for anyone, whether inside the organisation or outside of it, to breach security.</p><h3 class="article-body__section" id="section-4-seek-out-an-asm-solution"><span>4. Seek out an ASM solution</span></h3><p>There are numerous ASM platforms out there, including ASM as a service. Most of these solutions address ASM from four perspectives: asset discovery, classification, risk prioritisation and ongoing monitoring. If you’re familiar with the security mindset you might wonder why there’s no risk remediation step – but that’s the sum of the other parts.</p><h2 id="what-do-asm-services-offer-in-practical-terms">What do ASM services offer, in practical terms?</h2><p>The asset discovery part is all about making sure you know what you’re working with. You can’t begin to manage the risks to your IT systems unless you’re fully apprised of exactly what and where those systems are. Creating a map of potential entry points can immediately highlight which are the most attractive to a threat actor.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/penetration-testing/354693/ethics-of-red-team-security-testing-questioned-in-new-report" data-original-url="/security/penetration-testing/354693/ethics-of-red-team-security-testing-questioned-in-new-report">Ethics of red team security testing questioned in new report</a></p></div></div><p>This leads onto classification, where assets are analysed with regard to what they connect to, the attack routes they could enable, and the vulnerabilities they may contain. Once the process is complete, it’s time to prioritise, so that issues that represent the highest risk to the business can be dealt with most urgently. Those classifications, those priorities, will likely be subject to constant change, of course; that’s where the ongoing monitoring comes in, to ensure your organisation remains on top of its ASM game.</p><h2 id="what-s-the-best-asm-solution-for-my-company">What’s the best ASM solution for my company?</h2><p>As always in cyber security, there’s no one-size-fits-all answer. The best solution for your business won’t be the same as for someone else’s, perhaps for reasons of scalability, integration or cost. We can, however, give you some names to look up: Coalfire, CyCognito, ImmuniWeb, Randori, SearchLight, SpectralOps and UpGuard are all good places to start your ASM research.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Going passwordless ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless</link>
                                                                            <description>
                            <![CDATA[ Something you are, or something you have, could be more important than a password you know in the near future ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gFLpzoAsrEnfKmzKDL7anB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jan 2023 13:05:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Passwords: they can be tricky at the best of times. Proper password hygiene is one of the most important factors in endpoint security, as it keeps sensitive data secure and prevents threat actors from getting into important systems. </p><p>But despite the risks, the use of weak or recycled passwords continues to be a problem even amongst IT professionals. While systems such as two factor authentication have been used as an extra layer of security, groups like the FIDO Alliance and World Wide Web Consortium have been working to make passwords a thing of the past, in favour of more secure methods.</p><p>This week, we spoke to Richard Meeus, EMEA director of security & technology strategy for Akamai Technologies, to explore the solutions driving secure sign ons, and how the sector can adapt to this change.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52362789&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights">Highlights</h2><p>“The criminals know that we are bad with passwords, and we just use something like our pet's name or something like that. And it's relatively easy for people to get the passwords or, as most commonly happens, an organisation will be breached and their password and username database will be leaked out onto the internet. And then, those usernames and passwords are reused against websites all over the planet.”</p><p>“The concept of security authentication has always been based around, sort of, one of three concepts. So there's something you know, which is a password, something you are, which is your biometric. So use your face print or your thumbprint, or something like that. Or something you have, which could be a USB token, or something that you can punch numbers into as a handheld device. So one of those three things, and we've relied upon the something you know, predominantly, which is the password.”</p><p>“Anything that we can do within security that actually makes lives easier for end users, and makes them more secure, is a good thing. And reducing passwords, reducing the use of passwords is a good thing, because nobody likes them.”</p><p><a href="https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless" data-original-url="https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a></li><li><a href="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what" data-original-url="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what">If not passwords then what?</a></li><li><a href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="https://www.itpro.com/security/29705/what-are-biometrics">What are biometrics?</a></li><li><a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">What is two-factor authentication?</a></li><li><a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue" data-original-url="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">What is multi-factor authentication (MFA) fatigue and how do you defend against attacks?</a></li><li><a href="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication" data-original-url="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication">How to implement passwordless authentication</a></li><li><a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">Best password managers</a></li><li><a href="https://www.itpro.com/software/368045/best-free-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368045/best-free-password-managers-in-2022">Best free password managers</a></li><li><a href="https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better" data-original-url="https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better">The sooner the FIDO Alliance can shut down passwords, the better</a></li><li><a href="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security" data-original-url="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security">Will FIDO passwordless authentication save cyber security?</a></li><li><a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">The top 12 password-cracking techniques used by hackers</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: Going passwordless ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uoaH42Y3cyW7SJ5m8ruydz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jan 2023 12:40:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>​​This automatically-generated transcript is taken from the IT Pro Podcast episode</em> ‘<a href="https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless" data-original-url="https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless">Going passwordless</a>'. <em>We apologise for any errors.</em></p><h2 id="rory-bathgate">Rory Bathgate </h2><p>Hi, I'm Rory Bathgate. </p><h2 id="jane-mccallion">Jane McCallion </h2><p>And I'm Jane McCallion </p><h2 id="rory">Rory</h2><p>And you're listening to the IT Pro Podcast, where this week we're discussing passwordless security.</p><h2 id="jane">Jane </h2><p>Good password hygiene is one of the most important factors in endpoint security. If passwords are managed improperly, threat actors can access critical systems, and the use of weak or recycled passwords continues to be a problem even amongst IT professionals.</p><h2 id="rory-2">Rory </h2><p>In place of legacy systems such as one time passcodes sent via SMS, groups like the FIDO Alliance and World Wide Web Consortium are working to make passwords a thing of the past.</p><h2 id="jane-2">Jane </h2><p>Today, we're speaking to Richard Meeus, EMEA director of security & technology strategy for Akamai Technologies, to discuss the solutions that can enable more secure sign ons, and how the sector is handling this change. Richard, thank you for joining us.</p><h2 id="richard-meeus">Richard Meeus </h2><p>Thank you very much, delighted to be here.</p><h2 id="jane-3">Jane </h2><p>So everyone's been using passwords on their computers for decades. How come now they're being called insecure?</p><h2 id="richard">Richard</h2><p>Well, I don't think it's now that they're being thought of as being insecure, I think they've been insecure for a long time. I mean, passwords have been utilised as an authentication mechanism for centuries. And it's always been fairly trivial to find out what they were. What we've been doing recently is with a plethora of websites and services, especially after the pandemic that everybody went online. Everybody reused the same passwords. People, humans, users we're rubbish at passwords, we have a limited capacity to remember passwords. And therefore we tend to use the same one repeatedly. Or we just try and be very clever and add a ‘1’ to the end, to try and make it uncrackable. And because of this, the criminals know this, the criminals know that we are bad with passwords, and we just use something like our pet's name or something like that. And it's relatively easy for people to get the passwords or, as most commonly happens, an organisation will be breached and their password and username database will be leaked out onto the internet. And then, those usernames and passwords are reused against websites all over the planet. And if you look at some of the database repositories, the legitimate repositories which are used for you to see if you have had your username and password put out onto the internet, there's about 10 million — 10 billion sorry, username and password combinations in there. That's a lot more than the internet-connected population. In fact, it's about four times more than the internet connected population. So there's a good chance there's a criminal somewhere who has your username and your password, and is trying them on a number of websites. Right now. What we want to do is move to a situation where that risk is mitigated to a certain degree.</p><h2 id="rory-3">Rory </h2><p>With this risk of reusing passwords, certainly, or generating weak passwords. I know that a lot of businesses rely on things like password managers, can those be continued to be relied upon by businesses?</p><h2 id="richard-2">Richard </h2><p>I think password managers, as well as with organisations looking to protect their users, it's important that password managers are used properly. A password manager is a great tool, I use one for my home business use for creating complex passwords, complex unique passwords. So I don't know what my passwords are, because they are a random bunch of 25 alphanumeric and special characters. I have no idea what they are. And the password manager remembers that, so every single asset that I talk to has a unique password. Password managers, I think, are very useful especially in the short term and within enterprises. It's not so great for end users because the vulnerable people in society, and people who are not familiar with technology, may find them quite difficult to use. But in enterprises they're certainly very useful because it allows you to create complex, distinct, unique user passwords for every single application that you go to. My passwords are often 25 characters long and a stream of unrecognisable characters, and numbers, and estimation marks, and question marks, and special characters that will be impossible to guess or impossible to do a brute force hack upon. So I think they definitely have a position, especially in the enterprise.</p><h2 id="jane-4">Jane </h2><p>I mean, Richard, once again, I also use password managers. Are there risks associated with those? Recently we have seen LastPass, breached. And every time I see something like that my heart goes in my mouth. And then you realise, actually, your passwords are typically safe. But is there any kind of real chance that either the database itself could be breached particularly say, if you're reusing password for them? Or something a bit more sophisticated than that?</p><h2 id="richard-3">Richard</h2><p>Well, I think a lot of the time, there's always been that concern about “if I put all my eggs in one basket, is that creating more of a risk? I think that's been the typical response to people not wanting to use password managers. But I think when you actually look at the security that is around the actual passwords, and how they're stored and how they're utilised, I think that that overweighs any of that concern about the risk about having all your passwords in one basket, or eggs in one basket. So I don't think there's a chance that if you, people do use them, I think they are very good, they're very useful. It again, outweighs the risk of just having very simple passwords that you can try to remember.</p><h2 id="jane-5">Jane </h2><p>Yeah. </p><h2 id="rory-4">Rory </h2><p>So in response to this, to focus on passwordless security as an option. When someone says passwordless security, I mainly think of biometric security, fingerprints, facial recognition. Is this the most promising avenue for this technology? And what are some of the other methods that are in place?</p><h2 id="richard-4">Richard</h2><p>Yeah, well I mean the concept of security authentication has always been based around sort of one of three concepts. So there's something you know, which is a password, something you are, which is your biometric. So use your face print or your thumbprint, or something like that. Or something you have, which could be a USB token, or something that you can punch numbers into as a handheld device. So one of those three things, and we've relied upon the something you know, predominantly, which is the password. And we tend to use the something you have, like the USB key, or the something you are like the biometrics as an additional level and commonly called this is like two factor or multi factor authentication. So that what the concept is of going passwordless, is actually shifting away from using passwords as the primary method of authentication. And say, why do we need to use passwords as a primary, when we can use one of the other two, such as having a hardware device or using biometrics to do that first part of authentication? Obviously, there are many benefits to using the hardware device, or your thumbprint, or your face print. Because they're not likely to have the same level of simplicity around them. You know, it's not going to be quite as simple as password 123, when you're talking about your thumbprint, so there's a lot of sort of intrinsic benefit to that already.</p><h2 id="jane-6">Jane </h2><p>I mean, when we're talking about this, we've sort of talked to him a little bit. When we talk about passwords you're speaking about moving the second part of two factor authentication to the front, the something you have, the something you are. Are we talking about getting rid of passwords completely, or do they become the second part of this 2FA? Or is it going to be my face and my token?</p><h2 id="richard-5">Richard</h2><p>Passwords can still be used, but I would suggest that they are taken away largely completely, because they prove that they can't really be utilised effectively or securely. Certainly, if you have a three factor authentication it’s often used when you're going into very secure facilities. Where you have to sort of take in your access card, do a thumbprint, and then you have to type a PIN code in there. And then the PIN code would be sort of synonymous with your normal password. So that sort of three factor authentication will still be relevant in a lot of cases. But I think the concept of using a password to log on to a website will eventually go away, because it's not an effective way to access that level and proportionate that level risk.</p><h2 id="rory-5">Rory </h2><p>And when you're talking about, I guess, in some cases this is consumers would be able to use, say a passkey, a physical passkey to verify their identity on a multitude of different accounts. In an enterprise model, could this be hard to, this specific something you have, could that be hard to implement in that if you left the company, you'd have to return what you had. It would potentially be harder than do changing a password?</p><h2 id="richard-6">Richard</h2><p>Absolutely, I think the same thing you have part is an interesting concept about what it can actually be. And something, because I think everybody's sort of familiar with the, the old dongles which have the sort of rotating password pass key on them, that have been around from people like RSA for many, many years. And if you look in your desk drawer, you'll probably find two or three of them where the batteries died that you've had from many years ago. And that's not an unusual situation. And so there is an overhead to managing all those additional keys, and people will forget them, people will lose them. So there is an additional overhead in terms of that. So ideally, you want to try and use something that you already have, and you're never likely to let go of. And that's probably something like a mobile phone. And you can use a mobile phone as the something you have component. And it also allows you to do the something you are component because it allows you to do, especially with the modern smartphones, the biometrics and things like facial recognition and fingerprint recognition.</p><h2 id="jane-7">Jane </h2><p>And I suppose if you've got company provided phones, then it's as easy as just returning the phone or remotely wiping it or any of that kind of thing if somebody leaves the company but they are, for whatever reason, not returning the phone.</p><h2 id="richard-7">Richard</h2><p>Yes, if you're provided a company phone you will normally have some sort of MDM, some mobile device management software on the phone. Whereas as soon as they leave the company or as soon as the employment is terminated, then it's a question of just hitting a button on the central console and it would remove any of those components. </p><h2 id="jane-8">Jane </h2><p>Yeah, I've thought of all kinds of nefarious things for employees to do. I think most of us more inclined to sort of lose our phone, on a train or whatever as well. </p><h2 id="richard-8">Richard </h2><p>Yeah,absolutely. But also remembering that without the knowledge of where you're going, and what you're going to, because you still have to get the thumbprint to actually authenticate because it's part of that you would have something you have, something you are. Smartphones make it very easy to do two factor authentication, by taking the biometrics and the something you have. So that gives you the two factor based on that. So if you do lose your phone, they may be able to guess the pin number or the swipe pattern you have to get into the phone. But it's unlikely then they'll have the biometrics to actually get through the next level, to get on to the corporate assets as required. </p><h2 id="jane-9">Jane</h2><p>Sure.</p><h2 id="rory-6">Rory </h2><p>Through things like FIDO, there's been talks — I know that some manufacturers at Google Apple, Microsoft, have been in talks — to standardise this kind of technology that you're talking about. So that regardless of the hardware you were using, like the standardised keys across either your business interactions, or on a consumer basis across all of your different accounts, do you think a unified approach like that will be necessary to avoid there being a different kind of tool sprawl for businesses and consumers in the future where they're having to oh, you know, “which passkey am I going to be doing through my phone?”</p><h2 id="richard-9">Richard</h2><p>I think there's going to be an argument for that. Not quite sure what things are going to happen in the short term, but it remains to be seen. I do think the work that FIDO is doing to promote easier and more secure access online is something that will be followed by more and more organisations. The current iteration, which is FIDO2, so fast identity online version two, even goes so far as to provide solutions that allow you to do phish proof MFA, because that is also a problem with MFA. It's not 100%. It's a lot better than not having multi factor authentication. But MFA is not 100%, and with the next generation, which is FIDO2, it will be phish proof. Again, it's never going to be 100%, but it's going to be a lot closer to where we want it to be.</p><h2 id="jane-10">Jane </h2><p>So Richard, you've mentioned, FIDO2 briefly there. Could you tell us a bit more sort of what that's about?</p><h2 id="richard-10">Richard</h2><p>Yeah, so FIDO2 is a methodology to make MFA sort of even better, because surprisingly, MFA doesn't solve all problems. You know, we think that it's going to address all of our authentication issues, but it doesn't and there's been several organisations that have been breached fairly publicly. So a very well known video game manufacturer, a well known taxi company, a global taxi company has recently been breached by what's called an MFA bypass. And an MFA bypass technique basically means that the device is talking to the website or the application, and the device that is doing the multi factor authentication are not linked. So this means that if you have stolen credentials, you can put those into the asset, put those into the website, the website will respond with an MFA challenge. And the attackers realise that the MFA challenge is going to be sent to the user, and they will try and persuade them to actually accept the challenge. And it's surprisingly easy to do that, with things like push MFA challenges. If you start sending people that at 3am in the morning, it's remarkable how quickly people will just click on ‘accept’, rather than have to listen to the bing, bing, bing, bing, bing, bing, constantly being reminded in the middle of the night. And this is what's happened to many, many organisations, is that because the device that’s making the request to the asset and the device are not linked, you can get this what's called push MFA or MFA bypass. So what FIDO2 wants to do is to locally connect the devices making the request to the origin and your external device. Now, you can do this through a USB key, plug the USB key into your device, they're now locally linked. Or you can do it through NFC, or you can do it as we do with Akamai, you can link them together through cryptographic keys. So my phone and my laptop are cryptographically linked, which basically means that the MFA is not valid unless it comes from my laptop. So if my credentials are stolen, and somebody tries to log in in another part of the world, and then tries to do a push MFA exertion on me, it won't even happen because the request has to come from my laptop. And this is what FIDO2 is doing, it’s ensuring that local MFA connectivity before it actually goes on to the next stage. And by doing this, it gets round a lot of the big MFA bypasses that have happened this year.</p><h2 id="jane-11">Jane </h2><p>So this all sounds really great. And as a consumer, I can see myself adopting it. I already have, I use my thumb on my phone, people use their faces on their phone. And, you know, really consumers can turn on a penny when it comes to adopting new technology, anything like that. For businesses, it can be a little bit more difficult, especially if there's some kind of integration that they need to do with legacy systems. So how quickly can that be done? I mean, is it a problem? Am I throwing up a problem where one doesn't exist? But if I'm not, how can this be managed, and how quickly can things change?</p><h2 id="richard-11">Richard</h2><p>I think with enterprise, it'll be a lot easier than it will be for consumers. For two different reasons. The main reason for consumers is that there will be a long tail of users who, for want of a better word, maybe a sort of Luddite about adopting the new technology. There are many people who don't want to have a smartphone with biometric controls on them for whatever reason. So for a service, such as public services, public sector, where they have to provide a fully inclusive service, there's gonna be a long tail of people there who won't fit into the parameters where you can do that full technology, but for multi factor authentication using biometrics or smartphone, so there will have to be solutions there to cater for those people. But with the enterprise, you have a lot more control. And you can certainly start linking all of your assets to talk to a central identity provider, be it Active Directory or some other form. And once you have authenticated with your main IDP, your main identity provider that can provide authentication tokens to every single other device within your estate, meaning once you're logged in, you're logged in across your estate. And that identity is protected by authentication through multifactor.</p><h2 id="jane-12">Jane </h2><p>So the other way around to what you find quite often then, is that for businesses actually, this is quite easy. I mean, are there any sort of key hurdles that might hold up passwordless security in businesses or is it really just as easy as kind of going, “right this is our, you know, the method that we do now internally, at least. And, and off we go”?</p><h2 id="richard-12">Richard</h2><p>There's always going to be some legacy applications that don't have the ability to use authentication. So there's a functionalities like OAuth, which allows applications to be authenticated elsewhere. If they don't have the functionality to have that capability, then you're going to have to have another way of authenticating with those legacy applications. So it's not necessarily going to be applicable across the board. But most modern organisations will have the facility to deploy the majority of their applications through that one password, or one authentication process, and then being able to pass that assertion through to all the relevant applications.</p><h2 id="rory-7">Rory </h2><p>Do you think that implementing a system like this might also help with oversight of who has access to which systems? Because currently, obviously with passwords, it's very easy within an organisation for someone to ping a password across on a Google chat to someone who maybe shouldn't have access to, to a back end system. So using authenticators might also improve observability across the system?</p><h2 id="richard-13">Richard </h2><p>I think there's a potential for that, I think that where that particular area’s going is more into is looking at the authorisation component. So with identity, you’ve got the identification, which is the username, you've got the authorisation. Sorry, the authentication, which is the something you are, something you have, something you are. And then there's the authorisation component, and authorisation is something that's being looked at when you look at things like zero-trust network access, which is a way of giving users access just to applications that they need. So it's really sort of going down heavy on lease privilege. This is a really good way to ensure that only the users authorised to access an application, get that level of access. Which means that anybody else does not have that level of access. So, if you gave somebody else a password, you'd have to have the username and have the password, but they still wouldn't be authorised, they still wouldn't physically be able to get to that particular asset. And I think that's why a lot of organisations are looking into it. Because I know zero trust is a word that bandied around a lot with, with wanton carelessness, sometimes, but it fundamentally comes down to lease privilege, which is something that IT professionals have been familiar with for many, many years. And that's where it's trying to get to, if you don't have the right identity, authentication and authorisation, you can't actually get to that application.</p><h2 id="jane-13">Jane </h2><p>So Richard, if the worst does happen, and a business is hit by a cyberattack, can using a passwordless solution help minimise the impact? Or does it just minimise the risk?</p><h2 id="richard-14">Richard</h2><p>That's a really good question. I think initially, it minimises the risk. Because I think if you, there was a report I think in the Verizon data breach incident report last year, that credential vulnerabilities were responsible for 84% of all breaches. So if you can get to addressing that vulnerability, that reduces the risk significantly of having a breach. So I think that's the first aspect. Once somebody has got inside your organisation, then absolutely, having good identity controls is in place, but it's a little bit late at that point, you then need to be looking at other security elements to be able to protect your organisation. And that can be through things like zero trust, network access, or micro segmentation to throw another technology into the mix to prevent them moving laterally through your organisation. But I think this is where passwords can be used, especially within the enterprise as part of a layered security model of trying to reduce the risk at all levels, reduce the level at authentication time, reduce the risk at connection time, whether connecting via IP or just the application layer, and then reducing the risk of moving throughout an organisation when deployed as part of a managed strategy, then you're able to reduce the risk at all levels as best as possible.</p><h2 id="jane-14">Jane </h2><p>Yeah, and I think you've kind of hit on something important there really, which is whether this is passwordless or really any other kind of security technology, or any technology, that it's not a panacea, it's not a cure-all, it has to be used as part of a wider security strategy. Whether that's training or like you say, other technologies that can help the progress or at least to slow the progress of anybody who's staging an attack. Is that a fair observation?</p><h2 id="richard-15">Richard</h2><p>Absolutely. I think that there aren’t many things that as security professionals we can do, that actually makes things easier for end users. Normally, we are seen as the Department of No, the Fun Police. So I think that anything that we can do within security that actually makes lives easier for end users, and makes them more secure, is a good thing. And reducing passwords, reducing the use of passwords is a good thing, because nobody likes them. Nobody likes them, nobody likes trying to have to remember them. There's always a challenge, there’s always some times you forget, or whatever. It's a problem. It's a massive security risk. So getting rid of that pain point from users would be a boon I would say.</p><h2 id="rory-8">Rory </h2><p>So you think that there's real potential for this to improve, maybe, productivity within the workforces? Or at least improve the use of access for vital systems within workforces?</p><h2 id="richard-16">Richard</h2><p>Absolutely. I think when you look at most organisations where you have, you know, probably thousands of applications within an organisation, although most users will only have access or need to use 10 or 20 of them. The ability to reduce the access to just the applications you need, and the ability to have to worry about a password is fantastic. At Akamai we've been passwordless for many years now. So I don't use a password to log on. I don't use a password to access applications, it's just all done through passwordless technology. And that makes it a lot easier for me not having to worry about, “oh, I need to access that particular system. Where is it located? What password do I need?” All that, it's a lot easier to use? And yes, it's anything that gets rid of that, “oh, what's the password for that application that I haven't used for two months?” Anything gets around that problem, which everybody has, if you can get if you can solve it, it's bound to help all sorts of users.</p><h2 id="jane-15">Jane </h2><p>So Richard, at Akamai you are ahead of the curve. But how far away do you think we are from universal adoption of this kind of security across businesses?</p><h2 id="richard-17">Richard</h2><p>I think that's a very difficult question. Because there are many companies and many verticals that are on all sorts of that journey, all different areas of the passwordless adoption journey. I think people will want to go there because the benefits are manifold. But there is always going to be an issue with inclusivity. Because you have to make sure that everybody is catered for. And if you can't cater to everybody, then there's always going to be an issue. So in the consumer space, I think it's going to be utilised to enable users, I still think you're going to have to have passwords for inclusivity. But if you're using it in the consumer space, and you want to get access to all of your favourite music sites, or TV sites, or shopping sites without having to remember a password all the time, I think people are going to embrace that. And that it will be seen as a benefit not only for the consumers, but also the vendors as well. In the enterprise space, I think that organisations will want to go down this level to a certain degree, I think there's always going to be legacy applications that won't suit that. Or the infrastructure will not benefit it as a whole. But I think overall, it's certainly a methodology that will be broadly adapted. The big vendors, as you mentioned at the beginning, are doing this. Microsoft has things like Microsoft Hello, which allows you to do passwordless authentication. It's something that's being adopted through many different vectors, so it will increase. Am I going to put a date on it and say you have no more passwords in five years. That’s a crystal ball I would love to have, but I couldn't say that.</p><h2 id="jane-16">Jane </h2><p>No fun, no fun.</p><h2 id="rory-9">Rory </h2><p>Well, Richard, thank you so much for being on the show.</p><h2 id="richard-18">Richard</h2><p>Thank you Rory, thank you Jane. It's been a pleasure. Thank you very much indeed for having me.</p><h2 id="jane-17">Jane </h2><p>Thank you. As always, you can find links to all of the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk</p><h2 id="rory-10">Rory </h2><p>You can also follow us on social media, as well as subscribe to our daily newsletter. Don't forget to subscribe to the IT Pro podcast wherever you find podcasts. And if you're enjoying the show, leave us a rating and a review</p><h2 id="jane-18">Jane </h2><p>I will be back next week with more from the world of it but until then goodbye. </p><h2 id="rory-11">Rory</h2><p>Goodbye</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: Surveying today's threat landscape ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369744/podcast-transcript-surveying-todays-threat-landscape</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cF4PGg7dXEoT5DQM2TFfPR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/s5TyC7BtxsqAM3qBoJeUBD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Dec 2022 15:45:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/s5TyC7BtxsqAM3qBoJeUBD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Surveying today&amp;#039;s threat landscape&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Surveying today&amp;#039;s threat landscape&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Surveying today&amp;#039;s threat landscape&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/s5TyC7BtxsqAM3qBoJeUBD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode ‘</em><a href="https://www.itpro.com/security/369743/the-it-pro-podcast-surveying-todays-threat-landscape" data-original-url="https://www.itpro.com/security/369743/the-it-pro-podcast-surveying-todays-threat-landscape">Surveying today’s threat landscape</a><em>'. We apologise for any errors.</em></p><h2 id="rory-bathgate-2">Rory Bathgate</h2><p>Hi, I’m Rory Bathgate. And you’re listening to the IT Pro Podcast, where this week we’re assessing the current threat landscape. Cyber security is at the forefront of company strategy — if you go into a boardroom, you’re likely to find it ranks at the very top of C-suite concerns. In an ever-changing threat landscape, full of exploits, state-sponsored threat actors, and increasingly novel strains of malware, businesses must maintain oversight of endpoints and stay up to date with pressing risks. This week, we’re speaking to Bernard Montel, technical director EMEA at exposure management firm Tenable, to discuss how businesses can tackle their threat surface area, and the biggest risks. Bernard, thank you so much for being on the show.</p><h2 id="bernard-montel">Bernard Montel</h2><p>Thank you very much for this invitation. I'm very proud to be part of your podcast today. We try to help our customers really to reduce the risk of the cyber attacks.</p><h2 id="rory-12">Rory</h2><p>Well, I really appreciate you being here. I'd like to start with quite a broad question. But just as a kind of a roundup of 2022, what would you say are some of the key security takeaways from the past year in terms of the threat landscape?</p><h2 id="bernard">Bernard</h2><p>What I would say is that 2022, unfortunately, was in the train of 2021. We have a lot of new threats and, I mean that the pressure is there. It's, you know, it didn't really stop. We had much more context in 2022. But the top one is still you know, the cyber criminals, which are there and ransomware that we talked about for the past couple of years now is still, you know, very here and number one in the threat that organisations globally have today. That's one of the takeaways that, you know, there are still a lot of attacks every single day and still ransomware as is the top one.</p><h2 id="rory-13">Rory</h2><p>Yeah, ransomware always comes up in these conversations. It seems to be something that has had a lot of focus recently. I saw a recent report that indicated that the UK government's National Emergency or Cobra meetings have centred around ransomware quite often recently. Would you say that this intense focus on ransomware is warranted, is it representative of the real scale of the threat?</p><h2 id="bernard-2">Bernard</h2><p>I mean, yeah, I mean, definitely, yes. But what we've seen as well, in 2022, is the emergence of, you know, attacks we had in the past, like, for example, the DDoS attack, which means denial of services. And also phishing attacks are also raising in 2022. So that's a kind of new way, because now we have also the three dimensions of the three kinds of attacks, we will also have seen some, you know, attacks using the three of them in the meantime. So we call it triple extortion, which means that not only a company or an organisation was hit by a ransomware attack, but in the meantime, they were hit by a denial of services attack, which means shutting down their their services. So we've seen that in 2022 DDoS attacks were quite old, but they are coming back in combination with ransomwares.</p><h2 id="rory-14">Rory</h2><p>So it sounds like it's a lot of the same old threats, a lot of classics, you might call them, the classic threats, they're here to stay. But have there been any big surprises in the year as well, any I know that there's been some methodology change in ransomware, we've seen the programming languages and some strains change to languages like Rust, would you say that this is keeping threat management kind of on its toes?</p><h2 id="bernard-3">Bernard</h2><p>So one of the main changes we've seen two years ago was really the supply chain attacks, you know, for attackers, only targeting one software and then having that domino effect, or you're you're hitting one, but you are compromising many. That is something which is still very very new. For example, very recently, Python has been attacked and compromised. Now, if you are compromising that kind of technology, immediately a huge amount of developers are using Python and if you're using a compromised version of its, as you can imagine, you know, the drama around it worldwide because it has been spread everywhere. So that is really the supply chain attacks. We all remember SolarWinds, but we have many others coming out. And Log4Shell year ago, roughly, you know, I think it would be the anniversary of Log4Shell right now, a couple of couple of days, I think it came out roughly around the 2 December or 3 December. You will be surprised that a year after, we've done a study at Tenable, a lot of companies are still vulnerable to Log4Shell. It's not that they've been lazy. We've seen once one element, which is very important is called reinfection, they've fixed the vulnerabilities partially or completely, but they install new software, and new technology, and now suddenly, those new technologies unfortunately, were using a very old library of of Log4j. So those are the supply chain elements. But you asked me a question regarding what is new. And what really new in 2022, is the wipers. Now ransomware groups are really inspiring themselves by some nation states groups, which were deleting data, in some parts of the world, and some of the conflicts of the world. But now, you know, such kind of techniques has been reused by, you know, ransomware groups for not only just encrypting data, because it's quite long and difficult. They prefer breaching, putting the data out, and then completely deleting the data with what we call the wipers, which is wiping the data instead of encrypting it. And that is quite new. I mean, in 2022.</p><h2 id="rory-15">Rory</h2><p>Yeah I mean, I mentioned it I think briefly in the intro, but this influx of state-sponsored groups, amidst or parallel to the rise of ransomware as a service groups and threat actors like that has seen a big increase in wiper activity. I mean, with Russia's invasion of Ukraine, obviously, we've seen a lot of attacks that aren't driven by profit, they're just driven with the intention of destroying systems, of causing chaos in systems, especially in critical national infrastructure. Would you say that this is kind of an accurate assessment that attacks on critical national infrastructure are increasing, are a growing threat, and these kinds of attacks that aren't so much driven by profit, that just are driven with chaos in mind, are maybe a growing concern?</p><h2 id="bernard-4">Bernard</h2><p>I would say that, you know, as I said, you know, those techniques are shared between those attackers groups, but the main motivation is still, you know, financial motivations. Top one is still very high on the fact that those attackers really want to get money. The fact that they are attacking critical infrastructures, and again, if you will linking the number of attacks against critical infrastructures using ransomware, this is very huge, which means that their main motivation is still financial motivations. So they are using techniques, which are very similar to what we've seen, as you said, in Ukraine. But I would say that the attacks against critical infrastructure are still very motivated by the money they can gain with that. But yes, I mean, we've seen anyway increases against critical infrastructures a lot. So, I leave you, you know, guessing if this is just, both together those nation state attacks and ransomware attacks together. But what is important for us is how they do operate, whatever the motivation, what is important if they, they do operate by using vulnerabilities, which are there sometimes for a while. You would be surprised if I would say to you that, some attacks, whatever their whatever their motivations are still using, for example, Log4Shell we discussed about it, but also ProxyShell, which is a very old one right now, you know, more than roughly a year and a half, even two years. So, the way they do operate, you know, it's more important to compare why they do that, because what is important for organisations is really to be able to identify any attack path that attack groups will use. But to go back to your question, yes, critical infrastructures are attacked dramatically today, and the government took that really seriously. We've seen for example, some governments shutting down some some attacker groups, we've seen government putting a lot of pressures against organisations. Like in Australia, one of the telcos has been attacked, not only have they lost a lot of customers, but they also have fines from the government, “hey guys, you know, we are there and we are forcing you to put some security policies”. And if you don't do that, and obviously you get fined by the government.</p><h2 id="rory-16">Rory</h2><p>Yeah, I mean, Australia, there's been this terrible sequence of attacks in Australia, some links to SingTel, some not linked to SingTel whatsoever. But as you say, the government have stepped in, they've increased the, I think the fine increased from 2 million Australian dollars to 50 million Australian dollars for privacy breaches. And also, there's this open discussion around legislation banning companies from paying the demand, for paying threat actors in ransomware. Do you think this kind of action is effective? Is it warranted? Or does that need to be either more done by governments or more done really, in the private sector?</p><h2 id="bernard-5">Bernard</h2><p>I mean, this is the only way they have to force organisations to increase the level of security. If you go back, for example, to GDPR which came out from the EU. I mean, by applying GDPR everywhere, mechanically the level of security has increased. That doesn't mean that we have reduced the number of attacks, the number of attacks as well has increased, but if we all together try to upload the level or the greater level of security, then mechanically, you know, we are better prepared. But that's the only way they have; the government have two kinds of responsibility. Number one is really protecting the government agencies. So they have some security operation centres, they have national security agencies for looking after attacks that are targeting themselves directly. But for the private organisations, you know, they cannot control them. So they have to be able to force them by directives, regulations, local, or whatever they are EU or UK based, they are already looking after the set of rules they're putting together, and the fines in fact, is the only way for forcing them. You know, if you only put recommendations, soft recommendations, I wouldn't say that they will follow it. If you're already putting fines, okay they would take that seriously, because they will be between a rock and a hard place, because, in one hand they have the pressure from the attack groups, and in the other hand they have the pressure from the governments. So they do something. So there, that's for sure.</p><h2 id="rory-17">Rory</h2><p>And on that point of companies doing something, just to circle back to what you were saying earlier about Log4Shell. I did see the Tenable research that was published, it's kind of a shocking statistic that 72% as of October of 2022, 72% of organisations remain vulnerable to Log4Shell. I know that you said earlier, this isn't necessarily negligence on the part of the companies and maybe to do with all the libraries that are difficult to strip out. But surely, there's got to be some sort of fire lit under the feet of these organisations to change this.</p><h2 id="bernard-6">Bernard</h2><p>Yeah, there is another study we've done last week, discovering external assets, which is, using very old protocols. This study has been done by Tenable against 22 major UK organisations, and we found that 100% of them were still using the old encryption protocols in some of the assets. But what is amazing with this very, very recent study is the number of assets, we found — external facing assets, which is huge. An organisation itself has more than 500,000 assets. How can you manage that? So, I would not blame them to not fix Log4Shell, that they didn't fix it in January or February. You know, we knew when Log4Shell came out how deep it was embedded into some of the technologies. So, a year after, yes, the number is quite high 72%. But that means that those organisations, they don't even know the asset they have. So that's the first takeaway. The second takeaway is, if they new such kind of assets, they are fixing it. But in the meantime, you know, the attacks surface is really growing and highly dynamic, that is the second takeaway. You cannot imagine if it was 15 years ago, when you had a set of assets, you knew what you needed to fix, you fixed it, and then for the next two years, you would be okay. Now, this is not the case anymore, developers are pushing codes or committing codes, once per week sometimes for making new features on some applications. So as you can imagine, it's super fast. So a lot of assets, they don't know a lot of assets, you know, that are moving and growing and changing roughly every week. So if you don't have a real time and continuous programme, then you are only doing screenshots, and then photographs, it doesn't give you any motion. So that's, I think, one of the takeaways, the third one if you want, which is if you don't do that all the time, or the continuous way then you are, you're late. And then that's what's happened after a year.</p><h2 id="rory-18">Rory</h2><p>So as much as possible, you should really have real-time security response to these threats, really be plugged into not just vulnerabilities, but oversight over your own footprint.</p><h2 id="bernard-7">Bernard</h2><p>Yeah, and another element, which is quite important is, you know, the majority of the organisation's invested a lot in real time security event detection: “I want to be aware if there are any alerts or any incident right now”. But then they didn't really think about, hey, what about if you're aware, in real time, on any vulnerability? Because then in this case, it will put you in a much more preventive, predictive approach. Some CISO that I talked with a couple of years ago, they said, “I would dream to predict what will happen”. In this case, you have to change your mind, you know, spend more time in prevention, rather than only putting all your effort in detection, because if you do that it's like our health; if you don't do any sport, you are eating fat and sugar, and then you will get some stuff, that's for sure. But if you are making a lot of prevention, your life is… we used to use the term cyber hygiene. And I like this one, because it really reminds me of our daily hygiene, you know, as a human. So, if you really are looking to understand in real time what's happened in your attack surface, immediately, you can identify a door that was closed, and that certainly is open. And if you don't do that, believe me, you know, the hackers would do that, because they are trying to scan and identify those vulnerabilities every single day. I mentioned the attack paths, and we organisations, global organisations are working in silos, we have people in charge of it, we have people in charge of security, we have innovation within the security space, we have, you know, a specialist on the cloud, specialist on identity and so on. Attackers don't do that, they have a small group of people, they try to find a way, they find one way and they — I'm used to using the spaghetti, you know, they are putting it and they find, “oh, yeah, well, I've got a meat now, you know, I'm very hungry, but I have everything I want, because I just pulled back at and then I found a way to get much more”. So that's one stuff, we need to understand the way they are behaving is smart and agile, so we have to change our mind and not work in silos with different people that never communicated before and together. So that's one stuff, I think we need to change if we really want to help our organisations to be more proactive.</p><h2 id="rory-19">Rory</h2><p>So would you say that that should prompt maybe more of a unification of companies? I know that this is a topic that we've discussed recently, as well, but this push for hybrid cloud, as well as, as you've pointed out, lead to this kind of silo structure, where you can you can expand and expand and expand and just tack on more silos, but that's not necessarily conducive to having a full understanding of your surface attack surface.</p><h2 id="bernard-8">Bernard</h2><p>Yeah, I mean if you look at what the SOC has done, the threat detection and response. They've done that journey already, you know, they collected a lot of data with logs, for example, rail, or EDR, or with what we call a SOAR, which is an orchestration for incidents. They have tried to have that view around those security events. If we do exactly the same on the prevention part, then we have the full picture. Then, we can ensure that aggregating the data, the prevention data, the static data or the state data that we can have. I just want to go back to the the analogy that I've done with doors open. Now that we have the attack surface, which is partially in the cloud, partially on-prem, IT, network identity, and some organisations have also industrial system OT, we don't have a cloud specialist to understand what's happening and address your system, we still will have those people in charge of their own domain, that's for sure. But what we need to have to aggregate the data together, we need to have a governance where we see in a nutshell, at a glance, all those indicators, I'm calling that the key risk indicators for companies. A company needs to understand if for their business critical applications, they have all the lights, you know, green, orange, yellow, red, they know immediately, whatever the technology behind it, a business critical application could be hosted in the cloud, and partially also having some on-prem data, on-prem identity. What is important is to have that risk-based governance, on the preventing part. Which is, every morning I open my dashboard, and I say, “I'm good today, I'm fine today, I know that my business critical application doesn't have any doors open today”. Tomorrow could be another day.</p><h2 id="rory-20">Rory</h2><p>It's interesting, because that does seem to be a point of contention within the industry. I've definitely spoken to some people who say, “Yeah, prevention is good, but you can't prevent everything, so, you know, occasionally, you've just got to, you've got to respond. It's all about the response when anything does happen”. But it sounds like just to link it back to Log4Shell. Correct me if I'm wrong, but it sounds like what you're saying is, we really have to prevent the next big vulnerability from taking place, because I guess, otherwise, you know, that could be catastrophic for our business, if you're not focused on prevention,</p><h2 id="bernard-9">Bernard</h2><p>When you are leaving your house, do you close the door? </p><h2 id="rory-21">Rory</h2><p>Well, that's right, exactly. </p><h2 id="bernard-10">Bernard</h2><p>That's, you know, we have closing and locking the door, okay, and putting an alarm system. If you leave the door open, and you put just the alarm system, believe me, it will ring, that's for sure. Because someone who's out will say “that door is open, what's going on here and what's wrong?” you know, and then suddenly, you will get a notification because your alarm system has detected a movement or whatever. So, I think we need to apply the same analogy. People need to identify if, before leaving your door, or your window is open. You know, I'm living in a second floor here. So I'm very sensitive, in my flat, that I'm not leaving the windows open, because people can climb and enter into my apartment. So before leaving, and looking after the windows, if those windows are closed, I'm safer. That doesn't mean 100% safe, it could be that someone will, you know, find another way, but I'm doing what I need to do. My duty is closing the windows, closing and locking the door, then having an alarm system, it’s not the other way back. People are looking at their detection, saying, as you said, you know, “I cannot prevent, so I will detect”. Okay, now, if you want to detect an encryption for a ransomware attack it’s just too late, you know, you have to be able to prevent any way. So focus on prevention, at least equally than the detection. Even in systems sometimes, if you are investing 80% on your prevention, then your detection complexity will reduce anyway, mechanically, it's easy to understand, I think,</p><h2 id="rory-22">Rory</h2><p>On a strategic level that makes perfect sense. On a technical level, something I'm wondering is, you're talking about maintaining prevention hygiene, and bringing together teams that were siloed. So on a more specific technical level, what kind of systems can be implemented by businesses to achieve this, this increase in prevention. </p><h2 id="bernard-11">Bernard</h2><p>As I said, you know, a cloud security specialist won't be, will never be an OT security specialist. These are different worlds. We don't want that, we don't want to do everything, we want to do something. So they will still have their own tools and what we call sensors, they will need to collect the data. So for example, if you're collecting the data, regarding your cloud misconfiguration, you know, someone has just deployed an application in the cloud and they've left misconfiguration somewhere leaving then again, the door open. Now, we need to collect that data and attach that to a platform where we can see that data linked to the business application. And if we do that for identity data, if we do that for vulnerability, classical vulnerability on-prem data, if we do that for web application, OT, and cloud all together, then we have in one place, what I'm calling again, the key risk indicators coming from those tools, coming from those solutions. And even if we go further, we can even collect data from non Tenable technology. Nothing is stopping us, you know, we need to be able to have those sensors covering those scopes. The scopes are technical, the scopes and the technology is what it is. Okay, so cloud technology is one, which is very different than active directory, which is very different than network or devices or OT, we won't change that. We will apply sensors on those different places within the attack surface. But if we stay there, and stop only there, each and single team will have their tools, or no one will be able to understand globally what's happened in the attack surface. So that is the answer. The answer is aggregating all those data into one place. That's exactly what we've done at Tenable. We have created a platform, which is aggregating the data, correlating the data, the same correlation, we've seen in the you know, in the security event detection part we apply the same correlation of preventing data is something that never existed before. And we really wanted to be able to call that, you know, subject as well.</p><h2 id="rory-23">Rory</h2><p>On this task of aggregating data, obviously, there's huge potential for automated systems. I know that there's a lot of, kind of naturally, a buzz around terms like artificial intelligence and machine learning. Obviously, it's not a silver bullet, you can't just plug in an AI and everything improves. But do you think that there's, there's scope for maybe more intelligent aggregation, and contact providing context to security teams for this?</p><h2 id="bernard-12">Bernard</h2><p>So in this platform, called Tenable One, we have a group of people called the data scientists and they have developed such a kind of algorithm, when you calculate the risk, you are collecting data, you are collecting the assets, and we need to understand the posture of the assets. By doing that, you know, for doing that, we need to calculate the risk. And so that's exactly what we've done. Again, within this platform, the value is the data. But if we stay there it’s just just the data, we need to be able to calculate some exposure score. And that we've done, for example, with some data scientists, and obviously some kind of artificial intelligence that they've developed to be able to understand the trends, understand the posture, understand the reason why, and the key risk indicators as has been put together.</p><h2 id="rory-24">Rory</h2><p>While we’ve got you here, I would be remiss not to ask if you have any burning predictions for 2023, or beyond, for the threat landscape: what you think is likely to be a key concern going forward.</p><h2 id="bernard-13">Bernard</h2><p>So in the beginning of the year, we've seen attacks against remote workers, and critical infrastructures. And also cloud because the cloud and remote workers are, you know, very linked together, we need it, we need to work from home. So we need to have much more cloud applications. Very recently, as I said, you know, we've seen ransomware attacks are very there, plus nation state attacks. Now using the tools, we see combinations of both. So again, I want to go back to the wipers, I want to go back to the supply chain. So my prediction, unfortunately, would be that we will see more and more attacks, you know, using not only double extortion, but now triple extortions — if you really want to target an organisation, you know, those attackers are now using one, two, three kinds of attacks in the meantime. So that is a trend that we've seen, and I think we will see that in 2023. The second part that will never, I think, stop is attacks against critical infrastructures. We've seen a rise of that. We've seen a lot of attacks against critical infrastructures. And again, the main motivation is most of the time, financial motivation, but we know we tend to deny as well that there have been nation state attackers as well. If you combine both together, the number of attacks against critical infrastructure has been very important. And the last one is obviously very related to the cloud. You mentioned hybrid cloud, and cloud will never stop, you know, some organisations will be slower than others. But definitely the cloud is here, and you know, we will see clearly attacks against cloud more and more.</p><h2 id="rory-25">Rory</h2><p>Well, on that note, thank you so much for your time. It's been a pleasure speaking to you, and I'd love to check back in with you at some point in the future to discuss the threats, what's come true and the state of the threat landscape going forward again. </p><h2 id="bernard-14">Bernard</h2><p>Thank you very much. </p><h2 id="rory-26">Rory</h2><p>As always, You can find links to all of the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk. You can also follow us on social media, as well as subscribe to our daily newsletter. Don't forget to subscribe to the IT Pro Podcast wherever you find podcasts. And if you're enjoying the show, leave us a rating and a review. We'll be back next week with a special festive edition of the podcast but until then, goodbye</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Surveying today's threat landscape ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369743/the-it-pro-podcast-surveying-todays-threat-landscape</link>
                                                                            <description>
                            <![CDATA[ With an expanding attack surface, can you afford to neglect detection in favour of response? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vjemWt6S9CH7byAEXUrJdE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8T6UqZtCPSyF4rFjhQ486Q-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Dec 2022 15:01:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8T6UqZtCPSyF4rFjhQ486Q-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Surveying today&amp;#039;s threat landscape&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Surveying today&amp;#039;s threat landscape&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Surveying today&amp;#039;s threat landscape&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8T6UqZtCPSyF4rFjhQ486Q-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In a sector of changing priorities, cyber security remains at the top of the list in any boardroom. With the threat landscape presenting challenges old and new, and the increasing risk of entities such as state-sponsored hacking, it is essential that businesses carefully craft their cyber security strategy to keep ahead of the next big attack.</p><p>The speed that threats evolve now demands real-time action from companies, who must maintain oversight of their attack surface and maintain as many assets as possible against vulnerabilities such as Log4Shell.</p><p>This week, we spoke to Bernard Montel, technical director EMEA at exposure management firm Tenable, to discuss how businesses can tackle their threat surface area, and the biggest risks.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52201813&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights-2">Highlights</h2><p>“You will be surprised that a year after, we've done a study at Tenable, a lot of companies are still vulnerable to Log4Shell. It's not that they've been lazy. We've seen once one element, which is very important is called reinfection, they've fixed the vulnerabilities partially or completely, but they install new software, and new technology, and now suddenly, those new technologies unfortunately, were using a very old library of of Log4j.”</p><p>“I mean, this is the only way they have to force organisations to increase the level of security. If you go back, for example, to GDPR which came out from the EU. I mean, by applying GDPR everywhere, mechanically the level of security has increased. That doesn't mean that we have reduced the number of attacks, the number of attacks as well has increased, but if we all together try to upload the level or the greater level of security, then mechanically, you know, we are better prepared.”</p><p>“An organisation itself has more than 500,000 assets. How can you manage that? So, I would not blame them to not fix Log4Shell, that they didn't fix it in January or February. You know, we knew when Log4Shell came out how deep it was embedded into some of the technologies.”</p><p><a href="https://www.itpro.com/security/369744/podcast-transcript-surveying-todays-threat-landscape" data-original-url="https://www.itpro.com/security/369744/podcast-transcript-surveying-todays-threat-landscape"><em>Read the full transcript here</em></a></p><h2 id="footnotes-2">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national" data-original-url="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">The new wave of cyber security threats facing critical national infrastructure (CNI)</a></li><li><a href="https://www.tenable.com/press-releases/tenable-research-finds-72-of-organizations-remain-vulnerable-to-nightmare-log4j">Tenable Research Finds 72% of Organizations Remain Vulnerable to “Nightmare” Log4j Vulnerability</a></li><li><a href="https://www.itpro.com/security/369684/businesses-urged-to-remain-vigilant-as-log4shell-issues-persist-one-year-on" data-original-url="https://www.itpro.com/security/369684/businesses-urged-to-remain-vigilant-as-log4shell-issues-persist-one-year-on">Businesses urged to remain vigilant as Log4Shell issues persist one year on</a></li><li><a href="https://www.itpro.com/security/369457/microsoft-says-its-just-too-difficult-to-effectively-disrupt-ransomware" data-original-url="https://www.itpro.com/security/369457/microsoft-says-its-just-too-difficult-to-effectively-disrupt-ransomware">Microsoft says “it’s just too difficult” to effectively disrupt ransomware</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/369216/systemic-id-problems-for-10-million-warns-minister" data-original-url="https://www.itpro.com/security/cyber-attacks/369216/systemic-id-problems-for-10-million-warns-minister">'Systemic ID problems for 10 million Australians’ after Optus breach, warns minister</a></li><li><a href="https://www.itpro.com/business/policy-legislation/369370/australian-government-to-increase-maximum-data-breach-penalty" data-original-url="https://www.itpro.com/business/policy-legislation/369370/australian-government-to-increase-maximum-data-breach-penalty">Australia to increase maximum data breach penalty to $50 million</a></li><li><a href="https://www.itpro.com/security/cyber-security/360602/government-callout-for-tech-to-plug-mod-security-holes" data-original-url="https://www.itpro.com/security/cyber-security/360602/government-callout-for-tech-to-plug-mod-security-holes">MoD launches callout for tech to plug cyber security holes</a></li><li><a href="https://www.itpro.com/security/359719/what-is-a-soc-audit" data-original-url="https://www.itpro.com/security/359719/what-is-a-soc-audit">What is an SOC audit?</a></li><li><a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know" data-original-url="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">What is GDPR? Everything you need to know, from requirements to fines</a></li><li><a href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation" data-original-url="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a></li><li><a href="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics" data-original-url="https://www.itpro.com/business-strategy/28163/what-is-big-data-analytics">What is big data analytics?</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence-ai/368107/what-good-ai-cyber-security-software-looks-like" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/368107/what-good-ai-cyber-security-software-looks-like">What good AI cyber security software looks like in 2022</a></li><li><a href="https://www.itpro.com/security/30102/how-to-use-machine-learning-and-ai-in-cyber-security" data-original-url="https://www.itpro.com/security/30102/how-to-use-machine-learning-and-ai-in-cyber-security">How to use machine learning and AI in cyber security</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware discovered carrying legitimate Windows certificates ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/369716/ransomware-discovered-carrying-legitimate-windows-certificates</link>
                                                                            <description>
                            <![CDATA[ Sophos researchers pointed to the sophisticated signatures as a sign of a new, dangerous strategy by a group tied to Cuba ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5LKCENA1airutTzMujNKho</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5wkeomh2nVzHq8qxPSsPaS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Dec 2022 11:34:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5wkeomh2nVzHq8qxPSsPaS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A chained lock situated on a laptop displaying a red screen]]></media:description>                                                            <media:text><![CDATA[A chained lock situated on a laptop displaying a red screen]]></media:text>
                                <media:title type="plain"><![CDATA[A chained lock situated on a laptop displaying a red screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5wkeomh2nVzHq8qxPSsPaS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security company Sophos has issued a warning over antivirus-nullifying malware it discovered bearing legitimate digital certificates, including signatures from Microsoft’s own digital verification service.</p><p>The drivers, found paired with a ‘loader’ executable that was used to install the driver, carried the digital signature of Windows Hardware Compatibility Program (WHCP), and appeared to be specially designed to limit the functions of <a href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation" data-original-url="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation">endpoint detection</a> and response (EDR) security programs.</p><p>Code signatures are cryptographic certificates that indicate a program has not been altered since its release by its manufacturer. WHCP signatures are only intended to be given to software that Microsoft has checked over and given its personal seal of approval, and therefore seen as trustworthy files to run by Windows systems.</p><p>Researchers say that the find shows that threat actors are working harder to move up the 'trust chain', employing increasingly sophisticated methods to sign malware with legitimate <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">cryptographic</a> signatures so that it can be installed on systems without detection.</p><p>Sophos made the discovery while responding to a <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attack, which revealed the driver and executable. Because it prevented the attack from occurring, it has not been able to definitively identify the ransomware variant that the driver sought to enable and deploy.</p><p>However, in a <a href="https://news.sophos.com/en-us/2022/12/13/signed-driver-malware-moves-up-the-software-trust-chain">blog post</a> researchers noted that the loader used is likely a variant known as BURNTCIGAR. Use of this variant is characteristic of the Cuba <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a> group, and a search of public repositories for similar drivers revealed an archive that contained both the driver and loader, along with a list of 186 files that are commonly-used in endpoint security and EDR software. Researchers surmised that these were processes intended to be killed by the <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> once activated, to allow the ransomware to run without resistance.</p><p>In a subsequent search for similar variants on the malicious driver, security researchers found as many as ten, having emerged in the middle of the year and grown in number since then. The earliest of such drivers found by Sophos was uploaded to antivirus aggregation website <a href="https://www.itpro.com/642751/google-acquires-online-security-startup-virustotal" data-original-url="https://www.itpro.com/642751/google-acquires-online-security-startup-virustotal">VirusTotal</a> in July, and carried the signature of Chinese software developer Zhuhai liancheng Technology Co., Ltd.</p><p>This company’s signature is flagged by Sophos as a potential unwanted application (PUA), and the threat actors appear to have moved away from this to less suspicious certificates in subsequent iterations. Indeed, other malicious drivers were signed by Nvidia, in addition to those that carried the WHCP signatures.</p><p>Following the discovery, Sophos Rapid Response collaborated with Microsoft to quell the threat, and to release a <a href="https://msrc.microsoft.com/update-guide/vulnerability/ADV220005">security update</a> that revokes the affected certificates as well as improving detection for legitimate drivers that have been involved in malicious activity. This was released as a part of Microsoft’s December Patch Tuesday.</p><p>“In 2022, we’ve seen ransomware attackers increasingly attempt to bypass EDR products of many, if not most, major vendors,” said Christopher Budd, senior manager of Threat Research at Sophos.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="/antivirus/28144/best-antivirus">Best antivirus for Windows 10</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369684/businesses-urged-to-remain-vigilant-as-log4shell-issues-persist-one-year-on" data-original-url="/security/369684/businesses-urged-to-remain-vigilant-as-log4shell-issues-persist-one-year-on">Businesses urged to remain vigilant as Log4Shell issues persist one year on</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/369662/internet-explorer-zero-day-exploited-by-north-korean-hackers" data-original-url="/security/zero-day-exploit/369662/internet-explorer-zero-day-exploited-by-north-korean-hackers">Google unearths Internet Explorer zero day exploited by North Korean hackers</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eNyWocwZkU6AFRW4cbpF2B" name="eNyWocwZkU6AFRW4cbpF2B.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" mos="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Getting board-level buy-in for security strategy</strong></p><p class="fancy-box__body-text">Why cyber security needs to be a board-level issue</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy" data-original-url="/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy">FREE DOWNLOAD</a></p></div></div><p>“The most common technique is known as ‘bring your own driver,’ which BlackByte recently used, and it involves attackers exploiting an existing vulnerability in a legitimate driver. Creating a malicious driver from scratch and getting it signed by a legitimate authority is far more difficult. However, should they succeed, it’s incredibly effective because the driver can essentially carry out any processes without question.</p><p>“In the case of this particular driver, virtually all EDR software is vulnerable; fortunately, Sophos’ additional anti-tampering protections were able to halt the ransomware attack. The security community needs to be aware of this threat so that they can implement additional security measures, such as eyes on glass, where necessary; what’s more, we may see other attackers attempt to emulate this type of attack.”</p><p>Earlier in 2022, a similar technique was employed by threat actors who <a href="https://www.itpro.com/security/malware/365023/nvidia-certificates-sign-malware-bypassing-windows-detection" data-original-url="https://www.itpro.com/security/malware/365023/nvidia-certificates-sign-malware-bypassing-windows-detection">masked malware using Nvidia certificates</a>, following a <a href="https://www.itpro.com/security/hacking/364068/nvidia-confirms-data-breach-lapsus-leak" data-original-url="https://www.itpro.com/security/hacking/364068/nvidia-confirms-data-breach-lapsus-leak">breach of Nvidia systems</a> by the <a href="https://www.itpro.com/security/cyber-attacks/367199/what-is-the-lapsus-group-who-is-behind-the-criminal-operation" data-original-url="https://www.itpro.com/security/cyber-attacks/367199/what-is-the-lapsus-group-who-is-behind-the-criminal-operation">LAPSU$ hacking group</a>. However, certificates are generally revoked by companies after they have been found to have been stolen, and Sophos’ discovery represents a step up in the methodology of attackers, as the drivers in use were, for all intents and purposes, seen as legitimate.</p><p>The Cuba ransomware group has previously claimed an <a href="https://www.itpro.com/security/ransomware/368918/cuba-ransomware-group-claims-attack-on-montenegro-government" data-original-url="https://www.itpro.com/security/ransomware/368918/cuba-ransomware-group-claims-attack-on-montenegro-government">attack on Montenegro’s government</a>, and has been linked to a number of attacks by security researchers. The group’s exact origins are unknown, but some have suggested it could be Russia-backed due to observations of Russian on the group’s <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a> site.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WithSecure Elements Endpoint Protection review: Holistic protection at a great price ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/369700/withsecure-elements-endpoint-protection-review-holistic</link>
                                                                            <description>
                            <![CDATA[ Smart cloud-hosted security offering affordable endpoint protection for a wide range of devices at a good price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4RHXbqM2fSjYfqpwxhhxgk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wF7qPATNm3uzXJs3zMBDMX-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 13 Dec 2022 12:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/wF7qPATNm3uzXJs3zMBDMX-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The WithSecure user interface]]></media:description>                                                            <media:text><![CDATA[The WithSecure user interface]]></media:text>
                                <media:title type="plain"><![CDATA[The WithSecure user interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wF7qPATNm3uzXJs3zMBDMX-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Finnish company F-Secure offers separate consumer and business security solutions and has relaunched its enterprise endpoint protection portfolio under the new WithSecure brand. The underlying product family remains largely the same, with the Elements Security Center cloud portal providing a central point to manage them all.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/369665/vipre-endpoint-security-cloud-review-a-sound-choice-for-smbs-with" data-original-url="/cloud/cloud-security/369665/vipre-endpoint-security-cloud-review-a-sound-choice-for-smbs-with">Vipre Endpoint Security Cloud review: A sound choice for SMBs with Windows and Mac users</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369600/avast-premium-business-security-review" data-original-url="/security/endpoint-security/369600/avast-premium-business-security-review">Avast Premium Business Security review: Feature-rich endpoint management for SMBs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/363154/citrix-endpoint-security-is-not-enough-to-protect-business-data" data-original-url="/cloud/cloud-security/363154/citrix-endpoint-security-is-not-enough-to-protect-business-data">Citrix: endpoint security is not enough to protect business data</a></p></div></div><p>The Elements Endpoint Protection (EPP) module on review can look after <a href="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review">Windows</a> and <a href="https://www.itpro.com/software/operating-systems/369384/security-features-apple-macos-ventura-compelling-business-upgrade" target="_blank" data-original-url="https://www.itpro.com/software/operating-systems/369384/security-features-apple-macos-ventura-compelling-business-upgrade">macOS</a> workstations, Windows, <a href="https://www.itpro.com/operating-systems/28025/best-linux-distros" target="_blank" data-original-url="https://www.itpro.com/operating-systems/28025/best-linux-distros">Linux</a> and Citrix servers, plus Exchange and SharePoint hosts. Along with malware protection, EPP applies web content security and removable device controls, and the price includes patch management for Windows OSes as standard.</p><p>EPP's DeepGuard feature exposes zero-day attacks and unknown malicious programs by analysing file contents, system change attempts and program behaviour. An EPP Premium subscription increases yearly device costs to £34 and adds application controls plus WithSecure's DataGuard, which uses behavioural rules to detect potential ransomware activity.</p><p>The Elements portal home page provides an overview of licensed products, their status and the devices under protection. The EPP module is accessed from the same console, and its dashboard presents graphs showing the number of protected devices and the status of software updates with a list highlighting vital security events.</p><p>Deployment is simple: you can email a link to users or download the agent directly and place it in a central distribution point. Either way, the agent takes five minutes to install, connect to the portal and acquire updates. We deployed the iOS protection app by sending email invites from the portal and, when the app had loaded, it created a VPN link to the nearest WithSecure concentrator and applied reputation-based web filtering. The Elements home page is being updated and currently can't show mobile devices, but the EPP dashboard displayed them without any problems.</p><p>A preconfigured read-only profile is assigned to devices on first contact. This enables full protection and allows users to access the local interface, run manual scans and turn off features. </p><p>Another default profile is provided that stops users from accessing the agent settings, and we cloned these and used them as a basis for our own profiles. Profiles offer full control and are used to manage real-time scanning, permit users to run manual scans, determine when automatic updates occur and schedule regular system scans. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yGrD2DVbt65GR3FxUz7gnR" name="" alt="The WithSecure UI" src="https://cdn.mos.cms.futurecdn.net/yGrD2DVbt65GR3FxUz7gnR.png" mos="https://cdn.mos.cms.futurecdn.net/yGrD2DVbt65GR3FxUz7gnR.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Web protection includes reputation-based web page scanning, safe search enforcement, browser plug-ins to show link reputations in searches and content control, with a list of 32 URL categories you can block. The infection reports from the older portal have been replaced with a more informative security events view, where you can also enable email alerts. </p><p>We were impressed with EPP's lightning-fast reactions: after introducing malware to our test clients, the security events page listed them in 15 seconds with email warnings issued within five minutes.</p><p>EPP can be augmented with the optional Endpoint Detection and Response (EDR) module, which provides a proactive stance on attacks that can automatically isolate compromised systems before they affect others. You can also extend your security umbrella over Microsoft 365, as the Collaboration Protection module keeps threats at bay for Exchange and SharePoint Online, and both this and EDR are accessed from the same cloud portal as EPP.</p><p>WithSecure's Elements Endpoint Protection is a good-value choice. It's simple to deploy, supports a wide range of client platforms and is easily managed from the Elements cloud portal.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hyundai vulnerability allowed remote hacking of locks, engine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine</link>
                                                                            <description>
                            <![CDATA[ Researchers discovered flaws in a number of apps linked to car brands that allowed for personal details and remote control of vehicles using easily-obtained IDs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i8ZbxHzNYiVmtEjxPnd238</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PsNDgsB39eqkzsJDBUMT4M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Nov 2022 13:03:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PsNDgsB39eqkzsJDBUMT4M-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A phone screen displaying the Hyundai logo, with a car&amp;#039;s dashboard in the background]]></media:description>                                                            <media:text><![CDATA[A phone screen displaying the Hyundai logo, with a car&amp;#039;s dashboard in the background]]></media:text>
                                <media:title type="plain"><![CDATA[A phone screen displaying the Hyundai logo, with a car&amp;#039;s dashboard in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PsNDgsB39eqkzsJDBUMT4M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have discovered a vulnerability affecting Hyundai and Genesis cars, which would have allowed hackers to remotely control functions such as the door locks and engine. </p><p>The exploit impacts cars by Hyundai and Genesis released since 2012 and targets a weakness in the use of insecure vehicle data in mobile apps intended for use by the owners of the vehicles.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4qUL44hnm28GfMZkPQvas" name="4qUL44hnm28GfMZkPQvas.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/4qUL44hnm28GfMZkPQvas.png" mos="https://cdn.mos.cms.futurecdn.net/4qUL44hnm28GfMZkPQvas.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Forrester Wave API management solutions, Q3 2022</strong></p><p class="fancy-box__body-text">The 15 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/application-programming-interface-api/369374/the-forrester-wave-api-management" data-original-url="/development/application-programming-interface-api/369374/the-forrester-wave-api-management">FREE DOWNLOAD</a></p></div></div><p>The API calls used to control the locks, horn, engine, headlights, and boot controls of cars were easily exploitable, and could be backwards engineered to give hackers full remote access to the car's functions, the researchers said.</p><p>In a <a href="https://twitter.com/samwcyo/status/1597695281881296897">thread</a> on Twitter, bug bounty hunter Sam Curry explained the process in full. Within the affected apps, functionality like locking and unlocking the user’s car was secured behind an access token, a JSON web token generated from an authenticated email account, checked against the HTTP request made in the app and the car’s vehicle identification number (VIN). </p><p>However, the regular expression (regex) used to accept email strings as valid allowed for the inclusion of special characters. Curry and fellow researchers quickly discovered that by appending a carriage return line feed (CRLF) character at the end of an email address that already existed on the system, they could send an HTTP request to a secure endpoint. This contained a list of vehicles registered to the given address, allowing for the VINs of any chosen customer to be harvested.</p><p>Using the faked JWT, the researchers sent an unlock vehicle request to a car owned by a collaborator, and received “200 OK” back at the same time as the car's locks responded to the request.</p><p>Once the manual process had been figured out, the researchers were able to massively reduce the steps a threat actor would have to take, using a simple <a href="https://www.itpro.com/development/programming/368567/coding-vs-programming-vs-scripting-whats-the-difference" data-original-url="https://www.itpro.com/development/programming/368567/coding-vs-programming-vs-scripting-whats-the-difference">script</a> written in <a href="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer" data-original-url="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer">Python</a>. Using this, all that was required was the victim’s email address to gain access to their car, and commands could be run entirely within the program.</p><p>"Hyundai worked diligently with third-party consultants to investigate the purported vulnerability as soon as the researchers brought it to our attention," a Hyundai spokesperson told <em>IT Pro</em>. </p><p>"Importantly, other than the Hyundai vehicles and accounts belonging to the researchers themselves, our investigation indicated that no customer vehicles or accounts were accessed by others as a result of the issues raised by the researchers. </p><p>"We also note that in order to employ the purported vulnerability, the e-mail address associated with the specific Hyundai account and vehicle as well as the specific web-script employed by the researchers were required to be known. Nevertheless, Hyundai implemented countermeasures within days of notification to further enhance the safety and security of our systems. We value our collaboration with security researchers and appreciate this team’s assistance."</p><p>Earlier in the year, Curry and other researchers stress-tested a number of similar telematics apps, with the common link of developer SiriusXM Connected Vehicle Services (SiriusXM), as outlined in a subsequent Twitter <a href="https://twitter.com/samwcyo/status/1597792097175674880">thread</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/25250/researchers-prove-self-driving-cars-can-be-hacked" data-original-url="/security/25250/researchers-prove-self-driving-cars-can-be-hacked">Researchers prove self-driving cars can be hacked</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/369147/11-million-tesla-cars-recalled-over-software-glitch" data-original-url="/security/vulnerability/369147/11-million-tesla-cars-recalled-over-software-glitch">1.1 million Tesla cars recalled over software glitch</a></p></div></div><p>“We take the security of our customers’ accounts seriously and participate in a bug bounty program to help identify and correct potential security flaws impacting our platforms," a Sirius XM Connected Vehicle Services spokesperson told <em>IT Pro</em>.</p><p>"As part of this work, a security researcher submitted a report to Sirius XM's Connected Vehicle Services on an authorization flaw impacting a specific telematics program. The issue was resolved within 24 hours after the report was submitted. At no point was any subscriber or other data compromised nor was any unauthorised account modified using this method.”</p><p>SiriusXM provides connected vehicles systems for cars from a number of household automotive brands. Researchers discovered that through the use of only the VIN of a customer’s car, it was possible to not only remotely activate vehicle features, but to also fetch a customer’s user profile within the NissanConnect app. This contained details including the victim’s name, phone number, and address. Similar vulnerabilities were replicated in the apps of Honda, Infiniti, FCA, and Acura.</p><p>Derek Abdine, CEO at <a href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai" data-original-url="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai">artificial intelligence (AI)</a> company furl, <a href="https://twitter.com/dabdine/status/1597876317025812480">responded</a> to Curry with the claim that VINs are widely available on dealership websites.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1597876317025812480"></a></p></blockquote><div class="see-more__filter"></div></div><p>All vulnerabilities were reported to the relevant companies, which have patched the vulnerabilities.</p><p>Concerns around the vulnerability of cars that connect to apps have been around for years. In 2016, the <a href="https://www.itpro.com/security/hacking" data-original-url="https://www.itpro.com/hacking/26234/fbi-issues-connected-car-hacking-warning">FBI warned connected cars can be hacked</a>, and particularly stressed the risk posed by cars that connect to mobile devices. The same year, <a href="https://www.itpro.com/security/27278/tesla-patches-model-s-after-chinese-hack" data-original-url="https://www.itpro.com/security/27278/tesla-patches-model-s-after-chinese-hack">Chinese hackers remote targeted a Tesla</a>, with security researchers as Tencent’s Keen Labs passing the details of the successful attack onto the EV firm to patch.</p><p><em>This article originally stated that Hyundai cars could be accessed without the need for a victim's email address. This was inaccurate, and the article has now been updated to reflect this.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Avast Premium Business Security review: Feature-rich endpoint management for SMBs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/369600/avast-premium-business-security-review</link>
                                                                            <description>
                            <![CDATA[ Avast delivers a wealth of tough, easily managed endpoint protection measures at a good price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ac2f6wFvPsmTL6rd9StoEC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dPQ2LF5HMAmYcr8g4NgaG5-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Nov 2022 12:00:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/dPQ2LF5HMAmYcr8g4NgaG5-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Avast Premium Business Security interface ]]></media:description>                                                            <media:text><![CDATA[Avast Premium Business Security interface ]]></media:text>
                                <media:title type="plain"><![CDATA[Avast Premium Business Security interface ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dPQ2LF5HMAmYcr8g4NgaG5-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SMBs that want endpoint protection with an emphasis on simplicity will find Avast's cloud-managed business security solutions could fit the bill nicely. It's easy to control costs, too, with Avast offering a range of versions covering home and small offices with up to ten users, plus Essential, Premium and Ultimate versions which can all protect up to 100 devices.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/363154/citrix-endpoint-security-is-not-enough-to-protect-business-data" data-original-url="/cloud/cloud-security/363154/citrix-endpoint-security-is-not-enough-to-protect-business-data">Citrix: endpoint security is not enough to protect business data</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368882/avast-launches-ransomware-shield-for-small-businesses" data-original-url="/security/cyber-security/368882/avast-launches-ransomware-shield-for-small-businesses">Avast launches Ransomware Shield for small businesses</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some" data-original-url="/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some">Avast One Essential review: A great free antivirus solution with some tempting extra features</a></p></div></div><p>We reviewed Premium Business Security (PBS), which takes all the protection services from the Essential version and adds removable device controls plus Avast's built-in VPN service for securing workstation internet connections. The Ultimate version includes Windows patch management and increases yearly costs for 25 devices to £1,023.</p><p>Installation choices are plentiful. You can download the <a href="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review">Windows</a> and <a href="https://www.itpro.com/software/operating-systems/369384/security-features-apple-macos-ventura-compelling-business-upgrade" target="_blank" data-original-url="https://www.itpro.com/software/operating-systems/369384/security-features-apple-macos-ventura-compelling-business-upgrade">macOS</a> agents and place them in a central distribution point or email a downlink to staff and remote workers. LAN deployment can be sped up by promoting one system to scanning agent status, viewing the list of discovered devices and pushing the agent to them directly from the cloud portal.</p><p>Protection starts immediately: unless otherwise requested, endpoints are assigned a default policy that has all the main security services enabled. Policies are a powerful tool and allow you to enable Avast's CyberCapture Windows service for blocking unknown files and new threats, real-time anti-malware scanning, app behaviour, mail and web activity shields, a client firewall, a security browser extension, anti-spam and a sandbox for running untrusted or unknown apps in a safe environment.</p><p>If permitted, users can load the agent interface, view their protection status, run on-demand scans, access the sandbox and use the webcam shield to block snoopers by only permitting their camera to be used by specific apps. Supporting Windows and macOS clients, the ransomware shield protects nominated files and folders from encryption attempts by untrusted apps.</p><p>Mobile support includes Android and iOS devices, but although the apps are included free with every device seat in your subscription, Android users get the lion's share of security services and neither can be cloud-managed. All we could do with the iOS Security & Privacy app on an iPad was enter our subscription key, create an instant connection to Avast's VPN service for secure web browsing and see if the app considered our Wi-Fi connection safe.</p><p>The Avast cloud management portal sees a substantial redesign, making it even easier to use, and its simplified dashboard tells you everything you need to know about your security posture. A top table shows all threats broken down into unresolved, quarantined and resolved status, with each providing hot links for viewing detected threats and compromised endpoints.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dEepSJfbVh7mxRAUSTFsXo" name="dEepSJfbVh7mxRAUSTFsXo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" mos="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2022 IBM's Security X-Force cloud threat landscape report</strong></p><p class="fancy-box__body-text">Recommendations for preparing and responding to cloud breaches</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report" data-original-url="/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report">FREE DOWNLOAD</a></p></div></div><p>A pie chart alongside provides an overview of all protected systems, while below is a real-time graph showing all activity for the past two weeks. Reporting doesn't see many improvements, with the portal offering a set of canned reports for executive summaries, threats, devices, audit logs, tasks and USB device usage, with no options to create custom ones.</p><p>Avast responds quickly to threats. After introducing genuine malware to our test Windows 10 clients, the agent blocked every one and warnings were posted in the dashboard in as little as 30 seconds. We also set up email notifications from the portal, and alerts for all of our tests were received in no more than five minutes. </p><p>Mobile device management would round out Avast's <a href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation" target="_blank" data-original-url="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation">endpoint security</a> offering nicely, but we can't fault it for the sheer depth of protection features on offer. SMBs will find it simple to deploy and easily managed, while its subscription plans are good value.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Magic quadrant for application performance monitoring and observability ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/369399/magic-quadrant-for-application-performance-monitoring-and-observability</link>
                                                                            <description>
                            <![CDATA[ Enabling continuous updating of diverse & dynamic application environments ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qLFK2Z5h94Mh4TFfuncX5d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vSVSxNza7ehoh8LX9kUicj-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Oct 2022 11:08:56 +0000</pubDate>                                                                                                                                <updated>Tue, 03 Jan 2023 11:08:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/vSVSxNza7ehoh8LX9kUicj-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title and text and black header banner with Gartner logo]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title and text and black header banner with Gartner logo]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title and text and black header banner with Gartner logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vSVSxNza7ehoh8LX9kUicj-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>APM and observability tools have become powerful analytics platforms that ingest multiple telemetry feeds, providing critical insight into application performance. The significant differences amongst the vendors mean infrastructure and operations leaders need to consider strategic monitoring choices.</p><p>This Gartner report looks at the capabilities of APM and observability tools, including security functionality, application monitoring on mobile, support for VDIs, and integrations with service management tools, amongst others.</p><p>Read now to gain insights into the current vendor landscape and how IBM Instana has been recognised as a leader in this field.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49900/ibm-q1-2023-magic-quadrant-for-application-performance-monitoring-and-observability?locale=1&p=false&wp=10620"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malwarebytes unveils new MDR service to help bridge cyber skills gap ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369318/malwarebytes-unveils-new-mdr-service-to-help-bridge-cyber-skills-gap</link>
                                                                            <description>
                            <![CDATA[ The new offering combines managed detection and response (MDR) with the vendor’s EDR technology ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">v7odQcp5T8vQSWkpvawcCg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/B2de2D6BREgYYBqXk3pwaf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Oct 2022 10:05:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/B2de2D6BREgYYBqXk3pwaf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MalwareBytes antivirus app on a smartphone]]></media:description>                                                            <media:text><![CDATA[MalwareBytes antivirus app on a smartphone]]></media:text>
                                <media:title type="plain"><![CDATA[MalwareBytes antivirus app on a smartphone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/B2de2D6BREgYYBqXk3pwaf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Malwarebytes has announced a new managed detection and response (MDR) service, which has been designed to help organisations bridge their cyber security staff and knowledge gaps.</p><p>Combined with the firm’s endpoint detection and response (EDR) technology, the MDR offering provides threat prevention and remediation services through a team of cyber security experts, including both automated and human-led protection.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nAkAthFBggqpbeuovZyehc" name="nAkAthFBggqpbeuovZyehc.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nAkAthFBggqpbeuovZyehc.png" mos="https://cdn.mos.cms.futurecdn.net/nAkAthFBggqpbeuovZyehc.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Facilitating Fintech</strong></p><p class="fancy-box__body-text">Reducing the risk of potential data interception among fintech solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369240/facilitating-fintech" data-original-url="/security/369240/facilitating-fintech">FREE DOWNLOAD</a></p></div></div><p>The service includes dedicated analysts assigned to remotely monitor an organisation’s network 24/7 to detect, analyse, and prioritise new threats. </p><p>In an announcement, the company said its new offering can function as an extension of existing teams, or as a complete solution for organisations that lack dedicated security staff. </p><p>"We've recruited an incredible team of dedicated experts across the globe and empowered them with our award-winning tools and AI-based threat modelling to be a powerful force multiplier for SMBs and MSPs," said Bob Shaker, VP of managed services at Malwarebytes.</p><p>Malwarebytes’ EDR technology provides lightweight, integrated endpoint security that bundles together real-time continuous monitoring and <a href="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points" data-original-url="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points">endpoint</a> data collection, with automated response and analysis, it said.</p><p>For SMBs and managed service providers (MSPs) swamped with security alerts, the combination of EDR with human threat intelligence has been designed to help prioritise, detect advanced <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> attacks, analyse past indicators of compromise, as well as reinforce resiliency.</p><p>Additionally, the vendor says it will also help reduce security costs and provide rapid time-to-value, thanks to <a href="https://www.itpro.com/business-strategy/automation/368115/ai-is-now-powerful-enough-to-automate-the-back-office" data-original-url="https://www.itpro.com/business-strategy/automation/368115/ai-is-now-powerful-enough-to-automate-the-back-office">automated onboarding</a> that provides a speedy route from purchase to service operation. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service" data-original-url="/business-operations/31711/what-is-a-managed-it-service">What is a managed IT service?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/367718/malwarebytes-hires-new-channel-chief-to" data-original-url="/business-operations/managed-service-provider-msp/367718/malwarebytes-hires-new-channel-chief-to">Malwarebytes hires new channel chief to lead MSP and partner network</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/366301/the-ingredients-for-a-successful-vendor-msp" data-original-url="/business-operations/managed-service-provider-msp/366301/the-ingredients-for-a-successful-vendor-msp">The ingredients for a successful vendor-MSP partnership</a></p></div></div><p>Malwarebytes MDR arrives as many organisations are struggling to recruit staff with the required <a href="https://www.itpro.com/technology/digital-divide/359566/171-million-britons-lack-essential-digital-skills-for-work" data-original-url="https://www.itpro.com/technology/digital-divide/359566/171-million-britons-lack-essential-digital-skills-for-work">digital skills</a>. Back in April, <a href="https://www.itpro.com/technology/digital-divide/367485/two-in-three-it-employers-struggle-to-recruit-staff-with-adequate" data-original-url="https://www.itpro.com/technology/digital-divide/367485/two-in-three-it-employers-struggle-to-recruit-staff-with-adequate">research conducted by the Open University</a> found that more than three quarters (77%) of surveyed IT decision-makers said they were currently facing a digital skills gap in their organisation.</p><p>Back in 2020, a <a href="https://www.itpro.com/business-strategy/careers-training/354984/half-of-uk-businesses-suffer-from-a-basic-cyber-security" data-original-url="https://www.itpro.com/business-strategy/careers-training/354984/half-of-uk-businesses-suffer-from-a-basic-cyber-security">UK government report</a> also discovered that 27% of businesses have a skills gap when it comes to incident response, and that 48% of surveyed companies were hiring individuals without confidence in their abilities to perform basic tasks. </p><p>With its new MDR service, Malwarebytes said it is now taking steps to help bridge this gap and ensure businesses have adequate protection.</p><p>“This is just the beginning as we continue to accelerate product innovation and deliver new services to secure chronically underserved SMBs and empower MSPs to be their heroes," said Shaker.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The future of work is already here. Now’s the time to secure it. ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369060/the-future-of-work-is-already-here-nows-the-time-to-secure-it</link>
                                                                            <description>
                            <![CDATA[ Robust security to protect and enable your business ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hF9RyNtveqSZoFbVALGxoK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LSdLhNv8ZDJAzbBQMKxLSa-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Sep 2022 06:26:03 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Oct 2022 06:26:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/LSdLhNv8ZDJAzbBQMKxLSa-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with BT logo and title, and businessman looking into the distance]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with BT logo and title, and businessman looking into the distance]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with BT logo and title, and businessman looking into the distance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LSdLhNv8ZDJAzbBQMKxLSa-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As organisations continue to emerge and evolve with new technologies in the wake of the pandemic, it’s the time for great business opportunities: moving operations to the cloud and adopting automation for improved workflows. However, alongside this, cyber criminals are taking advantage of the lack of innovation in security measures to protect these digital transformations.</p><p>This whitepaper explores the importance of improving security measures in parallel with your business innovations, to protect against advancing cyber threats, and leverage the benefits from your digital advancements.</p><p>Download now to learn more about:</p><ul><li>The business areas that require the most protection</li><li>Which security measures to prioritise</li><li>How to achieve robust end-to-end safeguarding</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YLnkHU4nVmM6RwMsBBxfRi" name="" alt="BT logo" src="https://cdn.mos.cms.futurecdn.net/YLnkHU4nVmM6RwMsBBxfRi.png" mos="https://cdn.mos.cms.futurecdn.net/YLnkHU4nVmM6RwMsBBxfRi.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49806/bt-enterprise-form?locale=1&p=false&wp=10314"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Acronis Cyber Protect 22 Advanced review: The next level of data protection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/server-storage/backup/369088/acronis-cyber-protect-22-advanced-review-the-next-level-of-data</link>
                                                                            <description>
                            <![CDATA[ Joined-up hybrid backup and cybersecurity services, all easily managed from a single cloud portal ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oC12JiwR6WK1ohVTjhyAKq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SsyYn9s283agFmjUTocgYL-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Sep 2022 13:56:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Backup]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/SsyYn9s283agFmjUTocgYL-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Acronis Cyber Protect 22 Advanced ]]></media:description>                                                            <media:text><![CDATA[A screenshot of Acronis Cyber Protect 22 Advanced ]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Acronis Cyber Protect 22 Advanced ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SsyYn9s283agFmjUTocgYL-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Acronis’ Cyber Protect puts a different spin on data protection to most rivals, as it combines hybrid backup with AI-driven cybersecurity measures and endpoint management. This will appeal to SMBs that want to avoid the expense of separate solutions, since it means they can pay a single subscription fee for all their data backup and workstation protection services.</p><p>Platform support is impressive and includes Windows, macOS and Linux systems, all popular business apps and almost any virtualisation host you care to name. You can choose from on-premises or cloud-managed versions; we’ve reviewed the latter as this <a href="https://www.itpro.com/agile-working/31887/how-do-i-best-support-my-remote-workers" data-original-url="https://www.itpro.com/agile-working/31887/how-do-i-best-support-my-remote-workers">extends protection to home workers</a> and mobile devices.</p><p>Acronis offers Essentials, Standard, Advanced and Backup Advanced editions. We tested the Advanced version, which activates features such as deduplication, backup malware scans and security posture reports. All security services are enabled and include malware protection, web content filtering, <a href="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult" data-original-url="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult">patch management</a>, remote desktop services and vulnerability assessment reports.</p><p>Subscriptions are based on the type and number of protected systems, with workstations priced at £79 each per year and <a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines" data-original-url="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines">one VMware or Hyper-V host</a> and unlimited VMs costing £729. This includes 250GB of cloud storage, with further 1TB chunks costing £379 per year, while the optional cloud disaster recovery service starts at £389 for an extra-small cloud VM.</p><p>The web portal presents detailed overviews on protected systems, backup repository status, alerts, detected malware, blocked URLs and patch status. It can get very busy but each chart and graph is widget-based so you can easily customise it to your own requirements.</p><p>Protection plans combine backup requirements, encryption passwords, schedules and security settings. Primary and secondary storage locations can be assigned to a plan, and we used <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/368728/synology-diskstation-ds3622xs-review-big-storage" data-original-url="https://www.itpro.com/server-storage/network-attached-storage-nas/368728/synology-diskstation-ds3622xs-review-big-storage">local Synology NAS shares</a> for fast local backups and the Acronis cloud repository for our secondary, off-site store.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QgZxXBEMD39MZdndQVR9yW" name="" alt="A screenshot of Acronis Cyber Protect 22 Advanced" src="https://cdn.mos.cms.futurecdn.net/QgZxXBEMD39MZdndQVR9yW.jpg" mos="https://cdn.mos.cms.futurecdn.net/QgZxXBEMD39MZdndQVR9yW.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Within workstation plans, you can enable real-time malware scanning, apply URL filtering using up to 44 categories, schedule vulnerability assessments and run patch management remediation tasks. A data-protection map reports on unprotected files, while device controls can be used to block access to USB ports, removable storage, printers and screenshot activities.</p><p>No email invitation options are provided so agents must be copied to each workstation, installed manually and logged in to the cloud console. This can get tedious but, once registered, they can be assigned to a plan that automates all further backup and protection. </p><p>A separate agent is provided for Hyper-V systems while for VMware, we downloaded the agent VM, installed it on a vCenter host and configured it with our cloud credentials. Once the host agents were deployed, the portal listed all their VMs, and using a plan to protect them at the host level ensured newly created VMs would be included.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/backup/367217/it-pro-panel-building-your-backup-strategy" data-original-url="/server-storage/backup/367217/it-pro-panel-building-your-backup-strategy">IT Pro Panel: Building your backup strategy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/backup/358644/acronis-true-image-2021-review-the-consummate-do-it-all-package" data-original-url="/server-storage/backup/358644/acronis-true-image-2021-review-the-consummate-do-it-all-package">Acronis True Image 2021 review: The consummate do-it-all package</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/backup/357713/how-good-is-your-backup-really" data-original-url="/server-storage/backup/357713/how-good-is-your-backup-really">How good is your backup, really?</a></p></div></div><p>Along with swift file and folder recovery services for remote workstations, the portal provides excellent restore functions for Hyper-V and VMware. We were able to recover entire VMs to their original location, as a new VM on the same host or another location while for even faster recovery, it can create a temporary VM on the host from a local backup.</p><p>An Advanced Backup subscription adds Microsoft 365 protection with facilities for Exchange Online, OneDrive for Business, SharePoint Online and Teams. It’s included in the free 30-day trial, and we had no problems authenticating it with our live Microsoft 365 account and creating protection plans for cloud-to-cloud backups of all four components.</p><p>Acronis Cyber Protect takes data protection to another level with its clever partnership of hybrid backup and endpoint security. Agent deployment could be further improved, but the whole package is easily managed from one cloud portal and it provides extensive platform support.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Avira Free Security review: An effective antimalware suite, but heavy on the marketing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/368331/avira-free-security-review-an-effective-antimalware-suite-but-heavy-on</link>
                                                                            <description>
                            <![CDATA[ It’s hard to fully appreciate Avira’s malware protection when the packaging feels so manipulative ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">prfG8w5ZJd21BfQA2J9mYK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iDZfUUPTNDboLNBuQXh9f3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jun 2022 11:34:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darien Graham-Smith ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nZP8qH6BDshBkBZo9Kvhbe.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iDZfUUPTNDboLNBuQXh9f3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Avira Free Security&amp;#039;s main dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of Avira Free Security&amp;#039;s main dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Avira Free Security&amp;#039;s main dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iDZfUUPTNDboLNBuQXh9f3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Avira Free Security looks smart, with its dark colour scheme and tasteful splashes of colour. It also looks quite substantial for a free security suite: distributed across the Security, Privacy and Performance pages you’ll find a total of 16 big buttons for various promising-sounding functions.</p><p>Unfortunately, once you start clicking around, you discover that many of the apparent features are dummies. Try to enable web, email or <a href="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022" data-original-url="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022">ransomware protection</a> and you’re merely greeted with an advert inviting you to upgrade to the commercial Avira Prime suite. </p><p>Other buttons do half a job, then invite you to pay for the rest of it. For example, the software updater scans your system and warns you about apps that might be obsolete, but when you click “Update” it reveals that automatic updates require – you guessed it – an Avira Prime subscription. It’s not unreasonable to ask people to pay for security services, but this isn’t a respectful way to do it. It doesn’t help that the full suite is pretty pricey, costing £52 for five devices in the first year, rising to £86 after that. </p><p>Although it’s disappointingly light on features, Avira Free Security delivers quite creditable virus protection. In the latest tests by independent security lab <a href="https://www.av-comparatives.org">AV-Comparatives.org</a> it managed a 99.96% malware protection rate while connected to the internet – matching <a href="https://www.itpro.com/security/antivirus/361689/microsoft-defender-effective-effortless-protection-for-zero-cost" data-original-url="https://www.itpro.com/security/antivirus/361689/microsoft-defender-effective-effortless-protection-for-zero-cost">Microsoft Defender</a> – with an impressive false positive rate of just one wrong detection in over 10,000 items. That’s better than any other free security solution we’ve tried.</p><p>Perhaps because so little is actually included in the free package, it’s also very lightweight. In performance tests carried out by <a href="https://www.av-test.org/en/antivirus/home-windows">AV-Test.org</a>, Avira slowed down web browsing on a standard PC by just 8% – just a whisker above Defender’s 5%. Apps launched quickly too, with an 8% slowdown that was once again barely any different to the 6% impact of using Windows’ built-in protections.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GNAKpUP4nUGYghXb23yUqW" name="" alt="A screenshot of Avira Free Security" src="https://cdn.mos.cms.futurecdn.net/GNAKpUP4nUGYghXb23yUqW.jpg" mos="https://cdn.mos.cms.futurecdn.net/GNAKpUP4nUGYghXb23yUqW.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Alongside the main application, the Avira installer sets up the company’s Phantom VPN service. Like <a href="https://www.itpro.com/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some" data-original-url="https://www.itpro.com/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some">Avast’s VPN</a>, this allows limited use for free, but it’s much more restrictive, allowing just 500MB of protected traffic per month. There’s a link to the web-based Avira <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for" data-original-url="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">password manager</a> service too, which can store and auto-fill any number of passwords for free. The optional Avira Safe Shopping browser extension warns you away from fake sites and blocks trackers – though it also inserts coupon deals into web pages, which feels a little sleazy for a security product.</p><p>The component we’re most uneasy about is Avira System SpeedUp – a completely separate app which installs without asking for permission, and pops up when you click various buttons on the Performance page, including Battery saver and Advanced tools. It’s effectively another limited demo: unlocking its features requires a separate SpeedUp Pro licence, which starts at £4 a year, then rockets up to £22.</p><p>To be fair, it’s easy to ignore Avira’s upsell attempts. You can leave the antivirus running in the background and enjoy very good malware protection, with minimal impact on performance. If you do want additional features, though, Avast One Essential gives you much more for free, while those seeking a minimal experience might as well stick with Microsoft Defender.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky Free review: Effective and lightweight – everything you want from a free antivirus solution ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/368179/kaspersky-free-review-effective-and-lightweight-everything-you-want-from</link>
                                                                            <description>
                            <![CDATA[ It’ll be a real shame if politics means people missing out on this top-class security tool ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7YVseFThdABESAaykq8u5S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JaTcpxne5ktuJYFE8JMeS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jun 2022 15:03:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darien Graham-Smith ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nZP8qH6BDshBkBZo9Kvhbe.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JaTcpxne5ktuJYFE8JMeS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Kaspersky Free&amp;#039;s main dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of Kaspersky Free&amp;#039;s main dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Kaspersky Free&amp;#039;s main dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JaTcpxne5ktuJYFE8JMeS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky Lab makes no secret of its Russian origins, and in the current climate <a href="https://www.itpro.com/security/cyber-security/367288/is-kaspersky-still-safe-to-use" data-original-url="https://www.itpro.com/security/cyber-security/367288/is-kaspersky-still-safe-to-use">you might be wary of trusting it with your security</a>. In the past few years though the company has taken steps to put its operations beyond reach of the Kremlin: data storage and processing are now handled in Switzerland, while additional “transparency centres” in Brazil, Canada, Malaysia and Spain allow governments and other institutions to review the company’s code and practices.</p><p>There’s no question about Kaspersky’s malware-blocking credentials, though. In the latest independent tests by <a href="https://www.av-comparatives.org">AV-Comparatives.org</a> the Kaspersky engine achieved a superb online protection score of 99.98% – slightly better than <a href="https://www.itpro.com/security/antivirus/361689/microsoft-defender-effective-effortless-protection-for-zero-cost" data-original-url="https://www.itpro.com/security/antivirus/361689/microsoft-defender-effective-effortless-protection-for-zero-cost">Microsoft Defender</a> on 99.96%. It racked up fewer false positives too: against a set of more than 10,000 items, Kaspersky wrongly raised the alarm just twice, while Defender missed the mark five times. <a href="https://www.av-test.org/en">AV-Test.org</a> confirms the engine’s effectiveness: in its tests for January and February 2022, Kaspersky provided impeccable 100% protection against both <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">new “zero-day”</a> and widespread threats.</p><p>The user experience is delightfully clean. Although Kaspersky’s main business is commercial security products, the Kaspersky Free Windows client has no adverts or non-functional buttons – a real breath of fresh air. </p><p>Instead there are just a few buttons for the major functions. From the Home page you can quickly scan your computer for malware and check online to see whether your personal credentials have been compromised; on the Security page you’ll also find buttons to download emergency boot media, and to scan your Windows configuration for suspicious or corrupted settings.</p><p>That may sound a bit minimal, but there’s more going on behind the scenes. Kaspersky Free also quietly takes care of web and email scanning, while the System Watcher component keeps an eye out for <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">ransomware-like behaviour</a> and automatically offers to undo potentially harmful activity. If anything, these components are perhaps a bit <em>too</em> unobtrusive: unless you delve into the program settings you might never realise that they’re enabled. Still, that’s better than AVG’s approach, which puts big fake buttons in its interface purely to tell you that these features <em>aren’t</em> available in the free suite.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JA5nbrycaXyBFeuRc3DVj" name="" alt="A screenshot of Kaspersky Free's performance dashboard" src="https://cdn.mos.cms.futurecdn.net/JA5nbrycaXyBFeuRc3DVj.jpg" mos="https://cdn.mos.cms.futurecdn.net/JA5nbrycaXyBFeuRc3DVj.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/367661/panda-free-antivirus-review-a-free-security-tool-with-a-personality-all" data-original-url="/security/antivirus/367661/panda-free-antivirus-review-a-free-security-tool-with-a-personality-all">Panda Free Antivirus review: A free security tool with a personality all of its own</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender" data-original-url="/desktop-software/26635/how-to-turn-on-windows-defender">How to turn on Windows Defender</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/367781/mcafee-appoints-greg-johnson-as-new-ceo" data-original-url="/business-strategy/careers-training/367781/mcafee-appoints-greg-johnson-as-new-ceo">McAfee appoints Greg Johnson as new CEO</a></p></div></div><p>A few other tools are hidden away under Settings. A Privacy Cleaner scans your system for records of recently accessed files, cookies, caches and so forth, while an optional on-screen keyboard helps defeat keyloggers. The resource consumption options let you tweak things like automatic scans, to help minimise battery drain or avoid possible interference with games.</p><p>That’s not a huge issue, as Kaspersky Free is fairly lightweight. In AV-Test.org’s performance tests, it slowed down web browsing on a standard PC by 14% – that’s some way behind Defender’s 5% impact, but better than <a href="https://www.itpro.com/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some" data-original-url="https://www.itpro.com/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some">Avast One Essential</a> on 17% and well ahead of <a href="https://www.itpro.com/security/cyber-security/355934/avg-antivirus-free-review" data-original-url="https://www.itpro.com/security/cyber-security/355934/avg-antivirus-free-review">AVG AntiVirus Free’s 28%</a>. Similarly, Kaspersky had a 10% impact on application launch speed, versus 6% from Defender and 12% from Avast and AVG.</p><p>One thing that Kaspersky Free lacks is centralised administration; you can connect up to three installations under an individual email address, but it’s not designed to be managed across businesses. Even if you can live with that, it’s understandable if you’re still <a href="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning" data-original-url="https://www.itpro.com/security/antivirus/367251/ncsc-kaspersky-warning">uncomfortable rolling out a Russian security solution</a>. But with its excellent protection, generous feature set and unobtrusive design, Kaspersky Free has enough going for it to deserve serious consideration.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Avast One Essential review: A great free antivirus solution with some tempting extra features ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/367693/avast-one-essential-review-a-great-free-antivirus-solution-with-some</link>
                                                                            <description>
                            <![CDATA[ If Microsoft Defender isn’t doing it for you, Avast has you covered with strong protection in a user-friendly package ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">97r5rfmZov1v5qSXaKoyAJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jqr4y6C52nezCX6uBNvJRn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 May 2022 08:00:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darien Graham-Smith ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nZP8qH6BDshBkBZo9Kvhbe.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jqr4y6C52nezCX6uBNvJRn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Avast One Essential&amp;#039;s main dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of Avast One Essential&amp;#039;s main dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Avast One Essential&amp;#039;s main dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jqr4y6C52nezCX6uBNvJRn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This popular security suite has recently received a new name and a new look, but the price hasn’t changed: Avast One Essential is free forever, across Windows, Android, macOS, and iOS devices.</p><p>Naturally, there’s a paid option too. The full Avast One package costs £40 a year for up to five devices, or £55 for up to 30 devices. This is sold as a family licence, however, and doesn’t include corporate-friendly management options. Note too that these prices only cover the first year of service, after which the cost doubles.</p><p>Still, the free edition is useful enough. Job one, of course, is virus protection, and here Avast One is hard to criticise. In the most recent tests by independent security lab <a href="https://www.av-comparatives.org">AV-Comparatives.org</a>, the Avast engine provided excellent 99.8% protection when connected to the internet – a fraction above Microsoft Defender’s 99.6%. <a href="https://www.av-test.org/en">AV-Test.org</a> achieved even better results, reporting a 100% score for Avast against both unknown zero-day threats and prevalent malware during the first two months of 2022.</p><p>The Windows edition of Avast One also includes a nifty custom firewall, and a <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">ransomware protection</a> feature that blocks untrusted processes from writing to your personal folders. While similar capabilities are already built into Windows, Avast’s implementations have a friendlier interface, making it less of a chore to check and configure these security settings.</p><p>Something Windows definitely can’t match is <a href="https://www.itpro.com/networking/27210/do-i-need-a-vpn" data-original-url="https://www.itpro.com/networking/27210/do-i-need-a-vpn">a free VPN</a>. Avast One can protect your privacy by routing all your internet traffic through a private server, with a pretty generous transfer limit of up to 5GB a week. The catch is that you don’t get to pick your server location – Avast selects the fastest one for you. If you want a free choice of all available servers, across 37 countries, you’ll need a paid subscription.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WX5KxCTMjdHk9xX4rG69Yf" name="" alt="A screenshot of Avast One Essential's ransomware protection module" src="https://cdn.mos.cms.futurecdn.net/WX5KxCTMjdHk9xX4rG69Yf.jpg" mos="https://cdn.mos.cms.futurecdn.net/WX5KxCTMjdHk9xX4rG69Yf.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Other free features include <a href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">password protection</a>, which checks whether your credentials have leaked online, and a speedup module that identifies potentially unwanted programs running in the background. A secure custom browser is included too, to help protect you against snoopers.</p><p>We do have some reservations about Avast. The interface feels a bit overloaded, with a proliferation of panes, scrollable lists and buttons – some of them acting as advertisements for features that aren’t actually included in the free edition. Most perplexingly, the shortcut buttons to launch a quick scan or activate the VPN are hidden off the bottom of the home page, so you have to scroll down to find them.</p><p>Then again, the number of controls reflects the breadth of features on offer, and how configurable they all are, while premium-only features are all clearly marked as such – an example we wish more free software would follow.</p><p>Another possible point of concern is false positives: AV-Comparatives noted that, during its tests, Avast One incorrectly gave warnings about 10 legitimate files. Still, that’s out of more than 10,000 test cases, and it’s a lot better than <a href="https://www.itpro.com/security/antivirus/367661/panda-free-antivirus-review-a-free-security-tool-with-a-personality-all" data-original-url="https://www.itpro.com/security/antivirus/367661/panda-free-antivirus-review-a-free-security-tool-with-a-personality-all">Panda’s free solution</a>, which wrongly intercepted a shocking 96 items.</p><p>In all, Avast One Essential is an effective and likeable option for those seeking a free antivirus solution. It’s not as manageable as Microsoft Defender, but it has a good spread of features that add some worthwhile extra layers of protection.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Deliver a modernised end-user experience that pays for itself ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/digital-transformation/367723/deliver-a-modernised-end-user-experience-that-pays</link>
                                                                            <description>
                            <![CDATA[ Start modernising PC lifecycle management today ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dhYCGPrPoVPwHjeMakGhTF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MvhpzpHefE4nmX4AeKi7si-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 May 2022 09:39:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/MvhpzpHefE4nmX4AeKi7si-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title band at bottom and image of man working at a laptop above, with a bicycle in the background]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title band at bottom and image of man working at a laptop above, with a bicycle in the background]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title band at bottom and image of man working at a laptop above, with a bicycle in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MvhpzpHefE4nmX4AeKi7si-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Get five steps to adopting the Dell Technologies Unified Workspace and start modernising PC lifecycle management today. </p><p>This end-to-end approach to deploying, securing, and managing Dell devices saves up to nearly a week of IT time per 1000 devices deployed, provides 11 times faster support, and configures your entire endpoint fleet from a single console. </p><p>Download this whitepaper to find out how this solution improves the employee experience and ramps up productivity to end up paying for itself.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Hks5B9XYkXuxDdWtEGVjkf" name="" alt="Dell Intel logo" src="https://cdn.mos.cms.futurecdn.net/Hks5B9XYkXuxDdWtEGVjkf.png" mos="https://cdn.mos.cms.futurecdn.net/Hks5B9XYkXuxDdWtEGVjkf.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49666/form-9460?locale=1&p=false&wp=9361"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft's Windows Autopatch brings automated updates for IT admins ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/operating-systems/microsoft-windows/367333/windows-autopatch-automated-updates</link>
                                                                            <description>
                            <![CDATA[ Endpoint Manager updates also include targeted IT messages for organisations and more security controls ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DDdbk1ogWWUTps766g4eC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/E2pGTXpsxJZTCJuY3tUBqK-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 05 Apr 2022 16:30:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/E2pGTXpsxJZTCJuY3tUBqK-1280-80.png">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft&amp;#039;s Remote help feature]]></media:description>                                                            <media:text><![CDATA[Microsoft&amp;#039;s Remote help feature]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft&amp;#039;s Remote help feature]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/E2pGTXpsxJZTCJuY3tUBqK-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has announced a range of endpoint management features to take the administrative burden away from IT teams, including automated updates, a premium tier of Endpoint Manager and targeted messaging across an organisation.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/367260/windows-11-growth-slows-in-march" data-original-url="/operating-systems/microsoft-windows/367260/windows-11-growth-slows-in-march">Windows 11 growth slows in March</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/361004/the-new-frontier-of-endpoint-management" data-original-url="/security/endpoint-security/361004/the-new-frontier-of-endpoint-management">The new frontier of endpoint management</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/operating-systems/microsoft-windows/367249/windows-11-change-browser-one-click-feature" data-original-url="/operating-systems/microsoft-windows/367249/windows-11-change-browser-one-click-feature">Microsoft finally makes it easier to switch default browsers in Windows 11</a></p></div></div><p>The first of the new automated services is 'Windows Autopatch', which is designed to free up IT teams by making the management of Windows and Microsoft 365 updates easier. The aim its to minimise the burden of updates for Windows, Edge, and Office and have an automatic process for all <a href="https://www.itpro.com/security/endpoint-security/361004/the-new-frontier-of-endpoint-management" target="_blank" data-original-url="https://www.itpro.com/security/endpoint-security/361004/the-new-frontier-of-endpoint-management">company endpoints</a>. The service keeps all devices protected and compliant so that IT teams can focus on other areas of the business.</p><p>Autopatch works via a gradual deployment that's meant to prevent overloading on machines. If there are any issues during deployment the service can be stopped and <a href="https://www.itpro.com/operating-systems/27717/how-to-fix-a-stuck-windows-10-update" target="_blank" data-original-url="https://www.itpro.com/operating-systems/27717/how-to-fix-a-stuck-windows-10-update">even reversed if it causes significant disruption</a>.</p><p>Autopatch will be available from July this year at no additional cost to Windows Enterprise E3 subscribers.</p><p>Elsewhere, there are also a number of updates for endpoint management, including 'application management for <a href="https://www.itpro.com/web-browsers/24526/what-is-microsoft-edge" target="_blank" data-original-url="https://www.itpro.com/web-browsers/24526/what-is-microsoft-edge">Microsoft Edge</a>'. This is a BYOD-type feature that aims to help IT teams manage access to corporate resources. It allows managers to configure how data flows in and out of their organisation and also define the treat level on any device.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RCUbdVJemfoD2p34KyonJo" name="RCUbdVJemfoD2p34KyonJo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/RCUbdVJemfoD2p34KyonJo.png" mos="https://cdn.mos.cms.futurecdn.net/RCUbdVJemfoD2p34KyonJo.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Bring insights and data closer to customers with edge computing</strong></p><p class="fancy-box__body-text">How to innovate, make faster decisions and provide engaging experiences</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/367318/bring-insights-and-data-closer-to-customers-with-edge-computing" data-original-url="/security/cyber-security/367318/bring-insights-and-data-closer-to-customers-with-edge-computing">FREE DOWNLOAD</a></p></div></div><p>This seems to be primarily aimed that those workers logging into company Edge accounts on their own devices, for temporary reasons, such as checking unfinished work or sending last-minute emails, but without creating a security risk.</p><p>There will also be a premium version of Microsoft Endpoint Manager, which is aimed at companies that want a <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero-trust security model</a>. The first feature for the premium tier is Endpoint Manager Remote, which deals with helpdesk and users connections for hybrid environments.</p><h2 id="company-wide-messages-direct-to-your-device">Company wide messages direct to your device</h2><p>Finally, IT teams will also have a new communication tool that allows for businesses to send messages to every user device simultaneously through Windows 11. These can be sent directly to users across "various surfaces", according to Microsoft. That includes desktops, lock screens, or even right above a user's taskbar.</p><p>The idea is that critical company announcements can be sent as device notifications instead of becoming lost in an email folder. Messages can be sent with customised links and URLs directly from the Endpoint Manager admin centre. A defined target of users is set via an integration with the Azure Active Directory.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Unified endpoint management solutions 2021-22 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/367050/unified-endpoint-management-solutions-2021-22</link>
                                                                            <description>
                            <![CDATA[ Analysing the UEM landscape ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r9nz11fQuavkrRBSoUtkhL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Mar 2022 14:43:21 +0000</pubDate>                                                                                                                                <updated>Mon, 04 Jul 2022 10:43:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title on shaded pink/purple background]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title on shaded pink/purple background]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title on shaded pink/purple background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The rise of hybrid working means that many businesses now have to manage a workforce that is remote for part or all of the working week. In this climate, organisations are increasingly turning to unified endpoint management (UEM) solutions to keep their employees and their devices secure.</p><p>Companies seeking to adopt more modern management practices are driving growth in the UEM market, and these solutions are now considered a vital piece of the broader enterprise IT infrastructure puzzle.</p><p>Read the report to understand Omdia's analysis of the UEM landscape, as well as why IBM was named one of the leaders for unified endpoint management.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49716/ibm-q3-2022-en?locale=1&p=false&wp=9820"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How a platform approach to security monitoring initiatives adds value ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/367042/how-a-platform-approach-to-security-monitoring-initiatives-adds-value</link>
                                                                            <description>
                            <![CDATA[ Integration, orchestration, analytics, automation, and the need for speed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dnP93SwkUbq8cZ4NS2v1Bc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Mar 2022 13:57:25 +0000</pubDate>                                                                                                                                <updated>Fri, 01 Apr 2022 13:57:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title on burgundy square graphic]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title on burgundy square graphic]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title on burgundy square graphic]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mG92862tEkcmYjwLpumZzk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The most productive security teams are going beyond the use of tactical tools for investigation and reporting of security incidents. Instead, they are taking a more strategic, proactive, platform-oriented approach to identifying and assessing security-related risks, proving compliance, and maturing the flexibility and resilience of ongoing operations.</p><p>Read this report to learn about the evolution of security monitoring capabilities and discover what comprehensive security technologies companies are investing in to support their work from anywhere (WFA) / hybrid work model.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49614/ibm-q2-2022?locale=1&p=false&wp=8951"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to keep your customers’ endpoint security covered ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/367001/how-to-keep-your-customers-endpoint-security-covered</link>
                                                                            <description>
                            <![CDATA[ The new capabilities that allow for more oversight and control ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6u2KPer3SdZGtY8mmePGhW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Mar 2022 12:32:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:description>                                                            <media:text><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:text>
                                <media:title type="plain"><![CDATA[Hand hovering over laptop with padlock graphic superimposed]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xtx8rK72HcYorinhyiM3Ma-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The shift to hybrid working models has transformed the role of endpoint security in the modern enterprise. As a recent<a href="https://www.gartner.com/smarterwithgartner/gartner-top-security-and-risk-trends-for-2021"> </a>report from <a href="https://www.gartner.com/smarterwithgartner/gartner-top-security-and-risk-trends-for-2021" rel="nofollow" target="_blank">Gartner</a> makes clear, remote work is now just work. 64% of employees are now able to work from home and two-fifths of them are actively doing so. "The movement to hybrid (or remote work) is a durable trend with more than 75% of knowledge workers expecting future hybrid work environments," the report concludes. "From a security perspective, this requires a total reboot of policies and tools to better mitigate risks."</p><p>This is a big deal for resellers and MSPs. IT teams charged with managing and securing a dispersed workforce face countless new points of vulnerability. Those who relied on their traditional network and perimeter-based security models are likely to find – perhaps painfully – that they no longer deliver the protection needed. That’s why channel partners need to step in to help their customers protect their endpoints, making the most of new capabilities like AI and automation to give them more oversight and control.</p><h3 class="article-body__section" id="section-1-start-with-zero-trust"><span>1. Start with Zero-Trust</span></h3><p>Once you’re securing endpoints both inside and outside the corporate network, the classic network security architecture of perimeters and firewalls breaks down and you need a new model to replace it. Zero-trust security isn’t a technology or a set of features, but an approach that makes no assumptions about which endpoints, infrastructure, programs or processes can be trusted, and instead uses intelligence and automation to monitor and hunt for threats. When every action is checked and classified and anomalous behaviour found and blocked, you close down the chances of a compromised endpoint resulting in a serious breach.</p><p>With the right technology and services in place, MSPs and businesses can build zero-trust into their endpoint security solutions and start delivering threat detection and remediation capabilities that protect their customers from attack.</p><h3 class="article-body__section" id="section-2-layer-up-and-get-smart-about-security"><span>2. Layer up and get smart about security</span></h3><p>Antivirus products and network firewalls are no longer enough. Endpoint protection involves multiple layers of security, both on the endpoint itself, in the network and running from the cloud. Endpoint protection platforms combine real-time protection and reporting with advanced detection aided by security analytics and real-time intelligence feeds. Endpoint detection and response systems monitor continually for behaviour linked to new exploits, advanced persistent threats and fileless attacks, with everything rooted in zero-trust.</p><p>The most effective of these solutions make extensive use of automation and AI, incorporating machine learning and deep learning for continuous monitoring, detection and protection in a way that neither adds to the workload of the IT team nor slows end-users down at work. They also work perfectly within managed services and solutions, giving providers the chance to offload work from their enterprise customers at the same time as strengthening their endpoint protection. What’s more, the more data MSPs can capture and analyse from a range of customers, the better equipped those automated, intelligent systems will be at detecting and warding off incoming threats.</p><h3 class="article-body__section" id="section-3-centralise-through-the-cloud"><span>3. Centralise through the cloud</span></h3><p>Managing security through a central, cloud-based platform just makes sense. You can monitor endpoints whether they’re on premises or remote. You can apply policies and monitor security from one location using one set of tools. Not only can you manage security, but updates, vulnerabilities, encryption, licensing, privacy and more.</p><p>From a reseller or MSP perspective, centralising through the cloud is even more beneficial. As well as the operational efficiencies in handling everything remotely, it becomes easier to protect and manage multiple customers in less time and without hiring new staff. It also helps ensure visibility across more complex or fragmented network architectures. When threats emerge or customers have concerns, you’re in a better position to have all the relevant answers.</p><h3 class="article-body__section" id="section-4-simplify-and-consolidate"><span>4. Simplify and consolidate</span></h3><p>While a layered approach is a necessity, that doesn’t mean you want to manage a wide range of security solutions and tools from an equally wide range of providers. This makes it difficult to build up in-depth knowledge, and often results in having solutions in place that overlap, waste time and effort or potentially conflict. You also don’t want solutions that require new IT infrastructure on the premises, or add new tools and processes to learn, adopt and update.</p><p>That’s why it pays for MSPs and channel partners to work with a small set of solutions using a minimal set of tools and make the most of built-in automation and integration with existing platforms. Simplify and consolidate, and it’s easier to scale-up, optimise and deliver effective, cost-efficient solutions.</p><h3 class="article-body__section" id="section-5-partner-with-a-specialist"><span>5. Partner with a specialist</span></h3><p>MSPs need more from a security vendor. They need specialist expertise, a depth of knowledge and continuous training to help maintain a view across what can be a fast-moving threat landscape. They need solutions and services they can tailor to their customers’ needs, and technologies that evolve to match new security demands. And if that vendor can also provide integrated solutions, automation, consolidation and simplicity, it becomes easier to drive new business and deliver a great service to customers new and old.</p><p>WatchGuard EPDR brings together Endpoint Protection (EPP) and Endpoint Detection and Response (EDR) capabilities into one easy-to-buy product for maximum security against sophisticated endpoint threats. It protects users from advanced threats, APTs, zero day malware, ransomware, phishing, rootkits, in-memory exploits and malware-less attacks, and also provides IDS, firewall, device control, and URL and content filtering capabilities. EPDR uniquely automates the prevention, detection, containment, and response actions for ultimate security that is easy to manage and deploy. </p><p>WatchGuard EPDR is managed in WatchGuard Cloud, providing a single pane of glass view into the entire WatchGuard Unified Security Platform. Offering a single, centralized interface for delivering and managing network security, advanced threat detection, MFA and endpoint security, WatchGuard Cloud delivers efficient management flows and the utmost in security visibility.</p><p><em><strong>To find out more about WatchGuard and how it’s transforming security for resellers and MSPs, please visit <a href="https://www.watchguard.com/wgrd-partners/security-of-one-partner" rel="nofollow" target="_blank">https://www.watchguard.com/wgrd-partners/security-of-one-partner</a></strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Cloud adds cryptomining protection following widespread exploitation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/362179/google-cloud-adds-cryptomining-protection</link>
                                                                            <description>
                            <![CDATA[ In nearly all cases of compromised Google Cloud instances, cryptomining malware was installed within 22 seconds ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6ZpU5yuuhcFAVLCRQ6eNZz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VZRu2qj6nNJz5g2hzREp5K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Feb 2022 10:47:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VZRu2qj6nNJz5g2hzREp5K-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Cloud logo on a wooden background with pedestrians walking on a street in front of it]]></media:description>                                                            <media:text><![CDATA[Google Cloud logo on a wooden background with pedestrians walking on a street in front of it]]></media:text>
                                <media:title type="plain"><![CDATA[Google Cloud logo on a wooden background with pedestrians walking on a street in front of it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VZRu2qj6nNJz5g2hzREp5K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Cloud has launched a new threat detection solution for Google Cloud Platform (GCP) specifically designed to tackle the mounting cases of <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptomining</a> malware operating through compromised cloud instances.</p><p>Google Cloud said the Virtual Machine Threat Detection (VMTD) is a first-to-market solution from a major cloud provider, now available in public preview as an added security layer within Security Command Center (SCC) Premium.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/361905/google-cloud-acquires-siemplify" data-original-url="/cloud/cloud-security/361905/google-cloud-acquires-siemplify">Google Cloud acquires Israeli security startup Siemplify</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/361672/hacked-google-cloud-platform-instances-are-riddled-with-cryptominers" data-original-url="/cloud/cloud-computing/361672/hacked-google-cloud-platform-instances-are-riddled-with-cryptominers">Compromised Google Cloud Platform instances are riddled with cryptominers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/362121/google-cloud-reports-31bn-annual-losses" data-original-url="/cloud/cloud-computing/362121/google-cloud-reports-31bn-annual-losses">Google Cloud lost $3.1 billion in 2021</a></p></div></div><p>Virtual machine-based computing accounts for a significant portion of businesses' operations running in the cloud and according to a <a href="https://www.itpro.com/cloud/cloud-computing/361672/hacked-google-cloud-platform-instances-are-riddled-with-cryptominers" data-original-url="https://www.itpro.com/cloud/cloud-computing/361672/hacked-google-cloud-platform-instances-are-riddled-with-cryptominers">November 2021 threat intelligence report from Google Cloud</a>, cryptomining activity was observed in 86% of all compromised GCP instances, making it the leading issue affecting Google Cloud customers.</p><p>The time it took for attackers to install this financially-motivated malware was quick, too, with more than half of cases (58%) seeing malware installed within just 22 seconds of compromising the platform.</p><p>Google Cloud said in most cases, this was due to exploitation of poor customer security practices or vulnerable third-party software. Leveraging the power of cloud computing can improve the efficiency of cryptomining malware due to its scalable nature, potentially raising monthly <a href="https://www.itpro.com/cloud/31922/four-ways-to-keep-cloud-costs-under-control" data-original-url="https://www.itpro.com/cloud/31922/four-ways-to-keep-cloud-costs-under-control">cloud bills</a> for businesses by a large sum.</p><p>"The economy of scale enabled by the cloud can help fundamentally change the way <a href="https://www.itpro.com/cloud/cloud-security/362149/tiktok-euromoney-cisos-retraining-staff-critical-to-cloud-success" data-original-url="https://www.itpro.com/cloud/cloud-security/362149/tiktok-euromoney-cisos-retraining-staff-critical-to-cloud-success">security</a> is executed for any business operating in today’s threat landscape," said Timothy Peacock, product manager at Google Cloud. "As more companies adopt cloud technologies, security solutions built into cloud platforms help address emerging threats for more and more organisations.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nrLP4J9zrGeXVej3Fjg2DP" name="nrLP4J9zrGeXVej3Fjg2DP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nrLP4J9zrGeXVej3Fjg2DP.png" mos="https://cdn.mos.cms.futurecdn.net/nrLP4J9zrGeXVej3Fjg2DP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Secure hybrid cloud for dummies</strong></p><p class="fancy-box__body-text">Accelerate transformation with hybrid cloud</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/362139/secure-hybrid-cloud-for-dummies" data-original-url="/cloud/hybrid-cloud/362139/secure-hybrid-cloud-for-dummies">FREE DOWNLOAD</a></p></div></div><p>"VMTD is one of the ways we protect our Google Cloud Platform customers against growing attacks like coin mining, data exfiltration, and ransomware," he added.</p><p>Now available in public preview, VMTD detects cryptomining attacks but as it moves closer towards general availability, Google Cloud said customers can expect to see a steady release of new detective capabilities that will integrate with other parts of GCP.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RJN67uiUsgTeNucZa2GoTH" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/RJN67uiUsgTeNucZa2GoTH.jpg" mos="https://cdn.mos.cms.futurecdn.net/RJN67uiUsgTeNucZa2GoTH.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Google Cloud said VMTD complements the existing threat detection capabilities supplied by the existing Event Threat Detection and Container Threat Detection products, providing cover for compute while the others services areas like <a href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes" data-original-url="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">Kubernetes</a>, identity, managed services, <a href="https://www.itpro.com/cloud-management/31243/our-5-minute-guide-to-cloud-managed-networking" data-original-url="https://www.itpro.com/cloud-management/31243/our-5-minute-guide-to-cloud-managed-networking">networking</a>, and <a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know" data-original-url="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">API</a>.</p><h3 class="article-body__section" id="section-agentless-approach"><span>Agentless approach</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iWPk9KpZwgazrj7FPbBkUb" name="" alt="A diagram of how Google Cloud's VMTD works on a technical level" src="https://cdn.mos.cms.futurecdn.net/iWPk9KpZwgazrj7FPbBkUb.jpg" mos="https://cdn.mos.cms.futurecdn.net/iWPk9KpZwgazrj7FPbBkUb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Google Cloud)</span></figcaption></figure><p>Google Cloud's VMTD provides memory scanning for customers on an agentless basis, which means GCP users can expect a smaller performance impact, lowered operational burden, and a less-exposed attack surface.</p><p>This is unlike a traditional <a href="https://www.itpro.com/security/endpoint-security/357421/why-endpoint-security-should-be-your-first-line-of-defence" data-original-url="https://www.itpro.com/security/endpoint-security/357421/why-endpoint-security-should-be-your-first-line-of-defence">endpoint security</a> model which involves running additional software inside virtual machines to gather signals and telemetry. Instead, Google Cloud said it 'instruments the hypervisor' - the underlying software that "orchestrates" its virtual machines - to include threat detection that's difficult to tamper with.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why software alone won’t solve the security crisis ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/362148/why-software-alone-wont-solve-the-security-crisis</link>
                                                                            <description>
                            <![CDATA[ The shift to remote working and emerging cyber threats have the potential to create a perfect storm. Endpoint security requires a new approach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rFtGHeh1yYdJWPN2xaVaWP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pAquuzPzzGwMmRGVB4dos8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Feb 2022 13:57:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pAquuzPzzGwMmRGVB4dos8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image showing padlocks on a blue background]]></media:description>                                                            <media:text><![CDATA[Abstract image showing padlocks on a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image showing padlocks on a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pAquuzPzzGwMmRGVB4dos8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Today, enterprises of all sizes are up against unprecedented security challenges. The growth of remote and hybrid working practices has left IT teams struggling to secure a wider range of endpoints that aren’t always under their direct control. According to figures from YouGov, 37% of UK workers spent some of their week working from home before the COVID-19 pandemic. By September 2021 that had risen to 50%, with 60% saying they would prefer to work remotely at least some of the time.</p><p>At the same time, the security landscape grows more threatening, with cyber criminals becoming more sophisticated in how they target their attacks. Last year the UK government’s Cyber Security Breaches survey found that four in ten businesses had experienced a breach or attack in the last 12 months, with that rising to 64% to 65% for medium-sized and larger enterprises. What’s more, the report concluded, a lack of monitoring tools and user monitoring raised the possibility that some attacks were slipping through unrecognised and unreported.</p><p>New working practices have opened up new vulnerabilities, and cyber criminals have been quick to exploit them. A 2021 study conducted for HP Wolf Security found that 75% of IT teams surveyed had seen a rise in employees opening phishing links, while 40% of office workers surveyed reported clicking on a malicious email. Almost half (49%) had done so more often since working from home, and 70% of those that had clicked or nearly clicked on a link hadn’t reported it to IT. </p><p>To compound the crisis, IT teams have never been under so much pressure. HP’s research shows that the shift to home working has resulted in IT teams spending more time and effort patching endpoint devices, provisioning and securing new devices or triaging threats. The complexity of securing remote and hybrid workforces can be overwhelming. 77% of those HP surveyed said that homeworking was making their job much harder and that burn-out was a serious concern.</p><p>In this landscape, traditional software-based endpoint security is no longer up to task. It can provide a decent base level of resilience but can’t safeguard against the full spectrum of malicious email attachments, file downloads, browser exploits, credential theft and phishing links. Software alone can’t detect attacks below the OS level designed to compromise the firmware, or control attacks based on browser-level exploits. Applications designed around recognising malware signatures are powerless to act against script-based fileless threats or zero-day attacks. This is crucial. Google patched out 16 different zero-day vulnerabilities, some critical, from its Chrome browser during 2021. That same browser has a 70% market share.</p><p><strong>Hardware-based security meets zero trust</strong></p><p>Meeting these challenges requires a new approach. To be more specific, businesses need to consolidate their endpoint security and adopt new security principles anchored in a zero-trust approach, where nothing from device integrity to user identity is taken for granted, and constant behind-the-scenes verification becomes the norm. This starts at the hardware level and extends upwards to cover software and services, minimising vulnerabilities across all endpoints to protect the enterprise as a whole.</p><p>The key to this approach is that it’s not just about recognising and blocking attacks but isolating and containing threats and providing automated recovery and remediation. For example, malware that attacks the PC’s BIOS can be difficult to detect, highly persistent and challenging to remove, giving the attacker scope to install ransomware, steal data or infect more applications and devices. HP Wolf Security meets these threats through HP Sure Start, a hardware-based technology that detects when the BIOS has been compromised and automatically restores it.</p><p>HP’s Endpoint Security Controller, built into HP’s business and enterprise-grade laptops and PCs, also powers HP Sure Run, which prevents crucial security processes from being disabled by a malware attack by monitoring security-critical processes and repairing and restarting them at any sign of failure. The same controller also enables HP Sure Recover, which allows remote workers or IT teams to securely reimage their devices if the OS is critically damaged or compromised. These hardware-level features add layers of protection you could never get from software alone.</p><p>The same applies to HP Sure Click Enterprise, which provides hardware-enforced application isolation and containment. HP Sure Click Enterprise runs each task in a non-persistent micro-virtual machine (micro-VM), which isolates and contains attacks, minimising the attack surface for malicious email attachments, phishing links, file downloads, browser exploits and credential theft attempts without bombarding users or IT teams with unnecessary alerts.</p><p>As for emerging fileless or zero-day attacks, HP Wolf Security finds the answer in HP Sure Sense: an AI-based threat prediction technology that uses deep learning to recognise the tell-tale signs of malicious behaviour and malware threats. It can then apply that training to identify new threats before they execute and stop them in their tracks. HP Sure Sense doesn’t replace existing tools but augments and improves them, adding an extra layer of endpoint protection to cover their blind spots. What’s more, because it’s AI-based and designed to work autonomously, it doesn’t need constant updates to remain effective.</p><p>Adopting this approach will involve a change of mindset, not to mention new investments in hardware and support, but when there’s an endpoint security crisis brewing, standing still is not an option. HP Wolf Security offers a layered solution that can help your organisation boost its resilience to cyber attacks by detecting and protecting against threats, and prepare you for breaches by boosting your recovery capabilities. With the threat of cyber attacks ever growing and changing, these are the tools you need to be ready for them.</p><p><strong><em>To find out more about streamlining your security stack – and how HP Wolf Security can help – watch our webinar</em></strong> <a href="https://event.on24.com/wcc/r/3506512/D227D5707BD798625B7A571C5456D032?partnerref=promotions" rel="nofollow" target="_blank"><strong><em>here</em></strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Cloud acquires Israeli security startup Siemplify  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/361905/google-cloud-acquires-siemplify</link>
                                                                            <description>
                            <![CDATA[ The SOAR specialist has been described as "the missing piece" for Google's Chronicle platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qSBYLFtG4mbfw8xWmsoDoE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/utnLHzNQbKwEwBSZusw8jh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Jan 2022 10:23:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/utnLHzNQbKwEwBSZusw8jh-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Google Cloud company logo fixed onto an office building]]></media:description>                                                            <media:text><![CDATA[The Google Cloud company logo fixed onto an office building]]></media:text>
                                <media:title type="plain"><![CDATA[The Google Cloud company logo fixed onto an office building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/utnLHzNQbKwEwBSZusw8jh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Cloud has announced the acquisition of Siemplify, an Israeli-based cyber security company that specialises in end-to-end security for enterprises. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security" data-original-url="/cloud-security/34458/what-is-cloud-security">What is cloud security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/354767/google-cloud-snaps-up-multi-cloud-analytics-platform-for-26bn" data-original-url="/cloud/cloud-computing/354767/google-cloud-snaps-up-multi-cloud-analytics-platform-for-26bn">Google Cloud snaps up multi-cloud analytics platform for $2.6bn</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/360898/google-cloud-market-share-engineering-shakeup" data-original-url="/business-strategy/careers-training/360898/google-cloud-market-share-engineering-shakeup">Google Cloud targets larger market share with engineering reshuffle</a></p></div></div><p>The exact terms of the deal were not announced, though <a href="https://www.reuters.com/markets/deals/google-beefs-up-internet-security-with-siemplify-buyout-2022-01-04" target="_blank"><em>Reuters</em></a> reports it is worth around $500 million. </p><p>Acquisition rumours were reported in the Israeli press just before Google Cloud made an official announcement on Tuesday. The CEO and co-founder of Siemplify, Amos Stern, also noted that his company is to be integrated into Google Cloud's Chronicle platform. </p><p>Founded in 2015, Siemplify is another example of the <a href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/361635/retail-giant-schwarz-group-snaps-up-israeli-cyber" target="_blank" data-original-url="https://www.itpro.com/business-strategy/mergers-and-acquisitions/361635/retail-giant-schwarz-group-snaps-up-israeli-cyber">growing tech prowess of Israel</a>, which has become a hotbed for new startups and data-centric businesses. Much like <a href="https://www.cloudpro.co.uk/business-intelligence/analytics/8663/mine-the-startup-that-can-track-down-your-data" target="_blank">digital footprint tracking service Mine</a>, Siemplify is another Israeli company founded by former members of the country's military intelligence agencies. </p><p>The company is typically referred to as a <a href="https://www.itpro.com/security/cyber-security/357409/cyber-security-automation-for-dummies" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/357409/cyber-security-automation-for-dummies">security orchestration, automation and response</a> (SOAR) service, which is "the missing piece" for Google's Chronicle platform, according to Forrester analyst Allie Mellen. </p><p>"Other security analytics platforms began incorporating SOAR as early as 2017," Mellen said. "This acquisition is an important step in providing a unified offering to practitioners and in being able to compete more directly in the security analytics platform space. Enabling the orchestration of response across multiple tools is an integral part of security operations and has become an integral part of a security analytics platform. This acquisition continues to demonstrate that."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FwQ9DSFpKvK9Gf3HgmfqU7" name="FwQ9DSFpKvK9Gf3HgmfqU7.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/FwQ9DSFpKvK9Gf3HgmfqU7.jpg" mos="https://cdn.mos.cms.futurecdn.net/FwQ9DSFpKvK9Gf3HgmfqU7.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Bridging the developer and security divide</strong></p><p class="fancy-box__body-text">Helping security learn developers' language</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/devops/361751/bridge-developer-security-divide" data-original-url="/development/devops/361751/bridge-developer-security-divide">FREE DOWNLOAD</a></p></div></div><p>Chronicle is one of Google's original moonshots founded within its "X" programme that was migrated to Google Cloud in 2019. It was designed for cyber security telemetry, specifically to track the movement of data across all devices and networks in a bid to prevent breaches. SOAR platforms act as the customer interface for that operation.</p><p>"Siemplify was one of the few remaining standalone SOAR offerings, as many others have been picked up by SIEM vendors over the years," Mellen added.</p><p>"Most other standalone SOAR vendors have been acquired or built out their portfolio with other products like threat intelligence platforms. In some ways, that makes this a heady acquisition and signals the end of the standalone SOAR or, frankly, SIEM. We predicted early on that the SOAR market could not stand on its own, and now it has truly come to fruition."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Skip the three words thing, go straight for the ‘use a password manager, dammit’ jugular ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/information-security-infosec/361806/skip-three-words-use-password-managers</link>
                                                                            <description>
                            <![CDATA[ Why you can do so much better than the three-random-word rule that’s still being churned out by the NCSC ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a3rBg6Dbo5uX8j4BFGZjPY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XFRQM6qBWrpukkeoV7Bq8A-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Dec 2021 08:00:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XFRQM6qBWrpukkeoV7Bq8A-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sticky notes on a monitor displaying assorted passwords]]></media:description>                                                            <media:text><![CDATA[Sticky notes on a monitor displaying assorted passwords]]></media:text>
                                <media:title type="plain"><![CDATA[Sticky notes on a monitor displaying assorted passwords]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XFRQM6qBWrpukkeoV7Bq8A-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>I’m about to so do something I’m sure won’t shock regular readers: pick an argument with the powers that be. The organisation in question, being the National Cyber Security Centre (NCSC) which, by and large, does a splendid job in both public and private sectors in matters of security advice and support. By and large, but not on one occasion recently when it decided the time was right to remind us of some password construction advice it <a href="https://www.itpro.com/security/25273/should-you-heed-gchqs-password-advice" target="_blank" data-original-url="https://www.itpro.com/security/25273/should-you-heed-gchqs-password-advice">first offered five years ago</a>. It was wrong then and remains so to this day. </p><p>Using the perfectly reasonable hashtag of #thinkrandom, that advice was to use three random words as your <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">password</a>. That’s three words, not four, so you can forget about the <a href="https://xkcd.com/936" target="_blank">XKCD comic suggestion of “correct, horse, battery, staple”</a> that’s wedged itself into cyber security folklore. Not that you should use it anyway, as password reuse is obviously verboten if you want to maintain any semblance of a strong security posture. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text">The top 12 password-cracking techniques used by hackers</p></div></div><p>While admitting the use of three random words is “not a password panacea”, <a href="https://www.ncsc.gov.uk/blog-post/the-logic-behind-three-random-words" target="_blank">the latest NCSC posting</a> serves to press home the message that it’s better than using traditional password complexity advice, because the latter relies upon us memorising lots of long and complex strings. Using three random words, we are advised, creates passwords that are “strong enough for many purposes”, and helps get around the reuse problem that it says traditional complex passwords creates. </p><h3 class="article-body__section" id="section-random-access-memories"><span>Random access memories</span></h3><p>Let’s deal with the last of these first: <a href="https://www.itpro.com/security/361695/over-90-of-it-decision-makers-reuse-passwords" target="_blank" data-original-url="https://www.itpro.com/security/361695/over-90-of-it-decision-makers-reuse-passwords">password reuse</a>. There is absolutely no bloody difference between trying to remember 97 unique complex and random password strings and doing so with 97 three random word passphrases. You will fail unless you are a memory savant. That is a fact. It’s a fact because as humans we are simply not wired to remember random things. </p><p>This brings me to the second problem I have with the advice: the reality of randomness. Most people, most of the time, will choose three words that are far from random when constructing a whole bunch of passphrases. What people will do is, totally subconsciously, adopt patterns in the phrases they come up with. Patterns in both the connections between the words used to make recall easier and patterns between the passphrases themselves to make multiple ones easier to recall. </p><p>Humans just don’t do randomness well; that’s why there are computer-me-bobs for creating truly random stuff, and more on that later. There’s a really interesting piece of research from the University of Cambridge Computer Laboratory, admittedly now almost a decade old but still relevant, that explains this very well. Its evidence on multi-word passphrases was pretty damning: “By our metrics, even five-word phrases would be highly insecure against offline attacks,” the researchers found, because people naturally sway towards speech rather than randomness. “Phrases like young man which come up often in speech are proportionately more likely to be chosen than rare phrases like young table” the research concluded. Which is exactly what I would expect.</p><h3 class="article-body__section" id="section-there-s-an-app-for-that"><span>There’s an app for that</span></h3><p>Look, I perfectly understand plenty of security professionals disagree with me here. Their argument generally being along the same lines as the NCSC, that adopting a three random words approach will create stronger passwords than those we often see being used and reused today. This is true, and I’m not suggesting that Password, or P@ssw0rd, or even P@ssw0rd1 is a super-duper credential to be using. What I am suggesting is that, rather than getting people to use three supposedly random words, it would be far better to advise them to use some form of secure password manager instead. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it" data-original-url="/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it">LastPass is crippling its free tier. Here’s how to ditch it</a></p></div></div><p>Skip the whole three words thing, don’t mention it at all, go straight for the “use a password manager dammit” jugular. That way you can create truly random and complex and extremely long passwords, or the application can, and have a unique one for every login. </p><p>Of course, the perennial problem of master password creation rears its very ugly head once more. Rather than go over old ground involving muscle memory, <a href="https://www.itpro.com/637915/sticking-security-where-the-sun-dont-shine" target="_blank" data-original-url="https://www.itpro.com/637915/sticking-security-where-the-sun-dont-shine">encrypted USB sticks</a> (which need yet another password) or a <a href="https://www.itpro.com/security/29705/what-are-biometrics" target="_blank" data-original-url="https://www.itpro.com/security/29705/what-are-biometrics">biometric</a> device (JEMpass) and even dice with multiple patterns rolled randomly into a locked box (DiceKeys), let’s approach this from the three random words angle. Or, rather, let’s not. Just three words, no matter how random, would make a spectacularly poor master password if you ask me. Instead, go for five or six, or more if your memory will allow.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=44789851&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><p>These would, of course, need to be random rather than your idea of random. Which is where one password manager, in fact <a href="https://www.itpro.com/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts" target="_blank" data-original-url="https://www.itpro.com/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts">1Password</a>, comes in. Did you see what I did there? Anyway, it has a password generator that <a href="http://1password.com/password-generator">anyone can use</a> – which has the option of generating a passphrase using random words. Just select the “memorable password” dropdown, set the number of words to something you are comfortable with, and you’re away. Other services, of course, are also available, such as <a href="https://www.itpro.com/security/information-security-infosec/360139/passwords-generated-by-kaspersky-password-manager-can" target="_blank" data-original-url="https://www.itpro.com/security/information-security-infosec/360139/passwords-generated-by-kaspersky-password-manager-can">Kaspersky's own password generator</a>. </p><p>As I say, don’t go for anything too short as this is the key that unlocks all your other passwords. I’d also avoid unchecking the “full words” box as this produces gibberish words that aren’t really easier than a long password to memorise. Practise typing the result over and over to get that muscle memory working, and if you are a 1Password user, be sure to save the “emergency kit” that can be printed out and stored somewhere secure. The reality is that for 99% of use cases a threat actor isn’t going to ransack your house searching for a master password, nor your office for that matter. If you do fall into the 1% then the chances are high that you’ll already be using some kind of security protocol that makes the entire three random words argument moot anyway.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts" data-original-url="/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts">1Password Business review: First choice for business travel and guest accounts</a></p></div></div><p>Talking of passwords in the workplace, I can’t wrap up this conversation without mentioning some more research, this time from Beyond Identity. This found that not only did nearly a quarter of employees questioned still have access to accounts from a previous job, but 41% admitted to <a href="https://www.itpro.com/business-strategy/public-sector/360897/nadine-dorries-appointed-digital-secretary-in-government" target="_blank" data-original-url="https://www.itpro.com/business-strategy/public-sector/360897/nadine-dorries-appointed-digital-secretary-in-government">sharing passwords</a> in the office, and 20% used the same passwords at home as they did for work-related accounts. Just in case you wondered why I bang on about the importance of password hygiene, month after month.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trend Micro Worry-Free Business Security review: Great cloud-managed malware protection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/361734/trend-micro-worry-free-business-security-great-cloud-managed</link>
                                                                            <description>
                            <![CDATA[ A reassuringly simple endpoint-protection solution – although mobile support is basic ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k1tRcJYbijSuasEWqYbZ46</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jfb3vkYKJRZyagdkUZPrEf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Dec 2021 10:35:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jfb3vkYKJRZyagdkUZPrEf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trend Micro Worry-Free Business Security screenshot]]></media:description>                                                            <media:text><![CDATA[Trend Micro Worry-Free Business Security screenshot]]></media:text>
                                <media:title type="plain"><![CDATA[Trend Micro Worry-Free Business Security screenshot]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jfb3vkYKJRZyagdkUZPrEf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Trend Micro offers an <a href="https://www.itpro.com/security/endpoint-security/357421/why-endpoint-security-should-be-your-first-line-of-defence" data-original-url="https://www.itpro.com/security/endpoint-security/357421/why-endpoint-security-should-be-your-first-line-of-defence">endpoint protection</a> choice for every business: firms that want to keep it all in house can install Worry-Free Business Security Standard on their own server, while those that prefer a hosted solution can use this fully cloud-based option.</p><p>It’s aimed at companies with up to 250 devices to protect, and the price is SMB-friendly. Yearly pricing starts at £58 for two devices, rising to £520 for 25, with each licence covering one Windows or Mac workstation, one Windows server or one mobile device.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation" data-original-url="/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them" data-original-url="/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them">Kaspersky Endpoint Security Cloud Plus review: One security solution to rule them all</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented" data-original-url="/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented">F-Secure Elements Endpoint Protection review: A strong business-oriented security solution</a></p></div></div><p>All the key security features are present. Along with anti-malware scanning you get protection against web threats, <a href="https://www.itpro.com/security/cyber-security/361012/what-is-a-web-filter" data-original-url="https://www.itpro.com/security/cyber-security/361012/what-is-a-web-filter">web content filtering</a>, a client firewall, removable device controls and mobile device security. A standout feature of both the standard and cloud-hosted versions is an advanced <a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" data-original-url="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">data-loss prevention module</a>, which comes preconfigured to recognise (and optionally block) 244 different types of sensitive data, including British financial and healthcare information.</p><p><a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">Ransomware</a> is very much on Trend Micro’s radar, too. The software subjects suspicious processes to a range of tests including predictive machine learning, behaviour monitoring and new program detection – and if the malware isn’t immediately stopped, the program can also directly detect malicious encryption attempts and undo any suspicious changes made by untrusted programs.</p><p>As the name implies, another focus of the Worry-Free suite is keeping deployment and administration simple. The cloud portal is easy to use, with a dashboard that keeps you posted on all client activity, detected security risks and policy violations. Clicking on any of the threat categories takes you straight to the portal’s log page, where you can quickly identify the threat type and which clients are affected.</p><p>The one place you might hit a hiccup is with initial client setup, as the email invitation process requires a standalone mail client running on your local system. This isn’t a huge obstacle, though: after logging on from a computer with Outlook installed, we were easily able to email invitations to our Windows 10 users. The messages pointed them to a tiny 7MB executable, and after launching the installer, they had the agent running and connected to the portal in less than five minutes, with settings applied from the portal’s default groups for instant protection.</p><p>Agents can then be manually moved into specific groups in the portal, each with custom policies. These define real-time and manual scan behaviour, apply <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">predictive machine learning</a> and use one of three web reputation levels to classify and block suspect web pages. Optional global settings can be applied for malware scanning, approved and blocked websites (which override URL-filtering policies) and password protection to stop users disabling the agent.</p><p>Data-loss prevention can be set up here too. We created a policy to block all sensitive data, then tried to use Gmail on a client PC to send an email containing a credit card number. The attempt was instantly blocked and logged, leaving Gmail complaining about a lack of network access.</p><p>Mobile protection is a mixed bag. Android devices get malware scanning, plus access to the web reputation service and password controls; if you’re using a <a href="https://www.itpro.com/hardware/laptops/355133/chromebooks-are-the-benjamin-button-of-tech" data-original-url="https://www.itpro.com/hardware/laptops/355133/chromebooks-are-the-benjamin-button-of-tech">Chromebook</a>, you get web threat prevention too. As usual, however, iOS options are far more limited. All you can do is enforce complex unlock passcodes, set expiration limits and apply device lock timeouts.</p><p>Even so, Trend Micro’s Worry-Free Business Security Services provides great desktop security, plus exceptional DLP and ransomware protection. For small numbers of users it’s good value, and SMBs will find the cloud portal very easy to work with.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Windows Defender review: An ideal (if unfriendly) business security solution ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/361689/microsoft-defender-effective-effortless-protection-for-zero-cost</link>
                                                                            <description>
                            <![CDATA[ Central management puts Defender head and shoulders above other free options; the fact that it's already deployed doesn't hurt either ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7ntNE117bFSk7Y8VuDFoPH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gkJd9oDuKhSMYFT4fCX5Wk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Dec 2021 09:00:06 +0000</pubDate>                                                                                                                                <updated>Wed, 01 Jun 2022 11:50:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Darien Graham-Smith ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nZP8qH6BDshBkBZo9Kvhbe.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gkJd9oDuKhSMYFT4fCX5Wk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft Defender user interface ]]></media:description>                                                            <media:text><![CDATA[Microsoft Defender user interface ]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft Defender user interface ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gkJd9oDuKhSMYFT4fCX5Wk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There's a saying that the best antivirus product is the one you actually have installed. That's the approach Microsoft has taken: its Defender security system is integrated into every installation of Windows 10 and 11, ensuring a baseline level of protection across the whole operating system.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29328/your-essential-guide-to-internet-security" data-original-url="/security/29328/your-essential-guide-to-internet-security">Your essential guide to internet security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="/malware/28153/whats-the-difference-between-antimalware-and-antivirus">What's the difference between antimalware and antivirus?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="/antivirus/28144/best-antivirus">Best antivirus for Windows 10</a></p></div></div><p><a href="https://www.itpro.com/security/cyber-security/367562/microsoft-targets-smbs-with-defender-for-business" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/367562/microsoft-targets-smbs-with-defender-for-business">Defender</a> isn't just widespread - it's effective. Every Windows computer with an internet connection automatically downloads the latest signatures and recognition algorithms on a daily basis, meaning newly identified threats can be very quickly shut down. </p><p>And we can't argue with the results. In the most recent tests by AV-Comparatives.org, Defender successfully blocked 99.96% of <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> samples; AV-Test.org reported that, during January and February 2022, the software scored a perfect 100% against both known threats and brand-new zero-day attacks.</p><p>Defender doesn't operate in a vacuum, however. It's one part of the wider <a href="https://www.itpro.com/hardware/printers" target="_blank" data-original-url="https://www.itpro.com/security/antivirus/360689/microsoft-windows-security-review-minimum-effort">Windows Security app</a>, which includes ransomware protection, reputation-based assessment, firewall management and even parental controls, to prevent kids from inadvertently accessing dangerous or inappropriate content.</p><p>Perhaps because all of this is plumbed into Windows at a low level, it has very little effect on system performance. AV-Test.org found that Windows Security slowed down web performance by a mere 5% on a standard PC, compared to browsing with protection disabled. For comparison, Avast One Essential had a 17% impact, while AVG had a massive 28% penalty.</p><p>Windows Security also had a minimal impact on application launch speed, incurring a 6% slowdown while Avast and AVG both hit 12%. Defender does seem to scan applications more rigorously when they're first installed: here Windows Security was 14% slower, compared to 9% for Avast and 16% for Avira Free. That's a smart way of doing things, though, since you might launch an application every day, but you're only going to install it once.</p><p>Our biggest issue with Microsoft Defender is to do with usability. The whole Windows Security app is a mess, with nine different pages of buttons and links to hunt through. Everyday functions rub shoulders with obscure technical features such as CPU extensions, and ransomware protection is bafflingly turned off by default. That might be to protect users from its impenetrable interface though, which requires you to dig deep into the advanced security settings to approve applications. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AZgR4DDC6ZhFpQLx5EfR6a" name="" alt="Microsoft Defender firmware settings" src="https://cdn.mos.cms.futurecdn.net/AZgR4DDC6ZhFpQLx5EfR6a.jpg" mos="https://cdn.mos.cms.futurecdn.net/AZgR4DDC6ZhFpQLx5EfR6a.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Then again, that might not matter - because one of the biggest benefits of Windows Security is that business users don't need to manage it for themselves. Using either group policies or Windows Intune, organisations can control every aspect of user security, ensuring protections are enabled, current and appropriate for the needs of the business and the individual.</p><p>That might not appeal to small businesses wanting to minimise their management commitment. In some scenarios, it will make more sense for staff to use a free consumer-grade antivirus solution. In a larger organisation, however, the benefits of central administration will surely outweigh any individual security features: for them, the best antivirus really is the one that's already installed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos Intercept X Advanced review: A huge range of endpoint protection measures for the price ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection</link>
                                                                            <description>
                            <![CDATA[ A superb range of security measures and a well-designed cloud portal make endpoint protection a breeze ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6HFEJFqZ4RWdkvLc7ZfE2n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m5cbEWuFRLnx33aE2GDuVJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Nov 2021 09:58:00 +0000</pubDate>                                                                                                                                <updated>Wed, 13 Dec 2023 15:37:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m5cbEWuFRLnx33aE2GDuVJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Sophos Intercept Z Advance interface on the ITPro background]]></media:description>                                                            <media:text><![CDATA[The Sophos Intercept Z Advance interface on the ITPro background]]></media:text>
                                <media:title type="plain"><![CDATA[The Sophos Intercept Z Advance interface on the ITPro background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m5cbEWuFRLnx33aE2GDuVJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sophos offers an impressive portfolio of security services and, as an early adopter of cloud management, it&apos;s ensured everything can be accessed from its Central administrative portal. Along with the Intercept X Advanced workstation and server endpoint protection on review, you can use Central to look after Sophos&apos; Mobile threat defense package along with its XGS firewalls, Wi-Fi 6/6E access points, 100 and 200 series network switches, and zero trust network access service.</p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="C89Mj92FzceM24PFbsdQpZ" name="C89Mj92FzceM24PFbsdQpZ.jpg" caption="" alt="Endpoint protection or endpoint security interlocking gears" src="https://cdn.mos.cms.futurecdn.net/C89Mj92FzceM24PFbsdQpZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a></p></div></div><p>That&apos;s a lot to pack into one management portal, but Sophos has done a fine job of keeping it simple. The main dashboard provides an overview of your company&apos;s security posture, and all endpoint protection services are neatly separated into three sidebar menu categories for workstations, servers, and mobiles.</p><p>Along with essential malware and threat protection services, Intercept X Advanced supports multiple security policies plus application and device controls. It employs AI-based deep learning to defend against unknown malware, blocks ransomware attacks using behavioral analysis and enables a threat analysis center.</p><p>An XDR (extended detection and response) license allows you to create your own custom threat cases. This provides deeper malware analysis and threat intelligence, on-demand endpoint isolation, and suspicious event detection and prioritization to identify targeted attacks.</p><h2 id="sophos-intercept-x-advanced-setup">Sophos Intercept X Advanced: Setup</h2><p>Deployment is swift. You place the <a href="https://www.itpro.com/microsoft-windows/32386/how-to-run-classic-versions-of-windows-on-modern-pcs">Windows</a> and macOS installers in a central distribution point or create users in the portal and email a link to them. A different agent is used for Windows servers but, in both cases, they only take ten minutes to install, connect to your portal account and retrieve a base security policy.</p><p>The base threat protection policy has all recommended security settings enabled and is always applied to users and devices if no other policy has been assigned. Other policies are provided for web, application, Windows firewall and device controls, and data loss prevention, although these are deactivated and require configuration and assignment. Policies present an extensive range of security measures and include CryptoGuard ransomware protection.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oY7E5fRXWfFRKWSREqFfZX" name="Why Network Monitoring Tools Fail Within Secure Environments.jpg" caption="" alt="Why Network Monitoring Tools Fail Within Secure Environments whitepaper" src="https://cdn.mos.cms.futurecdn.net/oY7E5fRXWfFRKWSREqFfZX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn about the three scenarios commonly encountered by end users that pose difficulties for network operations teams</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/networking/why-network-monitoring-tools-fail-within-secure-environments">DOWNLOAD NOW</a></p></div></div><p>When any file is opened for writing, it places a temporary clean copy in a proprietary cache on the local drive and, if it detects malicious encryption activity, it will automatically roll back the file to its original state.</p><p>Custom policies are easily created by cloning the preconfigured ones and tweaking their settings to suit. These can be assigned to device groups, and if you import users via the free Active Directory (AD) sync tool or <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Azure</a> sync service, you can apply policies to users so they&apos;re always protected no matter what device they have signed in to.</p><p>Sophos cuts through alert smokescreens as only unresolved events that need your attention to appear in the Central dashboard and cause email notifications to be issued. We used our malware collection to create a virus outbreak condition on one PC which was highlighted immediately, whereas other events such as successful malware removals and website blocks were only posted in the logs and reports section.</p><p>The portal&apos;s threat analysis center provides a basic dashboard showing the most recent threats. Selecting one provides a full analysis of events and a one-click option to clean up all associated files and Registry entries and block them so other devices can&apos;t run it. Sophos has also added a new XDR threat analysis center dashboard that provides smarter widget-based graphical views of <a href="https://www.itpro.com/malware/28076/what-is-malware">malware detection</a>.</p><p>Sophos Intercept X Advanced delivers a huge range of endpoint protection measures for the price. It&apos;s simple to deploy, device and user policies add flexibility and seamless integration with the Central cloud portal makes management simple.</p><p><em>This content originally appeared on ITPro&apos;s sibling magazine PC Pro. For more information and to subscribe, please visit PC Pro&apos;s </em><a href="https://subscribe.pcpro.co.uk/"><em>subscription site</em></a><em>. </em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky Endpoint Security Cloud Plus review: One security solution to rule them all  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them</link>
                                                                            <description>
                            <![CDATA[ Kaspersky is easy to manage, good value and tough on malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mvxtBGznwX6nZKgoKTZeNC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Nov 2021 11:19:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Kaspersky Endpoint Security Cloud Plus]]></media:description>                                                            <media:text><![CDATA[A screenshot of Kaspersky Endpoint Security Cloud Plus]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Kaspersky Endpoint Security Cloud Plus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky’s Endpoint Security Cloud Plus (ESCP) offers some of the most flexible licensing terms in the business. While some vendors expect you to purchase separate licence packs for different types of devices, each Kaspersky user licence covers one workstation, laptop or server, plus two iOS or Android mobile devices.</p><p>The service is designed to protect up to 1,000 Windows and Mac workstations and Windows servers, and is managed entirely in the cloud. The extensive roster of security features includes <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus">anti-malware</a>, threat and <a href="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022" data-original-url="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022">ransomware protection</a>, a client firewall, network vulnerability scanning and an attack blocker. </p><p>On top of all this, the Plus subscription we tested adds <a href="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points" data-original-url="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points">endpoint device controls</a>, URL-based web filtering, vulnerability assessments, <a href="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult" data-original-url="https://www.itpro.com/security/34257/it-pro-panel-why-is-patch-management-so-difficult">patch management</a> and encryption. It also adds the ability to block any email, file-sharing, messaging or social networking cloud services in use by your clients, while the standard licence only lets you monitor activity.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented" data-original-url="/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented">F-Secure Elements Endpoint Protection review: A strong business-oriented security solution</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" data-original-url="/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable">Kaspersky Internet Security review: Powerful, highly configurable protection</a> Avast Antivirus Free review: Our free favourite for older Windows PCs</p></div></div><p>A final benefit of the Plus licence is the Security for <a href="https://www.itpro.com/software/microsoft-office/360636/microsoft-to-raise-prices-for-office-365-and-microsoft-365" data-original-url="https://www.itpro.com/software/microsoft-office/360636/microsoft-to-raise-prices-for-office-365-and-microsoft-365">Microsoft 365</a> component. This provides dedicated security services for Exchange Online, OneDrive, SharePoint Online and Teams, with its data discovery tool highlighting files identified as containing sensitive information.</p><p>Deployment starts with creating a Business Hub account and defining your company. You’re then taken to the ESCP web portal, where wizards guide you through adding users, enabling cloud discovery and scheduling updates and scans. </p><p>Then you just need to get the software onto clients – and this too is painless, as you can email invitations to users directly from the cloud portal. We found the client software took around five minutes to install, then a further 15 minutes to fully register itself with the portal and update its signature database.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yRN9Kd5c4gj3hJKRycUxsm" name="" alt="A screenshot of Kaspersky Endpoint Security Cloud Plus" src="https://cdn.mos.cms.futurecdn.net/yRN9Kd5c4gj3hJKRycUxsm.jpg" mos="https://cdn.mos.cms.futurecdn.net/yRN9Kd5c4gj3hJKRycUxsm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>A default security profile is applied to each new device so full protection starts immediately, but it’s easy enough to create custom ones. There’s a huge range of options on offer, with clearly distinguished settings for Windows, Mac, Android and iOS devices. </p><p>For example, file, web and network threat protection are available for Windows and Mac devices, while Android users get standard antivirus measures. Since iOS is so locked down, the only options available here are access controls, which let you choose what mobile features are accessible, set screen lock and password policies and specify which networks can be connected to.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361094/the-truth-about-cyber-security-training" data-original-url="/security/cyber-security/361094/the-truth-about-cyber-security-training">FREE DOWNLOAD</a></p></div></div><p>It’s also worth noting that cloud discovery is only available for Windows devices. It works well, though: after you’ve given it a few hours to build up a picture of your network traffic, the portal shows a handy readout of the top five services and the devices using them.</p><p>Another Windows-centric feature is patch management. All available updates are displayed in the portal, and you can set a daily or weekly schedule to apply them all, or only those you’ve approved.</p><p>To make use of the Security for Microsoft 365 component you need to create a new workspace in your cloud account, which presents a separate portal. After granting access to our account, we were able to create profiles to protect our Exchange Online mailboxes from spam, phishing and malicious attachments, and apply anti-malware policies to our files in OneDrive and SharePoint Online.</p><p>The data discovery service, meanwhile, works with Exchange, OneDrive and SharePoint data, sending an alert to selected users if it finds confidential information. As with the ESCP portal, plenty of information is presented, with detection statistics for Exchange mailboxes, OneDrive files and SharePoint data.</p><p>Businesses seeking both device security and protection within Microsoft 365 will find Kaspersky Endpoint Security Cloud Plus has all the angles covered. You do need to use separate portals to manage everything, but there’s a huge range of security features on offer, and Kaspersky’s licensing scheme makes it very affordable.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ F-Secure Elements Endpoint Protection review: A strong business-oriented security solution ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/361556/f-secure-elements-endpoint-protection-review-a-strong-business-oriented</link>
                                                                            <description>
                            <![CDATA[ Cloud management, excellent protection and great mobile support, all for an affordable price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8RwvSA6M4pfp7kAbAp3wHX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/a5nJg693d8GiaKCCT4mrwh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Nov 2021 12:10:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/a5nJg693d8GiaKCCT4mrwh-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of F-Secure Elements Endpoint Protection]]></media:description>                                                            <media:text><![CDATA[A screenshot of F-Secure Elements Endpoint Protection]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of F-Secure Elements Endpoint Protection]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/a5nJg693d8GiaKCCT4mrwh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It turns out that Sweden isn't the only Nordic nation with a talent for efficiently packing a lot of functionality into a small space. That's proven by Finnish cybersecurity vendor F-Secure: its web-based portal lets you manage not just the Endpoint Protection package but the company’s entire portfolio of <a href="https://www.itpro.com/security/32107/how-to-choose-a-one-stop-business-security-package" data-original-url="https://www.itpro.com/security/32107/how-to-choose-a-one-stop-business-security-package">business security products</a>. So if you’re already using an F-Secure cloud service – or if you plan to in the future – it could help you simplify administration.</p><p>We found the cloud side of things easy to set up. Once we’d created a central management account, we simply had to enter our Elements Endpoint Protection (EEP) subscription details, after which the service immediately appeared in the console. Other F-Secure services are enabled in the same manner, and can be accessed from the portal’s upper right menu button.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360368/why-do-you-need-endpoint-security" data-original-url="/security/360368/why-do-you-need-endpoint-security">Why do you need endpoint security?</a></p></div></div><p>EEP offers protection for a good spread of endpoint types. Windows and Mac workstations are covered, as well as Windows, Linux and <a href="https://www.itpro.com/saas/28932/everything-you-need-to-know-about-citrix" data-original-url="https://www.itpro.com/saas/28932/everything-you-need-to-know-about-citrix">Citrix servers</a>, plus iOS and Android mobile devices. Malware protection is provided on all of these platforms, with F-Secure’s software analysing file contents, monitoring system change attempts and keeping an eye on program behaviour. EEP also offers <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">patch management</a>, web content security and removable device controls.</p><p>For the broadest possible security, you can move up to an EEP Premium subscription; this increases the per-device cost to £32 exc VAT, but adds application controls and dedicated <a href="https://www.itpro.com/security/29204/how-can-you-protect-your-business-from-crypto-ransomware" data-original-url="https://www.itpro.com/security/29204/how-can-you-protect-your-business-from-crypto-ransomware">ransomware protection</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YzcyP4FBZwNLYVtocffVQo" name="YzcyP4FBZwNLYVtocffVQo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/YzcyP4FBZwNLYVtocffVQo.png" mos="https://cdn.mos.cms.futurecdn.net/YzcyP4FBZwNLYVtocffVQo.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 Thales cloud security study</strong></p><p class="fancy-box__body-text">The challenges of cloud data protection and access management in a hybrid and multi cloud world</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/361528/2021-thales-cloud-security-study" data-original-url="/cloud/361528/2021-thales-cloud-security-study">FREE DOWNLOAD</a></p></div></div><p>The EEP console dashboard presents colour-coded charts for computers, patches and mobiles so you can instantly see your protection status. A table below lists any alerts and errors, with a link next to each that takes you to the relevant page for more detail. You can switch to the devices page for an overview of protected machines – and if one of your systems is infected, you can isolate it with a click, blocking all network access so it can’t do any harm. Once the system has been disinfected you can send an unblock command to remotely restore access.</p><p>This is also where you can invite users to install the EEP agent. Messages are sent by email, and include an agent download link for the appropriate platform; on Windows and macOS this takes around five minutes to install and connect to the EEP portal. On Android and iOS, users simply need to download the Android or iOS apps and log in using the pre-generated credentials in their email.</p><p>After installation, all client machines are set up with a default protection profile, which enables malware scanning, automatic quarantine actions and <a href="https://www.itpro.com/security/28013/what-is-private-browsing-and-how-can-it-keep-you-safe-online" data-original-url="https://www.itpro.com/security/28013/what-is-private-browsing-and-how-can-it-keep-you-safe-online">browsing protection</a>. For tailor-made protection, you can create your own profiles, which define real-time scanning options, permit users to run manual scans, determine when automatic updates occur and schedule regular system scans. Web protection options include reputation-based web page scanning, content control with a list of 32 URL categories you can block or allow, and an optional browser plug-in that shows link reputations next to search results.</p><p>For mobile devices, profiles can also enable the F-Secure <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/355071/does-your-business-need-its-own-vpn" data-original-url="https://www.itpro.com/network-internet/virtual-private-network-vpn/355071/does-your-business-need-its-own-vpn">VPN service</a>. There’s nothing users need to do to enable this: once the app is loaded, it creates a VPN connection to the nearest concentrator and applies the profile’s browsing controls. Protection against malicious websites and tracking cookies is included, too.</p><p>As for reporting, tabs in the portal show protection status, security events and infections. One-click menus at the top of each category send summary reports to administrators, and you can choose to issue email alerts to multiple users when infections are detected.</p><p>F-Secure Elements Endpoint Protection is a good choice for SMBs seeking easy protection: its cloud portal makes for simple management, and it’s easy to deploy a wide range of security services across all the device types you’re likely to be using.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft unveils Defender for Business at Ignite 2021 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/361424/microsoft-unveils-defender-for-business-at-ignite-2021</link>
                                                                            <description>
                            <![CDATA[ The new security suite is aimed at SMBs struggling to protect themselves in today's cyber security landscape ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MTaUNEMpkdkZYLsEWnfTK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tmfohEDnBA3rYdFfwqXtb6-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Nov 2021 16:07:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Microsoft]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/tmfohEDnBA3rYdFfwqXtb6-1280-80.png">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image mimicking a tablet view of Microsoft Defender for Business and all the features it offers small businesses]]></media:description>                                                            <media:text><![CDATA[Image mimicking a tablet view of Microsoft Defender for Business and all the features it offers small businesses]]></media:text>
                                <media:title type="plain"><![CDATA[Image mimicking a tablet view of Microsoft Defender for Business and all the features it offers small businesses]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tmfohEDnBA3rYdFfwqXtb6-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has announced a brand-new security suite designed specifically for the threats faced by small and medium-sized businesses (SMBs).</p><p>Microsoft Defender for Business was announced at Microsoft Ignite 2021 today and it will aim to bring what Microsoft is calling its "enterprise-grade <a href="https://www.itpro.com/security/endpoint-security/357421/why-endpoint-security-should-be-your-first-line-of-defence" data-original-url="https://www.itpro.com/security/endpoint-security/357421/why-endpoint-security-should-be-your-first-line-of-defence">endpoint security</a>" to companies with 300 employees or fewer.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/collaboration/361423/mesh-for-microsoft-teams-metaverse-official" data-original-url="/business-strategy/collaboration/361423/mesh-for-microsoft-teams-metaverse-official">Mesh for Teams is Microsoft's pitch for the metaverse</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/bugs/358304/microsoft-fixes-zero-day-defender-exploit-with-patch-tuesday" data-original-url="/security/bugs/358304/microsoft-fixes-zero-day-defender-exploit-with-patch-tuesday">Microsoft fixes actively exploited Defender zero-day flaw</a> Windows Defender review: An average default option</p></div></div><p>Entering public preview later this month, it will be available as a standalone product for businesses to purchase at a rate of $3 (£2.20) per user, or alternatively the new tools will be available as part of a Microsoft 365 Business Premium subscription.</p><p>Specifically designed to protect businesses against malware and ransomware across Windows, macOS, iOS, and Android devices, Defender for Business will have the following features:</p><ul><li><strong>Threat and vulnerability management</strong>: allows customers to build a secure foundation by identifying and addressing software vulnerabilities and misconfigurations</li><li><strong>Attack surface reduction</strong>: Using capabilities such as ransomware mitigation, application control, web protection, network protection, network firewall, and attack surface reduction rules, SMBs' attack surface can shrink</li><li><strong>Endpoint detection and response (EDR)</strong>: Behavioural-based detection and response alerts allowing SMBs to identify persistent threats and remove them from their environments</li><li><strong>Automated investigation and remediation</strong>: reduces alert volume and remediates threats. SMBs can automate Defender for Business to carry out tasks automatically, allowing them to prioritise the most important tasks</li><li><strong>APIs and integration</strong>:<strong> </strong>allows SMBs to automate workflows and integrate security data into their existing security platforms and reporting tools</li></ul><p>IT managed service providers will also have the option to use Microsoft Defender for Business with Microsoft 365 Lighthouse, applying the product's endpoint security production for multiple customers as they monitor security events with a multi-customer view.</p><p>“Small and medium businesses will be empowered to elevate their security by moving from traditional antivirus to next-gen protection, endpoint detection and response, and threat and vulnerability management - all while taking advantage of simplified setup and management,” said Microsoft on the announcement.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="H3KHXGLymSvXojrHveuBaQ" name="" alt="A look at the user interface on Microsoft's Defender for Business product" src="https://cdn.mos.cms.futurecdn.net/H3KHXGLymSvXojrHveuBaQ.png" mos="https://cdn.mos.cms.futurecdn.net/H3KHXGLymSvXojrHveuBaQ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Microsoft)</span></figcaption></figure><p>According to Microsoft's own research, almost 60% of SMBs report <a href="https://www.itpro.com/business-strategy/smb/360589/how-to-fix-the-weak-link-in-cyber-security" data-original-url="https://www.itpro.com/business-strategy/smb/360589/how-to-fix-the-weak-link-in-cyber-security">not feeling adequately equipped</a> to contend with today’s ever-widening cyber security threat landscape, citing insufficient resources and a lack of specialised security skills as the reason. </p><p>Microsoft said Defender for Business requires no specialist knowledge in order to install and manage effectively. It has a wizard-driven set-up and it will recommend security policies out of the box to expedite the process.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GmEy94iCPBFPs9V6HWFekm" name="GmEy94iCPBFPs9V6HWFekm.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" mos="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The best defence against ransomware</strong></p><p class="fancy-box__body-text">How ransomware is evolving and how to defend against it</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361095/the-best-defence-against-ransomware" data-original-url="/security/ransomware/361095/the-best-defence-against-ransomware">FREE DOWNLOAD</a></p></div></div><p>Among Microsoft's myriad Ignite 2021 <a href="https://www.itpro.com/business-strategy/collaboration/361423/mesh-for-microsoft-teams-metaverse-official" data-original-url="https://www.itpro.com/business-strategy/collaboration/361423/mesh-for-microsoft-teams-metaverse-official">announcements</a>, on the security side of things Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security) has added a new application governance capability which is generally available as of today. It aims to help identify and alert the customer to risky behaviour across data, users, and applications.</p><p>Defender for Cloud also received an update to multi-cloud environment control. Customers can now secure Azure and Amazon Web Services (AWS) environments from one place, giving users the same experience as they would find in AWS Security Hub.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ McAfee Total Protection review: Expensive at full price ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/361422/mcafee-total-protection-review-expensive-at-full-price</link>
                                                                            <description>
                            <![CDATA[ Protects your PC and includes a decent firewall, but costly and less effective than some rivals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">frAnsZCxt3GwkUh6Qz9d2q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cnc8XQekCjsciA9TXr57Z5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Nov 2021 11:08:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cnc8XQekCjsciA9TXr57Z5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of McAfee Total Protection]]></media:description>                                                            <media:text><![CDATA[A screenshot of McAfee Total Protection]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of McAfee Total Protection]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cnc8XQekCjsciA9TXr57Z5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>McAfee’s an old hand at anti-malware, and it’s become a little less bloated in recent years. Despite the 2020 sell-off of the enterprise security site of the business, the consumer anti-malware division continues as a publicly traded company, with former owner Intel still holding a 49% stake.</p><p>You get a lot of features packed into McAfee Total Protection, but they’re not always the ones you’d expect. Although McAfee’s malware defence engine includes components designed to spot the telltale behaviour of ransomware attempting to encrypt your personal files, you don’t get any direct control over this as a user.</p><p>Unlike many rivals, you can’t designate specific directories for the software to monitor for and block unauthorised changes to. However, handling ransomware threats in-engine as <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-days</a> when detected by McAfee’s behavioural analysis is a less obtrusive approach. Similarly, there’s no dedicated webcam protection module, although McAfee’s heuristic malware detection engine watches out for potential device hijacking. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/359978/antivirus-creator-john-mcafee-found-dead-in-spanish" data-original-url="/business-strategy/careers-training/359978/antivirus-creator-john-mcafee-found-dead-in-spanish">Antivirus creator John McAfee found dead in Spanish prison</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/360833/over-90-of-it-teams-feel-pressure-to-compromise-security" data-original-url="/security/360833/over-90-of-it-teams-feel-pressure-to-compromise-security">Over 90% of IT teams feel pressure to compromise security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/361344/f-secure-safe-review-simple-security-struggles-to-outdo-defender" data-original-url="/security/antivirus/361344/f-secure-safe-review-simple-security-struggles-to-outdo-defender">F-Secure Safe review: Simple security struggles to outdo Defender</a></p></div></div><p>Total Protection helpfully includes a dedicated firewall with a clean and pleasant interface, so you won’t have to use the Microsoft Defender Firewall’s creaky configuration UI. Also included are a vulnerability scanner to help you keep on top of required application updates, an “app boost” performance optimiser, a secure file shredder, an encrypted vault for your most sensitive data, and a “web boost” tool that prevents irritants such as auto-playing videos in chrome.</p><p>Silent detection is enabled by default to ensure that you’re not interrupted while gaming or watching videos at full screen, although the setting in question is buried in the settings menus, rather than being placed in the main interface.</p><p>You also get a copy of the McAfee True Key password manager thrown in for free, but you can do better with <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for" data-original-url="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">rivals such as Bitwarden</a>. Family tier subscriptions include the Safe Family parental control and tracking toolkit.</p><p>In <a href="https://selabs.uk">SE Labs</a>’ latest home antivirus test, McAfee got a 100% total protection rating, meaning that it blocked all malicious software and didn’t falsely identify any benign programs as malicious or potentially unwanted.</p><p>In <a href="https://www.av-comparatives.org">AV Comparatives</a>’ most recent real-world protection test, it blocked 99.7% of malware, in common with most of its rivals, with 2 false positive identifications of legitimate software.</p><p>And it defended against 100% of malware in three of <a href="https://www.av-test.org/en">AV-Tests</a> most recent four rounds of testing. McAfee's engine breezed through the reference malware sample set in two successive months, but only protected against all threats in August’s real-world test; in July, like a number of its rivals, it was caught out by a couple of malware exposures, but still blocked 99.3% of threats, with a single false positive. That’s only slightly less accurate than Microsoft Defender.</p><p>AV-Test’s performance data from the same period highlights a couple of minor impacts on system performance and responsiveness, however. There was a noticeable slowdown when loading websites compared to Microsoft Defender and while McAfee’s impact on software installation times was a little less pronounced than Defenders’, it was still significant compared to most rivals.</p><p>A one device, one year Total Protection account costs £29.99 for the first year and renews at £59.99 when bought from the McAfee website. The company was recently the subject of <a href="https://www.itpro.com/security/antivirus/359674/mcafee-to-refund-customers-following-cma-investigation" data-original-url="https://www.itpro.com/security/antivirus/359674/mcafee-to-refund-customers-following-cma-investigation">a CMA ruling</a> finding its auto-renewal practices to be unfair, and it now more clearly highlights that its subscriptions auto-renew at a higher price and makes it easier to opt out. Renewals are still significantly more expensive than the first year’s subscription, though - more than double in the case of a ten device account.</p><p>However, as is often the case, the official price isn’t the same as the real price. A one-year, three-device key for McAfee Total Protection 2021 currently costs £11.99 from Amazon, just over a third as much as the standard introductory price for a single device, let alone the auto-renewing subscription fee.</p><p>McAfee provides some auto-renewal bonuses, notably access to the company’s Safe Connect VPN service and a money-back protection guarantee. However, even for fans of the product, this isn’t really enough added value to justify auto-renewal costs versus buying a much cheaper key elsewhere when it’s time to renew.</p><p>Total Protection does an adequate but not astonishing job. If you’re in the market for new malware protection, <a href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" data-original-url="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable">Kaspersky Internet Security</a> is a better choice right now.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ F-Secure Safe review: Simple security struggles to outdo Defender ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/361344/f-secure-safe-review-simple-security-struggles-to-outdo-defender</link>
                                                                            <description>
                            <![CDATA[ F-Secure Safe doesn’t have the protection or features to stand out against its rivals. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3HARDoAhfmYovLBCUz3jfz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XKHYGQsaMw823MEWwCE7pb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Oct 2021 08:39:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XKHYGQsaMw823MEWwCE7pb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of F-Secure Safe&amp;#039;s main dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of F-Secure Safe&amp;#039;s main dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of F-Secure Safe&amp;#039;s main dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XKHYGQsaMw823MEWwCE7pb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Finland’s F-Secure Safe has most of the features you’d want from an antivirus suite for home or home office use, with the addition of a particularly solid set of parental controls and content filtering tools to replace those that come built into Windows 10 and <a href="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review">11</a>. These can be activated immediately at install time by specifying that you’re setting up an account for a child, and allow you to set up time limits, as well as web filtering, but don’t include app restrictions.</p><p>You get the expected - and vital - real-time malware protection as well as various on-demand and scheduled scan options. Although it doesn’t have as many dedicated options here as some rivals, a Full Scan covers everything you’ll need, including the boot sector. </p><p>Other features are pretty standard: Known-malicious websites are blocked by default, with the option of also blocking sites deemed to be suspicious. Additional security features are available via browser extensions for Firefox, Edge and Chrome, including a secure banking tool and a site reputation checker for search engine results on Google, Bing, Yahoo, and DuckDuckGo.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="/malware/28153/whats-the-difference-between-antimalware-and-antivirus">What's the difference between antimalware and antivirus?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/361329/the-it-pro-podcast-should-the-us-cyber-army-be-more-aggressive" data-original-url="/security/cyber-warfare/361329/the-it-pro-podcast-should-the-us-cyber-army-be-more-aggressive">The IT Pro Podcast: Should the US cyber army be more aggressive?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/360833/over-90-of-it-teams-feel-pressure-to-compromise-security" data-original-url="/security/360833/over-90-of-it-teams-feel-pressure-to-compromise-security">Over 90% of IT teams feel pressure to compromise security</a></p></div></div><p>F-Secure doesn’t have all that many features that you can directly control or interact with. DeepGuard leans on the F-Secure cloud to only allow the installation of applications that it knows to be safe. This helps to keep malware from installing itself, but can throw up false positive identifications of legitimate software as potential threats. Fortunately, this is relatively rare and you can easily unblock anything you do want via the Tools page in the F-Secure client.</p><p>F-Secure doesn’t get as much regular attention from testing houses as some of its rivals. Consequently, this review is based on data from <a href="https://www.av-test.org">AV-Test</a> and <a href="https://selabs.uk">SE Labs</a> only. Although F-Secure scored 100% in one real-world malware exposure test set and both reference set scanning tests from AV-Test, it - like many other malware detection engines - experienced a blip in July’s real-world tests, giving it a protection rate of 99.3%. It only threw up a single false positive, however.</p><p>SE Labs last tested F-Secure Safe in the first quarter of 2021, when it was solidly out-performed by <a href="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender" data-original-url="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender">Microsoft Defender</a>. Kaspersky, McAfee and Avast also had better protection and total accuracy ratings. F-Secure had a protection rate of 96% and allowed the installation of 97% of legitimate software without false positive alerts, giving it an SE Labs total protection score of 96%.</p><p>AV-Test’s performance data shows us that F-Secure Safe has a low impact on system performance. It compares particularly well to Microsoft Defender when it comes to installation times for new software on low-performance PCs, and has less of an impact on website loading times than rival <a href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" data-original-url="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable">Kaspersky Internet Security</a>.</p><p>Although F-Secure doesn’t always get perfect malware protection test scores, it’s nonetheless effective enough to provide solid defense against the kind of online threats you’ll encounter day-to-day. It has a decent range of features, but lacks dedicated webcam protection and has no firewall, so you’re still left wrangling the Microsoft Defender firewall’s rather dated interface.</p><p>While the product’s £59.99 (inc VAT) full price - the one you get on renewal - is fairly typical, its reduced first-year subscription fee of £39.99 is higher than that of many rivals, including those with more features. For that matter, Kaspersky Internet Security costs £34.99 after your first year. However, as with much antivirus software, Safe is available for much less if you buy a subscription key from either an online or bricks-and-mortar shop - a one year, one device subscription costs as little as £19.35 on Amazon. F-Secure also goes out of its way to highlight and make it easy to opt out of automatic renewal fees, which we welcomed.</p><p>Between protection and features, while Safe does what it needs to, it doesn’t stand out from the crowd, or even from your operating system’s integrated default option. If you’re looking for paid-for antivirus, Kaspersky Internet Security has more features and a lower introductory price.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaspersky Internet Security review: Powerful, highly configurable protection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable</link>
                                                                            <description>
                            <![CDATA[ Easy to use, efficient and accurate malware defense for users who want to personalise their protection ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">74d4mgodk5JrBJrFjdC82V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Oct 2021 11:15:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Kaspersky Internet Security&amp;#039;s main dashboard ]]></media:description>                                                            <media:text><![CDATA[A screenshot of Kaspersky Internet Security&amp;#039;s main dashboard ]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Kaspersky Internet Security&amp;#039;s main dashboard ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaspersky Internet Security is a long-standing entry in our antivirus awards list, and its performance this time around hasn’t disappointed. We’ve reviewed the Windows version, running under Windows 10, but you can use your Kaspersky licenses to protect any combination of Windows, macOS, Android and iOS devices.</p><p>As well as the expected real-time malware detection and schedule scans, KIS provides a useful selection of features. There’s a browser protection module, ransomware defense that prevents unauthorized changes from being made to selected directories, private browsing and ad blocking, webcam protection, an interruption-free gaming mode, and online monitoring to check the protection status of all devices associated with your Kaserpersky account. Unusually for an antivirus suite in this price range, Kaspersky Internet Security also includes a fully-featured firewall. </p><p>You also get the free version of Kaspersky’s Secure Connection VPN, with a 300MB per day bandwidth cap, installed as a standalone utility. The other standalone components are an optional free subscription to Kaspersky Password Manager, and the free Safe Kids parental controls. None of these stand out against <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for" data-original-url="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">the market leaders</a> in their sectors, however. As they aren’t really integrated into the KIS client, you won’t feel their absence if you do away with them.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/356467/kaspersky-endpoint-security-cloud-review-merciless-against" data-original-url="/security/endpoint-security/356467/kaspersky-endpoint-security-cloud-review-merciless-against">Kaspersky Endpoint Security Cloud review: Merciless against malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/361224/mysterysnail-zero-day-elevation-of-privilege-exploit-in-windows" data-original-url="/security/zero-day-exploit/361224/mysterysnail-zero-day-elevation-of-privilege-exploit-in-windows">Kaspersky exposes MysterySnail zero-day exploit in Windows</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/33558/kaspersky-endpoint-security-for-business-advanced-review-on-prem-security" data-original-url="/endpoint-security/33558/kaspersky-endpoint-security-for-business-advanced-review-on-prem-security">Kaspersky Endpoint Security for Business Advanced review: On-prem security done right</a></p></div></div><p>When it comes to the protection afforded by its anti-malware engine, you can’t go wrong with Kaspersky’s products. KIS netted perfect protection scores without a single false positive in the most recent tests by <a href="https://www.av-test.org">AV-Test</a> and <a href="https://selabs.uk">SE Labs</a>. <a href="https://www.av-comparatives.org">AV Comparatives</a>’ July/August 2021 data shows that it blocked an impressive 99.70% of malware in real-world exposure tests, once again without any false positives. Not quite perfect, but an impressive performance however you cut it, matching that of Microsoft’s impressive integrated Defender.</p><p>Where Kaspersky provides a real advantage is in its interface and performance. KIS has been a great choice for minimal impact on system resources for years, and currently out-performs built-in Microsoft Defender Antivirus on Windows 10 PCs, notably when it comes to how long it takes to install software, although Kaspersky had a greater impact on website opening times.</p><p>Perhaps the best feature of Kaspersky Internet Security is the fantastic interface it provides for actually controlling it. While in practice, most of the same things KIS does can be achieved using Windows’ integrated tools, it’s just easier to do with Kaspersky.</p><p>Its firewall in particular is designed to be lived with and used, making it easy to add and edit rules, while the Microsoft Defender firewall remains comparatively unfriendly to work with. Application controls are also a welcome addition, although they tend to block unsigned software by default, requiring an exception to run.</p><p>Kaspersky Internet Security is pretty cost-effective, starting at £14.58 exc VAT for a one year, one device subscription from Kaspersky’s website. Further discounts are sometimes available, and you can buy packaged codes at physical and online shops at prices as low as £11 inc VAT.</p><p>Watch out for renewals, though - that single-user subscription goes up to £29.16 exc VAT on the second year, and your auto-renewing subscription is set up automatically if you buy your license via the official Kaspersky site. That’s still a decent price for 12 months of malware protection, but you should make sure you’re aware of it and that you want to renew automatically rather than buying codes elsewhere.</p><p>It’s also worth noting that, <a href="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak" data-original-url="https://www.itpro.com/security/29822/kaspersky-claims-pirated-office-software-was-behind-nsa-exploit-leak">since 2017</a>, some US businesses and both UK and UK government departments won’t allow their colleagues or contractors to run Kaspersky software on devices used for work. Kaspersky subsequently moved significant parts of its operation from Russia to Switzerland.</p><p>We’d prefer it if KIS put a little less emphasis on promoting Kaspersky’s other products after we’d already paid for this one, but that’s a minor complaint about an otherwise outstanding antivirus suite.</p><p>Kaspersky Internet Security is our favourite paid-for anti-malware solution, providing a great user interface and outstanding protection against malware and minimal impact on performance, improving even on Windows’ very credible integrated malware defence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cellebrite launches industry-first remote data collection solution ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-insights/data-management/361063/cellebrite-launches-industry-first-remote-data-collection</link>
                                                                            <description>
                            <![CDATA[ New solution aids organizations’ e-discovery and corporate investigation procedures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7Rffh31gYQ8VwTaFE7Ua93</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sFGw736Q5af2fGhtYooLQk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Sep 2021 16:50:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sFGw736Q5af2fGhtYooLQk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Woman holding phone with network graphics superimposed]]></media:description>                                                            <media:text><![CDATA[Woman holding phone with network graphics superimposed]]></media:text>
                                <media:title type="plain"><![CDATA[Woman holding phone with network graphics superimposed]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sFGw736Q5af2fGhtYooLQk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cellebrite has announced its new remote mobile data collection solution for handheld devices and computer systems.</p><p>Integrated into Cellebrite’s Endpoint Inspector, the new solution streamlines corporate investigations, e-discovery, and incident response. It can retrieve data from iOS and Android mobile devices and computers running <a href="https://www.itpro.com/operating-systems/25067/how-to-download-and-install-windows-10" data-original-url="https://www.itpro.com/operating-systems/25067/how-to-download-and-install-windows-10">Windows</a> and macOS.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359282/tiktok-faces-billion-pound-class-action-for-alleged-data" data-original-url="/policy-legislation/data-protection/359282/tiktok-faces-billion-pound-class-action-for-alleged-data">TikTok faces billion-pound legal battle over "illegal" data collection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/359060/why-diy-data-collection-should-come-before-automation" data-original-url="/business-strategy/data-insights/359060/why-diy-data-collection-should-come-before-automation">Why DIY data collection should come before automation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/357049/how-businesses-were-left-to-scramble-over-data-collection" data-original-url="/policy-legislation/data-protection/357049/how-businesses-were-left-to-scramble-over-data-collection">How businesses were left to scramble over data collection for coronavirus contact tracing</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/356199/facebook-ordered-to-curb-data-collection-in-landmark-antitrust-ruling" data-original-url="/security/privacy/356199/facebook-ordered-to-curb-data-collection-in-landmark-antitrust-ruling">Facebook dealt data collection blow in landmark antitrust case</a></p></div></div><p>"We focused on simplifying the employee experience during data collection and deployed our domain expertise to engineer Endpoint Inspector to automate the complexity of the collection process and limit business interruption," said Ken Basore, general manager of enterprise solutions at Cellebrite. </p><p>Basore continued, "In Enterprises that deploy Endpoint Inspector, employees no longer need to hand over their device or spend hours with internal support personnel to follow complex procedures. We are pleased to be able to bring this value to our enterprise customers across life sciences, banking, insurance, and other industries.”</p><p>Commenting on scope, Cellebrite said its remote solution could gather evidence from devices inside or outside an organization's IT network. The capability adds to the firm’s Endpoint Intelligence solution that integrates data from disparate sources to provide a 360-degree view of employee communications.</p><p>Additionally, a Smart Collections feature within Cellebrite's remote data collection solution ensures only pertinent data is collected on any device. Data collection occurs with the explicit consent of employees, and an audit record is automatically generated upon confirmation.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PM4YT6gZtuxq487ioKfWVC" name="PM4YT6gZtuxq487ioKfWVC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/PM4YT6gZtuxq487ioKfWVC.png" mos="https://cdn.mos.cms.futurecdn.net/PM4YT6gZtuxq487ioKfWVC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Turning data into unmatched business value</strong></p><p class="fancy-box__body-text">Using data to drive better outcomes</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-insights/data-management/361024/turning-data-into-unmatched-business-value" data-original-url="/data-insights/data-management/361024/turning-data-into-unmatched-business-value">FREE DOWNLOAD</a></p></div></div><p>Together, Cellebrite’s Endpoint Intelligence platform and remote data collection solution help businesses counter fraud, detect intellectual property theft, investigate claims of employee misconduct, and more. </p><p>“Corporate investigators are under serious pressure, now having to face the additional challenge of sourcing data to support cases from a geographically scattered <a href="https://www.itpro.com/business/business-strategy/357031/the-new-hybrid-office" data-original-url="https://www.itpro.com/business/business-strategy/357031/the-new-hybrid-office">hybrid workforce</a>, who are using more devices and messaging services than ever before for professional communications. Today's announcement underscores the strategic importance of Cellebrite's <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/tags/cloud">cloud</a> capabilities and our commitment to ensure enterprise investigators can adapt to a hybrid workforce, " added Basore. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The new frontier of endpoint management ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/361004/the-new-frontier-of-endpoint-management</link>
                                                                            <description>
                            <![CDATA[ How analytics and security stacks are driving employee experience initiatives ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i5GTd3Jz9x7gxiqn6Ai5kd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ggoUPZEdst8prJ2vdDVrzN-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Sep 2021 11:21:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/ggoUPZEdst8prJ2vdDVrzN-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green and grey cover]]></media:description>                                                            <media:text><![CDATA[Green and grey cover]]></media:text>
                                <media:title type="plain"><![CDATA[Green and grey cover]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ggoUPZEdst8prJ2vdDVrzN-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9nSBKsLiBqmSLUrShDDrxj" name="" alt="HP Wolf logo" src="https://cdn.mos.cms.futurecdn.net/9nSBKsLiBqmSLUrShDDrxj.png" mos="https://cdn.mos.cms.futurecdn.net/9nSBKsLiBqmSLUrShDDrxj.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Enterprises are playing pandemic catch-up as they continue to adjust to the explosion of remote and hybrid workers.</p><p>The results from this Forrester survey of nearly 800 IT decision-makers highlight the need for improved, modern endpoint management.</p><p>See how IT priorities have shifted to increased predictive analytics, enhanced security, and automation for endpoint management tasks, and learn key recommendations from Forrester on steps organisations can take to update their endpoint management strategy.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/hp-inc-hpi-inc-ziji-us-the-wolf-us-dg?locale=1&p=false&wp=7227"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to plan for endpoint security against ever-evolving cyber threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361002/how-to-plan-for-endpoint-security-against-ever-evolving-cyber</link>
                                                                            <description>
                            <![CDATA[ Safeguard your devices, data, and reputation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rHtxSDRsVN7bQp69JKdKZP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7oa4dt5hmFgq9dJuQyrsQG-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Sep 2021 11:11:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/7oa4dt5hmFgq9dJuQyrsQG-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man and woman looking at a laptop in an office building ]]></media:description>                                                            <media:text><![CDATA[Man and woman looking at a laptop in an office building ]]></media:text>
                                <media:title type="plain"><![CDATA[Man and woman looking at a laptop in an office building ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7oa4dt5hmFgq9dJuQyrsQG-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9nSBKsLiBqmSLUrShDDrxj" name="" alt="HP Wolf logo" src="https://cdn.mos.cms.futurecdn.net/9nSBKsLiBqmSLUrShDDrxj.png" mos="https://cdn.mos.cms.futurecdn.net/9nSBKsLiBqmSLUrShDDrxj.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Endpoints have become a frequent target for cyber attacks and represent a weak link in many organisations’ overall security posture.</p><p>This guide explores the reasons why your endpoints could be at risk and highlights the opportunities to combat these threats.</p><p>Read on for guidance on security requirements that should be included in your next RFP and the questions you should ask to strengthen the security of your devices, data, and identity to protect your business against ever-evolving cyber threats.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/hp-inc-hpi-inc-ziji-us-the-wolf-us-dg?locale=1&p=false&wp=7226"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Modernise endpoint protection and leave your legacy challenges behind ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/360946/modernise-endpoint-protection-and-leave-your-legacy-challenges</link>
                                                                            <description>
                            <![CDATA[ The risk of keeping your legacy endpoint security tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mXCxokzuQsZVZkJBUhFmZm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Sep 2021 14:59:37 +0000</pubDate>                                                                                                                                <updated>Fri, 03 Dec 2021 10:59:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54-1280-80.png">
                                                            <media:credit><![CDATA[VMWare logo]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper front cover]]></media:description>                                                            <media:text><![CDATA[Whitepaper front cover]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper front cover]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>2020 was an unprecedented year for security teams amid the global health crisis. The threat landscape continues to evolve as malicious actors quickly adapt to the changing environment and are finding new ways to exploit your vulnerabilities. It is now more critical than ever to protect your workforce at the endpoint no matter where you are.</p><p>Legacy endpoint security tools have proven to be ineffective at preventing these sophisticated threats. It is time to consider a modern endpoint security solution to gain advantage over highly innovative attackers. </p><p>Download this eBook to gain insights into:</p><ul><li>8 common endpoint security challenges and how they are solved by modernisation</li><li>Benefits of modernising your endpoint security</li><li>Why VMware Carbon Black Cloud is the easy answer to security challenges</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zp66zZ45fHZZzUkAKqByzh" name="" alt="VMWare logo" src="https://cdn.mos.cms.futurecdn.net/zp66zZ45fHZZzUkAKqByzh.png" mos="https://cdn.mos.cms.futurecdn.net/zp66zZ45fHZZzUkAKqByzh.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: VMWare logo)</span></figcaption></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49446/form-9600?locale=1&p=false&wp=7892"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Medigate and CrowdStrike bolster IoT medical device security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/network-internet/internet-of-things-iot/360854/medigate-and-crowdstrike-team-to-bolster-iot-medical</link>
                                                                            <description>
                            <![CDATA[ CrowdStrike will integrate its Falcon software with Medigate’s device security platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vtQoHNefZ3f17Kpmc1oEgH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Sep 2021 16:56:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Internet of Things]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:description>                                                            <media:text><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A stethoscope on top of a MacBook keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tXqJNLL29ZERv7RyA3pJuB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Medigate and CrowdStrike have joined forces to provide integrated <a href="https://www.itpro.com/security/28968/the-importance-of-endpoint-security" data-original-url="https://www.itpro.com/security/28968/the-importance-of-endpoint-security">endpoint security</a> for <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot" data-original-url="https://www.itpro.com/cloud-computing/28037/what-is-iot">Internet of Things (IoT)</a> medical devices.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/internet-of-things-iot/360850/iot-devices-are-more-vulnerable-than-ever" data-original-url="/network-internet/internet-of-things-iot/360850/iot-devices-are-more-vulnerable-than-ever">IoT devices are more vulnerable than ever</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/360716/critical-flaw-in-iot-camera-system-could-lead-to-remote-takeover" data-original-url="/security/vulnerability/360716/critical-flaw-in-iot-camera-system-could-lead-to-remote-takeover">Critical flaw in IoT camera system could lead to remote takeover</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/internet-of-things-iot/360612/83-million-iot-devices-at-risk-of-hacking" data-original-url="/network-internet/internet-of-things-iot/360612/83-million-iot-devices-at-risk-of-hacking">83 million IoT devices at risk of hacking</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/360231/kanglim-and-ridecell-partner-on-iot-enabled-industrial-mobility" data-original-url="/business-strategy/automation/360231/kanglim-and-ridecell-partner-on-iot-enabled-industrial-mobility">Kanglim and Ridecell partner on IoT-enabled industrial mobility platform</a></p></div></div><p>With more and more medical devices entering hospital networks, <a href="https://www.itpro.com/business-strategy/chief-technical-officer-cto/358465/the-it-pro-podcast-technology-in-healthcare" data-original-url="https://www.itpro.com/business-strategy/chief-technical-officer-cto/358465/the-it-pro-podcast-technology-in-healthcare">health care</a> delivery organizations (HDOs) face the difficult challenge of ensuring visibility into every connected device or terminal. </p><p>Medigate and CrowdStrike aim to solve this problem by offering HDOs a consolidated view of <a href="https://www.itpro.com/security/network-security/356853/threat-intelligence-leads-to-intelligent-defense" data-original-url="https://www.itpro.com/security/network-security/356853/threat-intelligence-leads-to-intelligent-defense">threat</a> activity across connected devices. </p><p>As part of the partnership, CrowdStrike will integrate its Falcon <a href="https://www.itpro.com/software" data-original-url="https://www.itpro.com/software">software</a> with Medigate’s device security platform, allowing HDOs to manage risk outcomes, detect anomalies, and enhance response capabilities.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mRGPzAS5b3aycfspJetZ3a" name="mRGPzAS5b3aycfspJetZ3a.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/mRGPzAS5b3aycfspJetZ3a.png" mos="https://cdn.mos.cms.futurecdn.net/mRGPzAS5b3aycfspJetZ3a.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The ultimate guide to going mobile for fire/emergency medical services</strong></p><p class="fancy-box__body-text">Get your free guide to going mobile for fire services and EMS</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/mobile/360506/how-to-go-mobile-for-emergency-medical-services" data-original-url="/hardware/mobile/360506/how-to-go-mobile-for-emergency-medical-services">FREE DOWNLOAD</a></p></div></div><p>Falcon by CrowdStrike monitors and safeguards functions and applications installed on all managed endpoint devices and workloads. Medigate device security platform (MDSP) offers critical insights into clinical protocols, communications, and workflows in a network. </p><p>The integration will allow MDSP to incorporate Falcon’s telemetry into its passive network monitoring. In addition to providing a 360-degree view of the environment, the combined solution will enable HDOs to monitor their managed and unmanaged endpoints for signs of intrusion and block them from becoming successful.</p><p>“We have seen a significant number of cyber attacks and ransomware against hospitals over the past year and this number will only increase in the future. A hospital should focus on patient care, rather than seeking to respond to external threats, ” said Matthew Polly, vice president of worldwide alliances, channels, and business development at CrowdStrike. </p><p>“Medigate's unique interest in the healthcare IoT industry is very effective in helping to reduce the fields of attack. With CrowdStrike and Medigate, HDOs can accurately see, detect, respond and prevent attacks across the IT and clinical landscape to safeguard their operations and data - including patient information. "</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Challenging the rules of security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/360664/challenging-the-rules-of-security</link>
                                                                            <description>
                            <![CDATA[ Protecting data and simplifying IT management with Chrome OS ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2PWFnkKjWYzQMS8Cng7dHD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jhaHY3RvAk8nfb9KJaMSFL-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Aug 2021 14:42:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/jhaHY3RvAk8nfb9KJaMSFL-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper front cover]]></media:description>                                                            <media:text><![CDATA[Whitepaper front cover]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper front cover]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jhaHY3RvAk8nfb9KJaMSFL-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ETtemSzPbu3wwnNDtdchT9" name="" alt="Dell Technologies" src="https://cdn.mos.cms.futurecdn.net/ETtemSzPbu3wwnNDtdchT9.png" mos="https://cdn.mos.cms.futurecdn.net/ETtemSzPbu3wwnNDtdchT9.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>IT threats are constantly changing and one of the greatest security challenges is protecting endpoints as cyber criminals have more ways to break in than ever. A great amount of resources is taken up monitoring endpoints and identifying risks, but with workforces now distributed - with countless distributed devices - traditional security processes and tools aren’t proving to be effective. </p><p>Now is the time to rethink your model and utilise cloud-based applications to strengthen your endpoint security and simplify your endpoint management.</p><p>Download this guide to learn how Google has changed its approach to endpoint security through cloud computing and multi-layered defences.</p><p><em>.</em></p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/dell-enterprise-chrome-bant?locale=1&p=false&wp=7076"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ McAfee Total Protection review: Quick, effective and affordable ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/antivirus/360652/mcafee-total-protection-review-quick-effective-and-affordable</link>
                                                                            <description>
                            <![CDATA[ A solid security choice, with perfect malware protection, a fully functional VPN and more ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ebSFxqxke7TQWm3YzqGn41</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5PksUUakHkmPFwMtksjFmN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Aug 2021 09:33:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5PksUUakHkmPFwMtksjFmN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of the McAfee Total Protection dashboard]]></media:description>                                                            <media:text><![CDATA[A screenshot of the McAfee Total Protection dashboard]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of the McAfee Total Protection dashboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5PksUUakHkmPFwMtksjFmN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>McAfee’s security software hasn’t always wowed us in the past but, since parting company with Intel in 2017, it’s become a persuasive contender.</p><p>That’s partly to do with value. Total Protection is McAfee’s top-of-the-line offering and one of the most feature-packed security suites we’ve seen, yet you can get a three-PC package on Amazon for just £15 a year. The slightly leaner Internet Security suite can also be had for two quid less.</p><h2 id="mcafee-total-protection-review-features">McAfee Total Protection review: Features</h2><p>McAfee Total Protection keeps an active watch over your system and blocks viruses and other malicious items on access. It monitors web content, too, and the free browser extension for Chrome, Edge, Firefox and Internet Explorer will steer you away from dodgy websites.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/printers" data-original-url="/security/antivirus/360586/norton-360-standard-review-a-dependable-partner-in-security">Norton 360 Standard review: A dependable partner in security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/antivirus/360476/avast-antivirus-free-review-our-favourite-free-solution" data-original-url="/security/antivirus/360476/avast-antivirus-free-review-our-favourite-free-solution">Avast Antivirus Free review: Our favourite free solution</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/360491/bitdefender-internet-security-review-a-solid-suite-at-a-fair-price" data-original-url="/security/360491/bitdefender-internet-security-review-a-solid-suite-at-a-fair-price">Bitdefender Internet Security review: A solid suite at a fair price</a></p></div></div><p>Additional features include a custom firewall and access to McAfee’s True Key password manager across five devices. There’s also an automatic software updater, a simple network scanner that lets you inspect nearby LAN clients, and tools for encrypting or shredding sensitive files.</p><p>The optional App Boost component isn’t really a security feature but it can make your system feel more responsive by allocating extra system resources to foreground applications.</p><p>Also included is McAfee’s Safe Family parental control platform. This works across Windows, Android and iOS to track and block specific apps and online content, keep tabs on device location and even send you alerts when your kids enter or leave defined areas.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vET2KTbjZo5UmozE5zKjVJ" name="" alt="A screenshot of the McAfee Total Protection dashboard" src="https://cdn.mos.cms.futurecdn.net/vET2KTbjZo5UmozE5zKjVJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/vET2KTbjZo5UmozE5zKjVJ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Most unusually, your McAfee subscription also includes <a href="https://www.itpro.com/networking/27210/do-i-need-a-vpn" data-original-url="https://www.itpro.com/networking/27210/do-i-need-a-vpn">a complete VPN service</a>, with selectable servers in 23 locations around the world and no data caps. You can even set it to kick in automatically whenever you connect to a new network too – a very nice touch. The catch is that to use it you have to keep the automatic licence renewal option turned on. This could prove costly if you forget to cancel at the right time, as the price goes up significantly in the second year.</p><h2 id="mcafee-total-protection-review-protection">McAfee Total Protection review: Protection</h2><p>McAfee’s malware engine is regularly put through its paces by both <a href="https://www.av-comparatives.org">AV-Comparatives.org</a> and <a href="https://av-test.org">AV-Test.org</a> and, in the most recent tests carried out in the first half of 2021, Total Protection achieved a flawless 100% protection rating.</p><p>There’s a catch, though. While McAfee successfully blocked every nasty sample it was exposed to, it also wrongly flagged seven innocent items. That’s more than we’d like to see. Once you get into the habit of manually unblocking safe items, it becomes far more likely that you’ll end up unblocking something dangerous. By contrast, in the same test, F-Secure SAFE and Eset Internet Security made no mistakes at all.</p><h2 id="mcafee-total-protection-review-user-interface">McAfee Total Protection review: User interface</h2><p>In the past, some McAfee products were burdened with a sluggish, overcomplicated front-end; thankfully, that’s now been completely overhauled. The current release of Total Protection is nicely responsive and neatly organised, with tabs along the top and sensibly labelled controls in the main pane.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="c5fdkHzEjR5QWwGmwDkBdg" name="c5fdkHzEjR5QWwGmwDkBdg.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/c5fdkHzEjR5QWwGmwDkBdg.jpg" mos="https://cdn.mos.cms.futurecdn.net/c5fdkHzEjR5QWwGmwDkBdg.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Forrester Wave: Top security analytics platforms</strong></p><p class="fancy-box__body-text">The 11 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms" data-original-url="/security/cyber-security/360171/the-forrester-wave-top-security-analytics-platforms">FREE DOWNLOAD</a></p></div></div><p>It’s also one of the nimblest security suites around. In a range of different usage scenarios, AV-Comparatives.org and AV-Test.org reported it slowed down their test PCs by an average of 6.3%. That’s an excellent score; of the packages we’ve seen, only F-Secure SAFE did better, nosing ahead with 6.1%. Windows Defender meanwhile weighed in at a ponderous 12.5%.</p><p>Scanning is quite quick, too. McAfee Total Protection fully scanned an external hard disk containing 55GB of assorted data in well under two minutes. Again, it didn’t quite keep up with F-Secure SAFE, which whizzed through the test in 27 seconds, but many other suites took longer and Windows’ own scanner left us waiting around nearly ten minutes.</p><h2 id="mcafee-total-protection-review-verdict">McAfee Total Protection review: Verdict</h2><p>McAfee Total Protection partners slick and effective malware protection with a tempting array of genuinely useful add-ons. The fact that it can be had for such a low price makes it almost irresistible.</p><p>However, a worse than average false positive rate means you might need to be prepared to fish the odd file out of quarantine and, if you��re going to enable the VPN, make sure you set a reminder to cancel your subscription before you’re stung with a hefty renewal fee.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>