<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/sophos"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Sophos ]]></title>
                <link>https://www.itpro.com/uk/tag/sophos</link>
        <description><![CDATA[ All the latest sophos content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Wed, 29 Apr 2026 11:06:16 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ North Korean hackers are duping freelance developers with fake interviews to steal cryptocurrency and deliver malware — Sophos warns the 'Nickel Alley' group is using LinkedIn, Upwork, and Fiverr to target victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/north-korean-hackers-are-duping-freelance-developers-with-fake-interviews-to-steal-cryptocurrency-and-deliver-malware-sophos-warns-the-nickel-alley-group-is-using-linkedin-upwork-and-fiverr-to-target-victims</link>
                                                                            <description>
                            <![CDATA[ A fake interview process uses coding tests and repo downloads to deliver malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VLS4GwTGb87a7DRvRmQrAm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Apr 2026 11:06:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:description>                                                            <media:text><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think">North Korean hackers</a> are targeting software developers in a new malware campaign that uses a fake interview process to steal cryptocurrency.</p><p>The campaign targets developers, especially those in the finance and technology industries, with profiles on freelance websites such as Upwork or Fiverr. It offers well-paid job opportunities and targets specific, high-value individuals.</p><p>It uses typosquatting or compromised legitimate npm repositories that victims are persuaded to inadvertently download and execute. </p><p>Researchers at the Sophos Counter Threat Unit have attributed the campaign to Nickel Alley, a threat group operating on behalf of the North Korean government. </p><p>"The group notoriously targets professionals in the technology sector by advertising fake job opportunities, deceiving prospective candidates through a fake job interview process, and ultimately delivering malware," the company said in an <a href="https://www.sophos.com/en-us/blog/nickel-alley-strategy-fake-it-til-you-make-it" target="_blank"><u>advisory</u></a>.</p><p>As part of its attacks, Nickel Alley often creates a fake LinkedIn company page to build credibility, with a coordinating <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>account for <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>delivery. </p><p>The website homepage is generic and advertises 'tech talent' and managed service solutions. However, different domains are included on the LinkedIn company page and the GitHub account – which researchers noted shows inconsistency and lack of attention to detail. </p><h2 id="nickel-alley-ramping-up-operations">Nickel Alley ramping up operations</h2><p>The advisory from Sophos comes after a June 2025 X post warned of a campaign involving targeted emails promoting job opportunities at the fake Astra Byte Sync company. </p><p>The threat actors hadn't actually built the website at the time the emails were sent, meaning that the site simply displayed the hosting provider’s default page. </p><p>Over the last year, the group has used the popular <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix </a>tactic to deliver PyLangGhost RAT malware via fake job skills assessment tasks. </p><p>This involved the attacker-controlled web interface presenting an error informing the victim that they must run a command locally to fix the issue – a command that instead initiated a series of actions leading to PyLangGhost RAT. </p><p>It previously used a GoLang-based version known as GoLangGhost RAT. </p><p>Meanwhile, in October, Sophos analysts uncovered a targeted attack where the threat actors convinced a victim to download, or clone, the content of a GitHub repository and execute the code locally using the 'npm install' and 'npm start' commands. </p><p>The GitHub account masquerades as a software development company specializing in full stack web development and blockchain solutions, and contains links to an 'official' company website and a <a href="https://www.itpro.com/security/cyber-attacks/linkedin-social-engineering-attacks">fake LinkedIn company page</a>. </p><p>While the main aim of these attacks appears to be cryptocurrency theft, Sophos said the threat group has also made it clear that it plans to use initial access for further supply chain compromise or corporate espionage. </p><p>"Additionally, the threat group has strategically selected follow-on payloads based on profiling victims’ system. Software developers, especially those in the finance and technology industries, are at elevated risk due to Nickel Alley’s targeting profile," Sophos warned.</p><p>"Organizations should monitor command execution and network traffic that spawns from Node.js processes, as it may indicate malware retrieval. As a general security practice, organizations should encourage employees to report suspicious unsolicited social media or email-based recruitment contact."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 95% of organizations don’t fully trust their cybersecurity vendors – here’s why ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/95-percent-of-organizations-dont-fully-trust-their-cybersecurity-vendors-heres-why</link>
                                                                            <description>
                            <![CDATA[ Organizations are struggling to assess vendor credibility as trust becomes a key factor in risk management. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PMVLyEUCvQwKghFLJy3mgU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dpEPGS24gcSUzc2mm2ASUY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Apr 2026 16:11:41 +0000</pubDate>                                                                                                                                <updated>Thu, 02 Apr 2026 16:44:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dpEPGS24gcSUzc2mm2ASUY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI representation of zero trust, shown as a multicolored holographic padlock surrounded by other blue holographic padlocks, hovering above a futuristic computer chip landscape.]]></media:description>                                                            <media:text><![CDATA[A CGI representation of zero trust, shown as a multicolored holographic padlock surrounded by other blue holographic padlocks, hovering above a futuristic computer chip landscape.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI representation of zero trust, shown as a multicolored holographic padlock surrounded by other blue holographic padlocks, hovering above a futuristic computer chip landscape.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dpEPGS24gcSUzc2mm2ASUY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An overwhelming majority of organizations lack full confidence in their <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>vendors, research from Sophos has revealed, highlighting growing challenges around trust and transparency.</p><p>The firm’s vendor-agnostic <em>Cybersecurity Trust Reality 2026 </em>report, which is based on responses from 5,000 organizations across 17 countries, dives into how trust is influencing sector risk and decision-making.</p><p>The study found that 95% of participants do not have full trust in their cybersecurity providers, while 79% said they struggle to assess the trustworthiness of new partners. </p><p>Almost two-thirds (62%) said they even find it challenging for their existing vendors. Additionally, more than half (51%) reported increased anxiety around the likelihood of a significant cyber incident as a direct result of this trust gap.</p><p>According to Sophos, the findings reflect a broader shift in how organizations evaluate cybersecurity effectiveness – with trust now a key factor alongside technical performance.</p><p>“Trust is not an abstract concept in cybersecurity, it’s a measurable risk factor,” explained Ross McKerchar, CISO at Sophos.</p><p>“When organizations can’t independently verify a vendor’s security maturity, transparency, and incident handling practices, that uncertainty flows directly into boardrooms and security strategies.”</p><h2 id="trust-as-a-decision-making-factor">Trust as a decision-making factor</h2><p>Sophos’ report shows that organizations are increasingly looking for verifiable evidence when assessing cybersecurity vendors, rather than relying on marketing claims or blanket assurances.</p><p>The survey identified verifiable security artifacts as the most important driver of trust, including independent certifications, third-party assessments, and demonstrated operational maturity.</p><p>While <a href="https://www.itpro.com/business/business-strategy/why-the-ciso-role-is-so-demanding-and-how-leaders-can-help">CISOs </a>prioritize transparency during incidents and consistent technical performance, senior leadership was found to place greater importance on independent validation, certifications, and analyst performance.</p><p>According to Phil Harris, IDC’s research director for governance, risk, and compliance solutions, the findings underline the growing pressure on businesses to validate vendor credibility as regulatory scrutiny and AI adoption continues to increase.</p><p>“With regulatory pressure increasing globally, organizations must be able to demonstrate due diligence in vendor selection – especially where <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>is involved,” he commented. “Trust is shifting from a marketing message to a defensible compliance requirement.”</p><h2 id="transparency-in-the-ai-era">Transparency in the AI era</h2><p>As AI continues to become more widely embedded in cybersecurity tools, services, and workflows, organizations are placing a greater focus on how vendors are deploying and governing these new technologies.</p><p>Sophos’ report found that a lack of accessible and sufficiently detailed information remains a critical barrier to making trust assessments, with survey respondents calling for greater transparency, accountability, and ongoing validation from providers.</p><p>“CISOs are being asked to prove trust, not assume it,” added McKerchar. “Cybersecurity providers must do the same.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware victims are getting better at haggling with hackers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/ransomware-victims-are-getting-better-at-haggling-with-hackers</link>
                                                                            <description>
                            <![CDATA[ While nearly half of companies paid a ransom to get their data back last year, victims are taking an increasingly hard line with hackers to strike fair deals. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ginb9VXsuRKnw4a7CUhyTn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/s8hwwtw3YUfjrTLizyeYYA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Jun 2025 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/s8hwwtw3YUfjrTLizyeYYA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware payment negotiation concept image showing man and woman on desktop computers separated by a dividing wall.]]></media:description>                                                            <media:text><![CDATA[Ransomware payment negotiation concept image showing man and woman on desktop computers separated by a dividing wall.]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware payment negotiation concept image showing man and woman on desktop computers separated by a dividing wall.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/s8hwwtw3YUfjrTLizyeYYA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nearly half of companies paid a ransom to get their data back last year, according to new research, but they’re taking a hard line with hackers to strike fair deals. </p><p>In its latest <a href="https://news.sophos.com/en-us/2025/06/24/the-state-of-ransomware-2025/" target="_blank"><em>State of Ransomware</em></a> report, Sophos said this was the second highest rate of ransom payments in six years. However, more than half (53%) paid less than the original demand. </p><p>In nearly three-quarters (71%) of these cases, the hackers were haggled down, either through the victims’ own negotiations, or with help from a third party. </p><p>Chester Wisniewski, director, field CISO at <a href="https://www.itpro.com/business/acquisition/sophos-acquires-secureworks-for-usd859-million">Sophos</a>, said that for many organisations, the threat of falling victim to <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> groups is now “just a part of doing business”. </p><p>What Sophos’ research shows, however, is that victims are taking a more pragmatic approach to the situation and are recovering at a quicker pace.</p><p>"The good news is that, thanks to this increased awareness, many companies are arming themselves with resources to limit damage,” he said. “This includes hiring incident responders who can not only lower ransom payments but also speed up recovery and even stop attacks in progress." </p><p>Companies are getting better at negotiation, Sophos noted. The median ransom demand dropped by a third between 2024 and 2025, but the actual payment made also dropped by half. </p><p>Overall, the median ransom payment was a round one million dollars - this was also half the figure cited for the previous year.</p><h2 id="not-all-ransomware-victims-are-successful">Not all ransomware victims are successful</h2><p>It's worth noting that 28% paid more than the initial ransom, largely due to extra demands from the hackers. Sophos said this usually happened because the attackers realized they could ask for more or they got frustrated. </p><p>Other causes included a lack of backups or a failure to pay up quickly enough.</p><p>Ransom payments varied by industry, with state and local government reporting paying the highest median amount at $2.5 million, while healthcare reported the lowest at $150,000.</p><p>Initial demands also varied significantly depending on the organization's size and revenue. The median ransom demand for companies with over $1 billion in revenue was $5 million, while those with $250 million revenue or less were asked for less than $350,000.</p><p>For the third year in a row, the number one technical root cause of attacks was exploited vulnerabilities, while 40% of ransomware victims said adversaries took advantage of a security gap that they hadn't been aware of. </p><p>Nearly two-thirds (63%) of organizations blamed resourcing issues as a major reason they fell victim to the attack. </p><p>Indeed, a lack of expertise was cited as the top operational cause in organizations with more than 3,000 people, and lack of people or capacity was most frequently cited by those with between 251 and 500 employees.</p><h2 id="enterprises-are-getting-better-at-recovery">Enterprises are getting better at recovery</h2><p>The good news is that 44% of companies were able to stop the ransomware attack before data was encrypted – a six-year high - with data encryption at a six-year low, with only half of companies having their data encrypted.</p><p>Only 54% of companies used backups to restore their data – the lowest percentage in six years.</p><p>However, the average cost of recovery dropped from $2.73 million in 2024 to $1.53 million in 2025. </p><p>Companies are getting faster at recovery, Sophos noted, which is a positive sign both in terms of preparedness and resilience. More than half (53%) fully recovered from a ransomware attack in a week, up from 35% last year. </p><p>Meanwhile, only 18% took more than a month to recover, down from 34% in 2024.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers">The new ransomware groups worrying security researchers in 2025</a></li><li><a href="https://www.itpro.com/security/ransomware/ransomware-missteps-that-can-cost-you">Ransomware missteps that can cost you</a></li><li><a href="https://www.itpro.com/security/ransomware/building-ransomware-resilience-to-avoid-paying-out">Building ransomware resilience to avoid paying out</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos names Torjus Gylstorff as new chief revenue officer ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/sophos-names-torjus-gylstorff-as-new-chief-revenue-officer</link>
                                                                            <description>
                            <![CDATA[ Sophos has announced the appointment of seasoned industry executive Torjus Gylstorff as its new chief revenue officer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N4UnwQegqgiqxxMuB923Yg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qwmtBJH86uhfVyv9SZRFnf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Oct 2024 07:30:00 +0000</pubDate>                                                                                                                                <updated>Wed, 23 Oct 2024 14:12:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qwmtBJH86uhfVyv9SZRFnf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos logo pictured on a smartphone screen with UK flag in background.]]></media:description>                                                            <media:text><![CDATA[Sophos logo pictured on a smartphone screen with UK flag in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos logo pictured on a smartphone screen with UK flag in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qwmtBJH86uhfVyv9SZRFnf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity</a> giant Sophos has announced the appointment of seasoned industry executive Torjus Gylstorff as its new chief revenue officer.</p><p>As CRO, Gylstorff is tasked with leading Sophos’ global sales organization, including its partner and customer networks, as the company looks to drive sales of its portfolio of security offerings - such as its <a href="https://www.itpro.com/security/cyber-security/357814/a-buyers-guide-to-managed-detection-and-response-mdr-services">managed detection and response (MDR)</a> services and solutions for endpoint, network, email, and <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security">cloud security</a>.</p><p>Gylstorff arrives with 25 years’ experience in sales, channels, and business development across the technology and cybersecurity sectors, including leading global sales teams and building channel ecosystems.</p><p>Most recently, he served as worldwide sales leader for Thales’ Application and Data Security business, which followed a tenure as vice president of worldwide channels and alliances at <a href="https://www.itpro.com/security/25315/symantec-employees-fired-over-fake-security-certificates">Symantec</a>. </p><p>Previously, he has also led emerging business initiatives at Blue Coat Systems, as well as held various leadership positions at Norman Shark, IBM, and Lotus Software.</p><p>With Gylstorff on board, Sophos is aiming to expand its presence beyond its existing customer base of more than 600,000 global organizations in the small- and mid-sized business market. </p><p>The new CRO will leverage his channel expertise to develop strategies that strengthen and drive additional business with both new and existing MSPs, the firm said. </p><p>“Our vision at Sophos is a world where organizations of any size and means have a clear path to superior cybersecurity outcomes, and the work we do every day aims to close the cyber security divide and protect more organizations in the most at-risk segments of the market,” explained Sophos CEO Joe Levy. </p><p>“The best and most efficient way to do this is by scaling with channel partners and MSPs.”</p><p>Levy added that Gylstorff’s extensive industry experience will be a key asset to the company as it looks to drive the next phase of its “go to market evolution.”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eFfiXgmBiL6ZDantsTa7HP" name="IBM watsonx_ A differentiated approach to AI foundation models.jpg" caption="" alt="CEOs guide to generative AI-finance" src="https://cdn.mos.cms.futurecdn.net/eFfiXgmBiL6ZDantsTa7HP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/ceos-guide-to-generative-ai-finance"><em>Financial management that leverages the power of generative AI</em></a></p></div></div><p>“With Torjus, who has decades of experience in leading channel sales, managing sales operations and developing relationships with customers, we can scale faster and in a way that accelerates growth for partners, MSPs and Sophos,” he said.</p><p>The move by Sophos comes amid an exciting period for the cybersecurity giant, with the company having recently announced <a href="https://www.itpro.com/business/acquisition/sophos-acquires-secureworks-for-usd859-million"><u>plans to acquire Secureworks as part of an $859 million deal</u></a>. </p><p>The deal, revealed on 21 October, will see Sophos integrate solutions from both companies to create what it described as a broader and stronger security portfolio aimed at serving businesses at the small, mid, and enterprise level.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos acquires Secureworks for $859 million ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/sophos-acquires-secureworks-for-usd859-million</link>
                                                                            <description>
                            <![CDATA[ Sophos will look to integrate Secureworks’ Taegis XDR platform while combining the pair's threat intelligence capabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">K984BiEBsTrp9mSSyc6fyi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Oct 2024 15:27:16 +0000</pubDate>                                                                                                                                <updated>Tue, 22 Oct 2024 14:12:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:description>                                                            <media:text><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/careers-and-training/sophos-appoints-zendesks-teresa-anania-as-new-chief-customer-officer">Sophos</a> has announced plans to acquire <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> firm <a href="https://www.itpro.com/security/365642/secureworks-adds-xdr-to-security-analytics-platform-and-mssp-scheme">Secureworks</a> in a deal worth $859 million as it looks to bolster its portfolio. </p><p>The deal, revealed on 21 October, will see Sophos integrate solutions from both companies to create what it described as a broader and stronger <a href="https://www.itpro.com/security/cyber-security/357203/microsoft-aims-to-simplify-security-portfolio-with-defender-rebrand">security portfolio</a> aimed at serving businesses at the small, mid, and enterprise level.</p><p>In its statement announcing the <a href="https://www.itpro.com/business/acquisition/zscaler-chief-exec-rebuffs-broadcom-acquisition-rumors">acquisition</a>, Sophos said it expects the deal to strengthen the wider security community by bringing two industry leaders together. </p><p>Part of this mission will include <a href="https://www.itpro.com/security/cyber-security/360234/avast-and-norton-in-talks-over-multi-billion-dollar-merger">merging</a> the two companies' threat intelligence capabilities, which are well regarded in the industry.</p><p>According to the <a href="https://www.sophos.com/en-us/press/press-releases/2024/10/sophos-acquire-secureworks-accelerate-cybersecurity-services-and" target="_blank">joint statement</a>, the duo plan on boosting cyber resilience with their combination of security controls, <a href="https://www.itpro.com/software/development/ai-coding-tools-are-finally-delivering-results-for-enterprises-developers-are-saving-so-much-time-theyre-able-to-collaborate-more-focus-on-system-design-and-learn-new-languages">AI tools</a>, leading <a href="https://www.itpro.com/security/cyber-security/370051/information-overload-a-key-barrier-to-effective-threat-intelligence-mandiant">threat intelligence</a>, and the combined experience of their security operatives.</p><p>Sophos will look to complement its existing strengths in <a href="https://www.itpro.com/security/cyber-security/356399/getting-the-most-from-your-managed-security-practice">managed security services</a> and end-to-end security products with Secureworks’s security operations expertise and its Taegis platform, to provide holistic XDR and MSR solutions.</p><p>The acquisition will also see Sophos expand its current portfolio with new offerings such as identity detection and response (ITDR), next-generation <a href="https://www.itpro.com/security/security-information-and-event-management-siem/367048/six-myths-of-siem">SIEM</a> capabilities, operational technology, and vulnerability risk <a href="https://www.itpro.com/security/ruthlessly-prioritize-whats-critical-check-point-expert-on-cisos-and-the-evolving-attack-surface">prioritization</a>.</p><p>“By combining complementary AI-driven security platforms powered by automated prevention, detection and response, the two organizations can deliver advanced solutions for defeating modern, persistent adversaries even faster”, the statement said.</p><h2 id="secureworks-security-expertise-perfectly-aligns-with-sophos-cyber-mission">Secureworks’ security expertise ‘perfectly aligns’ with Sophos’ cyber mission</h2><p>Sophos, which itself was acquired by software investment fund <a href="https://www.itpro.com/business/acquisition/thoma-bravo-adds-dollar15bn-in-value-to-imperva-as-thales-acquisition-agreed">Thoma Bravo</a> for $3.9 billion, stated that its enhanced security offering made possible by the deal will give businesses the security capabilities to compete with cyber adversaries in an increasingly hostile <a href="https://www.itpro.com/security/world-economic-forum-warns-of-growing-cyber-insecurity-amid-heightened-threat-landscape">threat landscape</a>.</p><p>Discussing the deal, Joe Levy, CEO at Sophos, said Secureworks’ Taegis XDR platform will complement Sophos’ strengths in <a href="https://www.itpro.com/security/ntt-data-begins-rolling-out-new-mdr-service">MDR</a>.</p><p>“Secureworks offers an innovative, market-leading solution with their Taegis XDR platform. Combined with our security solutions and industry leadership in MDR, we will strengthen our collective position in the market and provide better outcomes for organizations of all sizes globally,” he stated.</p><p>“Secureworks’ renowned expertise in cybersecurity perfectly aligns with our mission to protect businesses from cybercrime by delivering powerful and intuitive products and services. This acquisition represents a significant step forward in our commitment to building a safer digital future for all.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Aa7PgiDrzJcbHNcZwdRhuK" name="Getting Value from Generative AI.jpg" caption="" alt="Getting Value from Generative AI" src="https://cdn.mos.cms.futurecdn.net/Aa7PgiDrzJcbHNcZwdRhuK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: HPE)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/getting-value-from-generative-ai"><em>How HPE Intel-based ProLiant Gen11 helps companies improve productivity</em></a></p></div></div><p>Wendy Thomas, CEO at Secureworks, added that the marriage of Secureworks’ XDR capabilities with Sophos’ <a href="https://www.itpro.com/security/rethinking-endpoint-security-for-modern-work">endpoint</a>, <a href="https://www.itpro.com/cloud/cloud-computing/the-end-of-the-slowdown-global-cloud-spending-is-set-to-surge-by-20-in-2024-as-enterprises-ramp-up-migration-plans-and-capitalize-on-generative-ai">cloud</a>, and network products will offer a robust solution to help businesses challenge threat actors.</p><p>“Our mission at Secureworks has always been to secure human progress. Sophos’ portfolio of leading endpoint, cloud, and network security solutions – in combination with our XDR-powered managed detection and response – is exactly what organizations are looking for to strengthen their security posture and collectively turn the tide against the adversary,” she explained.</p><p>“As Joe and I both believe, this transaction will strengthen our go-to-market offering with Sophos’ global scale, expertise and reputation.”</p><p>The transaction is expected to close in early 2025, subject to customary closing conditions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 96% of SMBs are missing critical cybersecurity skills –  here's why ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/96-percent-of-smbs-are-missing-critical-cybersecurity-skills-heres-why</link>
                                                                            <description>
                            <![CDATA[ The skills shortage hits SMBs worse as they often suffer from a lack of budget and resources ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">opjzp8b96iVyhkgVKkVT26</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GdukdG5256cDEMrsNoi3SU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Oct 2024 08:58:47 +0000</pubDate>                                                                                                                                <updated>Fri, 18 Oct 2024 10:39:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GdukdG5256cDEMrsNoi3SU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity workers sitting and standing in an office space while working on laptop devices.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity workers sitting and standing in an office space while working on laptop devices.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity workers sitting and standing in an office space while working on laptop devices.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GdukdG5256cDEMrsNoi3SU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The vast majority of small and medium-sized businesses (SMBs) have gaps in their <a href="https://www.itpro.com/security/strain-of-cyber-skills-deficit-still-impacting-firms-despite-global-workforce-surge">cyber skills</a> and expertise, according to <a href="https://assets.sophos.com/X24WTUEQ/at/gqpx2zb7wpnzcgpz7xp4vmnr/sophos-the-cybersecurity-skills-shortage-in-smaller-businesses-wp.pdf"><u>research from Sophos</u></a>.</p><p>96% SMBs find at least one aspect of investigating suspicious alerts difficult, with specific tasks including identifying which signals to investigate, prioritizing which signals to probe, or keeping accurate records.</p><p>Sophos’ survey fielded responses from 5,000 IT and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> professionals across 14 countries and was conducted in Q1 2024. </p><p>The security firm found that organizations with fewer than 500 staff - the definition of SMB for this report - perceive a shortage of in-house <a href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">cybersecurity skills</a> and expertise to be their second <a href="https://www.itpro.com/security/357783/ransomware-remains-the-top-cyber-security-risk-for-smbs">biggest security risk</a>. </p><p>By comparison, this factor ranks seventh in cyber threats for organizations with over 500 staff members. </p><p>The report noted that smaller teams make it more challenging for IT workers to take time out for security education and means staff have fewer opportunities to benefit from peer-to-peer learning. </p><p>The report also found that a third (33%) of the time, no one is actively monitoring, investigating, or responding to security alerts in SMBs. </p><p>“SMBs are most acutely impacted by the cyber security skills shortage,” Ben Aung, Sage’s chief risk officer, told <em>ITPro</em>. </p><p>“They have neither the budgets nor career opportunities to compete against larger organizations for <a href="https://www.itpro.com/security/cyber-security-staff-are-working-weekends-more-than-ever-before-and-it-needs-to-stop">cybersecurity talent</a>, and often lack the capabilities and resources to bring in new entrants and train them up,” he added. </p><h2 id="simplified-solutions-are-key-to-smb-cybersecurity">Simplified solutions are key to SMB cybersecurity</h2><p>As SMBs are critical to the supply chain of larger organizations, Aung said, it's important that governments, larger firms, and resellers meet the challenge of the SMB cyber skills shortage. The key, he thinks, is simplicity. </p><p>“These organizations can significantly reduce SMBs' cyber risks by offering technology and services which are secure, easy to configure and operate right out of the box,” he said. </p><p>“SMBs should be able to take advantage of digital tools and the cloud without needing a PhD in cyber security - it should be simple to enable multi-factor authentication (MFA), set user access permissions and important controls like security patching and data backups should just be set up by default,” he added. </p><p>Concerns over cyber skills shortages come amid a period of escalating threats for SMBs globally. Research from Kaspersky earlier this year, for example, found the <a href="https://www.itpro.com/security/small-businesses-face-continued-security-threats-as-trojan-attacks-surge"><u>number of cyber infections experienced by small businesses</u></a> in Q1 rose by 5% compared to the same period in 2023. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RtRMsoasFJS9cPNF8gGbTG" name="Securing your network in every direction with zero trust.jpg" caption="" alt="Securing your network in every direction with zero trust" src="https://cdn.mos.cms.futurecdn.net/RtRMsoasFJS9cPNF8gGbTG.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Illumio)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/securing-your-network-in-every-direction-with-zero-trust"><em>Why Zero Trust is essential to protecting modern networks</em></a></p></div></div><p>Over 2,400 firms encountered malware on their systems, with the most common form of attack being trojans that often find their way into IT systems under the guise of legitimate software. </p><p>Similarly, a recent study from Vodafone found nearly half (43%) of all cyber attacks in the UK specifically target SMBs. The impact this has on small businesses cannot be understated, the study found, with around 60% of these leading to business closures within just six months. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>More from ITPro</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/why-ransomware-attacks-happen-to-small-businesses-and-how-to-stop-them">Why ransomware attacks happen to small businesses – and how to stop them</a></li><li><a href="https://www.itpro.com/security/smb-security-gaps-drive-new-opportunities-for-channel-players">SMB security gaps drive new opportunities for channel players</a></li><li><a href="https://www.itpro.com/security/cyber-crime/cyber-crime-cost-uk-businesses-more-than-pound30-billion-in-2023-and-small-businesses-were-among-the-worst-hit">Cyber crime cost UK businesses more than £30 billion in 2023, and small businesses were among the worst hit</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Software vendors are flocking to CISA’s Secure by Design Pledge ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/software-vendors-are-flocking-to-cisas-secure-by-design-pledge</link>
                                                                            <description>
                            <![CDATA[ CISA’s Secure by Design Pledge is picking up momentum, adding a further 100 companies to its list of signees since May ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iDBmfv9uaQNYFwtPejLVAk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gKLTvnANq7qVnyR2s8pvxK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Aug 2024 12:16:49 +0000</pubDate>                                                                                                                                <updated>Thu, 01 Aug 2024 16:22:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gKLTvnANq7qVnyR2s8pvxK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software security concept image of path traversal vulnerabilities showing binary code with errors.]]></media:description>                                                            <media:text><![CDATA[Software security concept image of path traversal vulnerabilities showing binary code with errors.]]></media:text>
                                <media:title type="plain"><![CDATA[Software security concept image of path traversal vulnerabilities showing binary code with errors.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gKLTvnANq7qVnyR2s8pvxK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than 180 software companies have signed up to CISA’s voluntary Secure by Design Pledge to take greater responsibility for the security of their products.</p><p>The pledge requires <a href="https://www.itpro.com/security/a-robust-cyber-security-industry-requires-software-vendors-to-pull-their-weight-so-why-are-customers-working-so-hard">software vendors</a> to place added emphasis on building security principles into the design and manufacture of their products.</p><p><a href="https://www.itpro.com/security/what-is-cisa">CISA </a>director Jen Easterly <a href="https://www.itpro.com/security/nearly-70-software-vendors-sign-up-to-cisas-cyber-resilience-program">announced the project in April 2023</a>, revealing the first round of commitments from high-profile companies including HP, IBM, AWS, NetApp, and Microsoft at the RSA Conference in May 2024.</p><p>As of 8 May, Easterly revealed the pledge had already received around 70 signees in this first round, and the program appears to be picking up momentum with approximately another 100 joining up over the following months.</p><p>The latest of these was enterprise identity specialist SailPoint, which announced on 30 July it would be taking the pledge, committing itself to seven distinct goals, each aimed at boosting the security of software products before they hit the market.</p><p>Rex Booth, CISO at SailPoint, said every technology company has a role to play in the continuing effort to stay ahead of threat actors and raise levels of cyber resilience across the board.</p><p>“Every technology provider is an unwitting part of the cyber battlespace. But unlike in the physical world, there’s no cyber army coming to our rescue. Each of us is responsible for the security of our products and, by extension, the security of those we serve,” he explained.</p><p>“The Secure by Design pledge is a great way to promote a sense of communal responsibility among those of us with the greatest potential for impact. At SailPoint, we are proud to join our peers and support this important initiative.”</p><h2 id="secure-by-design-pledge-will-push-firms-to-take-ownership-of-security-outcomes-at-the-executive-level">Secure by Design Pledge will push firms to take ownership of security outcomes at the executive level</h2><p>The founding goal of the Secure by Design Pledge is to encourage software builders to shoulder more of the responsibility for ensuring their solutions are secure when they reach the hands of end-users.</p><p>“As a nation, we have allowed a system where the cybersecurity burden is placed disproportionately on the shoulders of consumers and small organizations and away from the producers of the technology and those developing the products that increasingly run our digital lives,” CISA stated in a <a href="https://www.cisa.gov/securebydesign" target="_blank">blog</a> announcing the pledge.</p><p>‘Every technology provider must take ownership at the executive level to ensure their products are secure by design”.</p><p>The seven goals CISA wants firms to focus on reflect attack techniques it has observed in the current threat landscape, including increased use of <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication (MFA)</a>, timely vulnerability disclosure, reducing use of default passwords, and improving customers’ ability to gather evidence of cyber intrusions affecting the manufacturer’s products.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tvawFkCaNr5vdotoTDCE6Z" name="The life sciences guide to AI-driven innovations.jpg" caption="" alt="The life sciences guide to AI-driven innovations" src="https://cdn.mos.cms.futurecdn.net/tvawFkCaNr5vdotoTDCE6Z.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/the-life-sciences-guide-to-ai-driven-innovations"><em>Reinvent your business with data and AI</em></a></p></div></div><p>The program asks software vendors to be able to demonstrate measurable progress towards achieving each of its seven targets, and one signee – Sophos – recently updated customers on its progress.</p><p>Sophos’ update gave further details on how it plans on meeting each of its seven targets, which include releasing passkey support for its cloud management, prohibiting the use of default credentials in all current and future products, as well as releasing a feature by September 2025 that will enable customers to automatically schedule updates for their Sophos Firewall.</p><p>Ross McKerchar, CISO at Sophos, noted that the project is not about meeting the goal and resting on one’s laurels, but instead to create a new way of thinking about how software products are designed.</p><p>“This is not a one and done initiative that CISA has created – it’s a much-needed way of thinking and framework that should be built into the design and architecture of security solutions”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos Firewall Virtual review: Affordable network protection for those that like it virtualized  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/sophos-firewall-virtual-review-affordable-network-protection-for-those-that-like-it-virtualized</link>
                                                                            <description>
                            <![CDATA[ Extreme network security that's cheaper than a hardware appliance and just as easy to deploy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FmDhEdUhiuNamoKsuKwpR7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fAYYv7wPaPJdPW4ojr8P6i-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Jun 2024 09:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fAYYv7wPaPJdPW4ojr8P6i-1280-80.jpg">
                                                            <media:credit><![CDATA[Sophos website/Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Sophos Firewall Virtual logo on the ITPro background]]></media:description>                                                            <media:text><![CDATA[The Sophos Firewall Virtual logo on the ITPro background]]></media:text>
                                <media:title type="plain"><![CDATA[The Sophos Firewall Virtual logo on the ITPro background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fAYYv7wPaPJdPW4ojr8P6i-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Businesses that want to avoid the extra cost of on-premises hardware security appliances will find Sophos&apos; Firewall Virtual appealing. Supporting all the main hypervisors, including VMware, Hyper-V, Citrix, and KVM, it allows businesses to virtualize all their security services and extend protection to the network perimeter, endpoints, and virtual environments.</p><p>There are no compromises on features as it delivers the same tough security measures as <a href="https://www.itpro.com/hardware/sophos-xgs-136w-review-a-desktop-security-dynamo">Sophos&apos; XGS desktop</a> and rackmount appliances. It&apos;s flexible too, as you can choose from a wide range of virtual models with licensing based on the number of virtual CPUs (vCPUs) and memory.</p><p>Licensing starts with one vCPU core and 2GB of <a href="https://www.itpro.com/hardware/31661/what-is-ram">RAM</a> and goes all the way up to unlimited cores and memory. Even better, you can upgrade them in the future if you need to increase performance.</p><h2 id="sophos-firewall-virtual-review-installation-and-deployment">Sophos Firewall Virtual review: Installation and deployment</h2><p>Broadcom&apos;s new VMware licensing strategy appears to have upset a lot of people so for our review, we opted to use Microsoft&apos;s Hyper-V and installed Firewall Virtual on a <a href="https://www.itpro.com/infrastructure/servers-and-storage/dell-poweredge-r660xs-review-rack-dense-power-at-an-attractive-price">Dell PowerEdge server</a> running Windows Server 2022. The process is simple enough as we downloaded the ZIP file from Sophos&apos; support site which contained primary and auxiliary virtual hard disks (VHDs). </p><p><a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines">Virtual machine</a> (VM) creation is swift as you assign the primary VHD and a virtual switch which is your LAN connection to the appliance. Next, you add the auxiliary VHD and a second switch for the appliance&apos;s WAN connection and power it up.</p><p>From here on, deployment is no different to the hardware appliances as you point a browser at the VM&apos;s LAN address and follow the quick start wizard. Commendably, it started by updating the firmware to the latest SFOS v20 and insisted we change the default admin password.</p><p>It then assists with setting up LAN and WAN port address assignments plus DHCP services. We opted for routed mode so the appliance provides all security functions and the wizard enabled a default set of firewall security policies which included web filtering, anti-malware, and zero-day protection. If you want to try it out, let the wizard assign a temporary serial number which enables a 30-day trial of the SFVUNL unlimited version with all security services enabled</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="R9LhU5tw4KT3js9MQ66ezQ" name="ControlCentre_Sophos_Firewall.jpg" alt="The Sophos Firewall Virtual control center" src="https://cdn.mos.cms.futurecdn.net/R9LhU5tw4KT3js9MQ66ezQ.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><h2 id="sophos-firewall-virtual-review-security-features">Sophos Firewall Virtual review: Security features</h2><p>Sophos offers a good range of flexible licensing options with the XStream Protection bundle enabling everything on its books. Along with the base firewall license, this includes the network, web, and zero-day protection modules, deep packet inspection, central orchestration, and enhanced 24/7 support.</p><p>There is one catch as the XGS hardware appliances employ a dual-processor architecture that uses Sophos&apos; Xstream flow processors to provide a dedicated hardware acceleration layer for the firewall, TLS 1.3 inspection, and IPsec VPNs. Called FastPath, the VMware version can use the VM&apos;s vCPUs for firewall acceleration only and this function isn&apos;t supported at all in Hyper-V with Sophos recommending turning it off from the CLI.</p><p>That aside, the virtual appliance offers all the same security measures and uses policies to combine firewall rules, service filters, and time schedules with other functions such as web and application filtering, intrusion detection, and email anti-spam for all common messaging protocols. A filtering feature makes it easy to find specific rules within complex policies and you can reset traffic counters back to zero without requiring an appliance reboot.</p><p>Application filters are extensive as Sophos currently provides over 3,600 predefined apps and you can create multiple custom policies that can be easily applied to specific firewall rules. Web filtering services are equally good as you have over 90 categories you can choose to block or allow and a predefined set of policies are included to get you started.</p><h2 id="sophos-firewall-virtual-review-monitoring-and-cloud-services">Sophos Firewall Virtual review: Monitoring and cloud services</h2><p>The appliance&apos;s web interface opens with the Control Center dashboard which tells you everything you need to know about your security posture. It shows network activity, appliance utilization plus security issues and provides graphs for blocked and allowed applications and web categories with the User and device Insights section revealing activity for SSL inspection, ATP (advanced threat protection), and zero-day protection.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vrTz3WaxLJqRqCJVv3596X" name="Policy_Sophos_Firewall.jpg" alt="The Policy page on the Sophos Firewall Virtual" src="https://cdn.mos.cms.futurecdn.net/vrTz3WaxLJqRqCJVv3596X.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Cloud application usage is closely monitored and a list of those identified by the appliance is presented in the Control Center. One-click takes you to the cloud app list so you can decide whether to allow them. Permitted apps must be sanctioned by an administrator, unsanctioned ones will be marked and blocked while tolerated apps can be allowed but with a QoS (quality of service) rule applied to control bandwidth usage</p><p>Remote management is enabled when you register and authorize the appliance with your Sophos Central cloud account which now offers customizable dashboards. The firewall management section provides a report hub for viewing all security and policy events and you can load the Control Center interface from here as well.</p><p>Sophos Central also brings the appliance&apos;s Synchronized Security feature into play. This uses a heartbeat to monitor systems running the Sophos Intercept X endpoint agent and can isolate all systems in the same network zone if malware is detected on any of them.</p><p>Make sure you enable traffic logging on each firewall rule as this allows the appliance to gather information for its reporting services. It&apos;s worth it as Control Center can provide a wealth of valuable information so you can keep a close eye on areas such as firewall, malware, threat, application, web content filtering, and spam activity.</p><p><br></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LHaLeTFyrsc5nvasAaVZWc" name="Dashboard_Sophos_Firewall.jpg" alt="The dashboard for the Sophos Firewall Virtual" src="https://cdn.mos.cms.futurecdn.net/LHaLeTFyrsc5nvasAaVZWc.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><h2 id="sophos-firewall-virtual-review-is-it-worth-it">Sophos Firewall Virtual review: Is it worth it?</h2><p>For network perimeter security services, the Sophos Firewall Virtual is a cost-effective alternative to hardware appliances and makes a lot of sense for businesses already heavily invested in virtualization. The Hyper-V version we tested doesn&apos;t support the FastPath feature but all the other security measures you&apos;d expect to see in Sophos&apos; XGS hardware appliances are present and correct, it&apos;s just as easy to deploy and can be easily upgraded with a new license to keep in step with demand.</p><p><strong>Sophos Firewall Virtual requirements</strong></p><p>Hypervisor – Microsoft Hyper-V, VMware ESXi 7, KVM, Citrix, Nutanix Prism</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MSPs are struggling with cyber security skills shortages  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/msps-are-struggling-with-cyber-security-skills-shortages</link>
                                                                            <description>
                            <![CDATA[ A shortage of tools and difficulties keeping pace with solutions were also ranked as key issues for MSPs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TbmVFbpybD4NwMmAXnMk65</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tAEZHSYPXPJqr9r6aH5EU6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 May 2024 11:26:02 +0000</pubDate>                                                                                                                                <updated>Wed, 29 May 2024 15:56:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ george.fitzmaurice@futurenet.com (George Fitzmaurice) ]]></author>                    <dc:creator><![CDATA[ George Fitzmaurice ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/N4xHCjSAXKcijjt3oiQtfc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tAEZHSYPXPJqr9r6aH5EU6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security concept image showing a digitized padlock sitting on a blue colored circuit board.]]></media:description>                                                            <media:text><![CDATA[Cyber security concept image showing a digitized padlock sitting on a blue colored circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security concept image showing a digitized padlock sitting on a blue colored circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tAEZHSYPXPJqr9r6aH5EU6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service">Managed service providers</a> (MSPs) are struggling to contend with rampant <a href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">cyber security skills</a> shortages, according to a new study by IT security firm Sophos. </p><p>Human staff, Sophos said, “remain central” to effective <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a>, with skilled professionals necessary to “configure, deploy, manage, respond to, and update technology solutions”.</p><p>The long-standing cyber security skills shortage is hampering MSPs&apos; ability to effectively perform their role supporting clients, the study noted.</p><p>“The shortage of skilled professionals is well-known, and organizations are increasingly turning to MSPs to fill the gaps, exacerbating the challenge,” the report stated. “Technology alone cannot automatically stop every cyber threat”.</p><p>Reflecting this problematic shortage of in-house cyber security skills, the report stated that 66% of MSPs use a third-party vendor to deliver <a href="https://www.itpro.com/security/cyber-security/357814/a-buyers-guide-to-managed-detection-and-response-mdr-services">managed detection and response (MDR) services</a>.</p><p>On top of that, a further 15% deliver MDR services as a joint effort, through a combination of their own security operations center (SOC) and a third-party vendor.</p><p>MSPs indicated that hiring new cyber security analysts to keep pace with customer growth and the latest cyber threats was a considerable challenge. The survey revealed that 34% of MSPs that provide an MDR service have an in-house SOC which, in turn, necessitates in-house specialist analysts.</p><h2 id="the-pace-of-technology-is-an-issue-for-msps">The pace of technology is an issue for MSPs</h2><p>Keeping pace with the latest cyber security solutions and technologies was also a key issue, cited as the single biggest challenge facing MSPs by 39% of respondents involved in the survey. </p><p>“Given the speed of innovation in this space, it is unsurprising that many MSPs are struggling to keep up. As threats evolve, so do the cyber controls that stop them,” the report stated.</p><p>There are difficulties in the provision of cyber security vendors as well, as the study revealed that over half (53%) of MSPs work with just one or two cyber security vendors, while 83% use between one and five.</p><p>According to Sophos, MSPs estimate a reduction of 48% in their day-to-day management time where they are able to manage all their cyber security tools from a single platform.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zPqJCyEu6wpL7hmyg2RA3f" name="The security awareness handbook 2.jpg" caption="" alt="Cartoon of two people looking at a pocketwatch" src="https://cdn.mos.cms.futurecdn.net/zPqJCyEu6wpL7hmyg2RA3f.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-security-awareness-handbook"><em>Get insight on the common security risks users face</em></a><em> </em></p></div></div><p>Other challenges facing MSPs included providing out-of-house coverage, such as on the weekends or during holidays, and winning over new customers.</p><p>“The speed of innovation across the cybersecurity battleground means it’s harder than ever for MSPs to keep up with threats and the cyber controls designed to stop them,” Scott Barlow, vice president of MSP at Sophos, said.</p><p>“When you couple this with a global skills shortage, which has made it infinitely more difficult for many MSPs to attract and retain cybersecurity analyst resources, it&apos;s unsurprising that MSPs feel unable to keep pace with the changing threat landscape,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos names Joe Levy as new CEO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/sophos-names-joe-levy-as-new-ceo</link>
                                                                            <description>
                            <![CDATA[ The experienced cyber security veteran takes the reigns as Sophos looks to expand its presence in the midmarket ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S3SMgNm3KcKYYrsqP6t4qM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 May 2024 06:30:58 +0000</pubDate>                                                                                                                                <updated>Thu, 23 May 2024 12:46:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:description>                                                            <media:text><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sophos has announced the appointment of Joe Levy as its new CEO as the cyber security provider looks to expand its customer base in the midmarket.</p><p>Levy steps into the job having led the business as acting CEO since February 15 and has moved swiftly to name Jim Dildine as Sophos’ new chief financial officer.</p><p>A seasoned cyber security veteran, Levy brings 30 years’ leadership experience in cyber security product development, services, and companies, and has spent nine years at Sophos to date.</p><p>During his time at the company, he has helped drive its transformation from a product-only vendor into the broader cyber security organization it is today, including the development of an incident response team and managed detection and response (MDR) service now leveraged by 21,000 organizations globally.</p><p>Levy is also credited with creating SophosAI and Sophos X-Ops solutions and is well-versed in the workings of the channel, having worked closely with MSPs throughout his career.</p><p>In an announcement, Levy said his leadership strategy will place a focus on expanding Sophos’ customer base in the midmarket, which already includes 600,000 customers worldwide and generates more than $1.2 billion in annual revenue.</p><p>“Our goal is to help more organizations in the midmarket – the estimated 99% of organizations that are below the cyber security poverty line – be better at detecting and disrupting inevitable cyber attacks,” Levy said.</p><p>“Our envisioned approach to achieving this is to work with MSPs and channel partners that can scale alongside us with our innovative critical cross domain technologies – endpoint, network, email, and cloud security – and managed services that they can resell and co-deliver.</p><p>“Cyber attacks against the midmarket could severely impact the world’s ability to function; they are relatively under-protected compared to the 1%, and Sophos is on a mission to change that.”</p><h2 id="sophos-x2019-new-cfo-will-support-expansion-strategy">Sophos’ new CFO will support expansion strategy</h2><p>Jim Dildine, who has been named as the company’s new CFO as part of Levy’s leadership strategy, also adds extensive operation expertise and a wealth of experience in channel-partner based cyber security business. </p><p>Most recently, Dildine spent four years serving as CFO at cyber security firm Imperva and has previously held the same role at Symantec’s enterprise security business. He has also held key financial roles, as well as chief technology officer, at Blue Coat Systems over a period of nine years.</p><p>At Blue Coat, Dildine oversaw considerable growth in market value while guiding the company through various ownership transactions, including its $4.6 billion sale to Symantec in 2016. He also led the company’s acquisition and integration of six security-focused companies during his tenure.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WEBINAR</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hiQsNSVTNyBakwNtsq5WA4" name="Delivering an AI-powered content supply chain for retail and CPG_thumb.jpg" caption="" alt="An on-demand webinar from IBM on  Delivering an AI-powered content supply chain" src="https://cdn.mos.cms.futurecdn.net/hiQsNSVTNyBakwNtsq5WA4.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/delivering-an-ai-powered-content-supply-chain-for-retail-and-cpg"><em>Solve application modernization challenges with generative AI</em></a></p></div></div><p>Commenting on his new role, Dildine said Sophos is “well on its way to breaking through to the next level” and achieving its growth ambitions.</p><p>“Everything the company has accomplished thus far is impressive, including how dedicated Sophos is to constantly be innovating its cyber security technology and <a href="https://www.itpro.com/security/how-to-choose-the-best-cyber-security-vendor-for-your-business">managed security services</a> for customers in the midmarket,” he said.</p><p>“Sophos is also equally committed to supporting its channel partners, MSPs, and staff around the world. I am looking forward to helping Joe accelerate growth and further position Sophos as a leader in the industry.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nearly 70 software vendors sign up to CISA’s cyber resilience program ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/nearly-70-software-vendors-sign-up-to-cisas-cyber-resilience-program</link>
                                                                            <description>
                            <![CDATA[ Major software manufacturers pledge to a voluntary framework aimed at boosting cyber resilience of customers across the US ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ki4Tx4b5a4zvGfx3ef2BfH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dRS2qaRw7vFoy4eWscarFB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 May 2024 12:01:38 +0000</pubDate>                                                                                                                                <updated>Thu, 09 May 2024 16:45:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dRS2qaRw7vFoy4eWscarFB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Jen Easterly, director of CISA, speaking at the Kyiv International Cyber Resilience Forum in 2024.]]></media:description>                                                            <media:text><![CDATA[Jen Easterly, director of CISA speaking at the Kyiv International Cyber Resilience Forum in 2024 ]]></media:text>
                                <media:title type="plain"><![CDATA[Jen Easterly, director of CISA speaking at the Kyiv International Cyber Resilience Forum in 2024 ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dRS2qaRw7vFoy4eWscarFB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nearly 70 leading US <a href="https://www.itpro.com/615307/should-software-companies-be-liable-for-data-breaches">software companies</a> have agreed to join a <a href="https://www.itpro.com/business-strategy/collaboration/357085/banks-sign-pledge-to-strengthen-uks-fintech-sector">voluntary pledge</a> drawn up by <a href="https://www.itpro.com/security/cisa-forced-to-take-its-own-systems-offline-following-ivanti-alert">CISA</a> urging developers to incorporate <a href="https://www.itpro.com/security/cyber-security/356010/government-awards-ps10-million-to-cutting-edge-security-by-design">secure by design</a> principles into their products.</p><p>CISA director <a href="https://www.itpro.com/security/cyber-attacks/cisa-urges-organizations-to-adopt-passwordless-security-in-lapsusdollar-report">Jen Easterly </a><a href="https://www.rsaconference.com/USA/agenda/session/A%20World%20On%20Fire%20Playing%20Defense%20in%20a%20DigitizedWorldand%20Winning" target="_blank">said</a> she has seen real change in the software ecosystem since the initiative’s announcement in April 2023, and on 8 May CISA announced the first round of commitments from high-profile companies at the <a href="https://www.itpro.com/tag/rsa">RSA Conference</a> in San Francisco. </p><p>Easterly said the goal of the project is to promulgate better <a href="https://www.itpro.com/software/qubes-os-review-an-os-built-with-security-in-mind">built in security</a> to counter both the ongoing “scourge of ransomware” as well as a concerning rise in state-sponsored threat campaigns focussed on disrupting critical national infrastructure.</p><p>“[Nation-state threat actors] are burrowing into our critical infrastructure not for espionage, not for data theft, not for intellectual property theft, but specifically to launch <a href="https://www.itpro.com/security/ncsc-ai-will-increase-speed-and-scale-of-critical-infrastructure-attacks">disruptive and destructive attacks</a> in the event of a major conflict”.</p><p>Easterly said this threat was “different in kind” to anything she has observed over the course of her career, and it is why the US government is <a href="https://www.itpro.com/security/cyber-attacks/368824/most-business-leaders-only-prioritise-cyber-security-after-a-major-breach">prioritizing cyber resilience</a> and implementing secure by design principles across as many digital products as possible.</p><p>The pledge consists of seven goals each with core criteria that defines what the manufacturers are pledging to work towards, which include examples of how they can demonstrate measurable progress towards achieving these targets.</p><p>Similarly, the pledge sets out a number of means by which the signees can demonstrate quantifiable progress towards their goals, but will give the companies some discretion to decide how best they can go about demonstrating their progress.</p><p>The first round of commitments included major players signing up to the pledge including <a href="https://www.itpro.com/software/microsoft">Microsoft</a>, <a href="https://www.itpro.com/tag/ibm">IBM</a>, <a href="https://www.itpro.com/amazon-web-services">AWS</a>, <a href="https://www.itpro.com/business/acquisition/crowdstrike-to-acquire-application-security-management-startup-bionic">CrowdStrike</a>, <a href="https://www.itpro.com/technology/artificial-intelligence/under-the-hood-of-gitlab-duo-chat-what-can-users-expect">GitLab</a>, <a href="https://www.itpro.com/security/sophos-and-tenable-team-up-to-launch-new-managed-risk-service">Sophos</a>, <a href="https://www.itpro.com/tag/lenovo">Lenovo</a>, <a href="https://www.itpro.com/news/live/netapp-insight-2023-all-the-news-and-announcementshttps://www.itpro.com/cloud/cloud-computing/netapp-ceo-hybrid-cloud-will-be-the-only-way-to-capitalize-on-generative-ai">NetApp</a>, and <a href="https://www.itpro.com/tag/hp">HP</a>.</p><h2 id="easy-wins-to-bolster-cyber-resilience-across-the-board">Easy wins to bolster cyber resilience across the board</h2><p>First up is increasing the use of <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatiguehttps://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication</a> (MFA) across software products, which it describes as the best defense against popular <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">password-based attacks</a> such as <a href="https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks">credential stuffing</a>.</p><p>Companies that sign on to the pledge will be asked to take efforts to reduce the use of default passwords in their products, suggesting they switch to random, instance <a href="https://www.itpro.com/data-breaches/32774/massive-collection-1-leak-exposes-773m-unique-records-onlinehttps://www.itpro.com/security/32680/the-best-passwords-are-the-ones-you-cant-remember">unique passwords</a> or requiring the user create a <a href="https://www.itpro.com/security/22197/how-secure-is-your-password">strong password</a> as soon as they begin the product’s installation process.</p><p>Within one year of signing the pledge, companies will also be expected to demonstrate the actions they have taken to significantly reduce the prevalence of one or more <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">vulnerability</a> classes in their products.</p><p>By eliminating vulnerabilities by class, CISA argues companies can prevent these flaws at scale which could significantly improve the efficiency of their efforts to keep their products secure.</p><p>The pledge wants software manufacturers to take <a href="https://www.itpro.com/software/software-supply-chain-attacks-are-rife-this-is-what-developers-need-to-watch-out-for">ownership of the security outcomes of their customers,</a> even after the product has been shipped. </p><p>As such, it targets increasing the installation of <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-managementhttps://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk">security patches</a> by asking companies to make it easier to install the updates. This could be achieved through introducing <a href="https://www.itpro.com/microsoft-windows/33219/windows-10-can-automatically-uninstall-fault-causing-updates">automatic update mechanisms</a> or by providing patch support, for example.</p><p>Timely <a href="https://www.itpro.com/security/new-eu-vulnerability-disclosure-rules-deemed-an-unnecessary-risk">vulnerability disclosure </a>is another important aspect to ensuring companies stay secure. By next year, signees are expected to publish their own <a href="https://www.itpro.com/security/vulnerability/356998/facebook-unveils-90-day-bug-disclosure-policy">vulnerability disclosure policy</a> (VDP) that provides a clear channel to report flaws.</p><p>Moreover, the pledge hopes to <a href="https://www.itpro.com/strategy/28655/google-boosts-transparency-in-adsense-tools">boost transparency</a> further asking its signatories to commit to demonstrating material improvements in the accuracy of their vulnerability reporting by providing an accurate Common Weakness Enumeration (CWE) and Common Platform Enumeration (CPE) fields in every <a href="https://www.itpro.com/security/exploits/360411/top-30-most-exploited-vulnerabilities">CVE</a> record for their products.</p><p>Finally, CISA wants companies to get better at recognizing and reporting <a href="https://www.itpro.com/security/cyber-attack-takes-frontier-communications-systems-offline-affecting-millions-of-broadband-customers">unauthorized access</a> to their internal systems. It states assenting companies should be able demonstrate a measurable uptick in their ability to gather evidence of cyber security instructions affecting their products.</p><h2 id="x201c-the-only-way-we-can-make-ransomware-and-cyber-attacks-a-shocking-anomaly-x201d">“The only way we can make ransomware and cyber attacks a shocking anomaly”</h2><p>The <a href="https://www.itpro.com/tag/eu">EU</a> received formal approval on its own approach to boosting security postures across the board, the <a href="https://www.itpro.com/business/policy-and-legislation/what-is-the-eus-cyber-resilience-act-cra">Cyber Resilience Act</a>, in March 2024, which is a legal framework that sets out cyber security requirements for both <a href="https://www.itpro.com/hardware">hardware</a> and <a href="https://www.itpro.com/software">software</a> products sold in the region.</p><p>The framework targets similar problems currently rife among digital products such as improving the security of the <a href="https://www.itpro.com/security/cyber-security/369082/c-suite-executives-say-software-supply-chain-hacks-have-become-chief-concern">software supply chain</a>, and better vulnerability reporting from manufacturers, but importantly this approach is legally binding and those who fall foul could be prosecuted.</p><p>The UK has also introduced legislation looking to eradicate common security issues with its <a href="https://www.itpro.com/security/everything-you-need-to-know-about-the-product-security-and-telecommunications-infrastructure-act">Product Security and Telecommunications Infrastructure</a> (PSTI) act which, like the Secure by Design pledge, wants to get rid of default passwords - but in this case it&apos;s for smart devices, unlike software products.</p><p>CISA’s Secure by Design pledge does not incorporate hardware, but added that companies that wish to demonstrate progress in those areas are welcome to do so. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4CnRiSfJ3o8xZAQJZorWsB" name="Customer operations for dummies.jpg" caption="" alt="Dark background and white text that says Customer operations for dummies" src="https://cdn.mos.cms.futurecdn.net/4CnRiSfJ3o8xZAQJZorWsB.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/digital-transformation/customer-operations-for-dummies"><em>Create a seamless customer service journey</em></a></p></div></div><p>More importantly, the goals outlined in the pledge are not legally binding, and it is not clear if the signatories can pick and choose which targets they want to try to meet, as the agency will have little recourse if they were to take this approach.</p><p>Speaking to this concern, Easterly argued that the strength of the approach centers around transparency, where customers will be able to see which <a href="https://www.itpro.com/security/24717/people-arent-taking-iot-security-seriously-claim-experts">vendors are taking security seriously</a>.</p><p>“It is a voluntary pledge but the great thing is we have a platform to be able to advance radical transparency and so consumers that have to make decisions about what technology they buy will see whether these technology manufacturers actually took those steps”, she explained.</p><p>“I think it is the only way we can make <a href="https://www.itpro.com/security/ransomware/357353/uk-ransomware-attacks-increased-by-80-in-past-quarterhttps://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> and cyber attacks a shocking anomaly, and that is to ensure that the technology is more secure.”</p><p>The fact the pledge already has 68 high-profile software manufacturers signed on suggests software developers are more than happy to signal to regulators they care about improving the <a href="https://www.itpro.com/security/privacy/361083/amazon-microsoft-google-back-trusted-cloud-principles">baseline security</a> of their products, and as such could prove to be a useful way of getting industry buy-in without having to resort to the threat of legislation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos and Tenable team up to launch new managed risk service  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/sophos-and-tenable-team-up-to-launch-new-managed-risk-service</link>
                                                                            <description>
                            <![CDATA[ The new fully managed service aims to help organizations manage and protect external attack surfaces ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RyVxWGJQ8zeE5Jq72tBQ77</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Apr 2024 08:20:53 +0000</pubDate>                                                                                                                                <updated>Fri, 05 Apr 2024 17:22:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:description>                                                            <media:text><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos branding and logo pictured on a vendor stand at a technology conference in Hannover, Germany.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/khRR7T5SMN6i6G4nyQqqbM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cyber security</a> provider Sophos has teamed up with exposure management specialist Tenable to deliver <em>Managed Risk</em>, a new vulnerability and attack surface management service for organizations around the world. </p><p>By leveraging Tenable’s One Exposure Management Platform, the new service aims to help customers thwart cyber attacks through capabilities that include attack visibility, continuous risk monitoring, vulnerability prioritization, investigation, and proactive notification.</p><p>A dedicated team will work with Tenable’s exposure management technology as well as collaborate with security operations experts from Sophos Managed detection and Response (MDR) business, sharing information and data around zero-days, known vulnerabilities, and exposure risks to assess potentially exploited environments.</p><p>Sophos Managed Risk is available with a term license via the company’s network of channel partners and <a href="https://www.itpro.com/security/kaseya-cyber-security-remains-a-top-revenue-driver-for-msps">MSPs</a>, with a Sophos MSP Flex version slated for availability later in the year.</p><p>In an announcement, Rob Harrison, Sophos’ senior vice president for endpoint and security operations product management, said the offering will help customers address “urgent, pervasive <a href="https://www.itpro.com/security">security</a> challenges” that they consistently struggle to control.</p><p>“We can now help organizations identify and prioritize the remediation of vulnerabilities in external assets, devices and software that are often overlooked,” he explained. </p><p>“It is critical that organizations manage these exposure risks, because unattended, they only lead to more costly and time-consuming issues and are often the root causes of significant breaches.”</p><p>Sophos said its latest research highlighted three key tasks that organizations must prioritize in order to minimize their risk: closing exposed remote desktop protocol (RDP) access, enabling <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authorization (MFA)</a>, and patching of vulnerable servers.</p><p>“We know from Sophos’ worldwide survey data that 32% of ransomware attacks start with an unpatched vulnerability and that these attacks are the most expensive to remediate,” Harrison added.</p><p>“The ideal security layers to prevent these issues include an active approach to improving security postures by minimizing the chances of a breach with Sophos Managed Risk, Sophos Endpoint, and 24x7 Sophos MDR coverage."</p><p>Available as an extended service with Sophos MDR, the new Managed Risk offering will work to assess an organization’s external attack surface, prioritize the riskiest exposures, and deliver tailored remediation guidance to eliminate blind spots.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WR9wYpoxHmf7jCmyd3yjRF" name="How Security and User Experience Can Power Your Hybrid Workforce’s Productivity.jpg" caption="" alt="How Security and User Experience Can Power Your Hybrid Workforce’s Productivity whitepaper" src="https://cdn.mos.cms.futurecdn.net/WR9wYpoxHmf7jCmyd3yjRF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/how-security-and-user-experience-can-power-your-hybrid-workforces-productivity"><em>Enable work-from-anywhere with Zscaler&apos;s Zero Trust Exchange</em></a></p></div></div><p>Sophos said customers will benefit from external attack surface management (EASM) for advanced identification and classification of internet-facing assets such as email servers, web apps, and public-facing API endpoints. Users will also be able to leverage continuous monitoring and proactive notification of high-risk exposures, as well as vulnerability prioritization and identification of new threats.</p><p>Additionally, organizations will benefit from regular interaction and scheduled meetings with Sophos experts to review discoveries, insights, and recommendations, as well as initiate enquiries with the Sophos Managed Risk team via the firm’s Central platform.</p><p>“While the latest zero day may dominate the headlines, the biggest threat to organizations, by a large margin, is still known vulnerabilities – or vulnerabilities for which patches are readily available,” commented Greg Goetz, Tenable’s vice president of global strategic partners and MSSP. </p><p>“A winning approach includes risk-based prioritization with context-driven <a href="https://www.itpro.com/business-intelligence/28220/what-is-data-analytics">analytics</a> to proactively address exposures before they become a problem.</p><p>“Sophos Managed Risk, powered by the Tenable One Exposure Management Platform, delivers outsourced preventive risk management, enabling organizations to anticipate attacks and reduce cyber risk.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos CEO steps down in sudden move ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/sophos-ceo-steps-down-in-sudden-move</link>
                                                                            <description>
                            <![CDATA[ Joe Levy will take the helm at Sophos as the company ramps up its focus on managed services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zVpBrbDAeRprsUCzAcSpJo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JieCRQiLGU9revS3bBSprn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Feb 2024 13:10:01 +0000</pubDate>                                                                                                                                <updated>Fri, 16 Feb 2024 14:34:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JieCRQiLGU9revS3bBSprn-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos logo and branding pictured at a tech conference.]]></media:description>                                                            <media:text><![CDATA[Sophos logo and branding pictured at a tech conference.]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos logo and branding pictured at a tech conference.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JieCRQiLGU9revS3bBSprn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sophos has confirmed that chief executive Kris Hagerman will step down as the company looks to consolidate its position as a cyber security as a service provider. </p><p>Joe Levy will assume the role following Hagerman’s departure after being appointed president last year.</p><p>Hagerman, who will serve as an advisor to the company until April 1, has been CEO of Sophos since 2012. He&apos;s led the company through significant growth, with revenue reaching more than $1 billion, and its worldwide customer base growing from around 150,000 customers to more than 580,000.</p><p>He also led the company&apos;s successful IPO on the London Stock Exchange in 2015, and oversaw its sale to Thoma Bravo in 2020.</p><p>"I am proud of our team’s accomplishments over the last 12 years as we have transformed Sophos into a true next-generation cyber security leader and an industry innovator in delivering <a href="https://www.itpro.com/business/acquisition/sonicwall-bolsters-cyber-services-portfolio-with-solutions-granted-acquisition">cyber security as a service</a>," Hagerman said.</p><p>"I am excited to pass the baton to Joe Levy as president and acting CEO to lead Sophos into the future. Joe and I have worked closely together for over nine years, and he has been pivotal in leading our product, services and technology initiatives that have underpinned Sophos’ growth. He has my full and enthusiastic support."</p><h2 id="sophos-eyes-managed-service-gains">Sophos eyes managed service gains</h2><p>Levy has been with the company for nine years, having joined from Blue Coat Systems. Since the sale to Thoma Bravo, Levy is credited with turning the company from a product-only vendor into a global <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> as a service company, with Sophos now having more than 20,000 managed services customers worldwide.</p><p>He also launched the company&apos;s operational threat intelligence unit, <a href="https://www.itpro.com/security/cyber-security/368599/sophos-announces-new-x-ops-unit-to-streamline-defence-against-cyber">Sophos X-Ops</a>, a 500-person team offering real-time and historical attack data. </p><p>"I am extremely excited for the opportunity to further grow Sophos as a global cyber security leader. Many organizations worldwide are still neglected relative to the industry’s focus on securing large enterprises, leaving them exposed to opportunistic and targeted attacks," Levy said.</p><p>"Our immediate goal is to work with our partners to further expand our collective ability to secure organizations that are unprotected or need stronger cyber defenses."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nkJY2faZ4P9fjuCkSx3EiA" name="nkJY2faZ4P9fjuCkSx3EiA.jpg" caption="" alt="Whitepaper on unified endpoint management and security,with image of female working remotely at a laptop on her sofa" src="https://cdn.mos.cms.futurecdn.net/nkJY2faZ4P9fjuCkSx3EiA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369803/unified-endpoint-management-and-security-in-a-work-from-anywhere"><em>Discover why endpoint security needs to be part of your zero trust strategy</em></a></p></div></div><p>Last January, Sophos announced that it was laying off 10% of its staff - around 450 people worldwide - as part of its restructuring.</p><p>The aim, it said, was to "achieve the optimal balance of growth and profitability" and to allocate more resources to its cyber security as a service operations.</p><p>"We’re pleased to appoint Joe as the President and acting CEO of Sophos. Joe’s hands-on career as a cybersecurity practitioner, innovator and successful business leader moves Sophos into a whole new level of competitiveness," said Chip Virnig, partner at Thoma Bravo and a Sophos board member.</p><p>"With his industry pedigree and accomplishments, Joe is well-positioned to lead Sophos in the direction the market is demanding."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware groups are using media coverage to coerce victims into paying ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/ransomware-groups-are-using-media-coverage-to-coerce-victims-into-paying</link>
                                                                            <description>
                            <![CDATA[ Threat actors are starting to see the benefits of a more sophisticated media strategy for extracting ransoms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YZcM98czAnCsxkhULWwRZh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7KqVdwYpjnkdDbb359mqMg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Dec 2023 14:46:35 +0000</pubDate>                                                                                                                                <updated>Wed, 13 Dec 2023 15:45:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7KqVdwYpjnkdDbb359mqMg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ransomware stock image featuring binary code in a room colored in red]]></media:description>                                                            <media:text><![CDATA[ransomware stock image featuring binary code in a room colored in red]]></media:text>
                                <media:title type="plain"><![CDATA[ransomware stock image featuring binary code in a room colored in red]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7KqVdwYpjnkdDbb359mqMg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28084/what-is-ransomware">Ransomware</a> gangs are leveraging media coverage of attacks to pile pressure on victims to meet their demands, according to new research.</p><p>Analysis from <a href="https://www.itpro.com/security/cyber-security/368599/sophos-announces-new-x-ops-unit-to-streamline-defence-against-cyber">Sophos X-Ops</a> has highlighted the increasingly close relationship between ransomware groups and the media, suggesting that while hackers are traditionally secretive, some now see the potential in using their publicity to enhance <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">extortion techniques</a>. </p><p>Victims may be concerned about the reputational damage they might suffer if the data or sensitive information was seized, or even the fines they could incur from bodies such as the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office</a> (ICO) for failing to prevent a data breach.</p><p>Sophos X-Ops said some hacking groups are explicit about promoting attacks via media channels to serve as a warning to victims. </p><p>The study specifically pointed to the Dunghill ransomware gang, which threatened to “send the data to all interested supervisory organizations and the media” if their demands were not met.</p><p>In addition to using media coverage to ratchet up pressure on victims, threat actors are also making use of press coverage to generate positive publicity and boost recruitment, according to Sophos X-Ops’ research.</p><p>Ransomware gangs are aware of the coverage of their activities and have been observed to publicly correct outlets who are inaccurate in their reporting, the study noted. </p><p>Sophos X-Ops said the trend points toward a concerted effort among some ransomware groups to develop a media strategy in an attempt to professionalize and commodify their image. </p><p>Some have been found to publish press-releases and refine their branding to boost credibility with victims and journalists alike. Others, such as Vice Society, have even promoted content listing them as a &apos;top ransomware group&apos;. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:992px;"><p class="vanilla-image-block" style="padding-top:50.10%;"><img id="fZjh6Fz3bXsWAVWso54Dgf" name="Sophos X-Ops .jpg" alt="Ransomware group Vice Society promotional page for content on the group" src="https://cdn.mos.cms.futurecdn.net/fZjh6Fz3bXsWAVWso54Dgf.jpg" mos="" align="middle" fullscreen="" width="992" height="497" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Sophos X-Ops)</span></figcaption></figure><p>Although increased publicity does also mean ransomware groups are exposed to a higher risk of law enforcement scrutiny, it also adds weight to their threats of leaking sensitive information.</p><h2 id="ransomware-groups-target-better-media-relations">Ransomware groups target better media relations</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9jRiDv3ZrwPArvTWH6TC3Z" name="2023 ThreatLabz state of ransomware report.jpg" caption="" alt="2023 ThreatLabz state of ransomware report" src="https://cdn.mos.cms.futurecdn.net/9jRiDv3ZrwPArvTWH6TC3Z.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how you can safeguard your organization against ransomware attacks with a zero trust strategy<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/2023-threatlabz-state-of-ransomware-report">DOWNLOAD NOW</a></p></div></div><p>Sophos X-Ops’ investigation shows threat actors’ attitudes towards the media are shifting with the majority of groups covered in its analysis displaying a marked turn towards collaborating with the media on their public image.</p><p>Some ransomware groups granted interviews to journalists in which they shed a positive light on their activities in what may be an attempt to drive recruitment, according to Sophos X-Ops.</p><p>The RansomHouse group, for example, features a message on its leak site that directly addresses journalists, offering to share information through a PR channel on Telegram before it is officially published.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:845px;"><p class="vanilla-image-block" style="padding-top:54.08%;"><img id="YSiCVQAm4vVYrBSCgK9j4c" name="Sophos X-Ops1.jpg" alt="Ransomware group Rhysida contact form for journalists" src="https://cdn.mos.cms.futurecdn.net/YSiCVQAm4vVYrBSCgK9j4c.jpg" mos="" align="middle" fullscreen="" width="845" height="457" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Sophos X-Ops)</span></figcaption></figure><p>Prominent ransomware group Rhysida’s contact form lists journalists before recoveries on its contact form, suggesting its interest in shaping its public image comes before extracting ransoms from its victims.</p><h2 id="some-ransomware-gangs-are-frustrated-by-media-coverage">Some ransomware gangs are frustrated by media coverage</h2><p>These groups are not completely embracing the media’s coverage of their attacks, however, with some groups becoming increasingly belligerent towards outlets and journalists deemed to have misreported on incidents involving them.</p><p><a href="https://www.itpro.com/security/ransomware/everything-we-know-so-far-about-the-rumored-alphv-takedown">ALPHV/BlackCat</a>, for example, released a 1,300-word blog post on its leak site criticizing publications for failing to check sources and publishing false information.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:602px;"><p class="vanilla-image-block" style="padding-top:46.68%;"><img id="tJqpdceYcVEQQHEiEDvpkA" name="Sophos X-Ops ALPHV.jpg" alt="Ransomware group ALPHV/BlackCat post criticizing media coverage" src="https://cdn.mos.cms.futurecdn.net/tJqpdceYcVEQQHEiEDvpkA.jpg" mos="" align="middle" fullscreen="" width="602" height="281" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Sophos X-Ops)</span></figcaption></figure><p><a href="https://www.itpro.com/security/cyber-attacks/moveit-cyber-attack-cl0p-sparks-speculation-that-its-lost-control-of-hack">Cl0p</a> were also found to be hostile towards media organizations, appearing to resent outlets challenging the narrative constructed through their own disclosures.</p><p>The BBC was called out by Cl0p for misrepresenting the information supplied by the group, who stated “the only story is we want money for our work. If we have your business files you have to pay”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos XGS 126w review: Easy deployment and deep security features ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/sophos-xgs-126w-review-easy-deployment-and-deep-security-features</link>
                                                                            <description>
                            <![CDATA[ Only Wi-Fi 5 services, but it delivers Xstream power, lots of security measures, and great remote management ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZPRp9mJD9qiHFEJrPA4joN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SUniuexjtVXufN3ktMKWZJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Sep 2023 11:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Nov 2023 10:01:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SUniuexjtVXufN3ktMKWZJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Sophos XGS 126W on the ITpro background]]></media:description>                                                            <media:text><![CDATA[The Sophos XGS 126W on the ITpro background]]></media:text>
                                <media:title type="plain"><![CDATA[The Sophos XGS 126W on the ITpro background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SUniuexjtVXufN3ktMKWZJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SMBs and branch offices looking for a powerful security appliance will find Sophos&apos; XGS 126w a worthy candidate. Inside this compact desktop model lurk two processors, allowing Sophos to claim an impressively high firewall IMIX (internet mix) throughput of 10.3Gbits/sec and 0.9Gbits/sec with all threat protection services enabled.</p><p><br></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5fGV7vP6WLwkJBAgVCiqD8" name="NEjje87dAuG8WVNiQvoKSF-970-80.jpeg" caption="" alt="An digital code with zeros and locks" src="https://cdn.mos.cms.futurecdn.net/5fGV7vP6WLwkJBAgVCiqD8.jpeg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security-appliances/26453/choosing-the-right-utm-appliance">What to look for in a unified threat management (UTM) device in 2023</a></p></div></div><p>This superpower is achieved by teaming up a 2.6GHz dual-core AMD Ryzen Embedded R1600 CPU with Sophos&apos; Xstream flow processor. The latter provides a dedicated FastPath hardware layer that handles TLS 1.3 encrypted traffic plus deep packet inspection (DPI) and application acceleration, with the latest SFOS v19 firmware adding IPsec VPNs to FastPath.</p><p><br></p><p>Network ports are plentiful, with the appliance offering 12 copper gigabit ports with 30W PoE+ on the last two and two gigabit SFP fiber ports for longer connection distances. The triplet of external aerials indicates that wireless is on the menu, although this is the older dual-band 2.4/5GHz 11ac variety.</p><p><br></p><p>Sophos&apos; new licensing scheme presents a pick-and-mix buffet of features so you can choose only those security services you need. We&apos;ve gone the whole hog with a three-year Xstream subscription, which activates the base firewall, all Xstream features, the network, web and zero-day protection modules, central orchestration, and enhanced 24/7 support. Email and web server protection are optional, with each costing £365 for three-year licenses.</p><p><br></p><h2 id="sophos-xgs-126w-review-setup">Sophos XGS 126w review: Setup</h2><p>Installation is a pleasant experience, as the web console&apos;s deployment wizard automatically upgrades the firmware to the latest version. All you need to do is set a strong admin password. The wizard configures the LAN port zones as well as internet access and enables essential protection with a default set of firewall policy rules that include anti-malware and web content filtering.</p><p><br></p><p>The appliance&apos;s local Control Center web console keeps you firmly in touch with the action, presenting a detailed overview of network activity, security issues, web traffic, and detected network attacks, plus blocked and allowed applications and web categories. The "User & device insights" section keeps a tally of the advanced security measures, and clicking on the zero-day protection portion opens a report on downloaded files sent to the Sophos cloud sandbox for further analysis to see if they can be safely released.</p><p><br></p><p>Policies make light work of security configuration: they bring together firewall rules, service filters, time schedules, web and application filtering, intrusion detection, and email anti-spam. The web filtering service offers 130 URL categories to block or allow, and SafeSearch and YouTube restrictions can also be enabled.</p><p><br></p><p>Application filters are equally extensive, with Sophos currently providing 3,532 signatures, 73 specifically for all Facebook activities. For more control over users and groups, you can download the <a href="https://www.itpro.com/software/364316/windows-vs-linux-vs-mac-the-channel-comparison">Windows, macOS, Linux</a>, iOS, and Android authentication clients from the web console and apply extra policies with daily upload and download restrictions and limits on internet usage.</p><p><br></p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LbVXVECgLJ3Ripr3r6rYVA" name="How the way we work will change the Office of the Future.jpg" caption="" alt="How the way we work will change the Office of the Future" src="https://cdn.mos.cms.futurecdn.net/LbVXVECgLJ3Ripr3r6rYVA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text">How the way we work will change the office of the future</p><p class="fancy-box__body-text"><em>Design a workspace that creates meaningful work experiences. <br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/business/how-the-way-we-work-will-change-the-office-of-the-future">DOWNLOAD FOR FREE</a></p></div></div><p>The internal wireless AP supports multiple <a href="https://www.itpro.com/broadband/30390/what-is-ssid">SSIDs</a> with client isolation, and their traffic can be placed in separate network zones with custom security policies. Guest users can be presented with hotspots and acceptable use policies, but this <a href="https://www.itpro.com/network-internet/wifi-hotspots/367703/what-is-wi-fi-6">Wi-Fi 5</a> AP doesn&apos;t support the more secure <a href="https://www.itpro.com/security/30848/why-wpa3-may-be-no-safer-from-attack-than-wpa2">WPA3 encryption</a>.</p><p><br></p><p>We have a Sophos Central account and registering the firewall with it provides full remote management services as the portal presents the same Control Center console.</p><p><br></p><p>There&apos;s more to be gained with the appliance&apos;s Synchronized Security feature, which uses a heartbeat to monitor systems running the Sophos Intercept X endpoint agent and isolate them if malware is detected.</p><p><br></p><p>The XGS 126w impresses with its easy deployment and deep set of security features. The Wi-Fi 5 access point is dated, but the appliance works seamlessly with the Sophos Central cloud service and its smart Xstream architecture delivers an impressive performance.</p><p><br></p><h2 id="sophos-xgs-126w-specifications">Sophos XGS 126w specifications</h2><div ><table><tbody><tr><td class="firstcol " ><strong>Chassis</strong></td><td  >Desktop chassis</td></tr><tr><td class="firstcol " ><strong>CPU</strong></td><td  >2.6GHz dual-core AMD Ryzen Embedded R1600 CPU</td></tr><tr><td class="firstcol " ><strong>Ports</strong></td><td  >12 x copper gigabit ports (PoE+ on ports 11/12) 2 x SFP gigabit ports</td></tr><tr><td class="firstcol " ><strong>RAM</strong></td><td  >4GB DDR4 RAM</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shrinking cyber attack “dwell times” highlight growing war of attrition with threat actors ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/shrinking-cyber-attack-dwell-times-highlight-growing-war-of-attrition-with-threat-actors</link>
                                                                            <description>
                            <![CDATA[ While teams are becoming more proficient at detecting threats, attackers are augmenting their strategies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cbV6LmmxazPtYpVU8ZK83E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Aug 2023 11:01:16 +0000</pubDate>                                                                                                                                <updated>Wed, 23 Aug 2023 15:15:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:description>                                                            <media:text><![CDATA[Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:text>
                                <media:title type="plain"><![CDATA[Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The arms race between security teams and threat actors is escalating as “dwell times” shorten, according to new research from Sophos. </p><p>Dwell times, which mark the time from when an attack starts to when it is detected, dropped from an average of 10 days to just eight for all attacks, the analysis shows. </p><p>This dip underlines the changing nature of attacks, Sophos said, with organizations becoming increasingly efficient at detecting and responding to incidents in rapid time. </p><p>“As adoption of technologies like XDR (extended detection and response) and services such as MDR (managed detection and response) grows, so does our ability to detect attacks sooner,” said John Shier, field CTO at Sophos. </p><p>“Lowering detection times leads to a faster response, which translates to a shorter operating window for attackers.”</p><p>While this may appear to be positive news for organizations, the reality is that rapid reaction times mean threat actors are accelerating attacks and adopting new techniques. </p><p>Shier suggested that many organizations have become “victims of their own success” with regard to security practices, prompting a more aggressive approach from attackers and placing significant strain on security practitioners. </p><p>“Criminals have been honing their playbooks, especially the experienced and <a href="https://www.itpro.com/security/ransomware/royal-hive-black-basta-ransomware-gangs-collaborating-on-cyber-attacks"><u>well-resourced ransomware affiliates</u></a>, who continue to speed up their noisy attacks in the face of improved defenses.”</p><p>For <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> attacks, the most prevalent form of attack analyzed, dwell time dropped significantly from 10 days to five, Sophos found. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pyFsy4LXwQC5LHt9D4U95N" name="The board's evolving perceptions of cyber risk_thumbnail.jpg" caption="" alt="Whitepaper cover with black and white image of man's face wearing glasses and with beard on the right side" src="https://cdn.mos.cms.futurecdn.net/pyFsy4LXwQC5LHt9D4U95N.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><em>78 global CISOs share their recommendations on how to communicate cyber risk as business risk to the C-suite peers and board.</em> </p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-boards-evolving-perceptions-of-cyber-risk">DOWNLOAD FOR FREE</a> </p></div></div><p>Similarly, in more than three quarters (81%) of ransomware attacks, Sophos said the final payload was launched outside of conventional working hours. Of those that were deployed during traditional operating hours, only five occurred on a weekday. </p><p>“The number of attacks detected increased as the week progressed, most notably when examining ransomware attacks. Nearly half (43%) of ransomware attacks were detected on either Friday or Saturday,” the firm said. </p><p>With security teams acting swiftly to respond to threats in record times, malicious actors have become increasingly conscious of operating hours and are purposefully targeting firms at the most inconvenient times possible. </p><p>Long-term, this means that organizations aren’t necessarily more secure, Shier said. </p><p>“This is evidenced by the leveling off of non-ransomware dwell times. Attackers are still getting into our networks, and when time isn&apos;t pressing, they tend to linger. But all the tools in the world won&apos;t save you if you&apos;re not watching.”</p><h2 id="growing-active-directory-risks">Growing Active Directory risks</h2><p>Among the most concerning finds from the Sophos report was a decrease in the time it takes for attackers to reach Active Directories (AD); on average, it took them just 16 hours.</p><p><a href="https://www.itpro.com/network-internet/active-directory/358456/a-new-age-of-asset-management"><u>Active directories are among the most critical assets </u></a>for any organization, being used to manage identity and access to company resources. Gaining access to a directory would enable attackers to “easily escalate” system privileges and conduct malicious activity, Sophos said. </p><p>The decreased dwell time in this regard should be a serious cause for concern for security teams, Shier warned. </p><p>"Attacking an organization&apos;s Active Directory infrastructure makes sense from an offensive view. AD is usually the most powerful and privileged system in the network, providing broad access to the systems, applications, resources, and data that attackers can exploit in their attacks,” he said.</p><p>“Getting to and gaining control of the Active Directory server in the attack chain provides adversaries several advantages. They can linger undetected to determine their next move, and, once they’re ready to go, they can blast through a victim&apos;s network unimpeded.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber security in the retail sector ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/369196/cyber-security-in-the-retail-sector</link>
                                                                            <description>
                            <![CDATA[ Retailers need to ensure their business operations and internal data aren't breached ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">624BQUecJEqpduY6AzKeGV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/W6BHvfUbvwbrTEvAMrTPmh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Sep 2022 13:51:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/W6BHvfUbvwbrTEvAMrTPmh-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title and logo]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title and logo]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title and logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/W6BHvfUbvwbrTEvAMrTPmh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Technology touches every part of retail, and in addition to customer-facing points of weakness online and in the real world, retailers also need to ensure their own business operations and internal data are not breached.</p><p>The threat posed by ransomware attacks is extremely damaging for retailers, both in terms of immediate financial loss and also with regards to customer data. Yet many retailers are running outdated and fragmented IT infrastructures supported by overstretched IT teams.</p><p>Learn how retailers can keep things up and running, ensuring safety for staff and customers, by having a Sophos Managed Detection & Response team in their corner at all times.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="U9egtyKJdTbfjyhrBbm5Dj" name="" alt="Sophos logo" src="https://cdn.mos.cms.futurecdn.net/U9egtyKJdTbfjyhrBbm5Dj.png" mos="https://cdn.mos.cms.futurecdn.net/U9egtyKJdTbfjyhrBbm5Dj.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="high" data-lazy-src="https://dennis.cvtr.io/forms/49805/sophos-july-2022?locale=1&p=false&wp=10317"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber security in manufacturing ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/369195/cyber-security-in-manufacturing</link>
                                                                            <description>
                            <![CDATA[ The increasing cost of cyber crime means manufacturers need to adapt ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5PgsTqNGozmjr3T4RLgqs5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pFJcpVRGtzBivW3SJxEQa6-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Sep 2022 11:19:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/pFJcpVRGtzBivW3SJxEQa6-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title and logo]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title and logo]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title and logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pFJcpVRGtzBivW3SJxEQa6-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>According to Sophos data, the average ransomware pay-out made by manufacturers in 2021 was £1.9 million ($2 million), which was higher than any other sector. This willingness to pay out high ransom demands in combination with a reliance on technology and automation in the sector makes it very appealing to cybercriminals.</p><p>There are countless examples of how manufacturers around the globe are finding themselves under attack from cybercriminals, which emphasises the need for them to prioritise strengthening their defences.</p><p>With a continually changing threat landscape and limited budgets, manufacturers are turning to Managed Detection & Response services from Sophos for 24/7 protection. Download this whitepaper to learn more.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="U9egtyKJdTbfjyhrBbm5Dj" name="" alt="Sophos logo" src="https://cdn.mos.cms.futurecdn.net/U9egtyKJdTbfjyhrBbm5Dj.png" mos="https://cdn.mos.cms.futurecdn.net/U9egtyKJdTbfjyhrBbm5Dj.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49805/sophos-july-2022?locale=1&p=false&wp=10312"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos XGS 116 review: A small and mighty appliance  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/369069/sophos-xgs-116-review-a-small-and-mighty-appliance</link>
                                                                            <description>
                            <![CDATA[ This clever and compact security gateway brings outstanding security and remote management features at a tempting price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xuJd28nDcP6VyU6mUE9svG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tZYMk5tvV6bVaanXUYKxof-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Sep 2022 10:34:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tZYMk5tvV6bVaanXUYKxof-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of the Sophos XGS 116 ]]></media:description>                                                            <media:text><![CDATA[A photograph of the Sophos XGS 116 ]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of the Sophos XGS 116 ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tZYMk5tvV6bVaanXUYKxof-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Don’t be deceived by its modest dimensions: the Sophos XGS 116 is a security powerhouse. Aimed at busy SMBs and branch offices, this desktop appliance boasts a raw firewall throughput of 7,700Mbits/sec, and even with full threat protection enabled it keeps up a creditable 685Mbits/sec.</p><p>That’s largely thanks to Sophos’ dual-processor architecture. The Xstream Flow Processor provides a hardware acceleration layer that’s optimised for specific network tasks, ensuring the main AMD CPU doesn’t get bogged down.</p><p>Connection options abound. The rear panel presents eight Gigabit Ethernet ports – with PoE+ on the last one – plus one fibre port. While there’s no built-in modem, an expansion bay lets you add VDSL2 or 3G/4G modules, although Sophos’ Flexi network cards only work with larger rackmount models <a href="https://www.itpro.com/security/361926/sophos-xgs-3300-review-xstream-firewall-performance" data-original-url="https://www.itpro.com/security/361926/sophos-xgs-3300-review-xstream-firewall-performance">like the XGS 3300</a>.</p><p>The flexible licensing model allows you to choose which features you want, and there are plenty on offer. We’ve shown the price of a three-year Xstream subscription above, which enables the base firewall licence along with Xstream TLS 1.3 SSL inspection, deep packet inspection, network, web and <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-day protection</a> modules, central orchestration and enhanced 24/7 support. The email and web server protection modules are optional extras, each costing around £142 for a three-year licence.</p><p>Deployment is easy thanks to the appliance’s web console wizard, which guides you through the steps required to get secure internet access up and running. We chose routed mode as we wanted the appliance to provide all security functions; protection starts immediately, with the wizard enabling a standard set of firewall security policies including web filtering and <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus">anti-malware</a>.</p><p>Henceforth, the Control Center dashboard provides everything you need to know about network activity and security issues. Graphs provide a clear visual overview of web traffic and network attacks, plus blocked and allowed applications and web categories. The User and Device Insights section keeps track of activity in modules such as SSL inspection, advanced threat protection and zero-day protection, and clicking on an icon takes you directly to a more detailed report.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XfftNW53zuzRxoF2mJAmNF" name="" alt="A screenshot of the Sophos XGS 116's control software" src="https://cdn.mos.cms.futurecdn.net/XfftNW53zuzRxoF2mJAmNF.jpg" mos="https://cdn.mos.cms.futurecdn.net/XfftNW53zuzRxoF2mJAmNF.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Remote management comes into play too, via <a href="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it" data-original-url="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it">the Sophos Central portal</a>. After we’d registered the appliance with our account, we were able to bring up live reports in a web browser, and to access the appliance’s Control Center console remotely for full configuration. </p><p><a href="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home" data-original-url="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home">Businesses with home workers</a> will love the Synchronised Security feature, which extends firewall protection to remote systems running <a href="https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection" data-original-url="https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection">the Sophos Intercept X endpoint agent</a>. A heartbeat service monitors and automatically isolates any that are compromised, while the application control feature detects unknown applications running on endpoints and pushes out firewall policies to secure them.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible" data-original-url="/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible">Sophos XG 230 Rev.2 review: Powerful and flexible</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one" data-original-url="/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one">Ubiquiti Networks UniFi Dream Machine Pro review: All the security you need in one handy box</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a" data-original-url="/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a">WatchGuard Firebox M290 review: Stiff security at a great price</a></p></div></div><p>All of this is controlled via policies that bring together firewall rules, service filters, schedules and specific settings for intrusion detection, email, applications and web filtering. That last feature is particularly impressive: the appliance comes with predefined settings to get you started, but you can choose to block or allow sites in over 90 categories. Application controls are equally extensive, with more than 3,500 predefined filters supplied, including 12 for Twitter and 73 for Facebook, so you can finely control social networking in the workplace.</p><p>A new filtering feature in the latest firmware also makes it easy to find specific rules within complex policies, and lets you reset traffic counters to zero with a click – a big improvement on the previous release, which required a reboot.</p><p>All told, the XGS 116 delivers strong gateway security measures at a great price. It has the power to cope with high demand, and the integration with Sophos’ endpoint security software will appeal to businesses that want to extend their protection to home workers.</p><h2 id="sophos-xgs-116-specifications">Sophos XGS 116 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >1U desktop chassis </td></tr><tr><td  ><strong>CPU</strong></td><td  >2.1GHz quad-core AMD RX-421ND CPU</td></tr><tr><td  ><strong>Memory</strong></td><td  >4GB DDR4</td></tr><tr><td  ><strong>Storage included</strong></td><td  >64GB SATA SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >8 x GbE ports (PoE+ on port 8), SFP GbE</td></tr><tr><td  ><strong>Other ports</strong></td><td  >RJ45/micro-USB COM ports, USB 3, USB 2, expansion slot</td></tr><tr><td  ><strong>Management</strong></td><td  >Sophos Control Center</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >320 x 213 x 44mm</td></tr><tr><td  ><strong>Weight</strong></td><td  >2.2kg</td></tr><tr><td  ><strong>Warranty</strong></td><td  >1yr standard hardware warranty</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos: Retail organisations pay significantly less in ransomware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/369006/sophos-retail-organisations-pay-significantly-less-in-ransomware-attacks</link>
                                                                            <description>
                            <![CDATA[ It's a game of volume in retail since despite being the second-most targeted industry, the average payment per case is well below the industry average ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wMc28v5i5dHNj9RJPYb745</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CD3HcfUA46fMgoQK8bxNHa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Sep 2022 11:28:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CD3HcfUA46fMgoQK8bxNHa-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Technology symbols overlaid in a clothing store]]></media:description>                                                            <media:text><![CDATA[Technology symbols overlaid in a clothing store]]></media:text>
                                <media:title type="plain"><![CDATA[Technology symbols overlaid in a clothing store]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CD3HcfUA46fMgoQK8bxNHa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Retail companies that are impacted by ransomware pay less than a third of the amount of the industry average when meeting ransom demands, new research has revealed.</p><p>The average payment made to a ransomware organisation in the retail sector throughout 2021 was $226,000 (£197,000), significantly less than the industry average of $812,000 (£708,000) per incident.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360747/why-retailers-are-the-most-targeted-sector-for-cyber-attacks" data-original-url="/security/cyber-security/360747/why-retailers-are-the-most-targeted-sector-for-cyber-attacks">Why retail is a top target for cyber attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022" data-original-url="/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022">How not to get hit by ransomware in 2022</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368167/double-extortion-ransomware-pushes-average-payments-close-to-1-million" data-original-url="/security/ransomware/368167/double-extortion-ransomware-pushes-average-payments-close-to-1-million">Double extortion ransomware pushes average payments close to $1 million</a></p></div></div><p>Nearly one in four (22%) paid less than $1,000 (£871) for each incident, Sophos said, and the vast majority (70%) paid less than $100,000 (£87,000) whereas just 47% of the global average got away with paying less than six-figure sums.</p><p>The overall cost to remediate an attack was down on 2020’s numbers in retail too at $1.27 million (£1.1 million), a reduction from $1.97 million (£1.7 million) the year before.</p><p>Total costs of ransomware incidents can cover a wide variety of things including paying the ransom fee itself, the cost of recovering systems, a potential rise in cyber insurance premiums, and the cost of improving systems to prevent further attacks, among other areas.</p><p>Retail was largely spared from paying the highest prices for their ransomware attacks, but incidents still increased over the year, according to the researchers, with as many as 77% of all retail organisations being impacted in some way.</p><p>This figure represents a sizeable increase on the previous year’s of 44% and shows how retail is being targeted more frequently compared to the wider industry where 66% of companies were impacted on average.</p><p>Sophos said retail was the <a href="https://www.itpro.com/security/cyber-security/360747/why-retailers-are-the-most-targeted-sector-for-cyber-attacks" data-original-url="https://www.itpro.com/security/cyber-security/360747/why-retailers-are-the-most-targeted-sector-for-cyber-attacks">second-most targeted industry</a> and was also reported slightly above average rates of data being encrypted in attacks - 68% vs the industry average of 65%.</p><p>Only 28% of retail organisations were able to stop their data from being encrypted after noticing an attack had begun - a figure that contributed to the reports that almost all companies (92%) said attacks impacted their ability to operate.</p><p>Retail firms are getting better at using backups to restore their data after it becomes encrypted - the industry’s long-recommended method of <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> remediation.</p><p>73% of retail companies used backups following an attack, a figure that’s up considerably over the previous year’s 56%, but companies still report not benign able to get all of the data back. </p><p>Only 62% of all encrypted data was recovered, on average, in retail which is in line with the industry average of 61% - a drop from 67% in 2020.</p><p>The number of businesses that were able to recover the entirety of their data was also down on the previous year’s figures - 5% and 9% respectively.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qEKM9GRE2S2PW5Bvuu8xp6" name="qEKM9GRE2S2PW5Bvuu8xp6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/qEKM9GRE2S2PW5Bvuu8xp6.jpg" mos="https://cdn.mos.cms.futurecdn.net/qEKM9GRE2S2PW5Bvuu8xp6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Escape the ransomware maze</strong></p><p class="fancy-box__body-text">Conventional endpoint protection tools just aren’t the best defence anymore</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368866/escape-the-ransomware-maze" data-original-url="/security/cyber-security/368866/escape-the-ransomware-maze">FREE DOWNLOAD</a></p></div></div><p>“The key takeaway here is that paying the ransom will only restore a part of your encrypted data and you cannot count on the ransom payment to get you all your data back,” Sophos said.</p><p>The received wisdom in the industry has always been to never pay the ransom. In doing so, victims directly fund cyber crime and validate the business model itself.</p><p>However, many organisations are known to flout this advice in the hope of more quickly regaining access to data and their operations. Sophos’ research showed that 49% of all retail companies paid their attackers' ransom demands in 2021.</p><p>The dynamic between criminal and victim in a ransomware case is a mutually beneficial one, from the criminal’s perspective: the criminal encourages payment and repays the trust of the victim for paying the ransom in returning the <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted files</a> through a decryption key.</p><p>Sophos’ data would suggest that the dynamic is being exploited by the criminals and if victims continue to lose access to a sizeable portion of their files, it may discourage payment.</p><p>In cases where the victim restores from backups, the effectiveness of the recovery is only as effective as the <a href="https://www.itpro.com/back-up/29084/how-to-enhance-your-backup-strategy" data-original-url="https://www.itpro.com/back-up/29084/how-to-enhance-your-backup-strategy">backup strategy</a> itself. If the backup is weeks old then the business will struggle to fully recover.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Products of the Year 2021: The year’s best hardware and software ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/361881/the-it-pro-products-of-the-year-2021-the-years-best-hardware-and-software</link>
                                                                            <description>
                            <![CDATA[ Our pick of the best products from the past 12 months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">toPW4PztjRHXhnvDGAe3Vr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fFLcnYfeuZediF4PqJmdKA-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 31 Dec 2021 09:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Networks]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/fFLcnYfeuZediF4PqJmdKA-1280-80.png">
                                                            <media:credit><![CDATA[Keumars Afifi-Sabet/IT Pro]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT Pro Product of the Year Awards 2021]]></media:description>                                                            <media:text><![CDATA[IT Pro Product of the Year Awards 2021]]></media:text>
                                <media:title type="plain"><![CDATA[IT Pro Product of the Year Awards 2021]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fFLcnYfeuZediF4PqJmdKA-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The past twelve months have brought challenges for almost all businesses, but they’ve also brought some terrific products. New generations of servers and appliances have arrived, offering levels of horsepower and capacity that would have seemed outlandish just a few years ago. At the same time, value has continued to climb, bringing new possibilities within reach of an SMB budget.</p><p>There’s been plenty of exciting developments for end users too. Stunning laptops, tablets and phones have turned our heads, along with powerful printers, scanners and screens. And while threats like phishing and ransomware haven’t gone away, the latest generation of security software is here to keep us safe.</p><p>As always, there’s no such thing as a perfect product – every business and every individual will have their own needs and preferences. But we’ve put together our selection of the greatest releases of the past twelve months, to reveal the standout products across a wide range of categories, and to celebrate the manufacturers who’ve driven innovation forward in 2021.</p><h2 id="best-laptop-2021">Best laptop 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="n5ekzj27BkFuHS8eWuu2Ai" name="" alt="LG Gram 17" src="https://cdn.mos.cms.futurecdn.net/n5ekzj27BkFuHS8eWuu2Ai.jpg" mos="https://cdn.mos.cms.futurecdn.net/n5ekzj27BkFuHS8eWuu2Ai.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-lg-gram-17"><span>WINNER: LG Gram 17</span></h3><p>Weighing just 1.35kg, the Gram 17 is barely heavier than many 14in laptops – yet it has a huge, bright 17in display that’s fantastic for productivity and on-the-go presentations.</p><p>There’s plenty of horsepower here too, with an 11th-generation Intel Core i7 processor and 16GB of RAM on board. With nearly 13 hours of battery life it won’t conk out half-way through the day, and a spacious keyboard and trackpad mean it’s also a pleasure to work on for extended periods. Throw in Thunderbolt 4 and Wi-Fi 6 and you have an excellent do-it-all, go-anywhere computer for a very reasonable £1,599 exc VAT.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/laptops/359449/lg-gram-17-review-slim-and-sophisticated" data-original-url="https://www.itpro.com/hardware/laptops/359449/lg-gram-17-review-slim-and-sophisticated">LG Gram 17 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hEr7oSf3KPynR2db7vDgAg" name="" alt="The Razer Book 13 front view" src="https://cdn.mos.cms.futurecdn.net/hEr7oSf3KPynR2db7vDgAg.jpg" mos="https://cdn.mos.cms.futurecdn.net/hEr7oSf3KPynR2db7vDgAg.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Keumars Afifi-Sabet/IT Pro)</span></figcaption></figure><h3 class="article-body__section" id="section-highly-commended-razer-book-13"><span>HIGHLY COMMENDED: Razer Book 13</span></h3><p>Razer made its name with gaming laptops, but the company’s first business-friendly model is a big hit. It looks stylish yet serious, with a superb screen that challenges the MacBook Pro for brightness and colour quality. Performance is top-notch too, thanks to an Intel Core i7-1165G7 processor, and there’s a great selection of ports, including full-sized USB and HDMI connectors. At 1.4kg it’s a little weighty for a 13in laptop, but overall it’s a great, capable choice for an everyday working companion.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/laptops/359288/razer-book-13-review-taking-on-the-big-guns" data-original-url="https://www.itpro.com/hardware/laptops/359288/razer-book-13-review-taking-on-the-big-guns">Razer Book 13 review</a></strong></em></p><h2 id="best-chromebook-2021">Best Chromebook 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AFpm85oNDCFf4kLvfXpQWZ" name="" alt="A photograph of the Acer Chromebook Spin 713 in presentation mode" src="https://cdn.mos.cms.futurecdn.net/AFpm85oNDCFf4kLvfXpQWZ.jpg" mos="https://cdn.mos.cms.futurecdn.net/AFpm85oNDCFf4kLvfXpQWZ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-acer-chromebook-spin-713"><span>WINNER: Acer Chromebook Spin 713</span></h3><p>There are plenty of sub-£500 Chromebooks on the market, but Acer’s Chromebook Spin 713 feels like something much more expensive. Its 13.5in QHD screen has a comfortable 3:2 aspect ratio, and it flips all the way around so you can work in laptop, stand or tablet mode. Unusually, there’s an HDMI output too, giving you additional working options.</p><p>Wi-Fi 6 and Bluetooth 5 round out the feature set, and with a total weight of just 1.2kg the Spin 713 is deliciously portable too. It would have been nice if Acer had given that beautiful screen an anti-glare coating, but when the rest of the package is this good we can live with a few reflections.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/laptops/360016/acer-chromebook-spin-713-review-a-high-end-package-with-a-budget-price" data-original-url="https://www.itpro.com/hardware/laptops/360016/acer-chromebook-spin-713-review-a-high-end-package-with-a-budget-price">Acer Chromebook Spin review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p4bHBnpLkge6x6UrxznS75" name="" alt="The Lenovo IdeaPad Flex 5 Chromebook" src="https://cdn.mos.cms.futurecdn.net/p4bHBnpLkge6x6UrxznS75.jpg" mos="https://cdn.mos.cms.futurecdn.net/p4bHBnpLkge6x6UrxznS75.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-lenovo-ideapad-flex-5"><span>HIGHLY COMMENDED: Lenovo IdeaPad Flex 5</span></h3><p>The Flex 5 is another Chromebook with a 360º-rotating screen, though its 16:9 aspect ratio is best suited to conventional laptop-style usage. It’s slimmer and lighter than the Acer Spin 713, and its bright display is less reflective. Connectivity is well covered with both USB Type-A and Type-C ports, along with Wi-Fi 6; if you’re looking for a no-nonsense Chrome OS workhorse, you won’t be disappointed.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/laptops/360057/lenovo-ideapad-flex-5-chromebook-review-a-dependable-workhorse" data-original-url="https://www.itpro.com/hardware/laptops/360057/lenovo-ideapad-flex-5-chromebook-review-a-dependable-workhorse">Lenovo IdeaPad Flex 5 review</a></strong></em></p><h2 id="best-tablet-2021">Best tablet 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rXfG5769dJSR8tHg229Zhg" name="" alt="A photograph of the 12.9in Apple iPad Pro on table with some plants" src="https://cdn.mos.cms.futurecdn.net/rXfG5769dJSR8tHg229Zhg.jpg" mos="https://cdn.mos.cms.futurecdn.net/rXfG5769dJSR8tHg229Zhg.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-apple-ipad-pro-12-9in"><span>WINNER: Apple iPad Pro 12.9in</span></h3><p>With Apple’s mighty M1 processor, the iPad Pro is fully as powerful as a MacBook Pro. And it has several advantages over the laptop: at 680g it’s less than half the weight, and the touchscreen makes for a slick, tactile experience. The 120Hz mini-LED display is stunning, and a battery life of around 13 and a half hours means you can keep working all through the day and beyond.</p><p>No doubt, the 12.9in format is bulky for a tablet, while the optional keyboard pushes up the weight – and the price, which is already steep at £916 exc VAT for the base model. Even so, this is unquestionably the best tablet on the market: it doesn’t just excel at tablet tasks, it redefines what a tablet can do.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/tablets/361463/apple-ipad-pro-129in-2021-review-a-giant-leap-for-apple-silicon" data-original-url="https://www.itpro.com/hardware/tablets/361463/apple-ipad-pro-129in-2021-review-a-giant-leap-for-apple-silicon">Apple iPad Pro 12.9in review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LAnrB5XpQSofRYiyKsmmpE" name="" alt="A photograph of the Nokia T20 standing up on a table" src="https://cdn.mos.cms.futurecdn.net/LAnrB5XpQSofRYiyKsmmpE.jpg" mos="https://cdn.mos.cms.futurecdn.net/LAnrB5XpQSofRYiyKsmmpE.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-nokia-t20"><span>HIGHLY COMMENDED: Nokia T20</span></h3><p>It’s short on flashy gimmicks, but Nokia’s T20 feels like a professional tablet. The aluminium build is strong and sturdy, performance and features are up to par, and while we felt the 10.4in screen looked a little cold, its 5:3 aspect ratio is very comfortable to work on. The most impressive part is the price – just £150 exc VAT for the Wi-Fi 5 edition, or £167 exc VAT for the LTE model.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/tablets/361736/nokia-t20-review-a-simple-sturdy-android-tablet-at-an-smb-friendly-price" data-original-url="https://www.itpro.com/hardware/tablets/361736/nokia-t20-review-a-simple-sturdy-android-tablet-at-an-smb-friendly-price">Nokia T20 review</a></strong></em></p><h2 id="best-smartphone-2021">Best smartphone 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZeHBHn7BP4mEyj6b8sjCf8" name="" alt="A photograph of the Apple iPhone 13 standing against a white background" src="https://cdn.mos.cms.futurecdn.net/ZeHBHn7BP4mEyj6b8sjCf8.jpg" mos="https://cdn.mos.cms.futurecdn.net/ZeHBHn7BP4mEyj6b8sjCf8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Bobby Hellard/Future)</span></figcaption></figure><h3 class="article-body__section" id="section-winner-apple-iphone-13"><span>WINNER: Apple iPhone 13</span></h3><p>The iPhone 13 improves on last year’s iPhone 12 models with better cameras and a bigger battery, adding nearly two hours of daily performance in our tests. You get more storage in the standard model too, up from 64GB to 128GB, and the latest Apple A15 Bionic CPU for true Android-smashing performance.</p><p>All the usual iPhone strengths are here, including an excellent screen and a vast library of high-quality apps for work or play. It’s hardly an adventurous update from the iPhone 12, but if you’re choosing a new smartphone today – and aren’t already enmeshed in the Android ecosystem – then the iPhone 13 is the obvious choice.</p><p><em><strong>Read our full <a href="https://www.itpro.com/mobile/mobile-phones/361428/apple-iphone-13-review" data-original-url="https://www.itpro.com/mobile/mobile-phones/361428/apple-iphone-13-review">Apple iPhone 13 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="V4i2AftiV8cg3rsnmcRKu" name="" alt="OnePlus 9 Pro smartphone" src="https://cdn.mos.cms.futurecdn.net/V4i2AftiV8cg3rsnmcRKu.jpg" mos="https://cdn.mos.cms.futurecdn.net/V4i2AftiV8cg3rsnmcRKu.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-oneplus-9-pro"><span>HIGHLY COMMENDED: OnePlus 9 Pro</span></h3><p>Standing 163mm tall, the OnePlus 9 Pro is large, but it’s perhaps the most beautiful Android smartphone we’ve seen, with a tiny bezel and beautifully textured case. Its 120Hz AMOLED display is a joy to behold, and a collaboration with Hasselblad ensures excellent photo and video quality. Performance is very strong too, courtesy of a top-tier Snapdragon 888 processor; at £829 exc VAT it’s not a budget option, but you get what you pay for.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/359792/oneplus-9-pro-review-an-instant-cult-classic" data-original-url="https://www.itpro.com/hardware/359792/oneplus-9-pro-review-an-instant-cult-classic">OnePlus 9 Pro review</a></strong></em></p><h2 id="best-desktop-server-2021">Best desktop server 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ajJKrfg9ebt9d2K7dPSsuS" name="" alt="HPE MicroServer Gen10 Plus front and rear" src="https://cdn.mos.cms.futurecdn.net/ajJKrfg9ebt9d2K7dPSsuS.jpg" mos="https://cdn.mos.cms.futurecdn.net/ajJKrfg9ebt9d2K7dPSsuS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-hpe-proliant-microserver-gen10-plus"><span>WINNER: HPE ProLiant MicroServer Gen10 Plus</span></h3><p>The MicroServer Gen10 Plus really can fit happily on a desktop, as its square chassis measures a mere 245mm along each side. Yet it’s powerful enough to run a wide range of business services, with your choice of a dual-core 3.8GHz Pentium Gold G5420 CPU or a quad-core 3.4GHz Xeon E-2224. Four integrated LFF SATA drive bays allow for plenty of storage.</p><p>The small size means there’s not much scope for internal expansion, but you do get a single PCI-E x16 slot, and remote management can be added via the cheap iLO5 enablement kit. With the entry-level diskless system starting at just £395 exc VAT, it’s an excellent SMB-friendly deal.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/358198/hpe-proliant-microserver-gen10-plus-review-pint-sized" data-original-url="https://www.itpro.com/infrastructure/server-storage/358198/hpe-proliant-microserver-gen10-plus-review-pint-sized">HPE ProLiant MicroServer Gen10 Plus review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dzomLTUuXSzPATGmMZRWcA" name="" alt="A photograph of the front and rear of the Dell EMC PowerEdge T550" src="https://cdn.mos.cms.futurecdn.net/dzomLTUuXSzPATGmMZRWcA.jpg" mos="https://cdn.mos.cms.futurecdn.net/dzomLTUuXSzPATGmMZRWcA.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-dell-emc-poweredge-t550"><span>HIGHLY COMMENDED: Dell EMC PowerEdge T550</span></h3><p>The T550 is a real “tower of power” – we tested it with a 12-core 2.1GHz Xeon Silver 4310 CPU, but if you need more grunt it can handle twin CPUs with up to 32 cores each. It also supports up to 24 SFF or eight LFF drives, and a maximum of 1TB of DDR4 RAM. Dell’s comprehensive iDRAC9 remote management platform comes as standard, making this an ideal answer to demanding workloads.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/361505/dell-emc-poweredge-t550-review-power-to-the-people" data-original-url="https://www.itpro.com/infrastructure/server-storage/361505/dell-emc-poweredge-t550-review-power-to-the-people">Dell EMC PowerEdge T550 review</a></strong></em></p><h2 id="best-1u-server-2021">Best 1U server 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nP4JqwijA3fNPS7ThV759i" name="" alt="A photograph of the Dell EMC PowerEdge R650" src="https://cdn.mos.cms.futurecdn.net/nP4JqwijA3fNPS7ThV759i.jpg" mos="https://cdn.mos.cms.futurecdn.net/nP4JqwijA3fNPS7ThV759i.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-dell-emc-poweredge-r650"><span>WINNER: Dell EMC PowerEdge R650</span></h3><p>Dell’s latest PowerEdge R650 design crams an amazing amount of potential into a 1U chassis. It supports Xeon Scalable CPUs with up to 40 cores and a massive 4TB of memory, with space inside for up to ten SFF drives and 16 Intel Optane modules to accelerate performance.</p><p>If that’s not enough, you also get three PCI-E Gen4 x16 slots and an OCP 3.0 edge slot, plus Dell’s BOSS card for fast booting from SSD media. And as usual with Dell, the iDRAC9 controller provides terrific remote management. It’s not a budget option – our review unit came to £15,417 exc VAT – but the PowerEdge R650 is an incredibly powerful and space-efficient server.</p><p><em><strong>Read our</strong></em> <em><strong>full <a href="https://www.itpro.com/infrastructure/server-storage/361379/dell-emc-poweredge-r650-review-a-slim-and-mighty-server" data-original-url="https://www.itpro.com/infrastructure/server-storage/361379/dell-emc-poweredge-r650-review-a-slim-and-mighty-server">Dell EMC PowerEdge R650 review</a></strong></em></p><h3 class="article-body__section" id="section-highly-commended-broadberry-cyberserve-xeon"><span>HIGHLY COMMENDED: Broadberry CyberServe Xeon</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JjqLzWqHp3FUrMojVcPBBM" name="" alt="Broadberry CyberServe Xeon E-RS100-E10 front and rear" src="https://cdn.mos.cms.futurecdn.net/JjqLzWqHp3FUrMojVcPBBM.jpg" mos="https://cdn.mos.cms.futurecdn.net/JjqLzWqHp3FUrMojVcPBBM.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This low-profile server offers a solid chunk of power for just under £1,000. That gets you a quad-core Intel Xeon E-2224 CPU with 16GB of RAM – upgradeable to 128GB – and you’re free to fit your own drives in the four SFF bays and twin M.2 SSD slots. The single PCI-E Gen3 x16 slot can be used to add 10GbE networking, and the Asus motherboard supports web-based management, including full OS remote control and virtual media services as standard.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/358798/broadberry-cyberserve-xeon-e-rs100-e10-review-a-cracking" data-original-url="https://www.itpro.com/infrastructure/server-storage/358798/broadberry-cyberserve-xeon-e-rs100-e10-review-a-cracking">Broadberry CyberServe Xeon E-RS100-E10 review</a></strong></em></p><h2 id="best-2u-server-2021">Best 2U server 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="A5cATCdywU9gM53RyE6wf5" name="" alt="A photograph of the Broadberry CyberServe SP2 208-8I G3" src="https://cdn.mos.cms.futurecdn.net/A5cATCdywU9gM53RyE6wf5.jpg" mos="https://cdn.mos.cms.futurecdn.net/A5cATCdywU9gM53RyE6wf5.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-broadberry-cyberserve-sp2-208-8i-g3"><span>WINNER: Broadberry CyberServe SP2 208-8I G3</span></h3><p>The CyberServe SP2 208-8I G3 is designed for a hardcore server role. The system we tested came with a pair of 36-core Xeon Scalable Platinum CPUs, 512GB of DDR4 RAM, five 960GB SATA SSDs and eight 128GB Intel Optane PMEM 200 modules. This allows for insanely fast storage access – and to help you make the most of it, the system comes with not one but two dual-port Intel 100GbE network cards.</p><p>You can upgrade even further by going up to 26 SFF drives in total, plus eight NVMe drives, and the spacious 2U design allows for six free PCI-E Gen4 slots. It’s a magnificent hardware package, and while the £21,895 price tag won’t be within everyone’s budget, it’s superb value for what you get.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/360442/broadberry-cyberserve-sp2-208-8i-g3-review-optane-a-gogo" data-original-url="https://www.itpro.com/infrastructure/server-storage/360442/broadberry-cyberserve-sp2-208-8i-g3-review-optane-a-gogo">Broadberry CyberServe SP2 208-8I G3 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LZuQSY9iT93kVmEphmKHg6" name="" alt="Dell EMC PowerEdge R750" src="https://cdn.mos.cms.futurecdn.net/LZuQSY9iT93kVmEphmKHg6.jpg" mos="https://cdn.mos.cms.futurecdn.net/LZuQSY9iT93kVmEphmKHg6.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-dell-emc-poweredge-r750"><span>HIGHLY COMMENDED: Dell EMC PowerEdge R750 </span></h3><p>Dell’s PowerEdge R750 comes in three versions – the R750xa is built for GPU-based workloads, while the R750xs is a cost-optimised version aimed at specific roles. The standard R750 is a great all-rounder though: the configuration we tested offered two 28-core 2GHz Xeon Scalable Gold 6330 CPUs and 1TB of RAM, upgradeable to a whopping 8TB using 256GB DIMMs. For storage you can choose between a 12-bay LFF backplane or a 16-bay SFF one, and add up to 24 NVMe SSDs. In short, there’s enough power and flexibility here for any business.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/359410/dell-emc-poweredge-r750-review-a-third-gen-xeon-scalable" data-original-url="https://www.itpro.com/infrastructure/server-storage/359410/dell-emc-poweredge-r750-review-a-third-gen-xeon-scalable">Dell EMC PowerEdge R750 review</a></strong></em></p><h2 id="best-storage-array-2021">Best storage array 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hGcbyak3sfv84GF6zADJPa" name="" alt="HPE MSA 2060 Storage" src="https://cdn.mos.cms.futurecdn.net/hGcbyak3sfv84GF6zADJPa.jpg" mos="https://cdn.mos.cms.futurecdn.net/hGcbyak3sfv84GF6zADJPa.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-hpe-msa-2060-storage"><span>WINNER: HPE MSA 2060 Storage</span></h3><p>With numerous hardware upgrades over the last generation, this is HPE’s fastest dedicated storage array ever. It’s also laden with powerful features: thin provisioning, snapshots and volume copies are all supported, along with striped SSD caches, RAID10, 5 and 6 options and HPE’s own MSA-DP+ array format, designed for improved performance and faster rebuild times.</p><p>The MSA 2060 even offers zero-configuration data tiering, automatically shunting data between regular SAS drives, fast solid-state storage and low-priority ML-SAS volumes according to usage. And it’s all configured and managed from a simple web portal, so there’s no need to be a storage expert to get the best from it.</p><p><em><strong>Read our full <a href="https://www.itpro.com/infrastructure/server-storage/358765/hpe-msa-2060-storage-review-storage-tiering-for-dummies" data-original-url="https://www.itpro.com/infrastructure/server-storage/358765/hpe-msa-2060-storage-review-storage-tiering-for-dummies">HPE MSA 2060 Storage review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cvpHBtHNxm4abWfZtZh67b" name="" alt="A photograph of the Qnap TS-h2490FU QuTS hero edition" src="https://cdn.mos.cms.futurecdn.net/cvpHBtHNxm4abWfZtZh67b.jpg" mos="https://cdn.mos.cms.futurecdn.net/cvpHBtHNxm4abWfZtZh67b.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-qnap-ts-h2490fu-quts-hero-edition"><span>HIGHLY COMMENDED: Qnap TS-h2490FU QuTS Hero Edition</span></h3><p>When performance is a priority, pure NVMe storage is the way to go. This impressive appliance can take up to 24 hot-plug U.2 drives, while Qnap’s 128-bit ZFS-based OS provides enterprise-class data integrity, with compression and deduplication options provided as standard. It’s all based on a powerful AMD EPYC processor, and it comes with a pair of dual-port 25GbE network cards, to ensure you can get the full performance from your storage.</p><p><em><strong>Read our full <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/359573/qnap-ts-h2490fu-quts-hero-edition-review-smash" data-original-url="https://www.itpro.com/server-storage/network-attached-storage-nas/359573/qnap-ts-h2490fu-quts-hero-edition-review-smash">Qnap TS-h2490FU QuTS Hero Edition review</a></strong></em></p><h2 id="best-nas-drive-2021">Best NAS drive 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rmLT3wZG8jv7CfrAWBdiEV" name="" alt="The Qnap TS-h973AX" src="https://cdn.mos.cms.futurecdn.net/rmLT3wZG8jv7CfrAWBdiEV.jpg" mos="https://cdn.mos.cms.futurecdn.net/rmLT3wZG8jv7CfrAWBdiEV.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-qnap-ts-h973ax"><span>WINNER: Qnap TS-h973AX</span></h3><p>Though it looks unassuming, Qnap’s TS-h973AX runs the company’s advanced QuTS hero OS, which offers an impressive range of native storage features. Those include fast, near-unlimited snapshots, transparent self-healing of data corruption and inline data deduplication and compression to make the most efficient use of your storage. Five LFF SATA bays plus four SFF bays provide plenty of room for expansion, while 10GbE and twin 2.5GbE network ports provide high-speed connections to the outside world.</p><p>In our tests the TS-h973AX provided fast read and write speeds, and there’s a whole library of apps to expand its capabilities, including backup and virtualisation tools. Costing just over £1,000 exc VAT for the diskless enclosure, it’s well within reach of smaller businesses.</p><p><em><strong>Read our full <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/359766/qnap-ts-h973ax-review-our-top-choice-desktop-nas" data-original-url="https://www.itpro.com/server-storage/network-attached-storage-nas/359766/qnap-ts-h973ax-review-our-top-choice-desktop-nas">Qnap TS-h973AX review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="E4D2DMuj8mBzoZEq3cP2Ef" name="" alt="A photograph of the Qnap TS-873A" src="https://cdn.mos.cms.futurecdn.net/E4D2DMuj8mBzoZEq3cP2Ef.jpg" mos="https://cdn.mos.cms.futurecdn.net/E4D2DMuj8mBzoZEq3cP2Ef.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-qnap-ts-873a"><span>HIGHLY COMMENDED: Qnap TS-873A</span></h3><p>Looking for a simple storage solution? The eight-bay TS-873A makes a great platform for Qnap’s lightweight, simple to manage QTS OS. Alternatively, for more advanced data-protection functions you can install the full QuTS hero OS and make use of all the same features as the TS-h973AX, above. Either way, it’ll run the full range of Qnap apps, and dual 2.5GbE ports help keep data flowing swiftly in and out.</p><p><em><strong>Read our full <a href="https://www.itpro.com/server-storage/network-attached-storage-nas/360351/qnap-ts-873a-review-a-supremely-versatile" data-original-url="https://www.itpro.com/server-storage/network-attached-storage-nas/360351/qnap-ts-873a-review-a-supremely-versatile">Qnap TS-873A review</a></strong></em></p><h2 id="best-printer-2021">Best printer 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2C5hu6dGJn7jYZg35bpg9a" name="" alt="A photograph of the Epson EcoTank ET-5880" src="https://cdn.mos.cms.futurecdn.net/2C5hu6dGJn7jYZg35bpg9a.jpg" mos="https://cdn.mos.cms.futurecdn.net/2C5hu6dGJn7jYZg35bpg9a.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-epson-ecotank-et-5880"><span>WINNER: Epson EcoTank ET-5880</span></h3><p>Forget about overpriced cartridges – this A4 MFP uses bottled ink that works out to just 0.2p per mono page and 0.8p for colour. That alone will make it attractive to busy offices, but the ET-5880 has other strengths too, including a swish 10.9cm touchscreen, 802.11n wireless connectivity and excellent colour output. It comes with a pair of 250-sheet paper cassettes, so you won’t be continually restocking it, and the integrated scanner has its own 50-page duplex ADF.</p><p>The one caveat is a print speed of 25ppm in standard quality mode: that’s not exactly slow, but it’s unexceptional for a modern office printer. Even so, the Epson’s user-friendliness and phenomenally low running costs make it our top choice for 2021.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/peripherals/360489/epson-ecotank-et-5880-review-phenomenally-low-running-costs" data-original-url="https://www.itpro.com/hardware/peripherals/360489/epson-ecotank-et-5880-review-phenomenally-low-running-costs">Epson EcoTank ET-5880 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vkJ27eixRPDnpGLJxFiTtC" name="" alt="A photograph of the Kyocera Ecosys M6235cidn" src="https://cdn.mos.cms.futurecdn.net/vkJ27eixRPDnpGLJxFiTtC.jpg" mos="https://cdn.mos.cms.futurecdn.net/vkJ27eixRPDnpGLJxFiTtC.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-kyocera-ecosys"><span>HIGHLY COMMENDED: Kyocera Ecosys</span></h3><p>This freestanding laser MFP won’t suit the smallest offices, but it offers a 35ppm print speed and a wide range of downloadable apps to extend its printing and scanning functions. It’s easy to operate, with a big 7in touchscreen, a range of mobile apps and a clear web-based management console. The clincher is the price: the basic model with wired networking and a single 250-page sheet feeder costs just £696 exc VAT, and low-cost consumables work out to a very reasonable 1p per mono page.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/peripherals/360559/kyocera-ecosys-m6235cidn-review-worth-splashing-out-on" data-original-url="https://www.itpro.com/hardware/peripherals/360559/kyocera-ecosys-m6235cidn-review-worth-splashing-out-on">Kyocera Ecosys M6235cidn review</a></strong></em></p><h2 id="best-scanner-2021">Best scanner 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ycDrKkgsvj9ZQJTVSsvuGL" name="" alt="A photograph of the Fujitsu ScanSnap iX1600" src="https://cdn.mos.cms.futurecdn.net/ycDrKkgsvj9ZQJTVSsvuGL.jpg" mos="https://cdn.mos.cms.futurecdn.net/ycDrKkgsvj9ZQJTVSsvuGL.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-fujitsu-scansnap-ix1600"><span>WINNER: Fujitsu ScanSnap iX1600</span></h3><p>This desktop scanner has a great set of features, including integrated Wi-Fi, a 50-sheet ADF, double-sided scanning and a 4.3in colour touchscreen. It’s fast too: we were impressed to see it rip through our pile of test documents at 43ppm, creating 200dpi scans that were perfectly clear and clean enough for OCR and archival.</p><p>Even better, this hardware is partnered by one of the best software suites around. You can scan to a huge range of applications and cloud services, send scans directly to an email address or beam them to a mobile device. For anyone who needs to scan and share documents in a digital or cloud-first environment, the Fujitsu ScanSnap iX1600 is a terrific choice.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/peripherals/360909/fujitsu-scansnap-ix1600-review-unparalleled-cloud-support" data-original-url="https://www.itpro.com/hardware/peripherals/360909/fujitsu-scansnap-ix1600-review-unparalleled-cloud-support">Fujitsu ScanSnap iX1600 review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JBAkJtk47CLnAGsxDdprgK" name="" alt="Canon imageFormula DR-S130 angled view" src="https://cdn.mos.cms.futurecdn.net/JBAkJtk47CLnAGsxDdprgK.jpg" mos="https://cdn.mos.cms.futurecdn.net/JBAkJtk47CLnAGsxDdprgK.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-canon-imageformula-dr-s130"><span>HIGHLY COMMENDED: Canon imageFormula DR-S130</span></h3><p>With its output tray folded away the DR-S130 takes up barely any more desk space than a sheet of A4. Yet it scans at a swift 30ppm, and thanks to Canon’s CaptureOnTouch V4 Pro software it can perform all the same scan functions as much pricier, bulkier models. You can set up profiles for different job types, run single- and double-sided scans, perform OCR and save the output in your choice of format and location. The only thing it can’t do is scan directly to cloud services, but for most individuals and SMBs it’ll fit the bill admirably.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/peripherals/358607/canon-imageformula-dr-s130-review-a-great-choice-for-remote-workers" data-original-url="https://www.itpro.com/hardware/peripherals/358607/canon-imageformula-dr-s130-review-a-great-choice-for-remote-workers">Canon imageFormula DR-S130 review</a></strong></em></p><h2 id="best-monitor-2021">Best monitor 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kYiAHzPtXj7Gck9rUuNEig" name="" alt="Dell UltraSharp 25 USB-C monitor" src="https://cdn.mos.cms.futurecdn.net/kYiAHzPtXj7Gck9rUuNEig.jpg" mos="https://cdn.mos.cms.futurecdn.net/kYiAHzPtXj7Gck9rUuNEig.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-dell-ultrasharp-25-usb-c"><span>WINNER: Dell UltraSharp 25 USB-C</span></h3><p>We don’t see a lot of 25in monitors, but the format works well for desktop productivity, and the Dell UltraSharp lives up to its name with a crisp 2,560 x 1,440 resolution. It also delivers excellent coverage of both the sRGB and DCI-P3 colour spaces, with an HDR400 certification for extended-range colour.</p><p>The final trump card is connectivity: the USB Type-C connector can handle both incoming video and outgoing power, so you can hook your laptop up to the big screen and charge it at the same time. It’s also possible to daisy-chain a second display via the DisplayPort connector, or to swivel the panel round through 90º and work in portrait mode. In short, it’s one of the cleverest monitors we’ve seen.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/monitors/361686/dell-ultrasharp-25-usb-c-review-a-cut-above" data-original-url="https://www.itpro.com/hardware/monitors/361686/dell-ultrasharp-25-usb-c-review-a-cut-above">Dell UltraSharp 25 USB-C review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="S4NEx95ZkrzyG35GATAjdb" name="" alt="Acer ConceptD CP5271UV" src="https://cdn.mos.cms.futurecdn.net/S4NEx95ZkrzyG35GATAjdb.jpg" mos="https://cdn.mos.cms.futurecdn.net/S4NEx95ZkrzyG35GATAjdb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-acer-conceptd-cp5271uv"><span>HIGHLY COMMENDED: Acer ConceptD CP5271UV</span></h3><p>The CP5271UV is an exceptionally versatile monitor. It offers custom display modes for print editing, video and games, and also supports high-end features including HDR600 for deep-colour content, dynamic refresh rates up to 170Hz and an incandescent peak brightness of 480cd/m2. It makes a great office monitor too, with integrated gigabit Ethernet and four USB 3.1 ports. At £667 exc VAT it’s considerably more expensive than your typical desktop display, but if you're in the market for a high-end screen it’s a steal.</p><p><em><strong>Read our full <a href="https://www.itpro.com/hardware/monitors/359177/acer-conceptd-cp5271uv-review-a-great-value-buy" data-original-url="https://www.itpro.com/hardware/monitors/359177/acer-conceptd-cp5271uv-review-a-great-value-buy">Acer ConceptD CP5271UV review</a></strong></em></p><h2 id="best-endpoint-security-suite-2021">Best endpoint security suite 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DN7YMQWkKGScDFqVLfGXhh" name="" alt="Sophos Intercept X Advanced screenshot" src="https://cdn.mos.cms.futurecdn.net/DN7YMQWkKGScDFqVLfGXhh.png" mos="https://cdn.mos.cms.futurecdn.net/DN7YMQWkKGScDFqVLfGXhh.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-sophos-intercept-x-advanced"><span>WINNER: Sophos Intercept X Advanced</span></h3><p>There’s a lot of hype around artificial intelligence, but it does have real applications: Sophos’ Intercept X suite uses machine-learning techniques to recognise malware and neutralise zero-day threats. It also includes a full range of traditional protections, defeating ransomware by intercepting encryption attacks and silently restoring the original file, and preventing data leaks by blocking the transmission of certain types of information.</p><p>The Advanced subscription adds an analysis centre, where you can forensically review attempted attacks, allowing you to identify and plug the gaps in your armour. It’s easy to deploy and manage too: a central web console lets you email out installer links to all clients, and then administer policies and settings for the whole site.</p><p><em><strong>Read our full <a href="https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection" data-original-url="https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection">Sophos Intercept X Advanced review</a></strong></em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sjU4CWxujUtVPZS4tA7a9e" name="" alt="A screenshot of Kaspersky Endpoint Security Cloud Plus" src="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e.jpg" mos="https://cdn.mos.cms.futurecdn.net/sjU4CWxujUtVPZS4tA7a9e.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-kaspersky-endpoint-security-cloud-plus"><span>HIGHLY COMMENDED: Kaspersky Endpoint Security Cloud Plus</span></h3><p>Kaspersky’s highly flexible licensing lets you protect workstations, laptops, servers and mobile devices all within a single subscription. As well as blocking viruses and intrusion attempts, the software can watch over your network for suspicious activity, and manage Windows Updates from a central portal. The premium Plus subscription adds the Security for Microsoft 365 component, which integrates into Exchange Online, OneDrive, SharePoint Online and Teams, providing monitoring and protection for your services as well as your endpoints.</p><p><em><strong>Read our full <a href="https://www.itpro.com/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them" data-original-url="https://www.itpro.com/security/361632/kaspersky-endpoint-security-cloud-plus-review-one-security-solution-to-rule-them">Kaspersky Endpoint Security Cloud Plus review</a></strong></em></p><h2 id="best-antivirus-suite-2021">Best antivirus suite 2021</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="f4chyD96aSYGdEHEtxvmNS" name="" alt="A screenshot of Kaspersky Internet Security's main dashboard" src="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS.jpg" mos="https://cdn.mos.cms.futurecdn.net/f4chyD96aSYGdEHEtxvmNS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-winner-kaspersky-internet-security"><span>WINNER: Kaspersky Internet Security</span></h3><p>Kaspersky is no stranger to our awards, and this latest version of its security suite shows why – in multiple independent tests it scored perfect 100% protection scores without a single false positive. Other notable features include browser protection, ransomware blocking, defences against webcam hijacking and even a fully featured firewall.</p><p>Do you need to pay for this type of protection? It’s true that Windows’ built-in security modules are nowadays very effective on their own. However, Kaspersky is much easier to configure, especially when it comes to customising firewall rules. It also has less of an impact on system performance, which makes the modest £15/yr subscription fee easy to swallow.</p><p><em><strong>Read our full</strong></em> <a href="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable" data-original-url="https://www.itpro.com/security/antivirus/361292/kaspersky-internet-security-review-powerful-highly-configurable"><strong><em>Kaspersky Internet Security</em> </strong><em><strong>review</strong></em></a></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jXGjknMrApJvm3bqNAC798" name="" alt="A screenshot of Avast Antivirus Free" src="https://cdn.mos.cms.futurecdn.net/jXGjknMrApJvm3bqNAC798.jpg" mos="https://cdn.mos.cms.futurecdn.net/jXGjknMrApJvm3bqNAC798.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h3 class="article-body__section" id="section-highly-commended-avast-antivirus-free"><span>HIGHLY COMMENDED: Avast Antivirus Free</span></h3><p>Avast is our favourite free antivirus solution for several reasons. First, it does a great job of blocking malware: independent labs have found its protection on par with Microsoft Defender and ahead of several paid-for suites. What’s more, it’ll run on older editions of Windows – which is ideal if you still have legacy machines running Windows 7 or 8.1 that can’t be upgraded. You do have to put up with a few in-application adverts for Avast’s paid-for products, but if you can’t use Windows’ built-in protections – or just don’t want to – then Avast Antivirus Free makes a lightweight and effective alternative.</p><p><em><strong>Read our full Avast Antivirus Free review</strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos Intercept X Advanced review: A huge range of endpoint protection measures for the price ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection</link>
                                                                            <description>
                            <![CDATA[ A superb range of security measures and a well-designed cloud portal make endpoint protection a breeze ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6HFEJFqZ4RWdkvLc7ZfE2n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m5cbEWuFRLnx33aE2GDuVJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Nov 2021 09:58:00 +0000</pubDate>                                                                                                                                <updated>Wed, 13 Dec 2023 15:37:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m5cbEWuFRLnx33aE2GDuVJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Sophos Intercept Z Advance interface on the ITPro background]]></media:description>                                                            <media:text><![CDATA[The Sophos Intercept Z Advance interface on the ITPro background]]></media:text>
                                <media:title type="plain"><![CDATA[The Sophos Intercept Z Advance interface on the ITPro background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m5cbEWuFRLnx33aE2GDuVJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sophos offers an impressive portfolio of security services and, as an early adopter of cloud management, it&apos;s ensured everything can be accessed from its Central administrative portal. Along with the Intercept X Advanced workstation and server endpoint protection on review, you can use Central to look after Sophos&apos; Mobile threat defense package along with its XGS firewalls, Wi-Fi 6/6E access points, 100 and 200 series network switches, and zero trust network access service.</p><div  class="fancy-box"><div class="fancy_box-title">READ MORE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="C89Mj92FzceM24PFbsdQpZ" name="C89Mj92FzceM24PFbsdQpZ.jpg" caption="" alt="Endpoint protection or endpoint security interlocking gears" src="https://cdn.mos.cms.futurecdn.net/C89Mj92FzceM24PFbsdQpZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a></p></div></div><p>That&apos;s a lot to pack into one management portal, but Sophos has done a fine job of keeping it simple. The main dashboard provides an overview of your company&apos;s security posture, and all endpoint protection services are neatly separated into three sidebar menu categories for workstations, servers, and mobiles.</p><p>Along with essential malware and threat protection services, Intercept X Advanced supports multiple security policies plus application and device controls. It employs AI-based deep learning to defend against unknown malware, blocks ransomware attacks using behavioral analysis and enables a threat analysis center.</p><p>An XDR (extended detection and response) license allows you to create your own custom threat cases. This provides deeper malware analysis and threat intelligence, on-demand endpoint isolation, and suspicious event detection and prioritization to identify targeted attacks.</p><h2 id="sophos-intercept-x-advanced-setup">Sophos Intercept X Advanced: Setup</h2><p>Deployment is swift. You place the <a href="https://www.itpro.com/microsoft-windows/32386/how-to-run-classic-versions-of-windows-on-modern-pcs">Windows</a> and macOS installers in a central distribution point or create users in the portal and email a link to them. A different agent is used for Windows servers but, in both cases, they only take ten minutes to install, connect to your portal account and retrieve a base security policy.</p><p>The base threat protection policy has all recommended security settings enabled and is always applied to users and devices if no other policy has been assigned. Other policies are provided for web, application, Windows firewall and device controls, and data loss prevention, although these are deactivated and require configuration and assignment. Policies present an extensive range of security measures and include CryptoGuard ransomware protection.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="oY7E5fRXWfFRKWSREqFfZX" name="Why Network Monitoring Tools Fail Within Secure Environments.jpg" caption="" alt="Why Network Monitoring Tools Fail Within Secure Environments whitepaper" src="https://cdn.mos.cms.futurecdn.net/oY7E5fRXWfFRKWSREqFfZX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn about the three scenarios commonly encountered by end users that pose difficulties for network operations teams</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/networking/why-network-monitoring-tools-fail-within-secure-environments">DOWNLOAD NOW</a></p></div></div><p>When any file is opened for writing, it places a temporary clean copy in a proprietary cache on the local drive and, if it detects malicious encryption activity, it will automatically roll back the file to its original state.</p><p>Custom policies are easily created by cloning the preconfigured ones and tweaking their settings to suit. These can be assigned to device groups, and if you import users via the free Active Directory (AD) sync tool or <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Azure</a> sync service, you can apply policies to users so they&apos;re always protected no matter what device they have signed in to.</p><p>Sophos cuts through alert smokescreens as only unresolved events that need your attention to appear in the Central dashboard and cause email notifications to be issued. We used our malware collection to create a virus outbreak condition on one PC which was highlighted immediately, whereas other events such as successful malware removals and website blocks were only posted in the logs and reports section.</p><p>The portal&apos;s threat analysis center provides a basic dashboard showing the most recent threats. Selecting one provides a full analysis of events and a one-click option to clean up all associated files and Registry entries and block them so other devices can&apos;t run it. Sophos has also added a new XDR threat analysis center dashboard that provides smarter widget-based graphical views of <a href="https://www.itpro.com/malware/28076/what-is-malware">malware detection</a>.</p><p>Sophos Intercept X Advanced delivers a huge range of endpoint protection measures for the price. It&apos;s simple to deploy, device and user policies add flexibility and seamless integration with the Central cloud portal makes management simple.</p><p><em>This content originally appeared on ITPro&apos;s sibling magazine PC Pro. For more information and to subscribe, please visit PC Pro&apos;s </em><a href="https://subscribe.pcpro.co.uk/"><em>subscription site</em></a><em>. </em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Eight steps to fight ransomware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/361046/eight-steps-to-fight-ransomware</link>
                                                                            <description>
                            <![CDATA[ Insights into how you can protect yourself from this ever increasing threat ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xrjDpnkJ5HgWgqqLAqtSPx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LxVHRZezHxTmqTdbierxdm-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Sep 2021 10:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/LxVHRZezHxTmqTdbierxdm-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper front cover]]></media:description>                                                            <media:text><![CDATA[Whitepaper front cover]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper front cover]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LxVHRZezHxTmqTdbierxdm-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AgqnvbQpJyPje4qg3Xqb2Q" name="" alt="Sophos logo" src="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q.png" mos="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Join Benedetto Conversano, Diageo and ex-IKEA CIO, as he shares exclusive insight into how your IT security team can fight ransomware.</p><p>In this webinar you will discover eight practical and actionable steps to fight ransomware, including:</p><p>• Why you should focus on impact rather than threats</p><p>• How to create and test a ransomware policy</p><p>• Developing a common cyber security language</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/sophos-abm-leads-webinar?locale=1&p=false&wp=7501"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The state of ransomware in retail 2021 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/360662/the-state-of-ransomware-in-retail-2021</link>
                                                                            <description>
                            <![CDATA[ Insights into the current state of ransomware in the retail sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dLsyKUmfM3X61Zdq3YwT6V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rMwTrMcckMGK2r23WND6KW-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Aug 2021 14:16:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/rMwTrMcckMGK2r23WND6KW-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper front cover]]></media:description>                                                            <media:text><![CDATA[Whitepaper front cover]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper front cover]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rMwTrMcckMGK2r23WND6KW-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AgqnvbQpJyPje4qg3Xqb2Q" name="" alt="Sophos logo" src="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q.png" mos="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Along with the education sector, retail was the biggest industry affected by ransomware during 2020. As some retailers began trading online for the first time during the pandemic, and others saw an increase in their web traffic and online purchases, cyber criminals took advantage of the opportunities presented to them.</p><p>Managing this increase in security challenges, with many retailers still using legacy security systems, meant IT team’s cybersecurity workload increased by over 70%; also increasing their security knowledge and skills in the meantime.</p><p>Download this report and discover insights into the prevalence of ransomware within the retail sector, the associated costs and how retailers can be ready to face future threats.</p><p><em>.</em></p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/sophos-abm-leads?locale=1&p=false&wp=7200"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos XG 230 Rev.2 review: Powerful and flexible ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible</link>
                                                                            <description>
                            <![CDATA[ This high-performance UTM appliance boasts extensive cloud management and remote-security services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mkwc6fB56akTVPe51CgB8R</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/V7eNyr8gNmyagDRTeHKUkk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Apr 2021 12:03:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/V7eNyr8gNmyagDRTeHKUkk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos XG 230 Rev.2]]></media:description>                                                            <media:text><![CDATA[Sophos XG 230 Rev.2]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos XG 230 Rev.2]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/V7eNyr8gNmyagDRTeHKUkk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This short-depth rack appliance is designed to keep up with busy networks. Along with a feast of copper and fibre network ports, Sophos’ XG 230 Rev.2 claims a mighty 32Gbits/sec raw firewall throughput – even with all of the security services enabled, it still pumps traffic through at a speedy 4.5Gbits/sec. </p><p>There’s room to grow further too, thanks to an internal expansion bay that supports eight different Flexi modules, with options ranging from PoE provision up to 10GbE and 40GbE connections. For redundancy, the appliance can accept an optional second power supply and a pair of network bypass ports to keep the traffic flowing even if UTM functions are temporarily disabled for any reason.</p><p>The price above is based on a three-year Sophos TotalProtect Plus subscription, a comprehensive SMB package that enables all network, web, email and web server protection services, along with Sandstorm cloud sandbox and FullGuard Plus support. The appliance also links up with <a href="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it" data-original-url="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it">the Sophos Central service</a>, which extends protection to external endpoints and adds cloud management capabilities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/354852/sophos-xg-135w-rev-3-review-the-full-package" data-original-url="/security/unified-threat-management-utm/354852/sophos-xg-135w-rev-3-review-the-full-package">Sophos XG 135w Rev. 3 review: The full package</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/359037/it-pro-panel-does-ai-have-a-place-in-security" data-original-url="/technology/artificial-intelligence-ai/359037/it-pro-panel-does-ai-have-a-place-in-security">IT Pro Panel: Does AI have a place in security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/355443/sophos-fixes-firewall-bug-being-actively-exploited-by-sql" data-original-url="/security/zero-day-exploit/355443/sophos-fixes-firewall-bug-being-actively-exploited-by-sql">Sophos fixes firewall bug being actively exploited in SQL injection attacks</a></p></div></div><p>Clearly there are plenty of features to get to grips with, but the XG 230’s web console gets you off to a flying start with an installation wizard that secures admin access, configures the network ports, runs a firmware upgrade and applies a base security policy. Once your basic setup is in place, the console’s Control Center dashboard is equally impressive, providing a clear overview of network activity and security issues, with graphs showing web traffic and detected network attacks, as well as details of blocked and allowed applications and web categories.</p><p>Setting up remote management is easy as you can connect the appliance to your Sophos Central cloud account directly from the web console. Once authenticated, the cloud portal provides the same console as the local one, with live report dashboards and full access to all management features.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qtfnKt2RhXHrgYP7iruebS" name="" alt="Sophos XG 230 Rev.2 rear" src="https://cdn.mos.cms.futurecdn.net/qtfnKt2RhXHrgYP7iruebS.jpg" mos="https://cdn.mos.cms.futurecdn.net/qtfnKt2RhXHrgYP7iruebS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>It’s very pleasing to see that any external devices running the Sophos Central endpoint agent appear automatically in the console, with no need for manual enrolment. Sophos’ Synchronized Security platform uses a “heartbeat” service to keep all supported products on the same page, with the synchronised application control feature automatically finding any unknown applications on remote endpoints and pushing out firewall policies to control them.</p><p>The appliance’s numerous ports can be grouped into various zones, providing a straightforward way to apply different security policies across groups of users and devices. If a device is reported as compromised, a setting in the firewall policy can immediately isolate all systems in the same zone.</p><p>Aside from that, you can set up firewall rules for sources and destinations, service filters, blocking actions and time schedules, and apply custom policies for web filtering, intrusion detection, email and application controls.</p><p>Those web-filtering options extend to 90 categories of URL that can be individually blocked or allowed, while the application controls currently support a whopping 3,530 predefined policies – including 73 just for Facebook activities. The Sandstorm feature intercepts any unknown files and sends them to a cloud sandbox, only allowing them to run locally if they’re deemed to be safe.</p><p>Although the appliance has no built-in Wi-Fi capabilities, it can function as a central controller for Sophos wireless APs, and it also supports Sophos’ SD-RED (Remote Ethernet Device) appliances, which let you easily extend your security policies to external offices. Just register your SD-RED box with the appliance, then ship it to a remote site and it will automatically set up an encrypted connection and start protecting traffic.</p><p>Overall, the Sophos XG230 Rev.2 is a powerful and flexible security appliance that’s well suited to SMBs. It’s packed with security measures while being easy to deploy, and Sophos Central integration provides great remote management and security for external users.</p><h2 id="sophos-xg-230-rev-2-specifications">Sophos XG 230 Rev.2 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >1U rack chassis</td></tr><tr><td  ><strong>CPU</strong></td><td  >3.3GHz Intel Pentium G4400 CPU</td></tr><tr><td  ><strong>Memory</strong></td><td  >8GB DDR4</td></tr><tr><td  ><strong>Storage included</strong></td><td  >128GB SATA SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >6 x copper Gigabit Ethernet, 2 x SFP Gigabit</td></tr><tr><td  ><strong>Other ports</strong></td><td  >HDMI, 3 x USB 3, RJ-45 serial, expansion slot</td></tr><tr><td  ><strong>Management</strong></td><td  >Sophos Central</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos Central Endpoint Protection review: Because you’re worth it ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it</link>
                                                                            <description>
                            <![CDATA[ It’s a tad pricey, but Sophos offers versatile user-based protection and the best mobile security around ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h68Yz2yVSQsn5iHJrv8xZq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Lez9fCitr8jMKFBgxthtHW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Aug 2020 09:51:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Lez9fCitr8jMKFBgxthtHW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[screenshot of sophos endpoint protect in use]]></media:description>                                                            <media:text><![CDATA[screenshot of sophos endpoint protect in use]]></media:text>
                                <media:title type="plain"><![CDATA[screenshot of sophos endpoint protect in use]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Lez9fCitr8jMKFBgxthtHW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sophos was one of the first security specialists to embrace cloud-managed endpoint protection, and over the years its Central solution has evolved into something impressively sophisticated. The cloud portal works with more or less every security component Sophos has to offer, providing one-stop management for all workstations, servers and mobile devices.</p><p>It opens with a handy dashboard view showing the most recent alerts, a summary of devices and users, plus details of how your access controls are performing. A menu at the side provides swift access to individual protection components, and if you have a Sophos firewall it can also be managed from here.</p><p>The deployment process is clever too. You can download the agent from the portal and install it the old-fashioned way, which takes about ten minutes – but if your users are set up on Active Directory, you can use the Sophos AD Sync tool to import users and groups into the portal, then email installation links to everyone with just a few clicks. Active Directory integration then allows you to create security policies that follow users around, regardless of which device they’re logged into.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/355932/keep-yourself-protected-with-out-list-of-the-best-security-suites" data-original-url="/security/cyber-security/355932/keep-yourself-protected-with-out-list-of-the-best-security-suites">Keep yourself protected with our list of the best security suites</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/356467/kaspersky-endpoint-security-cloud-review-merciless-against" data-original-url="/security/endpoint-security/356467/kaspersky-endpoint-security-cloud-review-merciless-against">Kaspersky Endpoint Security Cloud review: Merciless against malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/356418/avast-business-antivirus-pro-plus-review-a-balanced-security" data-original-url="/security/endpoint-security/356418/avast-business-antivirus-pro-plus-review-a-balanced-security">Avast Business Antivirus Pro Plus review: A balanced security suite</a></p></div></div><p>Protection starts as soon as the agent is installed, with a base security policy applied to everything. Real-time scanning and automatic cleanup are enabled (with live protection ensuring that the agent has the latest threat information from Sophos’ labs), and all internet traffic and downloads are monitored.</p><p>Web controls can be applied to selected users too. Four predefined URL-filtering policies are supplied, but it’s easy to tweak these or create new policies of your own. These can include web restrictions, blocking adverts and risky downloads and blacklisting specific URLs, IP address ranges and site categories.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RpVV4hrNM6KbUNrDZo4tr9" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/RpVV4hrNM6KbUNrDZo4tr9.jpg" mos="https://cdn.mos.cms.futurecdn.net/RpVV4hrNM6KbUNrDZo4tr9.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Application usage is controlled in much the same way. Sophos provides a list of over 1,000 apps to choose from, in categories ranging from browser plugins and email clients to encryption tools and FTP clients. You can completely block access to particular applications or merely monitor and log their use. </p><p>Another noteworthy feature of the software is its <a href="https://www.itpro.com/data-loss-prevention/28864/data-recovery-why-is-it-so-important" data-original-url="https://www.itpro.com/data-loss-prevention/28864/data-recovery-why-is-it-so-important">data-loss prevention</a> option, which prevents users from transferring files containing sensitive data, such as bank account details or personally identifiable information. We tested this by trying to email a spreadsheet containing personal email addresses outside of the organisation and found that the Sophos agent wouldn’t even let us attach the file.</p><p>The one area where Sophos proved a little erratic was alerting. During our tests we found that warnings about web-policy violations could take up to 50 minutes to appear in the portal dashboard and reports. The most important messages get through quickly, though: when we dropped our malware samples onto our test workstations, high-priority alerts appeared in the portal in one minute flat, with email warnings flying in shortly afterwards.</p><p>It’s also worth highlighting that the standard licence only covers workstations. If you want server protection, that’s an optional extra, starting at £69 per server per year. This works in just the same way as the desktop version, with the agent detecting the OS when it installs and configuring itself as needed.</p><p>Mobile coverage is another optional extra, but one that’s well worth considering, as the device management controls are stunningly good. Once we’d set up an APN, we were able to control virtually every feature and app on our iPads with remote locate, lock and wipe services all available.</p><p>No doubt about it, Sophos Central Endpoint Protection isn’t the cheapest option, especially if you’re looking to protect your entire hardware stack. Even so, its excellent protection features, user-centric policies and well-designed cloud portal make it a very appealing solution.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos XG 125w review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/firewalls/31925/sophos-xg-125w-review</link>
                                                                            <description>
                            <![CDATA[ The XG 125w is a no-compromises gateway security appliance that delivers a wealth of protection measures at a great price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k9fhCmmAyFTsPpxorZhA46</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6kggM55Hfag7xdBfiLnbXM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Sep 2018 08:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Firewalls]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6kggM55Hfag7xdBfiLnbXM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6kggM55Hfag7xdBfiLnbXM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SMEs that want centralized network protection need look no further than Sophos' XG 125w as this gateway appliance is packed to the rafters with security features. It's no performance lightweight either, claiming a high raw firewall throughput of 6.5Gbits/sec and 1.5Gbits/sec with all UTM functions enabled.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29593/panda-adaptive-defense-360-review" data-original-url="/security/29593/panda-adaptive-defense-360-review">Panda Adaptive Defense 360 review: Security in black and white</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30411/sophos-xg-450-review" data-original-url="/security/30411/sophos-xg-450-review">Sophos XG 450 review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/wifi-hotspots/31788/tp-link-omada-eap225-v3-review-scalable-wireless-at-a-giveaway-price" data-original-url="/wifi-hotspots/31788/tp-link-omada-eap225-v3-review-scalable-wireless-at-a-giveaway-price">TP-Link Omada EAP225 V3 review: Scalable wireless at a giveaway price</a></p></div></div><p>The XG 125w offers eight copper Gigabit and an SFP fibre Gigabit port, while its expansion bay accepts optional DSL, 3G/4G or Gigabit SFP modules. It also provides 2.4GHz/5GHz 11ac wireless services with support for multiple virtual SSIDs and hotspot guest access facilities.</p><p>Installation is a doddle; the web browser quick start wizard guided us through securing administrative access, setting up the LAN and WAN ports plus a secure wireless network and adding an email address for alerting. We opted for the default routed mode of operation as we wanted the appliance to provide all security functions including firewalling.</p><p>The base appliance has firewall, VPN, authentication and secure wireless management services enabled with a perpetual license. The price we've shown includes a 3-year TotalProtect subscription which actives the network, web, email and web server protection modules while a TotalProtect Plus subscription adds Sophos' Sandstorm feature which uses cloud sandbox technology to mitigate zero-day threats.</p><p>The wizard creates a base set of security policies to enable anti-malware scanning and web filtering for common sets of undesirable categories. The intuitive console makes it easy to customise security, where we could group ports into zones, apply firewall rules to sources and destinations and add service filters, blocking actions and time schedules.</p><p>From the Protect section of the console, you can create security policies for web filtering, IDP, email and application controls. Web filtering offers over 100 URL categories while the application controls provide 3,200 predefined apps, and policies are swiftly applied by selecting them in your firewall rules.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hqHp69qqReiFexALUsC3t7" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/hqHp69qqReiFexALUsC3t7.jpg" mos="https://cdn.mos.cms.futurecdn.net/hqHp69qqReiFexALUsC3t7.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Sophos' identity-based security opens up many extra security features. With this in action, we could apply Internet access and bandwidth usage policies, enforce data transfer limitations on uploads and downloads and have different daily, weekly, monthly and yearly limits for individual users and groups.</p><p>It's easy to implement; users authenticate to an external directory server or log in to the appliance using the free Sophos Client Authentication Agent (CAA). This can be downloaded directly from the appliance's captive web portal, which also has links for Linux and macOS clients plus certificates for Android and iOS mobiles.</p><p>We already use the Sophos Central cloud security service and loved the appliance's Security Heartbeat feature. All we needed to do was enter our Sophos Central credentials in the appliance's console and after registration, all our endpoint activity data was sent to the appliance, which displayed coloured status icons in the console's dashboard.</p><p>Minimum heartbeat conditions can be linked to firewall policies so if any remote endpoint detects a threat, the policy can immediately isolate all users and devices in the same zone. You can also use the SAC (synchronized application control) feature which detects unknown apps on Sophos Central endpoints and tames them with firewall policies.</p><p>The appliance's iView syslog server provides a wealth of free reporting facilities from the same console. With data logging enabled in our firewall policies, we could view graphs and charts on firewall, virus, spam, web content filtering and user activity, plus pull up a range of data protection compliance reports.</p><p>Along with a pleasantly swift deployment, the XG 125w impressed us with its depth of security features. Adding in its seamless integration with Sophos Central, the high performance and integral 11ac wireless services makes it our recommended gateway security appliance for SMEs.</p><h2 id="verdict">Verdict</h2><p>Along with a pleasantly swift deployment, the Sophos XG 125w impressed us with its depth of security features. Adding in its seamless integration with Sophos Central, the high performance and integral 11ac wireless services makes it our recommended gateway security appliance for SMEs.</p><p>Desktop chassis</p><p>1.6GHz Intel Atom C3508</p><p>4GB RAM</p><p>64GB SATA SSD</p><p>8 x Copper Gigabit, 1 x SFP Gigabit</p><p>2.4GHz/5GHz 802.11ac wireless</p><p>3 x 3 MIMO</p><p>3 x external aerials</p><p>HDMI</p><p>2 x USB 2</p><p>Micro USB</p><p>RJ-45 serial</p><p>Expansion slot</p><p>External PSU (max 2)</p><p>320 x 212 x 44mm (WDH)</p><p>3 year hardware warranty</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Majority of local authorities aren't secured against cyber threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/25062/majority-of-local-authorities-arent-secured-against-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ And the attitudes of public sector employees when it comes to security stink, according to research ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5YWhicUUMCGfbwAhGw2JEq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ohG2gLvS6sf2Cf7Vd8AHyN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Jul 2015 07:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ohG2gLvS6sf2Cf7Vd8AHyN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security Francis Maude]]></media:description>                                                            <media:text><![CDATA[Cyber security Francis Maude]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security Francis Maude]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ohG2gLvS6sf2Cf7Vd8AHyN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Just 41 per cent of local government employees think their systems would suitably secure their organisation against cyber threats, while 50 per cent have no idea whether their systems are prepared or not.</p><p>That's the worrying picture painted by a SophOS study, which surveyed just shy of 3,000 local government and police workers about their attitudes towards cyber threats and security.</p><p>The results revealed that although the possibility and variety of attacks have increased, budget cuts mean they are not particularly well protected against threats.</p><p>Although the biggest cuts have been to workforce numbers, with just over two-thirds (67 per cent) claiming job losses provided the biggest savings, frontline services came in slightly behind with 63 per cent saying their department had been affected by the reduction of such services.</p><p>Some 62 per cent of respondents said they were planning on making cuts to IT services or merging IT with other departments or local governments on IT resources to save money and this will have a knock-on impact on security.</p><p>However, almost half of the people questioned said they had increased awareness of data security after they had learned about high profile attacks happening to other governments and upcoming EU legislation.</p><p>Data loss is the public sector workers' main security concern, while remote access and targeted attacks were secondary worries.</p><p>"With cyber crime at an all-time high and public sector budgets reducing year-on-year, it's more important than ever that organisations maximise the resources available to them," James Vyvyan, regional vice president of Sophos UK and Ireland, said.</p><p>"There is a clear trend towards local authorities partnering with neighbouring authorities to increase and implement shared services. This collaborative approach is certainly helpful in the fight against cyber crime. Our research indicates that local authorities and police may also be missing the opportunity to consolidate their IT and security technologies, which can deliver further savings, helping to protect jobs and frontline services. "</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Foursys adds trio of security vendors to line-up ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/364996/foursys-adds-trio-of-security-vendors-to-line-up</link>
                                                                            <description>
                            <![CDATA[ Security VAR Foursys adds Secunia, SecurEnvoy and Rapid7 to portfolio ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ewFCqDocqrDcB7s2s5JaQU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4mhhcUHaNuRid3BUSy9QXK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 May 2015 10:54:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4mhhcUHaNuRid3BUSy9QXK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Business partnership tree puzzles]]></media:description>                                                            <media:text><![CDATA[Business partnership tree puzzles]]></media:text>
                                <media:title type="plain"><![CDATA[Business partnership tree puzzles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4mhhcUHaNuRid3BUSy9QXK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security reseller <a href="https://www.foursys.co.uk" target="_blank">Foursys</a> has taken on three new vendors as it plans to grow its business over the next year.</p><p>It has signed up <a href="http://secunia.com" target="_blank">Secunia</a>, which provides vulnerability management through application and operating system patching, two-factor authentication provider <a href="https://www.securenvoy.com" target="_blank">SecurEnvoy</a>, and <a href="http://www.rapid7.com" target="_blank">Rapid7</a>, which offers security data and analytics software and services.</p><p>The three new vendors join Foursys’ existing vendors <a href="https://www.sophos.com/en-us.aspx" target="_blank">Sophos</a>, <a href="http://www.clearswift.com" target="_blank">Clearswift</a>, <a href="http://www.websense.com/content/home.aspx" target="_blank">Websense</a> and <a href="http://www.forescout.com" target="_blank">Forescout</a>.</p><p>James Miller, Foursys managing director, says the additional technology vendors were selected based on their technical merits.</p><p>“We always select new technology partners that have a specific channel focus, that can partner with us to provide a strong, complementary fit with our existing security portfolio and who can ultimately add value for our current clients,” he says.</p><p>Adam Bruce, Northern Europe channel manager at SecurEnvoy describes Foursys as “a good fit”, pointing to the VAR’s close relationship with Sophos, “as our technology integrates closely with both the Sophos Safeguard and UTM products.</p><p>For Secunia, the deal extends the vendor’s footprint in the UK and Ireland: “We are delighted to be working with Foursys as a technically advanced and customer-centric security VAR, and we look forward to adding new value to their existing client service offerings,” comments Victoria Bentham, Secunia’s UK regional director.</p><p>“We are delighted to partner with Foursys,” adds Rob Attree, EMEA sales director for Rapid7. “The company has a proven record of bringing impactful security solutions to market to help their customers implement effective security programmes.”</p><p>A year after its directors completed a management buy-out of the company, Foursys has moved its headquarters from Cambridge to new premises in Bury St Edmunds, offering a threefold increase in office space.</p><p>The 15 new jobs at the firm are being created to cover a range of roles in security consulting, support, sales and administration.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos Cloud review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/23715/sophos-cloud-review</link>
                                                                            <description>
                            <![CDATA[ Sophos provides compelling reasons for moving your endpoint security into the cloud ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xbFkWG16C9HaJpST7de6zK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zJq3TiMHPyfcM9XE9AQsYF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Jan 2015 09:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zJq3TiMHPyfcM9XE9AQsYF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zJq3TiMHPyfcM9XE9AQsYF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Endpoint security has traditionally been a tough nut to crack across businesses of all sizes as many solutions have a reputation for being difficult to deploy, a nightmare to manage and inconveniently expensive. These problems are exacerbated by the exponential growth of corporate mobile devices making it nigh on impossible to protect them all.</p><p>Worry not as the cloud is coming to the rescue of businesses frightened off by these concerns and Sophos Cloud is one of best solutions we've yet seen. Along with cloud managed anti-malware, web filtering and removable device controls, it offers tough security measures for iOS and Android devices. </p><p>It's also a top choice if you want your security policies to apply to users as well as devices. In our books, this makes Sophos Cloud highly versatile as we used it to create security policies that followed users regardless of which device they logged in from.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vmgQD4eEycr56DuTZuRng7" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/vmgQD4eEycr56DuTZuRng7.png" mos="https://cdn.mos.cms.futurecdn.net/vmgQD4eEycr56DuTZuRng7.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The Sophos Cloud portal provides plenty of information about endpoint security events and alerts.</p><p><strong>Slick cloud portal</strong></p><p>After signing up we were provided with our own dedicated cloud portal which gave us access to every feature. Its dashboard comprises three big panels with clear overviews of all alerts, activities and web stats. </p><p>The next tab provides views of your users, groups and devices plus options to enable iOS support. It's here that you also create security policies and monitor Active Directory users and groups.</p><p>The new server protection feature applies custom policies to these systems. They are more basic than standard policies but provide a range of tough measures including real-time and scheduled malware scanning, automatic blocking of known malicious web sites and Sophos' HIPS (host intrusion prevention system) which watches out for suspicious program behaviour.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RPw5jxyK8vVpzHjXq5rBt6" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/RPw5jxyK8vVpzHjXq5rBt6.png" mos="https://cdn.mos.cms.futurecdn.net/RPw5jxyK8vVpzHjXq5rBt6.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Web filtering works well and, if permitted, users can play with the Sophos client software</em></p><p><strong>Lengthy deployment</strong></p><p>For testing we used the main lab network headed up by a Windows Server 2012 R2 Active Directory domain controller running the Hyper-V role and hosting an Exchange 2013 VM. For desktops we used a bunch of Windows 7, 8 and 8.1 hosts while for mobile testing we used an iPad 4.</p><p>Software deployment to our Windows systems was lengthy as the installer utility downloads the entire 156MB agent package for each one. A single install took up to 15 minutes whereas simultaneous installs on four devices took a total of 25 minutes.</p><p>It speeded up after this, though, as the agent was preconfigured for our account and each system appeared in the portal in seconds. Sophos also adds details of the current user logged in when the agent was installed and we used the new AD Sync tool to import users from our AD server.</p><p>We had problems with AD Sync's secure LDAP mode as it refused to access our server. Online help is minimal but we fixed it by selecting non-secure LDAP mode and changing the port number.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GXGx2MCEcJxMFf5eYXH7Z7" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/GXGx2MCEcJxMFf5eYXH7Z7.png" mos="https://cdn.mos.cms.futurecdn.net/GXGx2MCEcJxMFf5eYXH7Z7.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>After importing our AD users we could assign custom security policies to each one</em></p><p><strong>Policies and performance </strong></p><p>Despite the focus on user-based protection, static devices such as desktops aren't left out in cold as a base security policy is applied to everything. The real-time malware scanner is enabled by default, access to removable media can be restricted or monitored and anti-tamper controls are active.</p><p>For web filtering, we could tweak the base policy or create new ones and choose from a wide range of settings. These include blocking dodgy file downloads, using one of four predefined URL filtering policies or setting our own web usage restrictions.</p><p>Alert responses are fast as after introducing real malware to our clients, the Action Center pane changed to red alert status in only 25 seconds. This was the same amount of time it took to push out a global USB storage device block policy.</p><p>A remote quick scan request to a Windows Server 2012 R2 system was fired up in less than 20 seconds and completed in 5 minutes while a locally run full scan of its 72GB system drive took 47 minutes. Sophos is a safe pair of hands as well with it scoring 96% for AV-Test's zero-day detection and returning a clean sheet in the widespread malware test.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qoh5HztRWYrCajzgaYQJa" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/qoh5HztRWYrCajzgaYQJa.png" mos="https://cdn.mos.cms.futurecdn.net/qoh5HztRWYrCajzgaYQJa.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Sophos offers extensive mobile device security features and includes options for iOS remote locks and wipes</em></p><p><strong>BYOD beware</strong></p><p>For mobile devices controls, iOS gets the lion's share. Along with passcode and complexity enforcement, we could control access to features such as the App Store, camera, screenshots and iCloud backup. </p><p>We also used policies to control which wireless networks mobile users could connect to and request alerts if their OS versions weren't up to date. Web filtering rules are on the cards and policies can be used to set company Exchange Server credentials.</p><p>Deployment to our iPad 4 required an Apple Push Certificate created and a download link for iOS emailed to the mobile user via the cloud portal. Once the Sophos Mobile Control app connected, it enforced our passcode policy, controlled access to apps by removing the icons for blocked ones and allowed us to issue remote lock and wipe commands from the portal. </p><p><strong>Conclusion</strong></p><p>Sophos Cloud is more expensive than products such as Trend Micro's Worry-Free cloud service but it beats everyone soundly for features. Its lightning quick portal, user based policies and top-notch mobile device support earns it a well-deserved Editor's Choice award.</p><h2 id="verdict-2">Verdict</h2><p>Combine the well-designed web portal, user based policies and top-notch mobile support and you have a quality cloud endpoint security solution. Sophos Cloud isn’t the cheapest but we think it’s well worth the extra outlay.</p><p><strong>Agent:</strong> Windows XP Pro and Server 2003 upwards, Mac OS X 10.7 upwards. Mobile: iOS 7, Google Android 4.0 upwards</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ In web browsers we should not trust ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22788/in-web-browsers-we-should-not-trust</link>
                                                                            <description>
                            <![CDATA[ Davey Winder explains why end users should be wary of putting too much trust in their chosen web browser ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pUcJtfUp7i8X1vYn4BVLgU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HWrxtXTtQpxRiDCRNEY4ok-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Jul 2014 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Web Browsers]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HWrxtXTtQpxRiDCRNEY4ok-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A mouse cursor hovering over a web page url bar]]></media:description>                                                            <media:text><![CDATA[A mouse cursor hovering over a web page url bar]]></media:text>
                                <media:title type="plain"><![CDATA[A mouse cursor hovering over a web page url bar]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HWrxtXTtQpxRiDCRNEY4ok-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security vendor Sophos published details of a 'trustworthy browser poll' last week, with a headline proclaiming Firefox "slams Chrome again" in the results.</p><p>Indeed it did, with 48 per cent of the 3,400 participants trusting it most. This compared with 27 per cent for Chrome, eight per cent for Safari, 7.4 per cent for Internet Explorer and just five per cent for Opera.</p><p>The remaining 4.6 per cent trusted browser clients such as Tor, Comodo Ice, Chromium and even Lynx, for those of you with a really long memory that stretches back as far as the text-only world wide web.</p><p>This last percentage group of stragglers also included the client we should all trust the most: none.</p><div><blockquote><p>If your employees work at home or outside the office, you need to be asking the question: do you trust them to be doubtful about the clients they use to access corporate data?</p></blockquote></div><p>My advice would be the level of trust we place in any given browser client is irrelevant at best and dangerous at worst. To trust a web browser client is, frankly, security suicide.</p><p>What the poll was really harvesting is data on the browser client the participants mistrusted the least. It's a subtle difference, you may think, but it's an important one. No web browser client can be trusted, and all should be viewed with more than just a degree of caution.</p><p>Interestingly, the Facebook group where the poll appeared seems to share this view, if the comments there (and the accompanying post on the Sophos blog) are anything to go by.</p><p>User mistrust was refreshingly high, with some informed folk insisting they regularly use VMs for security when browsing. Others, however, admitted they didn't trust their browser yet seemed resigned to sacrificing their concerns at the alter of usability.</p><p>Within the enterprise, admin will know all too well about the best methods of using a browser within a security-centric ecosystem to minimise the risk of compromise.</p><p>What interests me most about this poll is that Sophos is primarily known as a vendor of security protection to the business sector, so the users who responded are (one imagines) business users.</p><p>The talk of trust is one that scares me, and the security to convenience ratio should scare you as well. If, like so many organisations today, your employees work at home or outside of the office, you need to be asking the question: do you trust them to be doubtful about the clients they use to access corporate data?</p><p>I think you know what the answer is, and that should prompt you to be ensuring that your BYOD and remote working security policy and risk mitigation infrastructure are up to scratch. Trust me on this one...</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos works on its delivery ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/364993/sophos-works-on-its-delivery</link>
                                                                            <description>
                            <![CDATA[ Sophos exec reveals vendor wants to improve ways partners can deliver services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t68zfQQfMhicaaF14WBjdw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Apr 2014 18:32:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christine Horton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos logo]]></media:description>                                                            <media:text><![CDATA[Sophos logo]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security vendor <a href="http://www.sophos.com/en-us" target="_blank">Sophos</a> has revealed plans to improve its delivery processes to make life easier for partners, especially those providing services to small businesses.</p><p>Speaking to <em>Channel Pro</em>, Sophos’ channel director, James Vyvyan, says the vendor’s focus is on “designing our solutions so that they are easy for partners to deliver and manage.”</p><p>He says: “For example, two of our UK partners are on the beta programme for our upcoming UTM product [Sophos acquired UTM vendor Astaro in July 2011], which means they are directly plugged into the people designing and making our products and can feedback from a partner perspective. This is important because if partners can deliver services in a cost-efficient way they will obviously make more money.”</p><p>With the exception of “three or four” accounts worldwide, the vendor pushes all its products through the channel, including £40m worth of business through its UK partners.</p><p>Half of this figure is generated by Sophos’ top 15 partners, says Vyvyan (pictured), who adds this same group – which includes firms such as <a href="http://www.softcat.com" target="_blank">Softcat</a>, <a href="http://www.trustmarquesolutions.com" target="_blank">Trustmarque</a>, <a href="http://www.phoenixitgroup.com/Phoenix_IT_Group/Home.aspx?id=3" target="_blank">Phoenix IT</a>, <a href="http://uk.insight.com" target="_blank">Insight</a>,<a href="http://www.tsg.com" target="_blank"> TSG</a> and <a href="http://www.scc.com" target="_blank">SCC</a> – has tripled their Sophos business over the past three years. He cites Softcat as an example, which did £2m of Sophos business in FY11, and finished on £3.3m in FY12.</p><p>The firm is currently identifying “the right type of partner” to join this top strategic tier. Vyvyan says this could be a VAR or managed service provider, dependent on the firm’s skills and reach. “Our focus is on a few partners and getting it really right with them. I would love to add two or three partners to that but only if they add value and quality,” he explains.</p><p>Sophos splits its channel organisation into ‘Solution Partner’, for volume sales, and ‘Strategic’, its VAR business. Vyvyan reveals the vendor is bulking up both with additional channel support. As well as the recent addition of two internal account managers to its Solution Partner channel, the vendor is looking to recruit a third, as well as a new field-based channel account manager to help develop its strategic channel.</p><p>“In order to meet global sales expectations we need to use the channel more, [but] in the UK we’re a long way down the road in comparison to the rest of the world,” claims Vyvyan.</p><p>The channel exec also hinted at further changes to be announced within the Sophos partner programme during the coming months.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos boosts UTM portfolio with Cyberoam acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/acquisition/364995/sophos-boosts-utm-portfolio-with-cyberoam-acquisition</link>
                                                                            <description>
                            <![CDATA[ Cyberoam purchase set to bolster Sophos' UTM credentials ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i2Ap9NGtVj7gMB6we7Hv1Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Feb 2014 15:32:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos logo]]></media:description>                                                            <media:text><![CDATA[Sophos logo]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AgqnvbQpJyPje4qg3Xqb2Q-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="http://www.sophos.com" target="_blank">Sophos</a> is set to boost it’s network security credentials with the acquisition of Indian network security vendor <a href="http://www.cyberoam.com" target="_blank">Cyberoam</a>.</p><p>The deal will add Cyberoam’s unified threat management (UTM), next-generation firewall and network security expertise to Sophos’ existing portfolio of products.</p><p>According to Kris Hagerman, CEO at Sophos, Cyberoam’s ‘channel first’ strategy and its pedigree in service and support was a key element for the acquisition: “The acquisition expands and accelerates our network security roadmap to grow our presence in UTM, advanced threat protection, wireless and next generation firewall,” he says.</p><p>In terms of integration, Sophos says it will be business as usual with no changes expected for either company’s UTM roadmap this year.</p><p>Hemal Patel, CEO of Cyberoam states that together, Cyberoam and Sophos form a powerhouse in network security. “Our global footprint, commitment to the channel and complete security portfolio are clear competitive differentiators.”</p><p>British firm Sophos had previously <a href="https://www.channelpro.co.uk/news/security/2549/sophos-gets-utm-bandwagon-astaro-acquisition" target="_blank">acquired UTM specialist Astaro in 2011</a>.</p><p>There has been no word on the cost of the deal.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tumblr spammers blast blog site over slow response to attack warning ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/644488/tumblr-spammers-blast-blog-site-over-slow-response-to-attack-warning</link>
                                                                            <description>
                            <![CDATA[ Blogging platform falls victim to spammers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HJkb6at1CHnkZUypotYfZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t2cMUd9yCWBF4pMxxyouGP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Dec 2012 13:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t2cMUd9yCWBF4pMxxyouGP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hackers]]></media:description>                                                            <media:text><![CDATA[Hackers]]></media:text>
                                <media:title type="plain"><![CDATA[Hackers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t2cMUd9yCWBF4pMxxyouGP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The group responsible for carrying out an attack on Tumblr, which resulted in abusive messages being posted on thousands of users' blogs, claim they warned the site an attack could happen weeks ago.</p><p>The blogging site was hit by a spamming group called GNAA yesterday who used the platform to post a 200-word anti-Tumblr rant on thousands of the firm's blogs.</p><p>"This is in response to the seemingly pandemic growth and worldwide propagation of the most F******G WORTHLESS, CONTRIVED, BOURGEOISIE, SELF-CONGRATULATING AND DECADENT B******T THE INTERNET EVER HAD THE MISFORTUNE OF FACILITATING," the post stated.</p><p>We contacted Tumblr two weeks ago...but they never got back to us.</p><p>In an interview with news site <em>Gawker</em>, <a href="http://gawker.com/5965196/hackers-behind-tumblr-worm-say-they-warned-tumblr-of-vulnerability-weeks-ago?tag=the-internet" target="blank">a person reporting to be a GNAA spokesperson</a>, said the group warned Tumblr an attack could take place weeks ago.</p><p>"Someone would have done a lot worse than just posting a message over and over if they didn't fix it right away," said the spokesperson.</p><p>"We contacted Tumblr about it about two weeks ago. We used the 'can't find what you're looking for' link at the bottom of the email troubleshooting page. They never got back to us."</p><p>The site is used to publish more than 70 million posts a day and reportedly hosts nearly 71 million blogs.</p><p>In a blog post, a Tumblr spokesperson said the firm had moved quickly to resolve the issue.</p><p>"We quickly identified the source, removed the posts, and restored service to normal," the post stated.</p><p>"No accounts have been compromised, and you don't need to take any further action."</p><p>In a further post on the Naked Security blog, Graham Cluley, senior technology consultant at security software vendor Sophos, was able to shed some light on how the attack was carried out.</p><p>"The worm took advantage of Tumblr's reblogging feature, meaning that anyone who was logged into Tumblr would automatically reblog the infectious post if they visited one of the offending pages," wrote Cluley.</p><p>"Each affected post had some malicious code embedded inside them...If your computer was logged into Tumblr, it would result in the GNAA content being reblogged on your own Tumblr," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DataFort Hi-5 disaster recovery review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/644320/datafort-hi-5-disaster-recovery-review</link>
                                                                            <description>
                            <![CDATA[ If you can’t afford to have your critical systems down for more than two hours then DataFort’s Hi-5 can make your businesses a success rather than just another sad statistic. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nbTEYX9cM7RuT1QJsBeeS3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oUXVSWo9BKhXGWoYtYLJuj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 26 Nov 2012 08:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oUXVSWo9BKhXGWoYtYLJuj-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[DataFort Hi-5]]></media:description>                                                            <media:text><![CDATA[DataFort Hi-5]]></media:text>
                                <media:title type="plain"><![CDATA[DataFort Hi-5]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oUXVSWo9BKhXGWoYtYLJuj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The cloud lends itself perfectly to offsite disaster recovery with and businesses have an enormous choice of hosted backup services.</p><p>DataFort's Hi-5 (www.datafort.com) differs from the majority as it's designed to provide on-site and off-site protection. In the event of a total disaster a business will be able to reinstate your critical systems and services either on-premises or in the cloud.</p><p>It also uses a pricing structure based only on the number of systems to be protected and not on the amount of data being stored offsite. This is preferable to capacity based solutions as all costs are up front and will only increase if you add more systems to the scheme.</p><p>Hi-5 is DataFort's premium disaster recovery service and is designed for businesses that can't tolerate more than two hours of total downtime. Costs start at 500 per server per month and this includes cloud disaster recovery invocation. If access to your premises is denied, DataFort will invoke VMs of your critical systems at its remote site and make them available to your users over the Internet.</p><h2 id="hi-5-deployment">Hi-5 deployment</h2><p>To test Hi-5, we arranged for an engineer to come down to our lab at an agreed time and deploy the hardware. We were supplied with an HP ProLiant DL160 G6 1U rack server configured to take image based backups of our chosen systems every fifteen minutes. You don't touch the appliance as this is deployed headless and managed remotely by DataFort.</p><p>For our test systems we used a Windows Server 2008 R2 system running Hyper-V. Within this we had one VM running Server 2008 R2 as a PDC providing file and print services and another running Microsoft Exchange Server 2010.</p><p>The DataFort engineer set the local Hi-5 appliance to protect both systems. Initially, full image backups are taken and then updated regularly using snapshots. For cloud recovery, all data is replicated to DataFort's remote vaults and to speed things up the engineer can take an encrypted copy of the data back to HQ to seed the vault.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qDf9dGvHPw6tVfPRnkPLGf" name="" alt="DataFort Hi-5" src="https://cdn.mos.cms.futurecdn.net/qDf9dGvHPw6tVfPRnkPLGf.png" mos="https://cdn.mos.cms.futurecdn.net/qDf9dGvHPw6tVfPRnkPLGf.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>DataFort protects physical and virtual Windows servers and for testing we used two Hyper-V VMs</em></p><h2 id="data-restoration-testing">Data restoration testing</h2><p>Disasters don't run to a schedule so to test Hi-5 we left it running for a while and invoked the various recovery services without warning. Initially, we used the tests systems for over a month and ran various file copies to them, edited documents stored locally and send and received emails using OWA during this period.</p><p>For our first test we deleted a 1GB folder on the PDC that contained 5,000 files. We called the standard DataFort support number which was answered after a couple of rings. File and folder recovery procedures are very straightforward as we advised DataFort that we wanted this specific folder restored from the latest backup.</p><p>The technician remotely accessed our local appliance and copied the folder back to its original location on the PDC. The process was very swift as the time from initial phone call to folder restoration was less than seven minutes. File versioning is also supported so if you want to go back in time you advise the technician what dates you're interested in.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qdCzU6csSgnkLtkipfxVkM" name="" alt="DataFort Hi-5 - 2" src="https://cdn.mos.cms.futurecdn.net/qdCzU6csSgnkLtkipfxVkM.png" mos="https://cdn.mos.cms.futurecdn.net/qdCzU6csSgnkLtkipfxVkM.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Part of our Exchange recovery test involved deleting an entire user's mailbox which included 6,000 messages</em></p><h2 id="exchange-granular-recovery-tests">Exchange granular recovery tests</h2><p>Exchange server protection costs extra but provides full granular recovery so you can restore entire datastores, mailboxes and individual emails. Prices are very reasonable with DataFort charging 75 per Exchange datastore per month for this service.</p><p>To test this we engaged in some Exchange related mayhem. For one user we deleted a thread containing four emails from the previous month and from the Exchange admin console, we deleted another user's entire mailbox which contained nearly 6,000 messages.</p><p>We called DataFort support, asked for these all to be restored, grabbed a coffee and chilled out while they got on with it. Forty minutes later DataFort called us to say everything was back in place. A quick check confirmed that the four emails were back and the deleted user, their mailbox and all 6,000 emails had also been restored.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cGekFU7q7DqqpBbrbo8Upc" name="" alt="DataFort Hi-5 - 3" src="https://cdn.mos.cms.futurecdn.net/cGekFU7q7DqqpBbrbo8Upc.png" mos="https://cdn.mos.cms.futurecdn.net/cGekFU7q7DqqpBbrbo8Upc.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>After invoking the Hi-5 cloud recovery, we could access our Exchange mailboxes using OWA and continue working as normal</em></p><h2 id="invoking-the-cloud">Invoking the cloud</h2><p>To simulate a complete disaster with access denied to premises, we pulled the plug on both the test server and local appliance and asked for cloud recovery to be invoked. DataFort called us back in 26 minutes to say that all our services were ready and waiting.</p><p>Sure enough, we could RDP to the remote PDC and Exchange servers and drive mappings remained in place. Using OWA we could remotely access all our Exchange user accounts and send and receive email - as far as our users were concerned this was the real thing.</p><p>Once the on-premises systems are restored, they are brought up to date using the remote backups. For those that have a secondary contingency site, DataFort also offers an optional service where it can deliver servers loaded with the latest images within one business day of the disaster.</p><h2 id="conclusion">Conclusion</h2><p>During testing we found Hi-5 worked very well and delivered on DataFort's promises. Backup processes require no user intervention, data and systems recovery is equally non-stressful and it is comparatively good value. We can also vouch for DataFort's efficacy as we've been using its personal cloud backup service since 2004 and it's always been there whenever we've needed it.</p><h2 id="verdict-3">Verdict</h2><p>DataFort’s Hi-5 takes the strain out of backup and disaster recovery as it’s very simple to deploy, incurs no management overheads and is virtually transparent. It’s extremely good value as the price for each protected system includes unlimited storage capacity and our tests show it delivers when it’s needed most.</p><p>OS: Windows Server 2000 upwards (physical and virtual machine)</p><p>Options: Exchange granular recovery, £75 per datastore per month</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos sounds alarm over Apple iTunes malware scam ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/644323/sophos-sounds-alarm-over-apple-itunes-malware-scam</link>
                                                                            <description>
                            <![CDATA[ Security vendors warns PC users to be on their guard against unsolicited emails as the festive season approaches. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m3QauMww21rzHHw3BoZesy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZhdA6fpyrk2kvVNqHZjvnF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Nov 2012 17:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZhdA6fpyrk2kvVNqHZjvnF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Music cloud]]></media:description>                                                            <media:text><![CDATA[Music cloud]]></media:text>
                                <media:title type="plain"><![CDATA[Music cloud]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZhdA6fpyrk2kvVNqHZjvnF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>PC users are being duped by a new type of malware that uses a fake Apple iTunes credit card charge to steal money from their bank accounts.</p><p>Security vendor Sophos is warning people to be on their guard against the scam, which typically starts with computer users receiving a malicious email informing them of a $699.99 Apple iTunes credit card charge.</p><p>"At first glance, recipients may find the malicious emails quite realistic as they use Apple's logos and formatting to appear like a genuine emailed receipt from the company," said Sophos in a statement.</p><p>Users' computers can be infected by malware that logs keystrokes and compromise bank accounts.</p><p>When users click on one of the links contained in the email, they are taken to a web page purporting to belong to the IRS, which houses a Blackhole malware kit.</p><p>This is typically used to exploit vulnerabilities in Java, Adobe Reader and Adobe Flash Player, Sophos warns, which can lead to systems getting infected by a Zeus/Zbot Trojan.</p><p>However, if none of the exploits work, users are instructed to download a more recent version of their web browser, which contains a copy of the Zeus banking Trojan.</p><p>"The end result is that users' Windows computers are infected by malware that can log keystrokes and compromise bank accounts," said Sophos.</p><p>Graham Cluley, senior technology consultant at Sophos, said users should always treat links in unsolicited emails with caution.</p><p>"Instead, users should go to the website of the company in question, or call the number on the back of your card or billing statement to find out the truth," he advised.</p><p>"This is especially important at this time of year, as we typically see increased criminal activity during the Christmas season," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Twitter comes clean over password reset gaffe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/644041/twitter-comes-clean-over-password-reset-gaffe</link>
                                                                            <description>
                            <![CDATA[ Social networking site admits recent security clampdown resulted in unnecessary password resets for some users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nVzkfsj3WNdFMARm2TrTcP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Vh5YWqTW4g6mRTH3TJbPt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Nov 2012 10:54:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Vh5YWqTW4g6mRTH3TJbPt9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Twitter]]></media:description>                                                            <media:text><![CDATA[Twitter]]></media:text>
                                <media:title type="plain"><![CDATA[Twitter]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Vh5YWqTW4g6mRTH3TJbPt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Social networking site Twitter has been commended for admitting it reset more user passwords than it intended to during a recent security blitz.</p><p>The company came clean about the gaffe in a blog post yesterday. In it, the firm explained that it regularly resets the passwords of accounts that appear to have been compromised.</p><p>"We reset the password and send an email letting the account owner know this has happened along with information about creating a new password," said the post.</p><p>"This is a routine part of our processes to protect our users."</p><p>The company then went on to confess that it reset more passwords than it needed to during a recent security clampdown.</p><p>"We unintentionally reset passwords of a larger number of accounts, beyond those that we believed to have been compromised [and] we apologise for any inconvenience or confusion this may have caused," the post concluded.</p><p>Speaking to <em>IT Pro</em>, Graham Cluley, senior technology consultant at security software vendor Sophos, said Twitter was right to admit its mistake, adding that it was unlikely to have caused users many problems.</p><p>"People end up trusting a company more when they admit they made a boo-boo than if they tried to initiate a cover-up," he said.</p><p>"It's inconvenient for those affected...and people who hadn't had their accounts compromised might panic they had been hacked, and waste time trying to determine if anything bad had happened."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mozilla rush-releases Firefox security patch ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/643504/mozilla-rush-releases-firefox-security-patch</link>
                                                                            <description>
                            <![CDATA[ Web browser software vendor patches up Firefox URL tracking hole. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ffbhRMQYe17NzJqNhPQu2i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BstrLuvgxdVQZnsADRXG5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 Oct 2012 12:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Web Browsers]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BstrLuvgxdVQZnsADRXG5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hackers]]></media:description>                                                            <media:text><![CDATA[Hackers]]></media:text>
                                <media:title type="plain"><![CDATA[Hackers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BstrLuvgxdVQZnsADRXG5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Mozilla has rushed out a new version of its Firefox web browser following the discovery of a security hole that could have let hackers keep tabs on the websites users' visited.</p><p>The flaw was uncovered in the 16.0 release of the open source vendor's Firefox software earlier this week, resulting in the product being withdrawn from the company's installer page.</p><p>In a blog post, confirming the vulnerability, Michael Coates, Mozilla's director of security assurance, advised users to downgrade to the 15.01 version of Firefox until a patch was created.</p><p>"The vulnerability could allow a malicious site to potentially determine which websites users have visited and have access to the URL," wrote Coates.</p><p>"At this time, we have no indication that this vulnerability is currently being exploited in the wild."</p><p>The company released a Firefox software update for Windows, Mac, Linux and Android users yesterday.</p><p>Paul Ducklin, head of technology for Asia Pacific at anti-virus vendor Sophos, said in a further blog post that end users should not be put off from downloading the latest software.</p><p>"This latest issue reminds us that it's occasionally problematic to be too far ahead of the curve, [but] it's always risky to be behind," he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Skype users threatened by worm ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/643396/skype-users-threatened-by-worm</link>
                                                                            <description>
                            <![CDATA[ Malware spread by "lol" link could hold PC users to ransom. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2EqgG5g83St5GPTA6WN6g6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5cxHukG32vEgpRYEdhLgRE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Oct 2012 16:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Stephen Pritchard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5cxHukG32vEgpRYEdhLgRE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Skype user]]></media:description>                                                            <media:text><![CDATA[A Skype user]]></media:text>
                                <media:title type="plain"><![CDATA[A Skype user]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5cxHukG32vEgpRYEdhLgRE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Skype users are being targeted by a worm that downloads malware to their PCs, and may even demand money to regain use of their machines.</p><p>The malware Trojan allows hackers to take control of infected computers and use them as part of botnets, but security researchers have warned that the Trojan can also download "ransomware" to infected PCs.</p><p>Affected users risk being locked out of their computers, and forced to hand over money in order to regain access to their data.</p><p>The Skype worm spreads by convincing users to click on messages with a link to the malware. The link usually refers to a user's new profile picture, with text such as "lol is this your new profile pic?".</p><p>According to security researchers at security vendor Sophos, the link then downloads a zip file, which contains a Trojan. The Trojan allows hackers to control the infected PC remotely over HTTP. The malware, according to Sophos' Graham Cluley, is a version of the Dorkbot worm.</p><p>The worm has been spreading for some time via other social networks including Twitter and Facebook, and could also spread via USB sticks, Cluley warned. But Skype users might be less wary of clicking on links than users of services such as Facebook, he suggested.</p><p>"We are aware of this malicious activity and are working quickly to mitigate its impact," the company said in a statement. "We strongly recommend upgrading to the newest Skype version and applying updated security features on your computer. Additionally, following links - even when from your contacts - that look strange or are unexpected is not advisable." Skype has also <a href="http://blogs.skype.com/security/2012/10/security_notice_lol_is_this_yo.html" target="_blank">issued more detailed security advice to its users</a>.</p><p>So far, only Windows PC users appear to have been targeted by the attack.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Foursys nabs top Sophos partner spot ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/364994/foursys-nabs-top-sophos-partner-spot</link>
                                                                            <description>
                            <![CDATA[ Security VAR awarded first global Platinum Solution Partner status under new programme ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dywfjkWH2iqp28gtGdTC7e</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/87dZRKooaAKTpD9dtiBV3d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Sep 2012 16:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/87dZRKooaAKTpD9dtiBV3d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Network and security]]></media:description>                                                            <media:text><![CDATA[Network and security]]></media:text>
                                <media:title type="plain"><![CDATA[Network and security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/87dZRKooaAKTpD9dtiBV3d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT security specialist <a href="http://www.foursys.co.uk">Foursys</a> has grabbed the title of first Platinum Solution Partner under Sophos’ recently overhauled channel partner programme.</p><p>Sophos unveiled its <a href="https://www.channelpro.co.uk/news/7129/sophos-reveals-new-channel-programme" target="_self">new programme</a> in July, which was re-designed to <a href="https://www.channelpro.co.uk/news/6821/sophos-works-its-delivery" target="_self">accommodate different business models</a>, with partners selecting the partnership track that best suits them – reseller or solution provider.</p><p>Cambridge-based Foursys had been a Sophos Platinum Partner before the re-launch. Explaining the new status, the firm’s marketing manager, Andy Wool explains: “The ‘solution provider’ track allows us to offer additional services and a strategic Sophos focus to ensure our customers continue to receive the best service possible.”</p><p>“Platinum solution status is the highest level of Sophos technical accreditation and sales education,” comments Jonathan Bartholomew, channel sales manager for Sophos UK&I, who maintains the partner programme is designed to create and maintain long-term relationships.</p><p>“Becoming accredited as a Platinum solution partner allows partners to provide customers with additional services,” he says. “…Plus, as Sophos continues to invest in and acquire new technologies, there are clear opportunities to revisit customer.”</p><p>The new programme also incorporates parts of acquisition Astaro’s channel programme – and Foursys had to restructure its training accordingly. According to Wool, the VAR invests in a “comprehensive internal training programme for both sales and technical staff [involving] full day intensive sessions with our technical director and our other Sophos sales engineers who help carry out the training and role play in sales meeting environments and technical support telephone enquiries.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos flags security holes in London Wi-Fi hotspots ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/642706/sophos-flags-security-holes-in-london-wi-fi-hotspots</link>
                                                                            <description>
                            <![CDATA[ Security vendor hits out at widespread use of legacy router hardware across the Capital. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bVDeipN9BvMfvbg7QyKHAg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5ZmW2DTuiB5YLUmYGWrk5i-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Sep 2012 14:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Wifi and Hotspots]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5ZmW2DTuiB5YLUmYGWrk5i-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[London]]></media:description>                                                            <media:text><![CDATA[London]]></media:text>
                                <media:title type="plain"><![CDATA[London]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5ZmW2DTuiB5YLUmYGWrk5i-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security vendor Sophos has expressed concern over the number of London Wi-Fi hotspots that use the obsolete Wired Equivalent Privacy (WEP) encryption method.</p><p>James Lyne, director of technology strategy at Sophos, recently embarked on a cycling tour of London on a bike kitted out with a wireless network detection system.</p><p>Using GPS technology, Lyne was also able to create a "heat" map, depicting levels of wireless network security around central London.</p><p>His experiment uncovered 106,874 wireless hotspots scattered across more than 91 miles of London. Eight per cent of these were unencrypted, while 19 per cent were secured using the outdated WEP method of encryption.</p><p>Speaking to <em>IT Pro</em>, Lyne said: "I don't think people connect the security of wireless with the kind of information that can be stolen and the type of attacks that are possible."</p><p>As long as it is still working, people don't bother changing it.</p><p>The remaining networks used WPA or WPA2 encryption, which Sophos has no truck with, providing users do not rely on default or easy passwords to access them.</p><p>Lyne said the widespread use of WEP could be partly down to the large numbers of legacy routers in the Capital.</p><p>"I have not seen a device for a good long time that is not, at least, capable of WPA encryption," he said.</p><p>"There is clearly a legacy [hardware issue] that needs to be handled...but, as long as it is still working, people don't bother changing it."</p><p>He also called on networking vendors to make their wireless routers easier for end users to configure, claiming some may not realise their settings are leaving them vulnerable to attack.</p><p>"Why in the wireless network configuration do they call [the encryption level] WPA2? Why don't they make the default level strong security' and, if [users] need a lower level, have a warning box pop up that...makes them aware of the risks," he suggested.</p><p>"I think there's a lot that can be done to simplify this and make these devices easier for people to set up."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers claim to have stolen 400,000 Yahoo passwords ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/641680/hackers-claim-to-have-stolen-400000-yahoo-passwords</link>
                                                                            <description>
                            <![CDATA[ Has the search giant become the latest high-profile name to be targeted by hackers? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7a6fZe8754ieiG49LBr5F9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jJPgXmUDUAumoT5jwLKpbJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Jul 2012 14:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jJPgXmUDUAumoT5jwLKpbJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Yahoo logo]]></media:description>                                                            <media:text><![CDATA[Yahoo logo]]></media:text>
                                <media:title type="plain"><![CDATA[Yahoo logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jJPgXmUDUAumoT5jwLKpbJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Search giant Yahoo may have become the latest high-profile internet site to suffer a password leak after 453,491 of its users' login details were apparently posted online.</p><p>The username and passwords are said to belong to members of the Yahoo Voices content sharing network and were posted on the website of well-known hacking group D33Ds.</p><p>We hope that the parties responsible for managing the security of this sub-domain will take this as a wake-up call.</p><p>In an accompanying post, the hacking group said the attack should prompt Yahoo into tightening its security.</p><p>"We hope that the parties responsible for managing the security of this sub-domain will take this as a wake-up call, and not as a threat," said the group.</p><p>The breach follows on from last month's spate of password hacks, which blighted networking sites like <a href="https://www.itpro.com/641023/linkedin-investigates-alleged-password-leak" target="blank" data-original-url="https://www.itpro.com/641023/linkedin-investigates-alleged-password-leak">LinkedIn</a>, eHarmony and LastFM.</p><p>In another blog post by US security firm TrustedSec, it was claimed the information may have been obtained through an SQL injection attack.</p><p>"The most alarming part to the entire story was the fact that the passwords were stored completely unencrypted and the full 400,000+ usernames and passwords are now public," said the post.</p><p>"The passwords contained a wide variety of email addresses including those from yahoo.com, gmail.com, aol.com, and much more," it added.</p><p>At the time of writing, <em>IT Pro</em> was awaiting a response from Yahoo.</p><p>However, according to a report on the <em>BBC News</em> site, Yahoo said it was investigating the breach.</p><p>Anna Brading, a contributor to Sophos' Naked Security blog, said, even though D33Ds say they have no plans to use the data, it is accessible to anyone online.</p><p>"The only silver lining on the cloud is that the website hosting the passwords is temperamental, and people are experiencing difficulties accessing the information," said Brading.</p><p>"But maybe the access problems are being caused by so many people trying to access the stolen passwords at once? "</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google refutes Microsoft's Android malware claims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/641581/google-refutes-microsofts-android-malware-claims</link>
                                                                            <description>
                            <![CDATA[ Search giant and security experts have dismissd claims that hijacked Android phones have sent out malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7YiNGfDnqcEm8AAWjsCmgg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PraivuMqYMPYD2TRmjpE76-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jul 2012 13:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PraivuMqYMPYD2TRmjpE76-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Virus alert]]></media:description>                                                            <media:text><![CDATA[Virus alert]]></media:text>
                                <media:title type="plain"><![CDATA[Virus alert]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PraivuMqYMPYD2TRmjpE76-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has denied Microsoft claims that its Android operating system has been compromised by malware, resulting in phones being corralled into a botnet by hackers.</p><p>Earlier in the week, Microsoft engineer Terry Zink claimed compromised Android devices were part of an international botnet used to push out spam.</p><p>In a statement released today, Google said it had found no evidence to support Zink's claims.</p><p>"Our analysis suggests that spammers are using infected computers and a fake mobile signature to try to bypass anti-spam mechanisms in the email platform they're using," said a Google spokesman.</p><p>An investigation by the search giant suggested junk emails originated on PCs but spammers formatted them to look like they were sent from Android smartphones.</p><p>It said the method was used to give the messages a better chance of defeating spam filters.</p><p>Other security researchers had backed Zink's view, before backtracking later.</p><p>"So one of two things is happening here. We either have a new PC botnet that is exploiting Yahoo's Android APIs or we have mobile phones with some sort of malware that uses the Yahoo APIs for sending spam messages," said Chester Wisniewski of security software vendor Sophos.</p><p>He added that one of the interesting data points supporting the argument that this is new Android malware is the unusually large number of originating IPs on mobile networks.</p><p>Mobile security company Lookout also cast doubt on Zink's claim. The firm's CTO and co-founder, Kevin Mahaffey, said insecure Android applications were most likely to blame.</p><p>"In order for the botnet explanation to be valid, each of the originating devices would have to be infected with mobile malware," he said.</p><p>"While this is certainly a possibility (and one that we can't refute), there is another explanation that we believe is significantly more likely," he said.</p><p>Regardless of how this spam campaign works, it was clear from initial reports that the Yahoo Mail Android app may play a key role, he added.</p><p>"After taking a detailed look at the app, we've found a number of issues that have potentially broader implications for all Android users of Yahoo Mail," he said.</p><p>Mahaffey confirmed he had been in contact with Yahoo about vulnerabilities in the app and said the search firm's mobile team was "actively working on these issues."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft fixes Hotmail security flaw ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/640333/microsoft-fixes-hotmail-security-flaw</link>
                                                                            <description>
                            <![CDATA[ Software giant said it's "working hard" to protect email accounts from password resetting hackers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">v2SNPVqYUqsr2qeNkRjPa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4jHLeHn2e3aW3LyG35oUDB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Apr 2012 10:06:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4jHLeHn2e3aW3LyG35oUDB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password protection]]></media:description>                                                            <media:text><![CDATA[Password protection]]></media:text>
                                <media:title type="plain"><![CDATA[Password protection]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4jHLeHn2e3aW3LyG35oUDB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Software giant Microsoft has reportedly plugged a security hole in its Hotmail email service, which allowed hackers to access accounts and reset passwords.</p><p>The problem was made public by researchers at Vulnerability Labs last week in a post on its website, which contained details of how hackers have exploited the flaw.</p><p>"[It allows] attackers to reset the Hotmail/MSN password with attacker chosen values," said the post. "Remote attackers can bypass the password recovery service [and token-based protections] to setup a new password."</p><p>If successful, hackers are then able to gain unauthorised access to Hotmail and MSN accounts, it added.</p><p>It is not know how many of the 350 million Hotmail users from across the globe had been targeted by the scam. However, it has been claimed that Moroccan hackers had been planning to use the flaw to reset the accounts of up to 13 million users.</p><p>Hackers aren't interested in breaking into email accounts because they want to read your spam. They want to steal your identity.</p><p>Moreover, a report on Sophos' <a href="http://nakedsecurity.sophos.com/2012/04/27/microsoft-rushes-out-fix-after-hackers-change-passwords-to-hack-hotmail-accounts" target="blank">Naked Security blog</a> claims videos detailing how to exploit the flaw had been circulating on YouTube for some time.</p><p>"Hackers aren't just interested in breaking into email accounts out of curiousity or because they want to read your spam," said Graham Cluley, senior technology consultant at Sophos, in the blog post.</p><p>"No, they're also interested in stealing your identity and perhaps using an email account hack as a method to crowbar their way into other online accounts under your control."</p><p>When contacted for comment, a Microsoft spokesperson told <em>IT Pro</em>: "Hotmail engineering teams are working hard on not only protecting accounts, but also on recover[ing] them."</p><p>They also revealed the firm has launched a new, "streamlined" recovery tool to help affected users regain access to their accounts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos: Apple users "soft targets" for malware threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/640243/sophos-apple-users-soft-targets-for-malware-threats</link>
                                                                            <description>
                            <![CDATA[ Security vendor hits out Mac users for not taking anti-virus more seriously. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3Qt9Je7gJXnEoN1EZkDU8y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xVcUHg9FoTj3N2X5K2aHaT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Apr 2012 16:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xVcUHg9FoTj3N2X5K2aHaT-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[attack]]></media:description>                                                            <media:text><![CDATA[attack]]></media:text>
                                <media:title type="plain"><![CDATA[attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xVcUHg9FoTj3N2X5K2aHaT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The dismissive attitude of Apple users to computer viruses needs to change, as research from security vendor Sophos shows that 20 per cent of Macs carry Windows malware.</p><p>The firm explained that, while Windows malware is unlikely to cause much disruption to Mac users, it can be easily passed on to other computers.</p><p>Moreover, Sophos also discovered that approximately 1 in 36 Apple computers contain Mac OS X malware.</p><p>Mac users need to be responsible members of the internet community or they're going to continue passing on viruses</p><p>Its findings, published at Infosecurity Europe in London today, are the result of an analysis by Sophos of 100,000 Mac computers.</p><p>Sophos claimed that some of the Windows malware its research uncovered dated back to 2007 and would have been easily detected, if Apple users were not so laid back in their approach to anti-virus.</p><p>Speaking to <em>IT Pro</em>, Graham Cluley, senior technology consultant at Sophos, said the results, along with the discovery of the Mac-focused <a href="https://www.itpro.com/639967/apple-os-x-users-warned-of-botnet-risk" target="blank" data-original-url="https://www.itpro.com/639967/apple-os-x-users-warned-of-botnet-risk">Flashback malware</a>, should serve as a wake-up call for Apple users.</p><p>"For Mac users, the dream is over. They've been living in denial all this time. We've just found 600,000 users infected with Flashback. They are going to have to start running anti-virus," said Cluley.</p><p>"Mac users need to be responsible members of the internet community or they're going to continue passing on viruses to other people and contributing to the spam email problem."</p><p>He said part of the problem is that many Mac users consider their systems to be impervious to attack from viruses, making them a soft target for hackers and malware authors.</p><p>"If you're a bad guy writing malware, you wouldn't write it for computers that are constantly being updated with anti-virus signatures," said Cluley. "Why not write it for the platform where people are more laid-back about things like that?"</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous attack takes down Home Office ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/640003/anonymous-attack-takes-down-home-office</link>
                                                                            <description>
                            <![CDATA[ Hacking group makes good on pledge to stage Saturday night attacks on Government sites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uPB2QX9BySJT912Fban5d2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LBvnxPEYRSjeXF2AkYPRjF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Apr 2012 15:13:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LBvnxPEYRSjeXF2AkYPRjF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Computer hacker]]></media:description>                                                            <media:text><![CDATA[Computer hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Computer hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LBvnxPEYRSjeXF2AkYPRjF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hacking group Anonymous has followed up its threat to stage weekly attacks against the Government by taking the Home Office website offline.</p><p>The group used social networking sites Twitter and Tumblr to declare the launch of a Distributed Denial-Of-Service (DDoS) attack against the Home Office website on Saturday night.</p><p>In a series of tweets, published by the Anonymous Operations account, the group said the attack was in protest at the extradition of UK citizens to stand trial in the US.</p><p>According to a report on the <a href="http://www.bbc.co.uk/news/uk-17648852" target="blank"><em>BBC News site</em></a>, the attack resulted in the site becoming inaccessible for several hours.</p><p>The Saturday night attack followed an earlier tweet by the group on 4 April, which read: "Expect a DDoS every Saturday on the UK Government sites."</p><p>Expect a DDoS every Saturday on the UK Government sites.</p><p>Graham Gluley, senior technology consultant at security vendor Sophos, said the decision to stage attacks at weekends is unlikely to have been a coincidence.</p><p>"My guess is that [a weekend attack] might make life more difficult for those responsible for maintaining the uptime of such sites," Cluley told <em>IT Pro</em>. "Fewer staff are likely to be at work, for instance, and it might be trickier to call in other expertise."</p><p>Moreover, he also advised the Government to be prepared for attacks from a range of sources, not just Anonymous.</p><p>"Just because Anonymous have made threats doesn't necessarily mean that anything will occur or that attacks will be successful," he explained.</p><p>"Nevertheless, departments which feel they may be in the firing line will no doubt be consulting with those who manage their site's infrastructure and internet traffic to see what they can do to assist during times of high traffic," he concluded.</p><p>Jeremy Nicholls, business development director for Europe, the Middle East and Africa (EMEA) at DDoS protection vendor Arbor Networks, said the Home Office take down should raise awareness of how susceptible all firms are to attack.</p><p>"Any business operating online can become a target, because of who they are, what they sell or who they partner with," explained Nicholls.</p><p>"Furthermore, the explosion of inexpensive and readily-accessible attack tools [allows] anyone to carry out DDoS attacks. This has profound implications for the threat landscape, risk profile, network architecture and security deployments of internet-connected organisations."</p><p>At the time of writing <em>IT Pro</em> was awaiting an updated response from the Home Office about Saturday night's attacks and the threat the group poses to other Government sites.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TinKode suspect apprehended in Romania ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638620/tinkode-suspect-apprehended-in-romania</link>
                                                                            <description>
                            <![CDATA[ Police believe they've caught TinKode, the hacker who has claimed hits on US and UK Government websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">749EV49ZRCN6Pdymqthv2y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4Q5CL6KfsgGZWGdPyu2sqj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Feb 2012 11:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4Q5CL6KfsgGZWGdPyu2sqj-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker]]></media:description>                                                            <media:text><![CDATA[Hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4Q5CL6KfsgGZWGdPyu2sqj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Romanian authorities have arrested a man they believe to be notorious hacker TinKode.</p><p>A 20 year old named Razvan Manole Cernaianu has been taken in by police under suspicion of attacking US Government servers, including those at the Pentagon and NASA.</p><p>TinKode's motivation has been more about mischief-making than the more malicious attacks we often see.</p><p>He has also been accused by the Romanian Directorate for Investigating Organised Crime and Terrorism (DIICOT) of selling a program designed to attack the US Government website, showing a video on his blog of websites he successfully hacked.</p><p>"In my estimation over the last few years TinKode's motivation has been more about mischief-making than the more malicious attacks we often see, fueled by a desire for publicity via his active Twitter and Facebook accounts," said senior technology consultant for Sophos, Graham Cluley, in a <a href="http://nakedsecurity.sophos.com/2012/01/31/tinkode-arreste/?utm_source=twitter&utm_medium=gcluley&utm_campaign=naked%2Bsecurity" target="_blank">blog post</a>.</p><p>"Perhaps now is a good time to remind everyone who thinks it's cool or amusing to expose an organisation's weak security that hacking into a site is still a crime, regardless of what your incentive may be."</p><p>Back in late 2010, TinKode claimed responsibility for <a href="https://www.itpro.com/628414/hacked-royal-navy-site-sinks" target="_blank" data-original-url="https://www.itpro.com/628414/hacked-royal-navy-site-sinks">downing the UK's Royal Navy website</a>. He claimed to have done so with an SQL injection attack, asserting that he acquired usernames and passwords to different sections of the website, although the Royal Navy refuted the suggestion any classified information was taken.</p><p>TinKode was one of two hackers who claimed they were behind <a href="https://www.itpro.com/632293/mysql-hit-by-irony-attack" target="_blank" data-original-url="https://www.itpro.com/632293/mysql-hit-by-irony-attack">an SQL injection hit on Oracle-owned MySQL.com</a> in early 2011.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Koobface infections halted after Facebook exposure ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638395/koobface-infections-halted-after-facebook-exposure</link>
                                                                            <description>
                            <![CDATA[ Facebook's decision to name Koobface suspects has an immediate impact, but no arrests have been made. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nJMfX25g27PKaTb83WtEqq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8U9mVTAi5jpsmPSwjLVCuY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Jan 2012 10:28:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8U9mVTAi5jpsmPSwjLVCuY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook]]></media:description>                                                            <media:text><![CDATA[Facebook]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8U9mVTAi5jpsmPSwjLVCuY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/628150/koobface-turns-eyes-towards-macs" target="_blank" data-original-url="https://www.itpro.com/628150/koobface-turns-eyes-towards-macs">Koobface</a> has stopped infecting new machines, according to reports, following the public exposure of five people suspected to be behind the criminal operation.</p><p><a href="https://www.itpro.com/638350/koobface-crooks-unmasked" target="_blank" data-original-url="https://www.itpro.com/638350/koobface-crooks-unmasked">Facebook and Sophos chose to release the names</a> of those they believed to be running the Koobface botnet earlier this week.</p><p>Jan Droemer and Dirk Kollberg, German security researchers who wrote up an in-depth report on how they tracked the suspects, said servers running Koobface stopped responding after they released their information via a Sophos blog, according to <a href="http://www.reuters.com/article/2012/01/19/us-facebook-cybersecurity-idUSTRE80I05720120119" target="_blank">Reuters</a>.</p><p>Our decision to become transparent about this has had a 24-hour impact.</p><p>Koobface had stopped spreading via Facebook nine months ago but was continuing to propagate in different ways and via different social networks.</p><p>Kaspersky had estimated that Koobface had managed to infect between 400,000 and 800,000 machines in 2010. It first appeared in 2008.</p><p>The suspects left a vast trail of digital clues that led to their names appearing in reports, including Facebook pages.</p><p>They were also involved in more salacious affairs, including appearances at adult film conferences.</p><p>They also failed to lock investigators out of command and control (C&C) centre data, which eventually led to the leaking of their web pseudonyms.</p><p>Those identified have now erased social networking profiles found by the researchers.</p><p>"The thing that we are most excited about is that the botnet is down," said Facebook security official Ryan McGeehan.</p><p>"Our decision to become transparent about this has had a 24-hour impact. Only time will tell if it's permanent but it was certainly effective."</p><p>Facebook declared late on Tuesday it would continue to fight the botnet even though it had been banished from the social network.</p><p>"While we have been able to keep Koobface off Facebook, we won't declare victory against the virus until its authors are brought to justice," the company said in a <a href="http://www.facebook.com/notes/facebook-security/facebooks-continued-fight-against-koobface/10150474399670766" target="_blank">blog post</a>.</p><p>"We feel it is the interest of everyone online to work with law enforcement and the larger security community to identify the gang and see the full force of law brought to bear against those who have made millions in ill-gotten gains.</p><p>"To this end, we will be sharing our intelligence with the rest of the online security community in the coming weeks in an effort to rid the web of this virus forever."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Koobface crooks unmasked? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/638350/koobface-crooks-unmasked</link>
                                                                            <description>
                            <![CDATA[ Facebook and Sophos believe they have the names of the crooks behind the Koobface botnet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tfMPpzVyESdnr4KkzgNrQF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LpyZ8aCncEuvWF3hzjmXnE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Jan 2012 16:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LpyZ8aCncEuvWF3hzjmXnE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Worm]]></media:description>                                                            <media:text><![CDATA[Worm]]></media:text>
                                <media:title type="plain"><![CDATA[Worm]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LpyZ8aCncEuvWF3hzjmXnE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/638170/facebook-boosts-security-after-worm-steals-logins" target="_blank" data-original-url="https://www.itpro.com/638170/facebook-boosts-security-after-worm-steals-logins">Facebook</a> and security researchers believe they have the names of the gang behind notorious botnet Koobface.</p><p>The social networking giant, which has been one of the main targets of the Koobface criminals, is expected to announced it will start sharing information it has on the group with the security community today, the <a href="http://www.nytimes.com/2012/01/17/technology/koobface-gang-uses-facebook-to-spread-powerful-worm.html?_r=1" target="_blank">New York Times</a> reported.</p><p>Facebook is planning to name four men who it believes to be involved in the gang behind Koobface, a botnet that Kaspersky estimated had infected between 400,000 and 800,000 machines at its peak.</p><p>We wait to see what - if any - actions are taken to bring down the Koobface gang.</p><p>Koobface malware has primarily been spread via Facebook.</p><p>Investigators claimed the group is working in Russia and in plain sight. Despite the raft of information gathered on them, no prosecutions have been brought.</p><p>Leaving tracks uncovered</p><p>Sophos has been tracking the group, saying the crooks have made a number of mistakes, leaving digital traces across the internet. One error was not effectively locking people out of command and control (C&C) centre information.</p><p>"It turned out that the Apache web server on one of the active Command & Control servers (captchastop.com, 67.212.69.230) had the mod_status module enabled. Having enabled this web server module, any visitor is provided with public access to a live view of requests made to the web server, thereby revealing file and directory names," Sophos explained in a <a href="http://nakedsecurity.sophos.com/koobface" target="_blank">blog post</a>.</p><p>"Although this mistake was noted and corrected at the end of October 2009, it was only days later when the gang made yet another mistake by installing the Webalizer statistics tool in a publicly accessible way, allowing for an even better insight into the structures of their Command & Control system."</p><p>The Webalizer statistics revealed in late 2009 that a file named "last.tar.bz2" was a full daily backup of Koobface C&C software, which were obtained by Sophos for full analysis.</p><p>This meant IP addresses relating to the gang could be obtained. More critically, Sophos was able to attain a PHP script used to submit daily revenue statistics via short text messages to five mobile phones. This meant the researchers had phone numbers to play with as well as nicknames of recipients.</p><p>The nicknames Krotreal, LeDed and PoMuC proved particularly helpful. They were used to track down profiles of potential subjects on sites including Facebook, Twitter and Flickr, as well as photos which provided yet more useful information.</p><p>Other data acquired from the C&C server indicated one of the suspects worked at a software development company called MobSoft, which was determined to be based in St Petersburg.</p><p>One of the company's contacts had a mobile number the same as one of those found in the aforementioned Koobface SMS data.</p><p>The PoMuC suspect was linked to a similar company to Mobsoft called Elitum.</p><p>Sophos also used information of suspects' family members from social networks to further their investigations.</p><p>Another lead was a picture of one of the suspects at a porn conference with his wife.</p><p>"The full evidence is in the hands of the law enforcement agencies, and we wait to see what - if any - actions are taken to bring down the Koobface gang."</p><p>Facebook had not offered any official comment on the Koobface situation at the time of publication.</p><p>Koobface initially targeted Windows PCs but moved to <a href="https://www.itpro.com/628150/koobface-turns-eyes-towards-macs" target="_blank" data-original-url="https://www.itpro.com/628150/koobface-turns-eyes-towards-macs">attacking Macs</a> as well in late 2010.</p><p>Later that year, the botnet took a serious hit when <a href="https://www.itpro.com/628600/koobface-servers-closed-down" target="_blank" data-original-url="https://www.itpro.com/628600/koobface-servers-closed-down">servers hosting its C&C centre were taken down</a> in the UK.</p><p>The main C&C centre was located on servers based at UK hosting company Coreix, which worked with police in removing criminal activity from their systems.</p><p>Facebook claimed to have effectively stopped Koobface spreading on the social network last year.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sticking security where the sun don't shine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/637915/sticking-security-where-the-sun-dont-shine</link>
                                                                            <description>
                            <![CDATA[ Davey isn't a big fan of USB sticks. And, from a security standpoint, it's easy to see why. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">e3XNofatLsQy1CDvqesh7E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wg8fmvk57NfMa9gm4d3jeA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Dec 2011 13:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wg8fmvk57NfMa9gm4d3jeA-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[computer security]]></media:description>                                                            <media:text><![CDATA[computer security]]></media:text>
                                <media:title type="plain"><![CDATA[computer security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wg8fmvk57NfMa9gm4d3jeA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>COMMENT: I was somewhat saddened to learn that security vendor Sophos had purchased a job lot of USB sticks from a lost property auction and discovered that security is still not a priority for, well, pretty much anyone it seems.</p><p>OK, first things first, let's get the fact that the lost property auction in question was in Australia and the sticks in question were lost on a public transport system. I mention this as you may argue that there's a huge difference between the average consumer approach to securing data on these thumb-drives and the average enterprise-level security strategy employed. My response is, sadly, far too many enterprise employees are carrying, and losing, such devices complete with unencrypted data for me to agree with you.</p><p>Indeed, from the largest enterprises - NHS data disasters anyone? - to the smallest of SMEs, when it comes to USB thumb drives it would appear that security is being stuck where the sun doesn't shine.</p><p>Quite apart from the small point that nobody needs to be carrying data around in their pockets on a device so vulnerable to loss or theft when much more secure alternatives to transporting data exist to do so without encrypting that device, and the data upon it, is tantamount to ITSec suicide.</p><p>Despite all of that, the Sophos <a href="http://nakedsecurity.sophos.com/2011/12/07/lost-usb-keys" target="_blank">study</a> found that 100 per cent of the 50 lost USB sticks it purchased through the auction system contained unencrypted data. What's more, the researchers also found that 66 per cent contained malware.</p><p>Now, given that many employees seem quite happy to throw a bit of data onto a thumb drive to take work home with them, either in breach of existing security policies or because no such security procedures relating to the transport of data via mobile devices exists, one has to assume that malware being introduced to the corporate network via such a device is a real possibility. Yet another reason why, I would suggest, it is time to start taking USB sticks very seriously indeed.</p><p>Whenever I am asked about the subject, I always return the same three questions:</p><p>1. What data are you thinking of moving around like this?</p><p>2. What encryption methods are you thinking of using?</p><p>3. What on earth are you thinking?</p><p>The last one usually catches people by surprise, as they often haven't considered that the very same employees thinking about dumping data insecurely onto a thumb drive have a smartphone in their pocket, or a netbook in their bag, which could happily connect to a very secure VPN and grab the data from there without creating the same huge potential security hole.</p><p>Sure, USB sticks are cheap but in terms of security they are also pretty nasty. I'd rather see them included in a list of NOT ALLOWED ITEMS in an acceptable use policy document and confiscated on sight if spotted in the workplace. I admit this is unlikely to happen, so it usually ends up coming back to question number two and exploring the lack of encryption.</p><p>But it isn't just the encryption, or lack of, that's a problem. The management of these devices is also at fault. If your employees are going to use thumb drives no matter what, and sometimes it pays to be practical about such things, then much better they do so with your approval and under your control. By which I mean some kind of system which enables central management of the devices in terms of device auditing and data encryption as well as the ability to remotely wipe them clean of all data if lost or stolen.</p><p>If you are a large enterprise (other than the NHS, experience would suggest) then you probably already have something capable of doing this, and if not then you will surely have the budget to buy one in. At the smaller end of the enterprise equation, where the USB stick problem is most obvious, cost is an issue that is always thrown in my face when talking about security. Luckily, there are some reasonably low-cost solutions available which I have <a href="http://www.pcpro.co.uk/realworld/367957/easy-thumb-drive-security/2" target="_blank">covered</a> before for sister title <em>PC Pro</em> and are worth a look.</p><p>I'd still be happier if everyone took my stick it where the sun don't shine advice and did away with the problem of USB thumb drives altogether though...</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>