<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/unified-threat-management"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Unified-threat-management ]]></title>
                <link>https://www.itpro.com/uk/security/unified-threat-management</link>
        <description><![CDATA[ All the latest unified-threat-management content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Tue, 10 Jan 2023 12:07:01 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Threat hunting for MSPs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps</link>
                                                                            <description>
                            <![CDATA[ Are you ready to take your Managed Security Service to the next level? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8tyzcHxS2rBFUUWa64x83U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Jan 2023 12:07:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Red whitepaper cover with shaded revolving target image in background]]></media:description>                                                            <media:text><![CDATA[Red whitepaper cover with shaded revolving target image in background]]></media:text>
                                <media:title type="plain"><![CDATA[Red whitepaper cover with shaded revolving target image in background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Are you ready to take your managed security service to the next level? </p><p>When it comes to security, nothing is a hundred percent. What we know is that no organisation is immune regardless of where they are located, the size, or the vertical in which they operate. A collaborative and coordinated approach is the key to stopping today’s breaches and delivering the highest level of managed security to your customers in a seamless manner. </p><p>This eBook discusses the function & value of threat hunting, barriers to a successful threat hunting program and the threat hunting service as an extension of your team.</p><p>Download the eBook to find out more about threat hunting for MSPs.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TGd7tPyzEFMTXy7FQGZcVJ" name="" alt="WatchGuard logo" src="https://cdn.mos.cms.futurecdn.net/TGd7tPyzEFMTXy7FQGZcVJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/TGd7tPyzEFMTXy7FQGZcVJ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="high" data-lazy-src="https://dennis.cvtr.io/forms/49903/watchguard-2022?locale=1&p=false&wp=10692"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zyxel ZyWALL ATP200 review: A persuasive defence against unknown threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/369184/zyxel-zywall-atp200-review-a-persuasive-defence-against-unknown-threats</link>
                                                                            <description>
                            <![CDATA[ A top-value appliance with great cloud management and clever protection against unknown threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8H8Vt8PHc24ZJeMx2amVEz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/q5pTS26sGx4LB4jXGo8Vac-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Sep 2022 11:00:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/q5pTS26sGx4LB4jXGo8Vac-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Zyxel ZyWALL AP200]]></media:description>                                                            <media:text><![CDATA[The Zyxel ZyWALL AP200]]></media:text>
                                <media:title type="plain"><![CDATA[The Zyxel ZyWALL AP200]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/q5pTS26sGx4LB4jXGo8Vac-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zyxel's ZyWALL ATP appliances are designed to stay one step ahead of hackers. They have a sharp focus on zero-day threats, making use of advanced services such as cloud threat intelligence, machine learning and automated sandboxing of suspect files.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/368361/watchguard-firebox-m590-review-big-red-network" data-original-url="/security/unified-threat-management-utm/368361/watchguard-firebox-m590-review-big-red-network">WatchGuard Firebox M590 review: Big red network security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/369183/goto-resolve-basic-review-an-smb-friendly-remote-support-service" data-original-url="/software/369183/goto-resolve-basic-review-an-smb-friendly-remote-support-service">GoTo Resolve Basic review: An SMB-friendly remote support service</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/backup/369129/barracuda-backup-295-review-data-protection-in-a-box" data-original-url="/server-storage/backup/369129/barracuda-backup-295-review-data-protection-in-a-box">Barracuda Backup 295 review: Data protection in a box</a></p></div></div><p>The ATP200 on test is affordable, too. The price shown includes a one-year Gold licence, after which yearly renewals cost £276. That gets you a heap of security features - not just the technologies mentioned above, but also hybrid anti-malware, anti-spam, web content filtering, application controls, IPS and Zyxel's cloud-hosted SecuReporter Premium reporting service.</p><p>This desktop unit isn't overloaded with ports, but it presents two Gigabit WAN and four copper LAN ports, plus a handy SFP fibre socket for longer connections. Performance is good for the price, with <a href="https://www.itpro.com/server-storage/network-switches/368761/zyxel-xs1930-12hp-review-in-a-league-of-its-own" target="_blank" data-original-url="https://www.itpro.com/server-storage/network-switches/368761/zyxel-xs1930-12hp-review-in-a-league-of-its-own">Zyxel</a> claiming a 2Gbits/sec raw firewall throughput dropping to <a href="https://www.itpro.com/network-internet/30276/what-is-ethernet-the-standards-explained" target="_blank" data-original-url="https://www.itpro.com/network-internet/30276/what-is-ethernet-the-standards-explained">600Mbits/sec</a> with all security services enabled. </p><p>You have two management choices as all of Zyxel's ATP appliances can be either locally managed or brought under the control of the Nebula cloud platform, which provides a single portal for all the company's compliant wireless APs, switches and mobile routers. There's just one small catch, which is that the Nebula portal doesn't currently support Zyxel's</p><p>email security component, so if you want to use this you'll need to run the ATP200 in standalone mode.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DYc4uj5UCWp7hqDPQpNb5K" name="" alt="Zyxel user interface" src="https://cdn.mos.cms.futurecdn.net/DYc4uj5UCWp7hqDPQpNb5K.png" mos="https://cdn.mos.cms.futurecdn.net/DYc4uj5UCWp7hqDPQpNb5K.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>We opted for cloud management and found registration a very swift process thanks to the Nebula iPad app, which let us scan the appliance's QR code and immediately add it to our site. The same process can be used for zero-touch provisioning: once you've registered the appliance, you can send it off to a remote office and, once connected, it will receive all the settings configured in the portal.</p><p>We like the way that Nebula's dashboard can be customised to show whatever data is important to you. It came up showing the appliance's hardware status, detected apps and clients, WAN throughput and security alerts, but there was plenty of room for us to add performance and status widgets for our Zyxel PoE switches and Wi-Fi 6 APs. </p><p>Like most UTM appliances, the ATP200 is controlled via security policies, which combine firewall rules with application patrol settings -- you can manage access to over 3,500 business apps - and web-content filtering settings, which let you block or allow sites across 110 categories. </p><p>Enable the anti-malware hybrid mode and Zyxel's cloud-based threat intelligence comes into play too, combining a local signature database with cloud queries to check whether downloaded files are safe to allow through. The sandbox service is accessed from the same page: this isolates files it hasn't seen before and gives them a test run in the cloud to see if they are malicious. Friendly files are allowed through, while those deemed a threat are destroyed.</p><p>Another notable feature is Zyxel's collaborative detection and response service, which blocks rogue devices. You can specify how many times a device is allowed to trigger the malware, IDP or web threat services; once the threshold is reached, the appliance will automatically kick them into quarantine.</p><p>Finally, you can configure the SecuReporter cloud service, which receives logs from the ATP200, to decide whether personal information such as email addresses and usernames should be included or anonymised. The main dashboard provides an informative overview of all security events along with deeper insights into web, app and threat activity plus all security issues.</p><p>The ZyWALL ATP200 offers a persuasive defence against unknown threats, and the <a href="https://www.itpro.com/network-internet/33885/zyxel-nebula-control-center-2019-review-takes-all-the-pain-out-of-networking" target="_blank" data-original-url="https://www.itpro.com/network-internet/33885/zyxel-nebula-control-center-2019-review-takes-all-the-pain-out-of-networking">Nebula</a> portal integration is especially useful for businesses looking to protect remote offices. It's a real shame that email security is only supported in standalone mode - we hope that will be rectified soon - but even without that module, you still get a great set of security features for the price.</p><h2 id="zyxel-zywall-atp200-specifications">Zyxel ZyWALL ATP200 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop fan-less</td></tr><tr><td  ><strong>CPU</strong></td><td  >Dual-core CPU</td></tr><tr><td  ><strong>Memory</strong></td><td  >2GB RAM</td></tr><tr><td  ><strong>Network</strong></td><td  >7 x Gigabit (2 x WAN, 4 x LAN, 1 x SFP)</td></tr><tr><td  ><strong>Ports</strong></td><td  >2 x USB 3, DB9 serial port </td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >272 x 187 x 86mm</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos XGS 116 review: A small and mighty appliance  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/369069/sophos-xgs-116-review-a-small-and-mighty-appliance</link>
                                                                            <description>
                            <![CDATA[ This clever and compact security gateway brings outstanding security and remote management features at a tempting price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xuJd28nDcP6VyU6mUE9svG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tZYMk5tvV6bVaanXUYKxof-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Sep 2022 10:34:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tZYMk5tvV6bVaanXUYKxof-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of the Sophos XGS 116 ]]></media:description>                                                            <media:text><![CDATA[A photograph of the Sophos XGS 116 ]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of the Sophos XGS 116 ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tZYMk5tvV6bVaanXUYKxof-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Don’t be deceived by its modest dimensions: the Sophos XGS 116 is a security powerhouse. Aimed at busy SMBs and branch offices, this desktop appliance boasts a raw firewall throughput of 7,700Mbits/sec, and even with full threat protection enabled it keeps up a creditable 685Mbits/sec.</p><p>That’s largely thanks to Sophos’ dual-processor architecture. The Xstream Flow Processor provides a hardware acceleration layer that’s optimised for specific network tasks, ensuring the main AMD CPU doesn’t get bogged down.</p><p>Connection options abound. The rear panel presents eight Gigabit Ethernet ports – with PoE+ on the last one – plus one fibre port. While there’s no built-in modem, an expansion bay lets you add VDSL2 or 3G/4G modules, although Sophos’ Flexi network cards only work with larger rackmount models <a href="https://www.itpro.com/security/361926/sophos-xgs-3300-review-xstream-firewall-performance" data-original-url="https://www.itpro.com/security/361926/sophos-xgs-3300-review-xstream-firewall-performance">like the XGS 3300</a>.</p><p>The flexible licensing model allows you to choose which features you want, and there are plenty on offer. We’ve shown the price of a three-year Xstream subscription above, which enables the base firewall licence along with Xstream TLS 1.3 SSL inspection, deep packet inspection, network, web and <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-day protection</a> modules, central orchestration and enhanced 24/7 support. The email and web server protection modules are optional extras, each costing around £142 for a three-year licence.</p><p>Deployment is easy thanks to the appliance’s web console wizard, which guides you through the steps required to get secure internet access up and running. We chose routed mode as we wanted the appliance to provide all security functions; protection starts immediately, with the wizard enabling a standard set of firewall security policies including web filtering and <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" data-original-url="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus">anti-malware</a>.</p><p>Henceforth, the Control Center dashboard provides everything you need to know about network activity and security issues. Graphs provide a clear visual overview of web traffic and network attacks, plus blocked and allowed applications and web categories. The User and Device Insights section keeps track of activity in modules such as SSL inspection, advanced threat protection and zero-day protection, and clicking on an icon takes you directly to a more detailed report.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XfftNW53zuzRxoF2mJAmNF" name="" alt="A screenshot of the Sophos XGS 116's control software" src="https://cdn.mos.cms.futurecdn.net/XfftNW53zuzRxoF2mJAmNF.jpg" mos="https://cdn.mos.cms.futurecdn.net/XfftNW53zuzRxoF2mJAmNF.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Remote management comes into play too, via <a href="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it" data-original-url="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it">the Sophos Central portal</a>. After we’d registered the appliance with our account, we were able to bring up live reports in a web browser, and to access the appliance’s Control Center console remotely for full configuration. </p><p><a href="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home" data-original-url="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home">Businesses with home workers</a> will love the Synchronised Security feature, which extends firewall protection to remote systems running <a href="https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection" data-original-url="https://www.itpro.com/security/endpoint-security/361685/sophos-intercept-x-advanced-review-ai-powered-protection">the Sophos Intercept X endpoint agent</a>. A heartbeat service monitors and automatically isolates any that are compromised, while the application control feature detects unknown applications running on endpoints and pushes out firewall policies to secure them.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible" data-original-url="/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible">Sophos XG 230 Rev.2 review: Powerful and flexible</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one" data-original-url="/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one">Ubiquiti Networks UniFi Dream Machine Pro review: All the security you need in one handy box</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a" data-original-url="/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a">WatchGuard Firebox M290 review: Stiff security at a great price</a></p></div></div><p>All of this is controlled via policies that bring together firewall rules, service filters, schedules and specific settings for intrusion detection, email, applications and web filtering. That last feature is particularly impressive: the appliance comes with predefined settings to get you started, but you can choose to block or allow sites in over 90 categories. Application controls are equally extensive, with more than 3,500 predefined filters supplied, including 12 for Twitter and 73 for Facebook, so you can finely control social networking in the workplace.</p><p>A new filtering feature in the latest firmware also makes it easy to find specific rules within complex policies, and lets you reset traffic counters to zero with a click – a big improvement on the previous release, which required a reboot.</p><p>All told, the XGS 116 delivers strong gateway security measures at a great price. It has the power to cope with high demand, and the integration with Sophos’ endpoint security software will appeal to businesses that want to extend their protection to home workers.</p><h2 id="sophos-xgs-116-specifications">Sophos XGS 116 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >1U desktop chassis </td></tr><tr><td  ><strong>CPU</strong></td><td  >2.1GHz quad-core AMD RX-421ND CPU</td></tr><tr><td  ><strong>Memory</strong></td><td  >4GB DDR4</td></tr><tr><td  ><strong>Storage included</strong></td><td  >64GB SATA SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >8 x GbE ports (PoE+ on port 8), SFP GbE</td></tr><tr><td  ><strong>Other ports</strong></td><td  >RJ45/micro-USB COM ports, USB 3, USB 2, expansion slot</td></tr><tr><td  ><strong>Management</strong></td><td  >Sophos Control Center</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >320 x 213 x 44mm</td></tr><tr><td  ><strong>Weight</strong></td><td  >2.2kg</td></tr><tr><td  ><strong>Warranty</strong></td><td  >1yr standard hardware warranty</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CMS Distribution partners with GuardYoo for new Attack Surface Management offering ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/368877/cms-distribution-partners-with-guardyoo-attack-surface-management</link>
                                                                            <description>
                            <![CDATA[ The hosted service has been designed to strengthen resilience against vulnerabilities without sacrificing growth, company says ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qQoKXx77gMcfXXRJMnPms</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Eu5KdeHjMP4q5GMCaXRQAV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Aug 2022 10:16:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Eu5KdeHjMP4q5GMCaXRQAV-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract render of a matrix of data points layered on top of each other]]></media:description>                                                            <media:text><![CDATA[An abstract render of a matrix of data points layered on top of each other]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract render of a matrix of data points layered on top of each other]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Eu5KdeHjMP4q5GMCaXRQAV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>CMS Distribution has teamed up with Irish cyber security firm GuardYoo to provide a new Attack Surface Management Cloud Service offering.</p><p>The hosted service, dubbed CMS Cloud Service Powered by GuardYoo, aims to help partners maintain high level attack surface management, leveraging functionality such as artefact analysis and forensic reporting.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qEKM9GRE2S2PW5Bvuu8xp6" name="qEKM9GRE2S2PW5Bvuu8xp6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/qEKM9GRE2S2PW5Bvuu8xp6.jpg" mos="https://cdn.mos.cms.futurecdn.net/qEKM9GRE2S2PW5Bvuu8xp6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Escape the ransomware maze</strong></p><p class="fancy-box__body-text">Conventional endpoint protection tools just aren’t the best defence anymore</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368866/escape-the-ransomware-maze" data-original-url="/security/cyber-security/368866/escape-the-ransomware-maze">FREE DOWNLOAD</a></p></div></div><p>CMS says its new offering’s primary purpose is to strengthen organisations’ resilience against vulnerabilities and cyber threats - whilst also enabling their growth and “reaching their full business potential”.</p><p>“CMS is delighted to have penned an agreement to provide GuardYoo’s pen testing and security services under our ‘CMS Powered by’ brand,” commented Nick Bailey, Alliance Director at CMS Distribution.</p><p>“Our partners look to us to provide innovative new products and services, and adding GuardYoo strengthens that considerably.”</p><p>Regularly used by first responders tackling advanced cyber attacks, GuardYoo enables organisations to reduce their attack surface to a minimum with its self-service style assessment platform.</p><p>It allows partners to create, execute, and analyse cyber security assessments on clients’ infrastructure and can be augmented with additional services - such as <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing" data-original-url="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration and security testing</a>, as well as digital forensics and threat intelligence.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">What's behind the explosion in zero-day exploits?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368723/microsoft-unveils-new-threat-intelligence-and-surface-management" data-original-url="/security/cyber-security/368723/microsoft-unveils-new-threat-intelligence-and-surface-management">Microsoft unveils new threat intelligence and surface management solutions</a></p></div></div><p>CMS says GuardYoo’s level of research and frontline experience in <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber warfare</a>, combined with its own value-added offerings, will provide partners with a sophisticated attack surface management platform to help their clients identify and remediate <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">previously undetected vulnerabilities</a>.</p><p>“It’s a real pleasure for us at GuardYoo to partner with CMS Distribution who have a strong history of delivering value-added services to their channel,” said Darren Sexton, GuardYoo CEO.</p><p>“Through our partnership with CMS, we are able to provide cybersecurity partners with a sophisticated Attack Surface Management platform to help their clients accurately identify and remediate previously undetected vulnerabilities."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Introducing IBM Security QRadar XDR ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/368459/introducing-ibm-security-qradar-xdr</link>
                                                                            <description>
                            <![CDATA[ A comprehensive open solution in a crowded and confusing space ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">617YQci6eH7JM2chwaK9m6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Jul 2022 13:34:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title over a grey rectangle and a dark header banner with turquoise lines and ESG logo]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title over a grey rectangle and a dark header banner with turquoise lines and ESG logo]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title over a grey rectangle and a dark header banner with turquoise lines and ESG logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/R2jbpb4nBynt6hb5iyJKaD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Every businesses' priorities include strengthening their cyber security in the coming 12 months, which isn't a surprise with the increase in remote work, cloud computing, and digital transformation.</p><p>Despite this focus, organisations still lack the tools and resources to detect and respond to cyber threats in real-time.</p><p>This paper looks at what developments are happening in the world of threat detection and response and how eXtended Detection and Response (XDR) is emerging as a leading security operations architecture. Find out more.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDE4LyFCjKBJzACUQeK6rZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/TDE4LyFCjKBJzACUQeK6rZ.png" mos="https://cdn.mos.cms.futurecdn.net/TDE4LyFCjKBJzACUQeK6rZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49716/ibm-q3-2022-en?locale=1&p=false&wp=9817"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WatchGuard Firebox M590 review: Big red network security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/368361/watchguard-firebox-m590-review-big-red-network</link>
                                                                            <description>
                            <![CDATA[ A powerful mid-range UTM appliance with top-notch security features at a sensible price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u2STk6RbcZ1apHYEeG1AGQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DFEnEMjU597yvgnoSPhsJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jun 2022 09:06:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DFEnEMjU597yvgnoSPhsJ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of the WatchGuard Firebox M590]]></media:description>                                                            <media:text><![CDATA[A photograph of the WatchGuard Firebox M590]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of the WatchGuard Firebox M590]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DFEnEMjU597yvgnoSPhsJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WatchGuard has been busy beefing up its Firebox security appliances to handle the latest threats and the high demands of inspecting encrypted and HTTPS traffic. The Firebox M590 on review is a prime example: this 1U rack appliance ditches the dual-core Intel i3-6100 desktop–class CPU from the elderly T570 and replaces it with a 2GHz NXP LX2120A SoC, which puts twelve ARM Cortex A72 cores on the table.</p><p>Targeting mid-sized businesses and distributed enterprises with up to 1,000 users, the M590 claims a raw firewall throughput of 20Gbits/sec, 3.3Gbits/sec with UTM services enabled and a very creditable 1.9Gbit/sec with HTTPS content inspection activated. Other improvements over the M570 include a larger internal 128GB <a href="https://www.itpro.com/solid-state-storage-ssd/33908/best-ssds-the-top-nvme-and-sata-drives-around" data-original-url="https://www.itpro.com/solid-state-storage-ssd/33908/best-ssds-the-top-nvme-and-sata-drives-around">M.2 SSD</a>, dual 150W PSUs and two 10GbE SFP+ ports for high-speed connections over longer distances.</p><p>The single expansion bay to the right of the embedded ports accepts a range of modules including quad copper or fibre Gigabit, dual 10GbE SFP+ or a four-port multi-Gigabit option with PoE+. Our review system came with the latter, and the kit includes a chunky 54V power brick which needs to be plugged into a dedicated port at the rear to enable PoE+ delivery.</p><h2 id="watchguard-firebox-m590-review-management-and-deployment">WatchGuard Firebox M590 review: Management and deployment</h2><p>One area where WatchGuard excels is appliance management, as your choices are manifold. The M590 can be run in standalone mode and configured using its local web console and WatchGuard’s free System Manager (WSM) software suite, or linked up with the free VMware and Hyper-V virtualised Dimension software and its optional Command service.</p><p>Businesses managing multiple, geographically distributed Fireboxes will love WatchGuard’s Cloud service as they can access them all from a single web portal. Included with both security subscriptions, it offers two choices: you can elect to retain local management and set the appliance up to send all its logs to the cloud portal, or opt for full cloud management.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="95k2bvTvMZX7n8DVS6jtiN" name="" alt="A screenshot of the WatchGuard Firebox M590 control dashboard" src="https://cdn.mos.cms.futurecdn.net/95k2bvTvMZX7n8DVS6jtiN.png" mos="https://cdn.mos.cms.futurecdn.net/95k2bvTvMZX7n8DVS6jtiN.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The cloud option adds another benefit by bringing WatchGuard’s RapidDeploy feature into play. Upload a predefined configuration file created from a local Firebox, assign it to a newly registered appliance, pack it off to a remote site and after connection and power up, it automatically takes the file from your cloud account.</p><p>We began testing by registering the M590 with our WatchGuard customer account and once it was powered up, it pulled down our feature key and offered a quick start wizard. We initially chose local management with cloud logging and once we’d allocated the M590 to our cloud account, it duly started sending details on all traffic, detected threats and responses.</p><p>A new feature makes it dead easy to swap to full cloud management, and we just had to click one button in the portal’s device configuration page. After reconfiguration, the M590 disabled its local web interface, took all its settings from the cloud and furnished us with full remote configuration access.</p><h2 id="watchguard-firebox-m590-review-security-subscriptions">WatchGuard Firebox M590 review: Security subscriptions</h2><p>WatchGuard keeps licensing as simple as possible; all Fireboxes are available with two options and we’ve shown the price for the M590 appliance with a 3-year Total Security Suite (TSS) subscription. This starts with the same features as you’ll get with the cheaper Basic Security Suite (BSS) and includes gateway AV, anti-spam, web content filtering, application controls, intrusion prevention services (IPS) and WatchGuard’s RED (reputation enabled defence).</p><p>The TSS subscription essentially activates WatchGuard’s Automation Core (WAC) technology, which is designed to ease the life of support staff by providing proactive threat responses. ThreatSync collects event data from all Fireboxes, DNSWatch blocks user access to known malicious domains while IntelligentAV and its Cylance AI-based engine scans files after they’ve passed through the gateway AV scanner and uses <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> to identify and block <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">new malware</a>. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NJKoXvmhmXLRWSiFyjGjMM" name="" alt="A screenshot of the WatchGuard Firebox M590 security settings" src="https://cdn.mos.cms.futurecdn.net/NJKoXvmhmXLRWSiFyjGjMM.png" mos="https://cdn.mos.cms.futurecdn.net/NJKoXvmhmXLRWSiFyjGjMM.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>TSS also activates WatchGuard’s Gold support, which provides a one hour targeted response time for high priority issues. It also increases the cloud log retention period from 1 day to 30 days.</p><h2 id="watchguard-firebox-m590-review-cloud-configuration">WatchGuard Firebox M590 review: Cloud configuration</h2><p>We found the WatchGuard Cloud portal very easy to use with five main menu tabs provided for a dashboard view of account and Firebox status, monitoring, configuration, inventory and administration. The monitoring page opens with an overview of all Fireboxes showing all the action for every security service and you can drill down to individual appliances.</p><p>Move to the configuration page and you can select a specific Firebox and manage all its security services from one screen. The content scanning section provided access to gateway AV, IntelligentAV, the APT blocker and spamBlocker services and in many cases, they can be activated simply by clicking on a slider bar.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy" data-original-url="/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy">WatchGuard Firebox T40-W review: Powerful yet classy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361926/sophos-xgs-3300-review-xstream-firewall-performance" data-original-url="/security/361926/sophos-xgs-3300-review-xstream-firewall-performance">Sophos XGS 3300 review: Xstream firewall performance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a" data-original-url="/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a">WatchGuard Firebox M290 review: Stiff security at a great price</a></p></div></div><p>Network blocking includes <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet" data-original-url="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnet detection</a> and IPS settings with the Geolocation section below allowing you to block traffic from specific countries. Web filtering and application controls are both managed using custom actions where you choose from 130 URL categories to block or allow and browse nearly 1,300 predefined app signatures neatly organised into 11 categories for easy access.</p><p>From the inventory page, you view all activated Fireboxes and allocate new ones to your cloud account. The administration section provides access to Firebox audit logs and you can create scheduled reports for any or all devices, choose which services you want executive summaries for and provide email addresses of recipients.</p><h2 id="watchguard-firebox-m590-review-verdict">WatchGuard Firebox M590 review: Verdict</h2><p>The Firebox M590 is a versatile UTM appliance and WatchGuard’s simplified licensing schemes make it easy to choose the right level of protection. Deployment is cinch, it offers a wealth of enterprise-grade security services at a very competitive price and the choice of local or cloud management makes it equally well suited to mid-range businesses and enterprises needing to protect distributed remote offices.</p><h2 id="watchguard-firebox-m590-specifications">WatchGuard Firebox M590 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >1U rack</td></tr><tr><td  ><strong>CPU</strong></td><td  >12-core 2GHz NXP LX2120A</td></tr><tr><td  ><strong>Memory</strong></td><td  >8GB ECC DDR4</td></tr><tr><td  ><strong>Storage</strong></td><td  >128GB M.2 SATA SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >8 x Gigabit, 2 x 10GbE SFP+</td></tr><tr><td  ><strong>Expansion</strong></td><td  >1 x module bay</td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB 2, RJ-45 serial</td></tr><tr><td  ><strong>Power</strong></td><td  >Dual internal 150W PSUs</td></tr><tr><td  ><strong>Management</strong></td><td  >Web browser, WatchGuard WSM/Dimension/Command/Cloud</td></tr><tr><td  ><strong>Warranty</strong></td><td  >Included in subscription</td></tr><tr><td  ><strong>Optional modules</strong></td><td  >2 x 10GbE SFP+, £706; 4 x 1GbE copper, £462, 4 x multi-Gigabit PoE+ with 54V PSU, £1,383 (all exc VAT)</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WatchGuard Firebox T40-W review: Powerful yet classy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy</link>
                                                                            <description>
                            <![CDATA[ A powerful desktop security appliance with classy remote monitoring and configuration services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ddFSQuLvd3sZy3XD2U3Kzq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zHmmEniw7wboGg6DxRcCv8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Mar 2022 15:08:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zHmmEniw7wboGg6DxRcCv8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WatchGuard Firebox T40-W ports]]></media:description>                                                            <media:text><![CDATA[WatchGuard Firebox T40-W ports]]></media:text>
                                <media:title type="plain"><![CDATA[WatchGuard Firebox T40-W ports]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zHmmEniw7wboGg6DxRcCv8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Designed for small offices and remote sites, the Firebox T40-W offers enterprise-class gateway security measures at an affordable price. It’s big on performance, too, as its 1GHz quad-core CPU and 4GB of DDR4 RAM provide – WatchGuard claims – a high raw firewall throughput of 3.4Gbits/sec and 300Mbits/sec with the AV, IPS and application control services enabled.</p><p>Management choices are extensive, as the T40-W offers a local web console and can be monitored using WatchGuard’s free Dimension logging software. More importantly, it can be integrated with WatchGuard’s cloud portal, which now provides remote configuration services along with monitoring.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a" data-original-url="/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a">WatchGuard Firebox M290 review: Stiff security at a great price</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/366293/watchguard-wraps-up-panda-security-acquisition" data-original-url="/business-strategy/mergers-and-acquisitions/366293/watchguard-wraps-up-panda-security-acquisition">WatchGuard wraps up Panda Security acquisition</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/366071/watchguard-launches-virtual-firewall" data-original-url="/security/366071/watchguard-launches-virtual-firewall">WatchGuard launches virtual firewall</a></p></div></div><p>The T40-W offers a solid <a href="https://www.itpro.com/hardware" data-original-url="https://www.itpro.com/hardware">hardware</a> package, with five Gigabit ports for WAN, LAN and DMZ duties. The fourth LAN port adds extra versatility as it presents PoE+ services for powering compliant external devices. </p><p>Integral wireless services are limited to the older 11ac variety, while the 2.4GHz and 5GHz radios can’t both be active at the same time. Even so, this will be enough for many small businesses, and the appliance’s wireless gateway feature can provision and manage other WatchGuard access points. </p><p>The price above includes a one-year subscription to WatchGuard’s Total Security suite, which enables everything the company has to offer. Features include gateway AV, anti-spam, web content filtering, application controls, intrusion prevention services (IPS) and an advanced persistent threat (APT) blocker. </p><p>WatchGuard’s RED (reputation enabled defence) service provides tighter web security, and cloud management is included in both the Basic and Total subscriptions. Unlike the entry-level T20-W, this model has enough horsepower to handle the IntelligentAV malware scanner, which uses the Cylance AI-based engine.</p><p>Local deployment is swift as the web console quick-start wizard enables firewall-protected internet access and applies a base set of <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> policies. Network traffic is handled by various proxies, which include HTTP, HTTPS, FTP, SIP, POP3 and SMTP, and each one offers a wizard to simplify setup.</p><p><a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/cloud">Cloud</a> management is equally easy to master, and after registering the appliance with our WatchGuard support account, it appeared in the cloud console ready for allocation. You then choose between local or remote management, with the former simply activating monitoring and sending activity logs to your account.</p><p>Remote management requires a few more steps: you set up the WAN port, enable basic wireless services and apply a new administrative password. When the appliance is powered up, it takes all these settings from the cloud, disables local management and only provides options to view its status, upgrade the OS and load the cloud portal.</p><p>The cloud portal has full access to all the same settings you’ll see in the local console, so nothing is beyond its remit. You can configure gateway AV scanning and <a href="https://www.itpro.com/security/ransomware/361589/iran-backed-hackers-ransomware-critical-infrastructure-warning" data-original-url="https://www.itpro.com/security/ransomware/361589/iran-backed-hackers-ransomware-critical-infrastructure-warning">APT</a> blocking, enable IntelligentAV with one click on its slider bar and set up anti-spam policies for incoming SMTP, IMAP or POP3 traffic, and tag spam messages in their subject line for ongoing local rule processing.</p><p>The WebBlocker service presents 130 URL categories that can be blocked or allowed, and you can add new policies with different actions and apply them to custom firewall rules. The content-filtering section in the portal also provides access to WatchGuard’s application control service, which offers over 1,100 predefined app signatures, including 41 for fine-grained control over all popular social networking platforms.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AXyuyXZrhv9g2RHNga6TUU" name="" alt="WatchGuard Firebox T40-W" src="https://cdn.mos.cms.futurecdn.net/AXyuyXZrhv9g2RHNga6TUU.jpg" mos="https://cdn.mos.cms.futurecdn.net/AXyuyXZrhv9g2RHNga6TUU.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Cloud monitoring is excellent, with the portal providing detailed views of live activities, all traffic, the top clients, application usage, and much more. It also adds the same services as provided by WatchGuard’s Dimension server, so you can pull up views of appliance utilisation plus an executive dashboard, global threat map, and policy activity graphs.</p><p>Wireless services are comparatively basic, but the Firebox T40-W makes up for this with impressive performance and top-notch gateway security measures. It’s affordable for SMBs, and the configuration and monitoring services provided by the cloud portal will appeal to businesses deploying it to <a href="https://www.itpro.com/business-strategy/training/358122/upskilling-a-remote-workforce" data-original-url="https://www.itpro.com/business-strategy/training/358122/upskilling-a-remote-workforce">remote offices</a>.</p><h2 id="watchguard-firebox-t40-w-review-specifications">WatchGuard Firebox T40-W review: Specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop fan-less</td></tr><tr><td  ><strong>CPU</strong></td><td  >quad-core 1GHz NXP LS1043A</td></tr><tr><td  ><strong>Memory</strong></td><td  >4GB DDR4 ECC</td></tr><tr><td  ><strong>Storage included</strong></td><td  >16GB mSATA</td></tr><tr><td  ><strong>Network</strong></td><td  >5 x Gigabit (WAN, 4 x LAN – LAN4 with PoE+), 2.4/5GHz Wi-Fi 5</td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB-A 3, RJ-45 serial port</td></tr><tr><td  ><strong>Management</strong></td><td  >Web browser, Dimension and cloud management</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >217 x 206 x 44mm</td></tr><tr><td  ><strong>Weight</strong></td><td  >900g</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Unified endpoint management solutions 2021-22 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/367050/unified-endpoint-management-solutions-2021-22</link>
                                                                            <description>
                            <![CDATA[ Analysing the UEM landscape ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r9nz11fQuavkrRBSoUtkhL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Mar 2022 14:43:21 +0000</pubDate>                                                                                                                                <updated>Mon, 04 Jul 2022 10:43:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title on shaded pink/purple background]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title on shaded pink/purple background]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title on shaded pink/purple background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zN9yq6wvv8oBhbPFBWeEAd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The rise of hybrid working means that many businesses now have to manage a workforce that is remote for part or all of the working week. In this climate, organisations are increasingly turning to unified endpoint management (UEM) solutions to keep their employees and their devices secure.</p><p>Companies seeking to adopt more modern management practices are driving growth in the UEM market, and these solutions are now considered a vital piece of the broader enterprise IT infrastructure puzzle.</p><p>Read the report to understand Omdia's analysis of the UEM landscape, as well as why IBM was named one of the leaders for unified endpoint management.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rQy9MUeL7vDLefQJcJuEZZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" mos="https://cdn.mos.cms.futurecdn.net/rQy9MUeL7vDLefQJcJuEZZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49716/ibm-q3-2022-en?locale=1&p=false&wp=9820"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WatchGuard Firebox M290 review: Stiff security at a great price ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a</link>
                                                                            <description>
                            <![CDATA[ The Firebox M290 delivers an incredible range of gateway security measures priced right for SMBs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vWXWuY1hpBmPdAtnmuvCSn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Mx5kTTg444dfDWEBdbGFEB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Feb 2022 10:07:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Mx5kTTg444dfDWEBdbGFEB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of the WatchGuard Firebox M290]]></media:description>                                                            <media:text><![CDATA[A photograph of the WatchGuard Firebox M290]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of the WatchGuard Firebox M290]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Mx5kTTg444dfDWEBdbGFEB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>WatchGuard’s latest M-series rackmount security appliances have a sharp focus on value and are designed to offer SMBs and mid-sized companies affordable enterprise-level gateway security. Stepping up as the entry point of the family, the Firebox M290 on review certainly hits this target: the price we’ve shown includes the appliance and a 3-year Total Security Suite (TSS) subscription which enables every feature WatchGuard has to offer.</p><p>Clothed in <a href="https://www.itpro.com/security/unified-threat-management-utm/357252/watchguard-firebox-t20-w-review-superb-all-in-one" data-original-url="https://www.itpro.com/security/unified-threat-management-utm/357252/watchguard-firebox-t20-w-review-superb-all-in-one">Watchguard’s customary fire engine-red chassis</a>, this 1U rack appliance targets businesses with up to 75 users and boasts a high raw firewall throughput of 5.8Gbits/sec, dropping to 1.18Gbits/sec with all UTM services enabled. With <a href="https://www.itpro.com/security/361390/https-based-attacks-soar-over-300" data-original-url="https://www.itpro.com/security/361390/https-based-attacks-soar-over-300">the bulk of malware now being delivered over HTTPS-encrypted connections</a>, the M290 has the horsepower to handle these inspection overheads, as it’s powered by a quad-core NXP LX1046A CPU partnered by 4GB of DDR4 system memory.</p><p>Network connections look good too, and the M290 presents eight Gigabit ports which can be used for WAN, LAN or DMZ duties. There’s room for even more via the expansion slot at the front, which supports an optional module with four copper or fibre Gigabit ports, or dual 10GbE SFP+.</p><p>On top of this, WatchGuard also offers a 4-port multi-Gigabit module with PoE+, but while you can use it in the M290, this appliance doesn’t support the required optional 54V power supply, so its PoE+ services will be disabled. If you want this functionality, you’ll have to opt for the M590 or the M690, as these are the only ones which fully support this module.</p><h2 id="watchguard-firebox-m290-review-security-features">WatchGuard Firebox M290 review: Security features</h2><p>WatchGuard offers two Firebox licence schemes so you could save some cash with the Basic Security Suite subscription. Available for one or three year periods and costing £2,077 exc VAT for the latter, this activates gateway antivirus (GAV), antispam, web filtering, HTTPS inspection, IPS, application controls, WatchGuard’s RED (reputation enabled defence) cloud-based URL filtering and secure <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan" data-original-url="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan">software defined WAN (SD-WAN)</a> services. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="smy6A2u88PEUDWVoZccH3N" name="" alt="A screenshot of the WatchGuard Firebox M290's web console" src="https://cdn.mos.cms.futurecdn.net/smy6A2u88PEUDWVoZccH3N.jpg" mos="https://cdn.mos.cms.futurecdn.net/smy6A2u88PEUDWVoZccH3N.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>A TSS subscription includes all these features, but additionally augments them with WatchGuard’s advanced persistent threat (APT) blocker, plus its Threat Detection and Response (TDR) service with a 75 host sensor licence included. Malware protection is beefed up with IntelligentAV which uses the Cylance AI-based engine to scan files such as <a href="https://www.itpro.com/software/microsoft-office/362184/microsoft-disables-vba-macros-in-office-by-default" data-original-url="https://www.itpro.com/software/microsoft-office/362184/microsoft-disables-vba-macros-in-office-by-default">Office documents</a>, Windows portable executables and PDFs after they’ve passed through the GAV scanner.</p><p>WatchGuard’s DNSWatch service also monitors client DNS requests and blocks access to known malicious domains. Remote monitoring and management via the WatchGuard Cloud portal is enabled across all subscriptions and TSS increases the log retention to 30 days.</p><h2 id="watchguard-firebox-m290-review-management-choices">WatchGuard Firebox M290 review: Management choices</h2><p>Management choices are impressive - you can monitor and configure the M290 using its local web console and run WatchGuard’s free System Manager (WSM) suite on a separate Windows host to provide central management, logging and reporting services. </p><p>Next up is WatchGuard’s free Dimension software which is virtualized on a Hyper-V or VMware host. This provides a separate web console for viewing appliance utilisation, an executive dashboard, policy activity graphs and a global threat map, and enabling the optional Dimension Command feature brings Firebox management into play.</p><p>We think WatchGuard’s Cloud is a better choice than Dimension, as it provides all the same features without the need for a host system. You have two choices: you can keep local management enabled and set the appliance to send its logs to the cloud for monitoring and reporting, or disable local management and move it all into the cloud.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WnojsUjWvkaVjBQZ6HzkMW" name="" alt="A screenshot of the WatchGuard Firebox M290's config dashboards" src="https://cdn.mos.cms.futurecdn.net/WnojsUjWvkaVjBQZ6HzkMW.jpg" mos="https://cdn.mos.cms.futurecdn.net/WnojsUjWvkaVjBQZ6HzkMW.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h2 id="watchguard-firebox-m290-review-cloud-deployment">WatchGuard Firebox M290 review: Cloud deployment</h2><p>Initial deployment is swift, as the appliance’s web console provides a quick start wizard which runs through enabling <a href="https://www.itpro.com/security/firewalls/355328/how-to-build-your-own-firewall-with-pfsense" data-original-url="https://www.itpro.com/security/firewalls/355328/how-to-build-your-own-firewall-with-pfsense">firewall-protected internet access</a> and applying a base set of security policies. We had already registered the serial number of the M290 with our cloud support account so it grabbed our TSS feature key and applied it for us.</p><p>From our WatchGuard Cloud portal, we could see the appliance was available for allocation and selecting this offered two options: local management with cloud reporting and full cloud management. Initially, we chose the former and after a few minutes, a wealth of information from the M290’s activity logs started appearing in our portal including detailed views of traffic, web and application activity, all security services and the most active clients.</p><p>Swapping to full cloud management required the M290 to be deallocated, returned to our inventory and reallocated with this option selected. After running through WAN port setup and applying a new administrative password, the M290 disabled local management and only provided options to view its status, upgrade the OS and load the cloud portal.</p><h2 id="watchguard-firebox-m290-review-cloud-security-settings">WatchGuard Firebox M290 review: Cloud security settings</h2><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/361926/sophos-xgs-3300-review-xstream-firewall-performance" data-original-url="/security/361926/sophos-xgs-3300-review-xstream-firewall-performance">Sophos XGS 3300 review: Xstream firewall performance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/359220/zyxel-usg-flex-100-flexible-gateway-security" data-original-url="/security/unified-threat-management-utm/359220/zyxel-usg-flex-100-flexible-gateway-security">Zyxel USG Flex 100 review: Flexible gateway security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one" data-original-url="/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one">Ubiquiti Networks UniFi Dream Machine Pro review: All the security you need in one handy box</a></p></div></div><p>Configuring the M290 from the cloud portal is even easier than using its local web interface, as all security settings are accessed from a single web page. For content scanning, we could enable GAV and choose an action when a virus is detected, activate IntelligentAV with one click and set APT to drop traffic for high, medium and low threat levels.</p><p>Antispam uses policies for incoming SMTP, IMAP or POP3 traffic with options to allow, deny or tag suspect messages. The content filtering section provides access to the WebBlocker service which offers 130 URL categories that can be allowed, blocked or set to display a warning page to users. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="v9NuHn7peNG8Bp89c9QXkB" name="" alt="A screenshot of the WatchGuard Firebox M290's threat map" src="https://cdn.mos.cms.futurecdn.net/v9NuHn7peNG8Bp89c9QXkB.jpg" mos="https://cdn.mos.cms.futurecdn.net/v9NuHn7peNG8Bp89c9QXkB.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>WebBlocker actions are applied with firewall rules and are also used to manage the application control service. This presents nearly 1,300 predefined app signatures, including 12 sub-categories for all Facebook activities, making it easy to block or control its use in the workplace.</p><h2 id="watchguard-firebox-m290-review-verdict">WatchGuard Firebox M290 review: Verdict</h2><p>The Firebox M290 is an attractive choice for SMBs; it combines a superb range of security measures and delivers them at a sensible price. We found it easy to deploy and configure, with WatchGuard’s Cloud portal providing excellent remote management and monitoring features.</p><h2 id="watchguard-firebox-m290-specifications">WatchGuard Firebox M290 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >1U rack</td></tr><tr><td  ><strong>CPU</strong></td><td  >Quad-core NXP LX1046A</td></tr><tr><td  ><strong>Memory</strong></td><td  >4GB ECC DDR4</td></tr><tr><td  ><strong>Storage</strong></td><td  >128GB M.2 SATA SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >8 x Gigabit</td></tr><tr><td  ><strong>Expansion</strong></td><td  >1 x module bay</td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB 2, RJ-45 serial</td></tr><tr><td  ><strong>Power</strong></td><td  >Internal 65W PSU</td></tr><tr><td  ><strong>Management</strong></td><td  >Web browser, WatchGuard WSM/Dimension/Command/Cloud</td></tr><tr><td  ><strong>Warranty</strong></td><td  >Included in subscription</td></tr><tr><td  ><strong>Optional modules</strong></td><td  >2 x 10GbE SFP+, £711; 4 x 1GbE copper, £466 (all exc VAT)</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos XGS 3300 review: Xstream firewall performance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/361926/sophos-xgs-3300-review-xstream-firewall-performance</link>
                                                                            <description>
                            <![CDATA[ A powerful firewall appliance combining hardware acceleration with a vast array of security measures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">quuVhh2nhrxwNSbsRa38bH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wXAB7QBQsrXsWCXuyqv4qM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Jan 2022 11:18:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wXAB7QBQsrXsWCXuyqv4qM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of the Sophos XGS 3300]]></media:description>                                                            <media:text><![CDATA[A photograph of the Sophos XGS 3300]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of the Sophos XGS 3300]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wXAB7QBQsrXsWCXuyqv4qM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The XGS family of security appliances represent a radical shift in direction for Sophos as they take over from <a href="https://www.itpro.com/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible" data-original-url="https://www.itpro.com/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible">the older XG models</a> and deliver a new dual processor architecture. Built around Xstream flow processors, they provide a hardware acceleration layer which Sophos reckons can realise a minimum two-fold performance boost over equivalent XG models by removing much of the workload from the main CPU.</p><p>This is no idle claim: the XGS 3300 we have on review boasts a massive firewall IMIX (internet mix) throughput of 24.5Gbits/sec, dropping to 13.4Gbits/sec with IPS enabled. By contrast, the XG 330 it replaces could only muster equivalent throughputs of 12.5Gbits/sec and 8.5Gbits/sec respectively.</p><p>Intel gets the elbow too, as the Xeon E3 v5 CPUs in the XG range have been replaced by <a href="https://www.itpro.com/hardware/361903/amd-unveils-ryzen-6000-laptop-processors-with-rdna2-graphics" data-original-url="https://www.itpro.com/hardware/361903/amd-unveils-ryzen-6000-laptop-processors-with-rdna2-graphics">AMD’s Ryzen</a> Embedded V1000 series, sporting a 3.35GHz quad-core V1780B SoC (System on Chip). This is partnered by 16GB of DDR4 memory while firmware, log and report storage is handled by an internal 240GB SATA SSD.</p><h2 id="sophos-xgs-3300-review-licensing-and-deployment">Sophos XGS 3300 review: Licensing and deployment</h2><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one" data-original-url="/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one">Ubiquiti Networks UniFi Dream Machine Pro review: All the security you need in one handy box</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/359141/fortinet-fortigate-60f-a-fully-featured-security" data-original-url="/security/unified-threat-management-utm/359141/fortinet-fortigate-60f-a-fully-featured-security">Fortinet FortiGate 60F: A fully-featured security appliance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/359220/zyxel-usg-flex-100-flexible-gateway-security" data-original-url="/security/unified-threat-management-utm/359220/zyxel-usg-flex-100-flexible-gateway-security">Zyxel USG Flex 100 review: Flexible gateway security</a></p></div></div><p>Aimed at distributed edge deployments in large SMBs and mid-sized organisations, this 1U rack appliance presents eight copper and two SFP fibre Gigabit, plus dual SFP+ fibre 10GbE ports. It offers one Flexi expansion slot which accepts two-, four- and eight-port Gigabit and 10GbE modules, but be aware that it doesn’t support those from the older XG range.</p><p>Licensing has changed quite a bit too and you can customize features by choosing which protection modules you want. The Xstream bundle enables base firewall features including Xstream Network Flow FastPath along with TLS 1.3 and deep packet inspection, and adds the network, web and zero-day protection modules, central orchestration and enhanced 24/7 support. This doesn’t include the email and web server protection modules though, which are available as optional extras.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KkVQKRwzCyTGU3eV9ecMnf" name="" alt="A screenshot of the Sophos XGS 3300 firewall reporting console" src="https://cdn.mos.cms.futurecdn.net/KkVQKRwzCyTGU3eV9ecMnf.jpg" mos="https://cdn.mos.cms.futurecdn.net/KkVQKRwzCyTGU3eV9ecMnf.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>A dedicated management port is provided and we found initial deployment via the browser-based quick-start wizard swift. After insisting we secured administrative access, it helped set up LAN and WAN port address assignments plus DHCP services and provide an email address for alerting.</p><p>We chose routed mode, as we wanted the appliance to provide all security functions including firewalling. Protection starts immediately, with a base set of firewall security policies created for you which enable web filtering and anti-malware.</p><h2 id="sophos-xgs-3300-review-management-services">Sophos XGS 3300 review: Management services</h2><p>The local web console opens with a very informative Control Center dashboard presenting a detailed overview of network activity, security issues, web traffic, detected network attacks plus blocked and allowed applications and web categories. The User and device Insights section is particularly useful as it provides active icons for functions such as zero-day protection. Clicking on these shows downloaded files that have been sent to the Sophos cloud sandbox for detonation and analysis to see whether they are safe to release.</p><p>If you have <a href="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it" data-original-url="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it">a Sophos Central account</a>, you can manage the firewall remotely as well. It’s dead easy, too; after registering the XGS 3300 with our cloud account, we were able to view live reports from the portal and configure it using exactly the same console as the local one.</p><p>Sophos Central has another trick up its sleeve, and its endpoint agents can be brought under the firewall’s control with the Synchronized Security feature. This uses a heartbeat service to monitor endpoints running the Intercept X agent and if any are compromised, a firewall policy with a minimum heartbeat setting isolates all systems in the same zone. </p><p>The SAC (synchronized application control) feature also works with this service, as it detects unknown applications and pushes out firewall policies to control them. Cloud apps get the same tough love: the dashboard insights section lists all those detected and you can classify each one as sanctioned or unsanctioned and apply a traffic shaping policy to control their use.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6J6yYZ3BfuYZHC7ydWTjLo" name="" alt="A screenshot of the Sophos XGS 3300 Control Centre" src="https://cdn.mos.cms.futurecdn.net/6J6yYZ3BfuYZHC7ydWTjLo.jpg" mos="https://cdn.mos.cms.futurecdn.net/6J6yYZ3BfuYZHC7ydWTjLo.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><h2 id="sophos-xgs-3300-review-security-and-reporting">Sophos XGS 3300 review: Security and reporting</h2><p>The XGS 3300 is highly versatile, and you can place its ports in different zones and apply custom security policies to each one. Policies contain firewall rules for sources and destinations, service filters, blocking actions and time schedules and you can apply custom policies for web filtering, IPS and application controls.</p><p>The new filtering option makes it easy to find a specific rule in the list and firewall rule traffic counters for selected policies can now be reset back to zero from the web console without having to reboot the appliance. You don’t need to change rule priorities in policies with drag and drop either, as they can be reordered directly from the policy drop down menu.</p><p>There are plenty more security features to play with; web filtering offers 86 URL categories to block or allow while application controls currently provide 3,532 predefined apps. If you want Facebook gone from the workplace, you’ll be pleased to know Sophos provides 73 app categories covering every possible social activity. </p><p>Reporting is a standard feature on all XGS models with the web console providing a wealth of information on all things security related. The reports option in the web console’s side menu loads a variety of dashboards and graphs showing detected threats, malware and web content filtering activities, offers reports for key compliance standards, and all their content can be exported in PDF, HTML and CSV formats.</p><h2 id="sophos-xgs-3300-review-verdict">Sophos XGS 3300 review: Verdict</h2><p>The XGS 3300 is easy to deploy, although the sheer range of security features may present new users with a steep learning curve for ongoing configuration. Sophos does provide copious online documentation and videos but it’s a lot to wade through and it still refers to the XG firewalls.</p><p>Overall though, the XGS 3300 is clearly a very powerful and well-endowed firewall appliance. The network ports and zones make it very versatile, the latest SFOS 18.5 software adds many features designed to ease management, and integration with Sophos Central allows it to extend its protection umbrella to remote workers.</p><h2 id="sophos-xgs-3300-specifications">Sophos XGS 3300 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >1U rack</td></tr><tr><td  ><strong>CPU</strong></td><td  >3.35GHz quad-core AMD Ryzen Embedded V1780B</td></tr><tr><td  ><strong>Memory</strong></td><td  >16GB DDR4</td></tr><tr><td  ><strong>Storage</strong></td><td  >240GB SATA SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >8 x Gigabit copper, 2 x Gigabit SFP, 2 x 10GbE SFP+</td></tr><tr><td  ><strong>Expansion</strong></td><td  >1 x Flexi module slot</td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB 3, 1 x USB 2, RJ45 MGMT, COM, micro-USB</td></tr><tr><td  ><strong>Power</strong></td><td  >Internal PSU, optional external redundant PSU</td></tr><tr><td  ><strong>Management</strong></td><td  >Web browser, Sophos Central</td></tr><tr><td  ><strong>Warranty</strong></td><td  >Included in subscription</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ubiquiti Networks UniFi Dream Machine Pro review: All the security you need in one handy box ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one</link>
                                                                            <description>
                            <![CDATA[ An affordable security gateway that can take care of a wide range of security needs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rekMV1YvPZm8wfEiT4sngC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aA3UqZPtKiDCnx7nYQp6QC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Nov 2021 08:00:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aA3UqZPtKiDCnx7nYQp6QC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Photo of the Ubiquiti Networks UniFi Dream Machine Pro]]></media:description>                                                            <media:text><![CDATA[Photo of the Ubiquiti Networks UniFi Dream Machine Pro]]></media:text>
                                <media:title type="plain"><![CDATA[Photo of the Ubiquiti Networks UniFi Dream Machine Pro]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aA3UqZPtKiDCnx7nYQp6QC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As an all-in-one security gateway, Ubiquiti’s UniFi Dream Machine Pro takes some beating. This sleek 1U rack appliance provides gateway, routing, VPN and firewall services, plus threat protection, deep packet inspection and wireless network management too, courtesy of the integrated UniFi Controller. Slot a hard disk into the front-facing bay and the appliance can even be used as a recording vault for UniFi IP surveillance cameras.</p><p>Connectivity is well covered, as the appliance incorporates a managed eight-port <a href="https://www.itpro.com/server-storage/network-switches/355660/choosing-the-right-ethernet-switch" data-original-url="https://www.itpro.com/server-storage/network-switches/355660/choosing-the-right-ethernet-switch">Gigabit Ethernet switch</a>, alongside a Gigabit WAN port and two 10GbE SFP+ high-performance fibre ports for LAN and WAN duties. And the UDM Pro is no lightweight when it comes to performance: Ubiquiti claims a high firewall throughput of 3.5Gbits/sec with IDP/IPS enabled – quite remarkable at this price point. It’s achieved thanks to a speedy 1.7GHz quad-core ARM CPU, partnered with a generous 4GB of DDR4 RAM and 16GB of flash storage.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29068/is-your-company-taking-enough-accountability-on-cybersecurity" data-original-url="/security/29068/is-your-company-taking-enough-accountability-on-cybersecurity">Is your company taking enough accountability on cyber security?</a></p></div></div><p>The one thing that’s notably missing is a built-in wireless access point: the <a href="https://www.itpro.com/hardware/routers/354803/ubiquiti-networks-unifi-dream-machine-review-a-dream-come-true" data-original-url="https://www.itpro.com/hardware/routers/354803/ubiquiti-networks-unifi-dream-machine-review-a-dream-come-true">desktop Dream Machine</a> includes its own AP, but that wouldn’t make a lot of sense in a metal rack cabinet. Power over Ethernet isn’t supported either, but you can combine the appliance with one of Ubiquiti’s affordable PoE switches; we used its USW-Pro-24-PoE model for testing.</p><p>Gateway installation is a cinch. After connecting the appliance’s WAN port to an internet line, we used the UniFi Network iOS app on an iPad to discover the Dream Machine over Bluetooth. The app’s quick-start wizard then linked it to our Ubiquiti cloud account and automatically installed the latest firmware.</p><p>From here on, you can use the UniFi web portal to access the Network and Protect apps. The Network page opens with a smart dashboard of graphs showing measured internet speeds, most active clients and applications, client device types and wireless experience scores. Everything you need to know about your networks is on hand, with a <a href="https://www.itpro.com/network-internet/31778/what-is-network-topology" data-original-url="https://www.itpro.com/network-internet/31778/what-is-network-topology">detailed topology view</a>, lists of all managed UniFi devices and connected clients, plus a complete breakdown of all traffic. The latter includes pie charts for web, media streaming, file sharing, network protocols and more, along with breakdowns of upstream and downstream traffic.</p><p>As for protection, <a href="https://www.itpro.com/network-internet/31914/what-is-network-intelligence" data-original-url="https://www.itpro.com/network-internet/31914/what-is-network-intelligence">deep packet inspection</a> is enabled by default; you can either activate passive IDS to alert you to intrusions, or use IDP to block them, choosing a detection sensitivity level and selecting the types of threats you want to be protected against. URL content filtering can be applied too, with separate settings for work or home environments.</p><p>We were also able to use the iOS app to add the USW PoE switch to our account, and were blown away by its clever <a href="https://www.itpro.com/technology/augmented-reality-ar/357592/why-ar-not-vr-is-the-next-big-thing-in-business" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/357592/why-ar-not-vr-is-the-next-big-thing-in-business">augmented reality (AR) feature</a>: point your device camera at the ports and a live overlay immediately pops up, showing which ones are active and what’s connected to them.</p><p>For wireless testing we connected a set of UniFi nanoHD access points to the PoE switch and added them to our cloud account. Once online, they started broadcasting our <a href="https://www.itpro.com/broadband/30390/what-is-ssid" data-original-url="https://www.itpro.com/broadband/30390/what-is-ssid">predefined SSIDs</a> and guest networks, with details automatically appearing in the portal’s wireless experience graph.</p><p>Video surveillance is just as easy to set up. The appliance accepted our Seagate 10TB SATA drive without a murmur and instantly made it available for recording incoming video. After we’d added a UVC G4 Bullet IP camera to our account, we were able to view its live feed from the portal, enable smart detection and set up custom motion-detection events and recording actions.</p><p>The UniFi Dream Machine Pro is an impressive piece of kit to say the least, delivering an incredible range of easily managed features at an unbelievably low price. There are some great UTM appliances on the market, but the Ubiquiti simply does it all.</p><h2 id="ubiquiti-networks-unifi-dream-machine-pro-specifications">Ubiquiti Networks UniFi Dream Machine Pro specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >1U rack chassis </td></tr><tr><td  ><strong>CPU</strong></td><td  >1.7GHz quad-core ARM Cortex</td></tr><tr><td  ><strong>Memory</strong></td><td  >4GB DDR4</td></tr><tr><td  ><strong>Storage bays</strong></td><td  >1 x LFF/SFF hard disk bay</td></tr><tr><td  ><strong>Storage included</strong></td><td  >16GB eMMC</td></tr><tr><td  ><strong>Network</strong></td><td  >8 x Gigabit Ethernet LAN, 2 x 10GbE SFP+, Gigabit Ethernet WAN</td></tr><tr><td  ><strong>Management</strong></td><td  >UniFi web portal</td></tr><tr><td  ><strong>Warranty</strong></td><td  >1yr RTB warranty</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five questions to ask before you upgrade to a modern SIEM ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/security-information-and-event-management-siem/360173/five-questions-to-ask-before-you</link>
                                                                            <description>
                            <![CDATA[ Do you need a better defense strategy? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5kCUnhvP2QQhhQPNDDumqs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yi42ZzWeFY9Fmacd8eDdk3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jul 2021 10:40:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yi42ZzWeFY9Fmacd8eDdk3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[White title against a dark blue background - whitepaper from IBM]]></media:description>                                                            <media:text><![CDATA[White title against a dark blue background - whitepaper from IBM]]></media:text>
                                <media:title type="plain"><![CDATA[White title against a dark blue background - whitepaper from IBM]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yi42ZzWeFY9Fmacd8eDdk3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Provided by </em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDE4LyFCjKBJzACUQeK6rZ" name="" alt="IBM logo" src="https://cdn.mos.cms.futurecdn.net/TDE4LyFCjKBJzACUQeK6rZ.png" mos="https://cdn.mos.cms.futurecdn.net/TDE4LyFCjKBJzACUQeK6rZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Did you know that the average enterprise security team sees 200,000 security events per day? </p><p>As attackers become more dangerous and the regulatory environment continuously evolves, basic tools just can’t keep up. This is why upgrading to a Modern Security Information and Event Management (SIEM) solution is crucial.</p><p>SIEM solutions go beyond the automatic collection, parsing and normalising of logs. They apply advanced correlation and analytics to automatically detect threats, assess their severity and filter through the noise to alert you to critical events. They leverage built-in automation and intelligence to keep you protected — while simultaneously freeing up time to focus on remediation and recovery. </p><p>However, before you upgrade to a modern SIEM solution you need to be able to determine the best solution for your organisation. This report explores the five key questions to help you make this decision.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/li-285388-ibm-security-geo-qradar-q3-21-uk?locale=1&p=false&wp=6725"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Splunk debuts a new suite of cloud security solutions  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/359965/splunk-debuts-a-new-suite-of-cloud-security-solutions</link>
                                                                            <description>
                            <![CDATA[ The integrated suite offers a new pricing model too ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wuSFoVMsKcrGazCmwwg5gk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/p37KSnasu4XZocf4eQTJaf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Jun 2021 19:04:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/p37KSnasu4XZocf4eQTJaf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Magenta Splunk sign on a building ]]></media:description>                                                            <media:text><![CDATA[Magenta Splunk sign on a building ]]></media:text>
                                <media:title type="plain"><![CDATA[Magenta Splunk sign on a building ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/p37KSnasu4XZocf4eQTJaf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Log analysis company Splunk has launched Security Cloud, a suite of <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> solutions designed to make threat detection and mitigation smoother for <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> analysts. </p><p>The suite comes in two variants, Standard and Plus, and offers security analytics, threat intelligence, and automated response features. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/355558/splunk-partner-with-google-cloud-for-data-analytics" data-original-url="/cloud/cloud-computing/355558/splunk-partner-with-google-cloud-for-data-analytics">Splunk is now available on Google Cloud in beta</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/28357/splunk-and-new-relic-share-data-to-power-devops" data-original-url="/cloud/28357/splunk-and-new-relic-share-data-to-power-devops">Splunk and New Relic share data to power DevOps</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-leakage/25333/splunk-dont-make-cisos-scapegoats-for-data-breaches" data-original-url="/data-leakage/25333/splunk-dont-make-cisos-scapegoats-for-data-breaches">Splunk: Don't make CISOs scapegoats for data breaches</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-intelligence/24073/yahoo-expands-splunk-use-to-gain-more-big-data-insight-from-hadoop" data-original-url="/business-intelligence/24073/yahoo-expands-splunk-use-to-gain-more-big-data-insight-from-hadoop">Yahoo expands Splunk use to gain more Big Data insight from Hadoop</a></p></div></div><p>The Standard level offers data correlation across security tools, threat detection and guidance, and alignment with industry frameworks like MITRE's ATT&CK. The Plus suite adds threat intelligence, pre-built frameworks, and risk scoring. </p><p>Both suites use Splunk's core technology, which performs complex searches on large machine-generated data sets for probing an <a href="https://www.itpro.com/server/29744/it-infrastructure-what-are-the-building-blocks-of-your-company-s-technology" data-original-url="https://www.itpro.com/server/29744/it-infrastructure-what-are-the-building-blocks-of-your-company-s-technology">IT infrastructure</a>. They map these searches to security use cases and feature pre-built searches for <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/tags/cloud">cloud environments</a>. </p><p>The launch is part of Splunk’s strategy to bundle its existing technologies, including Observability Cloud and IT Cloud, into suites managed by front-end interfaces for easy administration. </p><p>This strategy includes a change to Splunk’s pricing model. Historically, the company charged for its services based on the volume of data that they ingested. Under the new model, each suite bases pricing on other metrics. Splunk charges for the Security Cloud based on the number of devices that it protects. </p><p>Splunk, which <a href="https://www.itpro.com/cloud/cloud-computing/355558/splunk-partner-with-google-cloud-for-data-analytics" data-original-url="https://www.itpro.com/cloud/cloud-computing/355558/splunk-partner-with-google-cloud-for-data-analytics">launched a service on Google Cloud</a> last year, also launched a security analytics solution for Amazon Web Services (AWS) that extracts data from Amazon's cloud environment and exposes them through a tailored interface. This service optimizes AWS security analytics for small teams, Splunk said. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hqxjmaqbxyxnQ7e4kT2cXa" name="hqxjmaqbxyxnQ7e4kT2cXa.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/hqxjmaqbxyxnQ7e4kT2cXa.jpg" mos="https://cdn.mos.cms.futurecdn.net/hqxjmaqbxyxnQ7e4kT2cXa.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The secure cloud configuration imperative</strong></p><p class="fancy-box__body-text">The central role of cloud security posture management</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/359672/the-secure-cloud-configuration-imperative" data-original-url="/cloud/359672/the-secure-cloud-configuration-imperative">FREE DOWNLOAD</a></p></div></div><p>Splunk will go live on the AWS marketplace on June 29. </p><p>This was a big week for Splunk, which also announced a $1 billion investment from technology investment company Silver Lake. It’ll use this money to fund growth initiatives, including a stock buyback scheme. </p><p>Splunk also announced it acquired cloud security company TruSTAR on May 18, fleshing out its security analytics offerings with a cloud-native product for gathering security intelligence from cloud-native environments. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fortinet FortiGate 60F: A fully-featured security appliance  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/359141/fortinet-fortigate-60f-a-fully-featured-security</link>
                                                                            <description>
                            <![CDATA[ The entry-level UTM appliance offers excellent cloud management and monitoring services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">26LudFBF3yLjQyinDadCwy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X5eekJCotjxVQseDUNiALQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Apr 2021 09:19:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X5eekJCotjxVQseDUNiALQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Fortigate]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Fortinet FortiGate 60F with white background]]></media:description>                                                            <media:text><![CDATA[The Fortinet FortiGate 60F with white background]]></media:text>
                                <media:title type="plain"><![CDATA[The Fortinet FortiGate 60F with white background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X5eekJCotjxVQseDUNiALQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FortiGate 60F sits in the middle of Fortinet’s entry-level range of UTM appliances and it hits a tempting sweet spot, offering a great specification at a price that SMBs will find very palatable.</p><p>That starts with connectivity. While there’s no built-in Wi-Fi, the 60F is flush with wired connections: along with five Gigabit LAN ports, it has two ports for WAN and failover services, as well as a dedicated DMZ connector. Two additional sockets can be used to manage locally attached FortiSwitch units, or as extra LAN ports. There’s enough performance to cope with a good number of clients too: thanks to Fortinet’s proprietary security processing unit (SPU), the appliance claims a hefty raw firewall throughput of 10Gbits/sec.</p><p>A range of subscription tiers allows you to pick which <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> services you want. The bare unit costs around £600, while the price above covers the appliance and a three-year UTP bundle, which enables IPS, malware detection, email and web security, anti-spam and app controls, topped off with full FortiCare support.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359119/us-agencies-warn-of-fortinet-fortios-vulnerabilities-being-exploited" data-original-url="/security/cyber-security/359119/us-agencies-warn-of-fortinet-fortios-vulnerabilities-being-exploited">Fortinet FortiOS vulnerabilities are being actively exploited</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356832/fortinet-and-ibm-join-forces-for-cyber-security-training" data-original-url="/security/cyber-security/356832/fortinet-and-ibm-join-forces-for-cyber-security-training">Fortinet and IBM join forces on cyber security training</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible" data-original-url="/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible">Sophos XG 230 Rev.2 review: Powerful and flexible</a></p></div></div><p>Deployment is up to you: you can launch a wizard from the local web console or use the FortiCloud portal to set the appliance up from the <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/cloud">cloud</a>. We chose neither, opting instead to attach an <a href="https://www.itpro.com/hardware/tablets/356785/apple-ipad-pro-129in-2020-review-believe-the-hype" data-original-url="https://www.itpro.com/hardware/tablets/356785/apple-ipad-pro-129in-2020-review-believe-the-hype">iPad</a> to the appliance’s USB port and use the FortiExplorer iOS app to configure it, register it, and upgrade the firmware. </p><p>There’s an impressive breadth of features on hand, some of which are very simple to configure; antivirus profiles merely define the protocols you want scanned and let you specify whether you want infections removed or quarantined. Firewall policies are more complex, bringing together source, destination, schedule, service, and action objects. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="DtfKqG6hCE4QtyNJBJAstQ" name="" alt="Fortinet FortiGate 60F ports" src="https://cdn.mos.cms.futurecdn.net/DtfKqG6hCE4QtyNJBJAstQ.jpg" mos="https://cdn.mos.cms.futurecdn.net/DtfKqG6hCE4QtyNJBJAstQ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>For web filtering, Fortinet uses its own FortiGuard database, which divides the web into eight main site types comprising 89 subcategories. You can choose to block or allow entire categories or subcategories of site, enable logging, apply usage quotas, enforce authentication, and optionally use the FortiSandbox service to have any downloads analysed in the cloud to catch potential threats that aren’t already known to the antivirus module.</p><p>Similarly, Fortinet provides over 2,000 application control signatures for general business apps and a further 106 cloud-specific ones. Policies can be set to monitor and log app usage, limit bandwidth usage through traffic shaping or block unwanted activities entirely.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HbDhkkFN5oyHUufR7czUgP" name="HbDhkkFN5oyHUufR7czUgP.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/HbDhkkFN5oyHUufR7czUgP.jpg" mos="https://cdn.mos.cms.futurecdn.net/HbDhkkFN5oyHUufR7czUgP.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Address multi-cloud configuration risks</strong></p><p class="fancy-box__body-text">Cloud security challenges and how to overcome them</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/358700/address-multi-cloud-configuration-risks" data-original-url="/cloud/cloud-security/358700/address-multi-cloud-configuration-risks">FREE DOWNLOAD</a></p></div></div><p>All of this can be monitored from the local console, which displays customisable dashboards covering security, network services, users, devices and details of wireless activity for any Fortinet APs the appliance is managing. However, where the 60F really shines is cloud management: a free account provides traffic and app visibility, cloud provisioning, and predefined reports, along with a rolling seven-day activity log. Everything that can be done from the local console can equally be achieved from here, and any Fortinet cloud-managed wireless APs and switches you may be using slot into the same interface as well.</p><p>Even better, the appliance ties in with Fortinet’s Security Fabric ecosystem, which provides a single point of management and monitoring for all Fortinet devices. After installing the FortiAnalyzer app on a Hyper-V host and authorising it with the appliance, we were able to use the app’s FortiView web console to gain a complete overview of all threats, web and app usage, compromised hosts, and much more.</p><p>The FortiGate 60F provides the most comprehensive range of security measures we’ve seen in an SMB-level appliance – yet it’s easy to deploy and reasonably priced. Factor in Fortinet’s irreproachable remote management features and you’re looking at a very persuasive appliance.</p><h2 id="fortinet-fortigate-60f-specifications">Fortinet FortiGate 60F specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Fanless desktop chassis</td></tr><tr><td  ><strong>Network</strong></td><td  >10 x Gigabit Ethernet (2 x WAN, 5 x LAN, DMZ, 2 x FortiLink)</td></tr><tr><td  ><strong>Other ports</strong></td><td  >USB 3, RJ-45 serial port</td></tr><tr><td  ><strong>Management</strong></td><td  >Local console, cloud management</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >216 x 160 x 39mm</td></tr><tr><td  ><strong>Weight</strong></td><td  >1kg</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DrayTek Vigor 2927Lac review: A secure all-rounder ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/network-internet/wifi-hotspots/359117/draytek-vigor-2927lac-review-a-secure-all-rounder</link>
                                                                            <description>
                            <![CDATA[ Ideal for SMBs and remote workers seeking a security router with top-notch WAN redundancy features ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p5fmfHi14eEs1Lk8iRjQhh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/teMvmdtgACyy8vRMxDB99X-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Apr 2021 10:35:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/teMvmdtgACyy8vRMxDB99X-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[DrayTek Vigor 2927Lac ]]></media:description>                                                            <media:text><![CDATA[DrayTek Vigor 2927Lac ]]></media:text>
                                <media:title type="plain"><![CDATA[DrayTek Vigor 2927Lac ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/teMvmdtgACyy8vRMxDB99X-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>DrayTek’s security routers feature all the key UTM functions, but one thing that distinguishes them is their keen focus on WAN redundancy. The idea is to ensure that your office can carry on working even if the main internet link goes down, and to that end, the Vigor 2927Lac sports two separate Gigabit WAN connectors, an integrated <a href="https://www.itpro.com/mobile/28690/lte-vs-4g" data-original-url="https://www.itpro.com/mobile/28690/lte-vs-4g">4G LTE</a> modem with dual SIM slots and a USB 2 port that will take an additional 4G modem as a further fallback.</p><p>You can even safeguard against the possibility of the hardware itself failing by deploying a pair of units in high-availability mode. In this configuration, the routers share a virtual IP address and can be set to hot-standby mode when sharing an internet connection, or active-standby if each has its own link.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/wifi-hotspots/359061/netgear-wax610-review-wi-fi-6-at-a-price-youll-love" data-original-url="/network-internet/wifi-hotspots/359061/netgear-wax610-review-wi-fi-6-at-a-price-youll-love">Netgear WAX610 review: Wi-Fi 6 at a price you’ll love</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/routers/358441/honor-router-3-review-top-value-wi-fi-6" data-original-url="/hardware/routers/358441/honor-router-3-review-top-value-wi-fi-6">Honor Router 3 review: Top-value Wi-Fi 6</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/wifi-hotspots/359029/tp-link-omada-eap265-hd-review-a-cloudy-wi-fi-5-access-point" data-original-url="/network-internet/wifi-hotspots/359029/tp-link-omada-eap265-hd-review-a-cloudy-wi-fi-5-access-point">TP-Link Omada EAP265 HD review: A cloudy Wi-Fi 5 access point</a></p></div></div><p>On the client side, you get five Gigabit Ethernet connectors (with the second WAN connector optionally serving as a sixth LAN port) and dual-band 802.11ac wireless, rated at 866Mbits/sec on the 5GHz band and 400Mbits/sec over 2.4GHz. Four SSIDs are supported per radio, each with its own security scheme and availability schedule. As the Vigor 2927Lac runs the Central AP Management (CAM) service, it can discover and provision up to <a href="https://www.itpro.com/network-internet/wifi-hotspots/357716/draytek-vigorap-1000c-review-impressively-powerful-for-the" data-original-url="https://www.itpro.com/network-internet/wifi-hotspots/357716/draytek-vigorap-1000c-review-impressively-powerful-for-the">20 DrayTek wireless APs</a>, and a future firmware upgrade promises to let the router act as <a href="https://www.itpro.com/network-internet/wifi-hotspots/357130/what-to-look-for-in-a-mesh-wi-fi-network" data-original-url="https://www.itpro.com/network-internet/wifi-hotspots/357130/what-to-look-for-in-a-mesh-wi-fi-network">the root node in a mesh Wi-Fi network</a>.</p><p>For remote users, the price also includes support for 50 IPsec VPN tunnels, plus 25 SSL VPNs – and a new feature is the option to create up to 16 hardware-accelerated IPsec VPNs.</p><p>Installation is a piece of cake. The web console provides a quick-start wizard to walk you through changing the default administrative password and configuring basic internet access. Redundancy settings are almost as easy to configure: any number of the various WAN connections can be set to backup mode, which means they will be automatically brought online when the primary link fails or if its traffic exceeds specific thresholds. Or you can set all links as active and let the router’s load-balancing function automatically distribute traffic across them.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QVqt4gNFbKFGSRmJB9grMD" name="" alt="DrayTek Vigor 2927Lac ports" src="https://cdn.mos.cms.futurecdn.net/QVqt4gNFbKFGSRmJB9grMD.jpg" mos="https://cdn.mos.cms.futurecdn.net/QVqt4gNFbKFGSRmJB9grMD.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The firewall is enabled by default, with a strict security policy that can be customised with rules and filters that specify connection directions, source and destination addresses, protocols and block or pass actions. Similar rules can also be used to enforce application controls, URL filtering and web-content filtering.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YnLJtg57DtFNyLpfRR5ogY" name="YnLJtg57DtFNyLpfRR5ogY.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/YnLJtg57DtFNyLpfRR5ogY.jpg" mos="https://cdn.mos.cms.futurecdn.net/YnLJtg57DtFNyLpfRR5ogY.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IT Pro 20/20: Meet the companies leaving the office for good</strong></p><p class="fancy-box__body-text">The 15th issue of IT Pro 20/20 looks at the nature of operating a business in 2021</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/359086/it-pro-2020-meet-the-companies-leaving-the-office-for-good" data-original-url="/business/business-strategy/359086/it-pro-2020-meet-the-companies-leaving-the-office-for-good">FREE DOWNLOAD</a></p></div></div><p>Application controls are enabled once you register your MyVigor account and DrayTek provides a list of 154 apps and protocols that can be controlled. Supported services include Facebook, WhatsApp and LinkedIn, but Twitter is missing.</p><p>When it comes to wireless, it’s good to see that the router arrives in a secure state, with the default networks using a strong password that’s printed on the base of the unit. Wizards are provided to help you set up your own SSIDs, provision guest access and present a hotspot web portal that supports a range of login methods, including social network providers and a unique PIN sent via email or SMS.</p><p>One thing that might initially turn you off the Vigor 2927Lac is its built-in URL-filtering feature, which relies on simple keywords and is frankly far too basic for business use. However, for around £21 a year you can add the far superior Cyren GlobalView service, which supports up to eight profiles and recognises 65 categories of site.</p><p>The Vigor 2927Lac isn’t the most feature-packed security appliance, but it has the fundamentals sewn up along with convenient Wi-Fi support for an affordable price – and if you’re looking for WAN redundancy, you won’t do better.</p><h2 id="draytek-vigor-2927lac-specifications">DrayTek Vigor 2927Lac specifications</h2><div ><table><tbody><tr><td  ><strong>Band support</strong></td><td  >Dual-band 802.11ac Wi-Fi</td></tr><tr><td  ><strong>Radios</strong></td><td  >2 x LTE aerials, 2 x wireless aerials</td></tr><tr><td  ><strong>Ports</strong></td><td  >7 x Gigabit Ethernet (WAN, WAN2/LAN, 5 x LAN), USB 2</td></tr><tr><td  ><strong>Additional features</strong></td><td  >Dual-slot 4G LTE modem</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >241 x 165 x 33mm</td></tr><tr><td  ><strong>Weight</strong></td><td  >440g</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos XG 230 Rev.2 review: Powerful and flexible ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/359101/sophos-xg-230-rev2-review-powerful-and-flexible</link>
                                                                            <description>
                            <![CDATA[ This high-performance UTM appliance boasts extensive cloud management and remote-security services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mkwc6fB56akTVPe51CgB8R</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/V7eNyr8gNmyagDRTeHKUkk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Apr 2021 12:03:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/V7eNyr8gNmyagDRTeHKUkk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos XG 230 Rev.2]]></media:description>                                                            <media:text><![CDATA[Sophos XG 230 Rev.2]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos XG 230 Rev.2]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/V7eNyr8gNmyagDRTeHKUkk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This short-depth rack appliance is designed to keep up with busy networks. Along with a feast of copper and fibre network ports, Sophos’ XG 230 Rev.2 claims a mighty 32Gbits/sec raw firewall throughput – even with all of the security services enabled, it still pumps traffic through at a speedy 4.5Gbits/sec. </p><p>There’s room to grow further too, thanks to an internal expansion bay that supports eight different Flexi modules, with options ranging from PoE provision up to 10GbE and 40GbE connections. For redundancy, the appliance can accept an optional second power supply and a pair of network bypass ports to keep the traffic flowing even if UTM functions are temporarily disabled for any reason.</p><p>The price above is based on a three-year Sophos TotalProtect Plus subscription, a comprehensive SMB package that enables all network, web, email and web server protection services, along with Sandstorm cloud sandbox and FullGuard Plus support. The appliance also links up with <a href="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it" data-original-url="https://www.itpro.com/security/endpoint-security/356634/sophos-central-endpoint-protection-review-because-youre-worth-it">the Sophos Central service</a>, which extends protection to external endpoints and adds cloud management capabilities.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/354852/sophos-xg-135w-rev-3-review-the-full-package" data-original-url="/security/unified-threat-management-utm/354852/sophos-xg-135w-rev-3-review-the-full-package">Sophos XG 135w Rev. 3 review: The full package</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/359037/it-pro-panel-does-ai-have-a-place-in-security" data-original-url="/technology/artificial-intelligence-ai/359037/it-pro-panel-does-ai-have-a-place-in-security">IT Pro Panel: Does AI have a place in security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/355443/sophos-fixes-firewall-bug-being-actively-exploited-by-sql" data-original-url="/security/zero-day-exploit/355443/sophos-fixes-firewall-bug-being-actively-exploited-by-sql">Sophos fixes firewall bug being actively exploited in SQL injection attacks</a></p></div></div><p>Clearly there are plenty of features to get to grips with, but the XG 230’s web console gets you off to a flying start with an installation wizard that secures admin access, configures the network ports, runs a firmware upgrade and applies a base security policy. Once your basic setup is in place, the console’s Control Center dashboard is equally impressive, providing a clear overview of network activity and security issues, with graphs showing web traffic and detected network attacks, as well as details of blocked and allowed applications and web categories.</p><p>Setting up remote management is easy as you can connect the appliance to your Sophos Central cloud account directly from the web console. Once authenticated, the cloud portal provides the same console as the local one, with live report dashboards and full access to all management features.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qtfnKt2RhXHrgYP7iruebS" name="" alt="Sophos XG 230 Rev.2 rear" src="https://cdn.mos.cms.futurecdn.net/qtfnKt2RhXHrgYP7iruebS.jpg" mos="https://cdn.mos.cms.futurecdn.net/qtfnKt2RhXHrgYP7iruebS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>It’s very pleasing to see that any external devices running the Sophos Central endpoint agent appear automatically in the console, with no need for manual enrolment. Sophos’ Synchronized Security platform uses a “heartbeat” service to keep all supported products on the same page, with the synchronised application control feature automatically finding any unknown applications on remote endpoints and pushing out firewall policies to control them.</p><p>The appliance’s numerous ports can be grouped into various zones, providing a straightforward way to apply different security policies across groups of users and devices. If a device is reported as compromised, a setting in the firewall policy can immediately isolate all systems in the same zone.</p><p>Aside from that, you can set up firewall rules for sources and destinations, service filters, blocking actions and time schedules, and apply custom policies for web filtering, intrusion detection, email and application controls.</p><p>Those web-filtering options extend to 90 categories of URL that can be individually blocked or allowed, while the application controls currently support a whopping 3,530 predefined policies – including 73 just for Facebook activities. The Sandstorm feature intercepts any unknown files and sends them to a cloud sandbox, only allowing them to run locally if they’re deemed to be safe.</p><p>Although the appliance has no built-in Wi-Fi capabilities, it can function as a central controller for Sophos wireless APs, and it also supports Sophos’ SD-RED (Remote Ethernet Device) appliances, which let you easily extend your security policies to external offices. Just register your SD-RED box with the appliance, then ship it to a remote site and it will automatically set up an encrypted connection and start protecting traffic.</p><p>Overall, the Sophos XG230 Rev.2 is a powerful and flexible security appliance that’s well suited to SMBs. It’s packed with security measures while being easy to deploy, and Sophos Central integration provides great remote management and security for external users.</p><h2 id="sophos-xg-230-rev-2-specifications">Sophos XG 230 Rev.2 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >1U rack chassis</td></tr><tr><td  ><strong>CPU</strong></td><td  >3.3GHz Intel Pentium G4400 CPU</td></tr><tr><td  ><strong>Memory</strong></td><td  >8GB DDR4</td></tr><tr><td  ><strong>Storage included</strong></td><td  >128GB SATA SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >6 x copper Gigabit Ethernet, 2 x SFP Gigabit</td></tr><tr><td  ><strong>Other ports</strong></td><td  >HDMI, 3 x USB 3, RJ-45 serial, expansion slot</td></tr><tr><td  ><strong>Management</strong></td><td  >Sophos Central</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zyxel ZyWall ATP100 review: Cost-effective, but not cloudy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/357268/zyxel-zywall-atp100-review-cost-effective-but-not</link>
                                                                            <description>
                            <![CDATA[ This security solution brings a good set of protection features to small businesses on a budget ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gwBQXUZDRNFBEV6A2vjgYt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x7DNP438eDbvsnyYHESnDd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Sep 2020 08:51:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x7DNP438eDbvsnyYHESnDd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x7DNP438eDbvsnyYHESnDd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Not every business needs an enterprise-grade UTM. If you’re looking for something simpler and cheaper, Zyxel’s ZyWall ATP100 could well be the answer. Designed for small offices of up to 25 users, it borrows key features from <a href="https://www.itpro.com/security/32084/zyxel-usg60w-review-makes-deployment-a-breeze" data-original-url="https://www.itpro.com/security/32084/zyxel-usg60w-review-makes-deployment-a-breeze">Zyxel’s high-end USG series</a> and adds cloud threat intelligence, sandboxing and analytics - all for a price that’s very hard to argue with.</p><p>It comes in the form of a fanless desktop unit with one Gigabit WAN port, four copper LAN connectors and an SFP fibre socket for longer cable runs. Across these connections, Zyxel quotes a firewall throughput of 1Gbit/sec, dropping to 380Mbits/sec with all security services enabled.</p><p>The £434 asking price includes a year-long Gold licence, after which renewals cost £212 per annum. The licence enables all services, including web-content filtering, application security, IDP, anti-spam, geo-enforcement and the SecuReporter web-based analytics and reporting service. The one box that’s notably unticked is cloud management, as Zyxel recently had to withdraw its SecuManager cloud management app due to security issues. This means that, for now, all ATP appliances can only be managed via their local web console, and there’s sadly no word on when or whether that will change. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/357252/watchguard-firebox-t20-w-review-superb-all-in-one" data-original-url="/security/unified-threat-management-utm/357252/watchguard-firebox-t20-w-review-superb-all-in-one">WatchGuard Firebox T20-W review: Enterprise-grade protection for remote staff</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/355932/keep-yourself-protected-with-out-list-of-the-best-security-suites" data-original-url="/security/cyber-security/355932/keep-yourself-protected-with-out-list-of-the-best-security-suites">Keep yourself protected with our list of the best security suites</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/354833/zyxel-nsg200-review-a-fine-spread-of-features" data-original-url="/security/unified-threat-management-utm/354833/zyxel-nsg200-review-a-fine-spread-of-features">Zyxel NSG200 review: A fine spread of features</a></p></div></div><p>Installation is swift, thanks to a wizard that enables internet access, installs the latest firmware and activates default security services. Since reporting data is stored in the cloud, you’re prompted to decide whether personal information such as email addresses and usernames should be uploaded; if not, you can still generate the full range of reports, but they’ll be anonymised.</p><p>For the best protection against malware, the anti-malware service can be set to operate in hybrid mode, which combines a local signature database with Zyxel’s online threat intelligence to check whether downloaded files are safe. Any files that haven’t been seen before are automatically dispatched to a cloud-based sandbox service for analysis: friendly files are allowed through, while those that are deemed a threat will be destroyed.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="D4fq5cBTozpuq2pwh5Akdm" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/D4fq5cBTozpuq2pwh5Akdm.jpg" mos="https://cdn.mos.cms.futurecdn.net/D4fq5cBTozpuq2pwh5Akdm.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Another service you might want to customise is App Patrol, which lets you control access to over 3,500 apps including webmail services, instant messenger platforms, Facebook and Twitter. To this, Zyxel’s web-content filtering adds over 100 categories of website that can be blocked; during testing, we found few sites slipped past it. Unusually, it’s also possible to enable geo-enforcement, by creating an address object for the region or country you want to block, then subjecting it to a security policy.</p><p>Enabling email protection is as easy as toggling on the sender-reputation and content-analysis features, and selecting whether suspect messages should be dumped or tagged for processing by local mail clients. The IDP, IP reputation and URL threat-filter services are even simpler to activate – a single click will do it, although you can pull up advanced settings and modify their behaviour should you so wish.</p><p>For everyday administration, two dashboard views keep you in touch with the action. One presents a hardware status overview along with port traffic statistics; the other one, rather more excitingly, provides seven-day charts and graphs of all security activity, with details of top apps and any detected threats. The SecuReporter service exposes a wealth of information about all web, app and threat activity, with the Analyzer page providing insights into security indicators, sandbox activity, traffic and users at risk. Custom reports can be sent to multiple recipients at regular intervals.</p><p>Network gateway protection is a must for any business, and the ZyWall ATP100 is a worthy choice. The lack of cloud management means it’s not suitable for companies with workers spread across multiple sites, but the range of security measures on hand is persuasive, especially considering the price. </p><h2 id="zyxel-zywall-atp100-specifications">Zyxel ZyWall ATP100 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Fanless desktop chassis</td></tr><tr><td  ><strong>CPU</strong></td><td  >Dual-core CPU </td></tr><tr><td  ><strong>Memory</strong></td><td  >1GB RAM</td></tr><tr><td  ><strong>Network</strong></td><td  >6 x Gigabit Ethernet (WAN, 5 x LAN)</td></tr><tr><td  ><strong>Other ports</strong></td><td  >USB 3, RJ-45 serial port</td></tr><tr><td  ><strong>Management</strong></td><td  >Web browser management </td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >216 x 148 x 33mm (WDH)</td></tr><tr><td  ><strong>Warranty</strong></td><td  >5yr limited warranty</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WatchGuard Firebox T20-W review: Enterprise-grade protection for remote staff ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/357252/watchguard-firebox-t20-w-review-superb-all-in-one</link>
                                                                            <description>
                            <![CDATA[ This affordable desktop appliance is a great choice for protecting small offices and home workers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jGjBwgB11RAVzjS566pjqQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oAUhNDmmshBaPKmzeDdUY4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Sep 2020 15:52:34 +0000</pubDate>                                                                                                                                <updated>Wed, 21 Sep 2022 10:14:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oAUhNDmmshBaPKmzeDdUY4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of the WatchGuard Firebox T20-W]]></media:description>                                                            <media:text><![CDATA[A photograph of the WatchGuard Firebox T20-W]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of the WatchGuard Firebox T20-W]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oAUhNDmmshBaPKmzeDdUY4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The T20-W is the entry point of WatchGuard’s Firebox table-top security appliances, and is aimed primarily at small and home office deployments. It could also be a sound choice for larger businesses wanting to protect remote sites, as it offers cloud management and zero-touch deployment.</p><p>The latter is handled via WatchGuard’s RapidDeploy service: once you’ve register a new appliance with your support account, you can assign it a configuration file created from a local Firebox appliance. When the appliance is plugged in at the remote site, it grabs the file from your account and instantly starts providing protection.</p><p>For management, you can either use the local web console or enable full cloud management, which disables the local interface and provides remote access to all configuration settings. Whichever you choose, WatchGuard keeps the workload low with proactive protection: the ThreatSync service can collect and collate event data from multiple Firebox units, while DNSWatch blocks access to known malicious domains. The T20-W doesn’t support the IntelligentAV scanner found on <a href="https://www.itpro.com/security/unified-threat-management-utm/368361/watchguard-firebox-m590-review-big-red-network" data-original-url="https://www.itpro.com/security/unified-threat-management-utm/368361/watchguard-firebox-m590-review-big-red-network">other Firebox models like the M590</a>, however – it’s too demanding for this appliance’s dual-core CPU.</p><p>Even so, the T20-W offers a good range of security measures. The price above includes a three-year Total Security subscription, which enables gateway antivirus, anti-spam, web content filtering, application controls, intrusion prevention services, an advanced persistent threat blocker and WatchGuard’s RED (reputation enabled defence) service – plus the aforementioned ThreatSync and DNSWatch features. All subscriptions include cloud management, and the Total Security licence includes log retention for up to 30 days.</p><p>Though compact, the T20-W offers a respectable range of connection options. Five <a href="https://www.itpro.com/network-internet/30276/what-is-ethernet-the-standards-explained" data-original-url="https://www.itpro.com/network-internet/30276/what-is-ethernet-the-standards-explained">Gigabit Ethernet ports</a> handle WAN, LAN and DMZ duties, although there’s no PoE+ as found on the more powerful <a href="https://www.itpro.com/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy" data-original-url="https://www.itpro.com/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy">Firebox T40-W</a>. Believe it or not, there’s built-in wireless too, although <a href="https://www.itpro.com/network-internet/wifi-hotspots/367703/what-is-wi-fi-6" data-original-url="https://www.itpro.com/network-internet/wifi-hotspots/367703/what-is-wi-fi-6">Wi-Fi 6</a> isn’t supported – you’re limited to Wave 1 802.11ac – and the 2.4GHz and 5GHz radios can’t be active simultaneously. Still, that will be fine for home workers, and if you need the extra performance of Wi-Fi 6 then the T20-W’s integrated wireless gateway can provision and manage <a href="https://www.itpro.com/network-internet/wifi-hotspots/358191/watchguard-ap225w-review-strong-secure-and-speedy" data-original-url="https://www.itpro.com/network-internet/wifi-hotspots/358191/watchguard-ap225w-review-strong-secure-and-speedy">WatchGuard access points such as the AP225W</a>. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dkPaAdRRww3BtYDR4XMxsT" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/dkPaAdRRww3BtYDR4XMxsT.jpg" mos="https://cdn.mos.cms.futurecdn.net/dkPaAdRRww3BtYDR4XMxsT.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Performance, too, should be ample for the target market: WatchGuard claims top firewall and UTM throughput rates of 1.7Gbits/sec and 154Mbits/sec respectively.</p><p>For testing, we registered the T20-W with our cloud account and initially chose local management. Even with this option active, the unit remains visible in the cloud portal, allowing you to monitor a wealth of detail about traffic, detected threats and responses.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a" data-original-url="/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a">WatchGuard Firebox M290 review: Stiff security at a great price</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/369069/sophos-xgs-116-review-a-small-and-mighty-appliance" data-original-url="/security/unified-threat-management-utm/369069/sophos-xgs-116-review-a-small-and-mighty-appliance">Sophos XGS 116 review: A small and mighty appliance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one" data-original-url="/security/361559/ubiquiti-networks-unifi-dream-machine-pro-review-all-the-security-you-need-in-one">Ubiquiti Networks UniFi Dream Machine Pro review: All the security you need in one handy box</a></p></div></div><p>The web console, meanwhile, provides wizards for configuring the various traffic proxies, which cover a whole range of protocols including HTTP, HTTPS, FTP, SIP, POP3 and SMTP. Enabling gateway AV and APT blocking are one-click manoeuvres, while the WebBlocker service presents 130 URL categories that can be blocked or allowed. Strict controls can also be applied to over 1,100 predefined apps, including all popular social networking services.</p><p>Moving to full cloud management is as easy as clicking a button in the device configuration page. We tried this and were happy to see the T20-W immediately reconfigured itself and provided full access to the full set of security services.</p><p>If wireless services are a priority then the Firebox T20-W might not be the ideal choice, but it’s bursting with security features, and WatchGuard’s swift deployment and cloud management make it ideal for extending enterprise protection to home workers.</p><h2 id="watchguard-firebox-t20-w-specifications">WatchGuard Firebox T20-W specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Fanless desktop chassis</td></tr><tr><td  ><strong>CPU</strong></td><td  >Dual-core 1GHz NXP LS1023A CPU</td></tr><tr><td  ><strong>Memory</strong></td><td  >2GB DDR4 ECC</td></tr><tr><td  ><strong>Storage included</strong></td><td  >4GB eMMC</td></tr><tr><td  ><strong>Network</strong></td><td  >5 x Gigabit Ethernet (WAN, 4 x LAN), 2.4/5GHz 802.11ac Wave 1 wireless</td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB 2, RJ-45 serial port </td></tr><tr><td  ><strong>Management</strong></td><td  >Web browser and cloud management</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >217 x 206 x 44mm</td></tr><tr><td  ><strong>Weight</strong></td><td  >900g</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DrayTek Vigor 2862 review: Price-conscious protection ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/354864/draytek-vigor-2862-review-price-conscious-protection</link>
                                                                            <description>
                            <![CDATA[ A bargain for SMBs that want a solid mix of security measures and top-notch WAN redundancy options ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mnAUxEUWomHA3Bko6K2jNR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qUo3C4cB3ZWN7kyF9VDd5d-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Feb 2020 16:01:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/qUo3C4cB3ZWN7kyF9VDd5d-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qUo3C4cB3ZWN7kyF9VDd5d-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>This unit may look like a regular router, but don’t be fooled - DrayTek’s Vigor 2862 is a bona fide security gateway, with optional remote management via the cloud-hosted VigorACS 2 service. </p><p>To be sure, it’s not as feature-packed as some chunkier, more expensive options. Notably, the Vigor 2862 doesn’t offer antivirus services, nor any sort of <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws" target="_blank" data-original-url="itpro.co.uk/security/34784/the-future-of-spam-is-scary">spam filtering</a>. You do, however, get a 400Mbits/sec SPI firewall, plus a good range of web-filtering and app-control options.</p><p>The Vigor 2862 will also make your day if you’re looking to provide <a href="https://www.itpro.com/agile-working/34343/now-is-the-time-to-embrace-remote-working" target="_blank" data-original-url="https://www.itpro.com/agile-working/34343/now-is-the-time-to-embrace-remote-working">secure connections for remote staff</a>, as it supports up to 32 concurrent IPsec VPN tunnels and 16 simultaneous SSL connections, via DrayTek’s free Smart VPN client for Windows, macOS, iOS and Android.</p><p>And while the appliance doesn’t have built-in wireless services, it does include DrayTek’s Central AP Management (CAM) feature for discovering and provisioning up to 20 <a href="https://www.itpro.com/wifi-hotspots/33924/draytek-vigorap-903-review-seamless-self-healing-mesh-wifi" target="_blank" data-original-url="https://www.itpro.com/wifi-hotspots/33924/draytek-vigorap-903-review-seamless-self-healing-mesh-wifi">DrayTek wireless APs</a> – and it can discover and centrally manage up to ten <a href="https://www.itpro.com/network-internet/34732/draytek-vigorswitch-p2280x-review-smart-and-switched-on" target="_blank" data-original-url="https://www.itpro.com/network-internet/34732/draytek-vigorswitch-p2280x-review-smart-and-switched-on">DrayTek VigorSwitch devices</a>.</p><p>We found installation was easy. The web console provides a quick-start wizard for changing the default admin password and configuring internet access, and additional wizards are provided for enabling DrayTek’s free DDNS service and <a href="https://www.itpro.com/networking/27210/do-i-need-a-vpn" target="_blank" data-original-url="https://www.itpro.com/networking/27210/do-i-need-a-vpn">setting up VPNs</a>. This latter task is a cinch, and VPN performance isn’t bad: testing with an external Windows 10 PC running the Smart VPN client, we saw file copies to a LAN system complete at a respectable 2.3MB/sec. Don’t get carried away with multiple SSL VPN connections, though, as during our tests we saw appliance CPU utilisation occasionally peaking as high as 88%.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tJfsjy3e6FdHCoCttSK8FG" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/tJfsjy3e6FdHCoCttSK8FG.png" mos="https://cdn.mos.cms.futurecdn.net/tJfsjy3e6FdHCoCttSK8FG.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Configuring the firewall isn’t too complicated, either. It’s all based on filters, which manage your incoming and outgoing traffic. Each filter comprises up to seven rules, defining specific traffic types and directions, along with a load-balancing policy and QoS priorities. </p><p>Filters can also define behaviours for the app-control service – a free extra that we activated from our MyVigor account after registering the router. You can manage various protocols and decide what to do with remote-control, tunnelling, streaming and web connections, as well as setting policies for IM and P2P apps and social media sites. As a test, we created an enforcement rule for Facebook and added it to the firewall filter – after which users on our network instantly found they were unable to log into their accounts.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/34405/draytek-vigor-2620ln-review-never-lose-connection-again" data-original-url="/network-internet/34405/draytek-vigor-2620ln-review-never-lose-connection-again">DrayTek Vigor 2620Ln review: Never lose connection again</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/routers/354803/ubiquiti-networks-unifi-dream-machine-review-a-dream-come-true" data-original-url="/hardware/routers/354803/ubiquiti-networks-unifi-dream-machine-review-a-dream-come-true">Ubiquiti Networks UniFi Dream Machine review: A dream come true</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/34066/draytek-vigorswitch-p2500-review-a-stand-out-switch" data-original-url="/network-internet/34066/draytek-vigorswitch-p2500-review-a-stand-out-switch">DrayTek VigorSwitch P2500 review: A stand-out switch</a></p></div></div><p>The Vigor 2862’s standard web-filtering provision is a rudimentary thing, based solely on keywords, but for just £38 a year you can upgrade to DrayTek’s much more powerful GlobalView service. This employs the Cyren web filter, which lets you decide whether to block or allow 64 different categories of site, and shows a warning message if users attempt to access a blocked page.</p><p>One last strength of the Vigor 2862 is its degree of WAN redundancy. Alongside a built-in ADSL2+/VDSL2 interface, the router features a pair of USB 2 ports that can both accept 3G/4G LTE USB modems, and one of its five Gigabit Ethernet ports can be used for a WAN link as well, for a total of four separate connections. It’s up to you whether you have these all active at the same time – in which case the router will perform load balancing across them – or whether you set specific ones as failover provisions. The new high-availability feature even allows you to deploy two routers in parallel, sharing a single virtual IP address, in either hot-standby or active-standby failover modes.</p><p>For the price, the DrayTek Vigor 2862 offers a remarkable range of security features. It might not have the grunt to cope with lots of simultaneous VPN connections, but its multitude of filtering and WAN options make it ideal for budget-conscious SMBs that need a secure and stable internet connection.</p><h2 id="draytek-vigor-2862-specifications">Draytek Vigor 2862 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop/rackmount chassis</td></tr><tr><td  ><strong>Network</strong></td><td  >5 x Gigabit Ethernet (4 x LAN, 1 x LAN/WAN2), ADSL2+/VDSL2 interface </td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB 2 </td></tr><tr><td  ><strong>Management</strong></td><td  >Cloud-hosted VigorACS 2 </td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >241 x 166 x 44mm (WDH)</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos XG 135w Rev. 3 review: The full package ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/354852/sophos-xg-135w-rev-3-review-the-full-package</link>
                                                                            <description>
                            <![CDATA[ Exceptional wired and wireless security, teamed up with great performance and remote management ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">itH3a62xTniDSAk1xRGJuo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CEpKWsVpdqZNShWy7etog4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Feb 2020 10:45:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CEpKWsVpdqZNShWy7etog4-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CEpKWsVpdqZNShWy7etog4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sophos’ newest SMB security appliance comes straight in at the top of the range. Taking performance to new heights, the XG 135w Rev. 3 quotes a huge raw firewall throughput of 8Gbits/sec, and a decent 1.2Gbits/sec with all security services enabled. </p><p>It’s not just fast, but versatile too. In addition to eight copper Gigabit Ethernet ports and one SFP fibre port, it presents dual-band 802.11ac wireless services, while an expansion slot allows you to add optional DSL, 3G/4G or Gigabit SFP cards – or a second Wi-Fi module. </p><p>Another strength is the price. The figure we’ve shown above includes a one-year TotalProtect Plus subscription, which covers the network, web, <a href="https://www.itpro.com/security/31891/how-to-make-your-email-hack-proof" target="_blank" data-original-url="https://www.itpro.com/security/31891/how-to-make-your-email-hack-proof">email</a> and web server protection modules, along with Sophos’ Sandstorm cloud sandbox and a FullGuard Plus support subscription. You don’t necessarily have to keep paying that, though: the cost of the base appliance includes a perpetual licence for firewall, VPN, authentication and secure wireless management services. </p><p>The browser-based installation wizard helps you hit the ground running, stepping you through the business of securing admin access, sorting out the LAN and WAN ports, creating main and guest wireless networks, installing the latest firmware and setting a base security policy so your users are protected from the outset.</p><p>You’re then taken to the main dashboard, which presents an informative overview of network activity and security issues, with graphs and charts detailing traffic statistics and blocked applications. Reporting options are excellent: Sophos’ iView platform provides a wealth of graphical information about security services, app and web activity, threats, mail usage and more.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4J2Xq4jo8nu4sR5cpF4EbN" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/4J2Xq4jo8nu4sR5cpF4EbN.jpg" mos="https://cdn.mos.cms.futurecdn.net/4J2Xq4jo8nu4sR5cpF4EbN.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>If you need to divide your users into different security groups, that’s no problem. The appliance’s ports can be assigned to different zones, each with its own firewall rules and policies for web filtering, IPS and application controls. These are easy to set up, as the appliance comes with 91 predefined website categories and over 3,400 predefined app profiles, including 73 solely relating to Facebook activities.</p><p>For finer control, it’s also possible to apply identity-based rules to specific users and groups, including daily bandwidth restrictions and limits on daily, weekly, monthly and even yearly internet usage. Sophos provides a free Client Authentication Agent (CAA) for Windows, although you have to download the certificate from the appliance and import it on all workstations.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/354833/zyxel-nsg200-review-a-fine-spread-of-features" data-original-url="/security/unified-threat-management-utm/354833/zyxel-nsg200-review-a-fine-spread-of-features">Zyxel NSG200 review: A fine spread of features</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/354850/watchguard-firebox-t70-review-compact-but-capable" data-original-url="/security/unified-threat-management-utm/354850/watchguard-firebox-t70-review-compact-but-capable">WatchGuard Firebox T70 review: Compact but capable</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/enterprise-security/354772/the-it-pro-podcast-breaking-out-of-the-security-bubble" data-original-url="/security/enterprise-security/354772/the-it-pro-podcast-breaking-out-of-the-security-bubble">The IT Pro Podcast: Breaking out of the security bubble</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354676/watchguard-firebox-t35-rugged-review-industrial-strength-security" data-original-url="/security/cyber-security/354676/watchguard-firebox-t35-rugged-review-industrial-strength-security">WatchGuard Firebox T35-Rugged review: Industrial-strength security</a></p></div></div><p>A third way to segment your protection is by using more than one wireless network: the appliance can broadcast up to eight SSIDs, each with its own <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" target="_blank" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption scheme</a>, <a href="https://www.itpro.com/network-access-control/30329/what-is-a-dhcp-server" target="_blank" data-original-url="https://www.itpro.com/network-access-control/30329/what-is-a-dhcp-server">DHCP</a>, client isolation and masking settings. Placing these <a href="https://www.itpro.com/broadband/30390/what-is-ssid" target="_blank" data-original-url="https://www.itpro.com/broadband/30390/what-is-ssid">SSIDs</a> in separate network zones lets you provision guest wireless access and apply firewall rules and security policies.</p><p>One last strength of the XG 135w Rev. 3 is that it’s fully manageable via the cloud. After we’d registered the appliance with the Sophos Central web portal, it presented exactly the same interface as the local console. It’s even possible to manage endpoints outside of your local network through Sophos’ Synchronised Security service. The dashboard shows all remote devices running the endpoint agent, and if any get compromised, you can automatically quarantine the network zone they’re located in. </p><p>The XG 135w Rev.3 impressed us mightily. It offers a good breadth of security features, yet is easy to set up, and to manage remotely – and it delivers great performance at a reasonable price.</p><h2 id="sophos-xg-135w-rev-3-specifications">Sophos XG 135w Rev. 3 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop chassis</td></tr><tr><td  ><strong>CPU</strong></td><td  >2.2GHz quad-core Intel Atom C3558</td></tr><tr><td  ><strong>Memory</strong></td><td  >6GB DDR4</td></tr><tr><td  ><strong>Storage included</strong></td><td  >64GB SATA SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >8 x Gigabit Ethernet, 1 x Gigabit SFP, 2.4/5GHz 802.11ac wireless, 3x3 MIMO, 3 x external aerials</td></tr><tr><td  ><strong>Other ports</strong></td><td  >HDMI, 2 x USB 2, micro-USB, RJ-45 serial, expansion slot</td></tr><tr><td  ><strong>Management</strong></td><td  >Sophos Central web console, cloud</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >320 x 212 x 44mm (WDH)</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WatchGuard Firebox T70 review: Compact but capable ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/354850/watchguard-firebox-t70-review-compact-but-capable</link>
                                                                            <description>
                            <![CDATA[ Top performance and a great set of security and management options ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uMp29zCd3ycihZo2ArkAYZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tCvv23s3pmRS8DVVawBJ5J-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Feb 2020 16:24:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tCvv23s3pmRS8DVVawBJ5J-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tCvv23s3pmRS8DVVawBJ5J-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Gateway security often involves a performance trade-off, but WatchGuard’s Firebox T70 is designed for SMBs who aren’t willing to compromise. It’s the vendor’s first appliance built on an Intel CPU, which enables it to deliver high-speed <a href="https://www.itpro.com/network-internet/31914/what-is-network-intelligence" target="_blank" data-original-url="https://www.itpro.com/network-internet/31914/what-is-network-intelligence">deep packet inspection</a> of HTTPS traffic – something many rival appliances struggle with.</p><p>Indeed, the T70’s numbers are impressive across the board. It claims a raw firewall throughput of 4Gbits/sec, and a remarkable 1.1Gbits/sec with all UTM services enabled. You don’t have to pay a steep premium for this performance either: the appliance costs a competitive £2,366 exc VAT, including a one-year subscription to WatchGuard’s Total Security Suite.</p><p>That subscription unleashes a wealth of security measures. Along with the aforementioned DPI, you get gateway antivirus, anti-spam, web-content filtering, application controls, network discovery, IPS, data-loss prevention and an <a href="https://www.itpro.com/security/34594/apt-groups-exploiting-vpns-to-carry-out-cyber-attacks" target="_blank" data-original-url="https://www.itpro.com/security/34594/apt-groups-exploiting-vpns-to-carry-out-cyber-attacks">advanced persistent threat (APT)</a> blocker. Web security is bolstered by WatchGuard’s Reputation Enabled Defense service, and the included Gold Support provides a free remote setup session with a WatchGuard engineer. </p><p>To be honest, though, we had no problem getting set up on our own. The appliance’s web console took us through the initial setup procedure, which involved securing admin access, enabling firewall-protected internet access and applying a base set of security policies. </p><p>Additional wizards are then on hand to help you set up the various proxies that manage HTTP, HTTPS, FTP, SIP, POP3 and SMTP traffic. It’s notably easy to set up web-content filtering: WatchGuard offers 130 URL categories to choose from, and you can simply pick those you want to block. Similarly, the T70’s application control module can manage access to hundreds of predefined apps, so it’s a piece of cake to control what’s allowed in the workplace.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NKnH6Gnn99NcwSPPuNrLe8" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/NKnH6Gnn99NcwSPPuNrLe8.jpg" mos="https://cdn.mos.cms.futurecdn.net/NKnH6Gnn99NcwSPPuNrLe8.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Gateway AV scanning is enabled on selected proxies too, and alongside basic malware detection, the IntelligentAV feature uses the Cylance AI-based engine to analyse files such as Office documents and PDFs. For anti-spam services, all you need to do is select whether you want to inspect SMTP, IMAP or POP3 traffic, and whether spam messages should be blocked or merely tagged. The APT service, meanwhile, generates hashes of inbound files and checks them with the Lastline cloud service to see if they match the signatures of any known threats. </p><p>Finally, that fast deep packet inspection feature we mentioned is enabled within the HTTPS proxy action. Here you just need to choose the domain names and WebBlocker categories you want it to inspect, then import the predefined proxy authority certificate to your computers. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354676/watchguard-firebox-t35-rugged-review-industrial-strength-security" data-original-url="/security/cyber-security/354676/watchguard-firebox-t35-rugged-review-industrial-strength-security">WatchGuard Firebox T35-Rugged review: Industrial-strength security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/354833/zyxel-nsg200-review-a-fine-spread-of-features" data-original-url="/security/unified-threat-management-utm/354833/zyxel-nsg200-review-a-fine-spread-of-features">Zyxel NSG200 review: A fine spread of features</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/firewalls/32644/watchguard-firebox-m670-review-dazzling-value" data-original-url="/firewalls/32644/watchguard-firebox-m670-review-dazzling-value">WatchGuard Firebox M670 review: Dazzling value</a></p></div></div><p>One feature the T70 lacks is Wi-Fi services, but it can centrally manage <a href="https://www.itpro.com/security/32706/watchguard-ap325-review-perfect-networking-for-smbs" target="_blank" data-original-url="https://www.itpro.com/security/32706/watchguard-ap325-review-perfect-networking-for-smbs">other WatchGuard APs</a>, pushing out wireless settings and applying security policies to their traffic. It can even power your APs, as PoE+ is provided on the sixth and seventh Ethernet ports.</p><p>And the T70 is ideal for those who like the idea of multiple-choice management, as you can use either its local web console or WatchGuard’s Dimension management platform (which we run in a Hyper-V VM in our lab). It’s also possible to link the T70 to a WatchGuard Cloud account, allowing you to remotely check on security services, detected threats and appliance performance; proper cloud-based configuration isn’t supported, but it’s promised soon.</p><p>If you’re seeking tough perimeter security that won’t slow down your network, the Firebox T70 is a superb choice. It’s easy to deploy and manage, it’s loaded with features and it’s powerful enough to cope with high demand.</p><h2 id="watchguard-firebox-t70-specifications">WatchGuard Firebox T70 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop chassis (fanless)</td></tr><tr><td  ><strong>CPU</strong></td><td  >1.6GHz Intel Celeron N3160 CPU</td></tr><tr><td  ><strong>Memory</strong></td><td  >2GB RAM</td></tr><tr><td  ><strong>Storage included</strong></td><td  >16GB SSD</td></tr><tr><td  ><strong>Network</strong></td><td  >8 x Gigabit Ethernet (PoE+ on ports 6 & 7)</td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB 2, RJ-45 serial port</td></tr><tr><td  ><strong>Management</strong></td><td  >Web, Dimension and cloud management</td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >233 x 206 x 48mm</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zyxel NSG200 review: A fine spread of features ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/unified-threat-management-utm/354833/zyxel-nsg200-review-a-fine-spread-of-features</link>
                                                                            <description>
                            <![CDATA[ A fully featured appliance offering cloud management and zero-touch deployment at a knock-down price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7yArQyK1wgx2BfhwEsVFfe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pvwGAZThhwAGPsndMpEMfc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Feb 2020 15:21:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pvwGAZThhwAGPsndMpEMfc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pvwGAZThhwAGPsndMpEMfc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zyxel’s security appliances divide into two families: the USG models are designed for local administration, while the NSG range can be managed from anywhere in the world using <a href="https://www.itpro.com/network-internet/33885/zyxel-nebula-control-center-2019-review-takes-all-the-pain-out-of-networking" data-original-url="https://www.itpro.com/network-internet/33885/zyxel-nebula-control-center-2019-review-takes-all-the-pain-out-of-networking">Zyxel’s Nebula Control Center (NCC)</a> cloud platform.</p><p>The model we tested this month is the NSG200, which is aimed at small offices, and the price shown includes your first year’s subscription to Zyxel’s Nebula Security Pack. This enables IDP, application control, content filtering and <a href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus</a> security services on the appliance, and also upgrades your access to the NCC console. The basic free service has limited features, including a logging limit of just seven days, but your Security Pack licence enables Nebula Professional, which gives you a full year’s worth of logging and adds other worthwhile features such as email alerts and auditing.</p><p>The web portal is easy to use, although you might find yourself wishing the main dashboard were more customisable; it provides an overview of your security and network status, but also dedicates space to details of Nebula-enabled wireless APs and switches – even if you don’t have any. Still, the new NCC console is already in beta, and this will let you choose which widgets you want to display on the dashboard, while also ditching the dark look in favour of a brighter colour scheme.</p><p>One big benefit of the NSG200’s cloud-based design is that it enables zero-touch deployment. Before you even unbox the appliance you can set up a top-level organisation in NCC, add sites below it and configure a security profile to be pushed to the device as soon as it’s added to a site. This can include antivirus and IDP services, and settings for the application control service – which Zyxel cutely calls “application patrol” – to manage access to over 3,000 apps, including Facebook and Twitter. There’s a web-content filtering service too, which lets you block access to any of 64 site categories. </p><p>All of this makes the NSG200 ideal for businesses with remote offices, as it means you can simply send the appliance to the desired location and it will automatically pick up all the appropriate settings as soon as it’s plugged in. The self-configuration process takes around five minutes, and once it’s up and running the NSG200 will also regularly check for firmware updates, and apply them either in the background or at nominated times. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vUKcxUYHbP95wRvVykoB9Z" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/vUKcxUYHbP95wRvVykoB9Z.jpg" mos="https://cdn.mos.cms.futurecdn.net/vUKcxUYHbP95wRvVykoB9Z.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>In fact, the most inconvenient part of setting up the NSG200 might be registering the appliance, as the web portal asks you to manually type in the unit’s MAC address and serial number. There’s an easier option, though: we simply used Zyxel’s iOS app to scan the QR code printed on the NSG200’s box. This captured the MAC address and all other required details, enabling us to add the appliance to an active site with a single tap.</p><p>As well as setting up security services, the NCC portal lets you configure the appliance’s two Gigabit WAN and five Gigabit LAN ports. If you have two internet connections, you can have both WAN ports active at the same time, and apply load balancing across them; the LAN sockets, meanwhile, can be divided into two groups, each with its own IP address and DHCP settings, and optional bandwidth limits applied to client IP address ranges and destinations. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/wifi-hotspots/34682/zyxel-multy-plus-review-smb-friendly-mesh-wi-fi" data-original-url="/wifi-hotspots/34682/zyxel-multy-plus-review-smb-friendly-mesh-wi-fi">Zyxel Multy Plus review: SMB-friendly mesh Wi-Fi</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354676/watchguard-firebox-t35-rugged-review-industrial-strength-security" data-original-url="/security/cyber-security/354676/watchguard-firebox-t35-rugged-review-industrial-strength-security">WatchGuard Firebox T35-Rugged review: Industrial-strength security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32084/zyxel-usg60w-review-makes-deployment-a-breeze" data-original-url="/security/32084/zyxel-usg60w-review-makes-deployment-a-breeze">Zyxel USG60W review: Makes deployment a breeze</a></p></div></div><p>Custom firewall rules can be set too, including sources, destinations, protocols, actions and a time schedule, and captive portals can be presented to guest users, complete with custom logos and AUPs. </p><p>In short, the Nebula console offers all the management options you’re likely to need, and the NSG200 itself is temptingly priced. It works best when partnered with <a href="https://www.itpro.com/wifi-hotspots/32997/zyxel-nwa1302-ac-review-the-perfect-companion-for-cloud-managed-networking" data-original-url="https://www.itpro.com/wifi-hotspots/32997/zyxel-nwa1302-ac-review-the-perfect-companion-for-cloud-managed-networking">Zyxel’s Nebula-enabled wireless APs and switches</a>, but even on its own it provides a fine spread of security features for SMBs seeking a cloud-based gateway security solution.</p><h2 id="zyxel-nsg200-specifications">Zyxel NSG200 specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Desktop/rackmount chassis</td></tr><tr><td  ><strong>CPU</strong></td><td  >Quad-core CPU </td></tr><tr><td  ><strong>Memory</strong></td><td  >1GB RAM</td></tr><tr><td  ><strong>Network</strong></td><td  >7 x Gigabit Ethernet (2 x WAN, 5 x LAN)</td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB 2, serial port </td></tr><tr><td  ><strong>Management</strong></td><td  >Nebula Cloud management </td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >300 x 178 x 44mm</td></tr><tr><td  ><strong>Weight</strong></td><td  >2kg</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why UEM is the key to enterprise IT security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/endpoint-security/354132/why-uem-is-the-key-to-enterprise-it-security</link>
                                                                            <description>
                            <![CDATA[ A guide to effective endpoint security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dfSsraZ2qUMGRk5SvAwQo8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 20 Oct 2019 16:04:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mVM9DUbmvCJhNp5jYeasdf-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GbULRnXuxFwwm7TSVcsybb" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/GbULRnXuxFwwm7TSVcsybb.jpg" mos="https://cdn.mos.cms.futurecdn.net/GbULRnXuxFwwm7TSVcsybb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>With IDC stating that 70% of data breaches begin with endpoints, enterprises are scrambling to secure and safeguard them - from servers to remote mobile devices - to keep their network safe from cyberattacks and secure the data stored within.</p><p>This whitepaper comprehensively explores unified endpoint management (UEM) as a security solution, offering context, implementation challenges, the threat of ransomware, and best practices for effective endpoint security. </p><p>Download it now to learn how to effectively secure all your endpoints to keep your data and network safe.</p><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/manage-engine-sept-dec-2019?locale=1&p=false&wp=3748"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SonicWall TZ300P review: A multi-site marvel ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/unified-threat-management-utm/33933/sonicwall-tz300p-review-a-multi-site-marvel</link>
                                                                            <description>
                            <![CDATA[ A competitively priced desktop UTM appliance, with plenty of security and management features ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kDV4jRtxUgUt87TLrS1kkg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4hCwVcvYSj79oug625b39f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Jul 2019 10:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4hCwVcvYSj79oug625b39f-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4hCwVcvYSj79oug625b39f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Targeting SMBs and remote offices, the TZ300P is one of SonicWall's most versatile desktop appliances yet. Alongside a stiff set of <a href="https://www.itpro.com/security/32107/how-to-choose-a-one-stop-business-security-package" target="_blank" data-original-url="https://www.itpro.com/security/32107/how-to-choose-a-one-stop-business-security-package">unified threat management (UTM)</a> security measures, it delivers <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan" target="_blank" data-original-url="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan">software defined WAN (SD-WAN)</a> services and <a href="https://www.itpro.com/wifi-hotspots/33755/upgrade-your-wireless-aps" target="_blank" data-original-url="https://www.itpro.com/wifi-hotspots/33755/upgrade-your-wireless-aps">wireless AP management</a> - and, for good measure, it even supports PoE.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/firewalls/32644/watchguard-firebox-m670-review-dazzling-value" data-original-url="/firewalls/32644/watchguard-firebox-m670-review-dazzling-value">WatchGuard Firebox M670 review: Dazzling value</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/33885/zyxel-nebula-control-center-2019-review-takes-all-the-pain-out-of-networking" data-original-url="/network-internet/33885/zyxel-nebula-control-center-2019-review-takes-all-the-pain-out-of-networking">Zyxel Nebula Control Center 2019 review: Takes all the pain out of networking</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/firewalls/31925/sophos-xg-125w-review" data-original-url="/firewalls/31925/sophos-xg-125w-review">Sophos XG 125w review</a></p></div></div><p>Recommended for up to 25 users, the TZ300P boasts a raw firewall throughput of 750Mbits/sec, dropping to 235Mbits/sec with UTM services enabled. The compact box offers five Gigabit Ethernet ports, one of which is set aside for WAN duties, while the rest are available for LAN usage. Two of these are PoE-enabled, which is handy - just note that the small 35W power threshold means that it will only drive a single PoE+ device. The other notable connector is a USB port, which can provide WAN redundancy via a 3G or 4G mobile adapter.</p><p>The appliance itself costs 720 to buy, rising to 1,085 with a one-year TotalSecure Advanced subscription. This really unlocks the potential of the device, not only entitling you to 24/7 support, but enabling IPS, antivirus and anti-spyware functions. It also activates content filtering, application intelligence and Capture ATP, which watches for files such as Office documents, PDFs and executables, scans them in its cloud sandbox and only releases them if they pass a barrage of malware tests.</p><p>The latest SonicOS firmware sports a fresh web console exposing a wealth of information. Graphs and charts show appliance utilisation, security service status, the latest threats, risky apps, bandwidth consumption and the busiest users.</p><p>There's also a quick-start wizard, which helped us set up the LAN and WAN ports for internet access and apply a security policy to the default zone. Optionally you can create multiple security zones, each with its own settings, and place selected ports in different zones. Zero-touch provisioning even allows you to send appliances to remote sites, where they will pick up their configuration as soon as they connect to the internet.</p><p>The various security features are very flexible. <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" target="_blank" data-original-url="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus">Virus scanning</a> can be enabled for selected zones, using one global configuration for HTTP, FTP, IMAP, POP3, SMTP, CIFS and TCP streams. <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security" target="_blank" data-original-url="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">HTTPS inspection</a> can be easily enabled too, while web filtering uses either the basic SonicWall CFS or the premium WebSense Enterprise hosted service, which costs an extra 179 per year.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="K2uZKAk8VWJjCYkCRtj6HV" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/K2uZKAk8VWJjCYkCRtj6HV.png" mos="https://cdn.mos.cms.futurecdn.net/K2uZKAk8VWJjCYkCRtj6HV.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The content filtering module is just as configurable: we were easily able to create filtering profile objects using the 64 available URL categories, assign action objects to block access and apply an acceptable use policy to redirect users to a consent web page.</p><p>Then there's app control, which you'll find on the console's new Investigate page. From here, you can freely browse the AppFlow logs, and if you spot any suspect apps you can create an instant rule to block or monitor them. Advanced control rules are more complex to create, as they use signature IDs to identify specific activities, but if you've had enough of Facebook in the workplace, you can manage or block any of its services.</p><p>On top of all this, you may choose to pay 182 per year for the optional anti-spam module. This handles spam, phishing and suspicious attachments, while the Exchange Junk Store feature allows users to view their personal quarantine areas and delete or release messages. It doesn't offer transparent scanning, though, so you need to set it up with details of your email server.</p><p>As a final bonus, if you're using more than one SonicWall appliance, the Capture Security Center service lets you manage them all from one central cloud console, with an impressive collection of analytics and reporting services.</p><p>No doubt, the TZ300P delivers a wealth of security measures at a great price. It's comprehensive yet easy to deploy, and with remote management and zero-touch provisioning it will particularly appeal to businesses with multiple offices.</p><h2 id="verdict">Verdict</h2><p>The SonicWall TZ300P delivers a wealth of security measures at a great price. It’s comprehensive yet easy to deploy, and with remote management and zero-touch provisioning it will particularly appeal to businesses with multiple offices.</p><p>Desktop appliance</p><p>800MHz dual-core CPU</p><p>1GB RAM</p><p>5 x Gigabit (WAN, 4 x LAN with 2 x PoE or 1 x PoE+)</p><p>USB 3</p><p>RJ-45 serial port</p><p>Web browser and CSC cloud management</p><p>External PSU</p><p>1yr hardware warranty and support</p><p>Options: Anti-spam service, £182 per year (exc VAT)</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kerio Control NG300W review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29572/kerio-control-ng300w-review</link>
                                                                            <description>
                            <![CDATA[ Lacking anti-spam but Kerio’s wireless-enabled NG300W appliance scores highly for value and performance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4qyjEQqTgyW1V5ctGNii3E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3tJrhwZScUdUkARbK4D3LG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Sep 2017 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3tJrhwZScUdUkARbK4D3LG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3tJrhwZScUdUkARbK4D3LG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kerio has traditionally offered a modest range of UTM appliances and its Control family gets a timely boost with two new wireless models. The NG300W on review takes the standard NG300 chassis and adds dual band 11ac wireless services and support for up to eight SSIDs.</p><p>It's built on a firm foundation, as Kerio's embedded Control software teams up a standard SPI firewall with deep packet inspection, IPsec VPNs, IPS, bandwidth management and QoS (quality of service). There's much more: it augments these with Kerio's own Web Filter service and Sophos' gateway antivirus.</p><p>The appliance is silent and its chunky aluminium chassis functions as a heatsink. Inside beats a speedy quad-core 2.4GHz Intel Atom C2558 partnered by 4GB of DDR3L, 32GB of SSD storage and four Gigabit ports. Kerio claims firewall and UTM speeds of 900Mbits/sec and 700Mbits/sec respectively, which means it'll handle the demands of most SMEs.</p><p>The unlimited-user model costs 1,647 ex VAT, but you can save 554 with a 25-user license. Ongoing costs are reasonable; unlimited and 25-user software maintenance charges are 478 and 316 per year and include updates to the Control, Sophos AV and web filter services.</p><p>Installation took five minutes, with the web browser wizard setting up Internet access and applying a base set of firewall rules for us. The three LAN ports default to being members of one switch with DHCP services but we could easily break them out and have selected ports providing their own services.</p><p>Likewise with wireless services, as each SSID can be set as a standalone interface or assigned to the LAN port group. Furthermore, making an SSID a guest interface isolates it from all LAN ports and users can be redirected to a customisable welcome web page with an AUP and optional password request.</p><p>For custom firewall rules, we chose from the long list of predefined services, added sources and destinations and decided whether to block or allow the traffic. Rules are placed in a list in order of priority and colour coded to show clearly which were blocking or allowing traffic.</p><p>We quickly applied antivirus scanning to HTTP, FTP, SMTP and POP3 traffic but noted that Kerio doesn't offer any anti-spam measures. The web filtering is a winner though, as it has over 150 URL categories to block or allow and during testing, we found very few websites escaped its net.</p><p>Bandwidth management and QoS (quality of service) controls are also available and Kerio includes a pre-defined rule that reserves a minimum bandwidth for SIP VoIP services. Intrusion prevention shouldn't be sniffed at either - this is handled by the well-respected Snort and can be activated for all traffic with one click.</p><p>Businesses looking to deploy multiple Control appliances to remote sites will like the free MyKerio web cloud portal. Once we'd enabled access from the appliance's local web console, we registered it with our account and could then manage the NG300W from anywhere we wanted.</p><p>VPN support extends to the IPsec, PPTP and L2TP variety and while Kerio doesn't support SSL VPNs, it makes up for this with the fact that its own VPN server is very easy to configure. Control VPN clients are available for Windows, OS X and Linux and performance is good too, with file copies between local and remote Windows hosts averaging 50MB/sec and appliance CPU utilisation hovering around 35-40 percent.</p><p>Anti-spam would have been a bonus but we can't fault the Control NG300W for anything else. It's pleasantly simple to manage, built like a tank and offers a good range of security measures for the price.</p><p><em>This review originally appeared in PC Pro issue 273</em></p><h2 id="verdict-2">Verdict</h2><p>Anti-spam would have been a bonus but we can’t fault the Control NG300W for anything else. It’s pleasantly simple to manage, built like a tank and offers a good range of security measures for the price.</p><p>Desktop chassis</p><p>2.4GHz Intel Atom C2558</p><p>4GB DDR3L</p><p>32GB SSD</p><p>4 x Gigabit (WAN, 3 x LAN)</p><p>2.4/5GHz 11a/ac/b/g/n wireless</p><p>2 x USB 2</p><p>RJ-45 console</p><p>External PSU</p><p>177 x 146 x 44mm (WDH)</p><p>Kerio Control and Web Filter</p><p>Sophos AV</p><p>1 year standard warranty.</p><p>Options: 3-year extended warranty, £113 ex VAT with initial purchase</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Three foolproof ways CEOs and CISOs can work together more effectively ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/29031/three-foolproof-ways-ceos-and-cisos-can-work-together-more-effectively</link>
                                                                            <description>
                            <![CDATA[ How involved is your Chief Information Security Officer (CISO) in business decisions? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sthrHoWqvaLScMk5aVv9nr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sPbXdZwtAFqqATwpK28Su5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Jul 2017 08:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Preece ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/MfwwRmvRe3qucjt85cMgeg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sPbXdZwtAFqqATwpK28Su5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Business agreement]]></media:description>                                                            <media:text><![CDATA[Business agreement]]></media:text>
                                <media:title type="plain"><![CDATA[Business agreement]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sPbXdZwtAFqqATwpK28Su5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If your Chief Information Security Officer isn't very involved in business decisions, you could be missing out on lucrative business opportunities.</p><p>Without collaboration at board level, these opportunities may never arise a fact many companies are attempting to rectify by encouraging CEOs and CISOs to work more effectively together.</p><p>For example, cyber security is a now an enterprise-wide risk factor that can't be overlooked, and the attitudes among directors is slowly shifting.</p><p>Almost half of boards now actively participate in the overall information security strategy according to a 2016 report by PWC, and companies are becoming more and more security-conscious as the business world continues to evolve. But while not many doubt the importance of security expertise in board meetings, actioning that benefit in any significant way can be a little trickier.</p><p>But what can executives do to take advantage of this shift, and create a more innovative, secure model? Here are three foolproof ways:</p><p><strong>CISOs should become more involved with the whole business</strong></p><p>The days of heavily siloed companies with employees working and communicating only within designated departments are dead and buried, and a new business model must be adopted if a company wishes to survive. That new way of working involves leaders across the business collaborating more effectively, and in order to do this, they must diversify their knowledge base.</p><p>Small things such as CISOs understanding the jargon of CEOs and vice versa can make everyday tasks at board level much easier to digest and subsequently take action upon. If everyone is speaking the same language, then data and metrics can be understood beyond those who are collecting and presenting the information.</p><p>This also goes the other way; a basic knowledge of security matters is essential for all C-level executives (and employees at all levels) to function best in their roles.</p><p><strong>Embrace specified knowledge points</strong></p><p>At the same time as deliberately widening their knowledge base, it's essential for CISOs to use their specialised skillsets. Anyone working in IT is almost always ahead of the rest of the company when it comes to awareness of technology trends and changes, and they can use that foresight to benefit the business as a whole.</p><p>CISOs and CEOs can work together to gain a significant competitive edge over rivals through effective communication, combining knowledge to move the company forwards. At the same time, CEOs can look to their security teams for guidance on which risks to take and which might be too dangerous.</p><p><strong>Realise security is everyone's problem</strong></p><p>Cyber security is no longer something that can be ignored or pushed on to workers down in the basement, and CEOs should not treat it as such. Security is now such a pressing issue for companies across almost every industry that prevention and defence techniques need to be woven into the very fabric of the business.</p><p>One easy way to do this is to collaborate with the CISO and his or her team on matters such as business growth and advantage from the very start, ensuring that security is not in the back of anyone's minds when making important company decisions. The CISO should be front and centre in board meetings, and everyone needs to be aware of the security risk of any new endeavors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kerio Control NG100 review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/unified-threat-management/27122/kerio-control-ng100-review</link>
                                                                            <description>
                            <![CDATA[ A compact unified threat-management appliance that’s ideal for small or remote offices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pRdCAda1Pz6dj2dGqRiGgN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2hMPuhucjx3VGDES8YhfsY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Aug 2016 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2hMPuhucjx3VGDES8YhfsY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2hMPuhucjx3VGDES8YhfsY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kerio's Control NG100 is the smallest UTM appliance we've ever seen, but the manufacturer has managed to pack plenty into this palm-sized slab of steel. It runs the full version of Kerio's Control software, providing SPI firewalling, IPsec VPNs, IPS, deep-packet inspection and bandwidth management. In addition, you also get Kerio's own Web Filter service and Sophos' gateway antivirus.</p><p>It's good value, too: inside beats a dual-core 1.33GHz Atom CPU, with 4GB of DDR3L RAM, 32GB of mSATA storage and three Gigabit ports. The 389 price includes a one-year licence for all software and signature updates. After this period, the maintenance cost is 122 per year, which includes updates to the Control, Sophos AV and Web Filter services.</p><p>The NG100 is aimed at small firms and remote offices, but you don't have to count seats too carefully, as the licence is for unlimited users. The only limitation is the bandwidth of the hardware itself: Kerio claims a UTM throughput of 30Mbits/sec.</p><p>Installation was swift: the web console's activation wizard automatically sorted out internet access and created a base set of firewall rules. It assigned WAN duties to the first Gigabit port, and grouped the other two together as a LAN switch along with DHCP services. If you prefer, these ports can be configured separately, each with their own firewall rules and DHCP services, and given separate weightings for traffic prioritisation.</p><p>Setting up the firewall was easy: we had no problem choosing from the extensive list of predefined services, selecting sources and destinations and applying block or allow actions to the traffic. IPS is handled by the well-respected Snort, which can be enabled for all traffic with a single click and updated automatically every hour.</p><p>The web-filtering service recognises 150 categories of site, which you can blacklist or whitelist: it worked well for us, with none of our test URLs slipping through the net - save a few bingo sites. Kerio doesn't offer anti-spam services, but the Sophos AV scanner can be applied not only to HTTP and FTP traffic, but to SMTP and POP3 too, allowing the NG100 to provide some measure of mail protection.</p><p>The NG100 supports transparent and non-transparent HTTP proxy operations, and you can apply user authentication locally or via Active Directory. You can also use one of the LAN switch ports to host a separate guest network: in this mode, the NG100 automatically sets up DHCP services and configures a firewall rule to allow guest internet access. When users first connect, they're sent to a customisable welcome page, which is hard-coded to block access to the rest of the LAN. But add an AUP to the welcome page, and the web filter doesn't apply to guest traffic.</p><p>The NG100 doesn't support SSL VPNs, but Kerio's proprietary VPN server is easy to configure. All we had to do was enable the service, choose the default certificate, and activate the predefined firewall rule to allow inbound VPN access. Control VPN clients are available for Windows, OS X and Linux. Performance is impressive: we copied a 2.5GB test file over a VPN link to a LAN system at an average of 7MB/sec - although we did see appliance CPU utilisation hitting 98% during the operation.</p><p>There are plenty of monitoring tools, too. The web console provides graphs displaying hardware, WAN/LAN utilisation and active users, and keeps logs of every activity. Firms with multiple sites will love the free MyKerio web portal service, which provides full remote access to each appliance's web console. The NG100 is probably the smallest UTM appliance you can buy, but it's no lightweight. It offers features that would put more expensive appliances to shame.</p><p><strong><em>This review was originally published in PC Pro issue 262.</em></strong></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/unified-threat-management/26280/kerio-control-ng500-review" data-original-url="/unified-threat-management/26280/kerio-control-ng500-review">Kerio Control NG500 review</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/networking/26877/kerio-operator-box-v300-review" data-original-url="/networking/26877/kerio-operator-box-v300-review">Kerio Operator Box v300 review</a></p></div></div><h2 id="verdict-3">Verdict</h2><p>The NG100 is probably the smallest UTM appliance you can buy, but it’s no lightweight. It offers features that would put more expensive appliances to shame.</p><p>1.33GHz Intel Atom E3825</p><p>4GB DDR3L</p><p>32GB mSATA</p><p>3 x Gigabit Ethernet</p><p>USB 2</p><p>USB 3</p><p>HDMI</p><p>RJ-45 console</p><p>External PSU</p><p>Kerio Control and Web Filter</p><p>Sophos AV</p><p>1yr standard warranty</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kerio Control NG500 review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/unified-threat-management/26280/kerio-control-ng500-review</link>
                                                                            <description>
                            <![CDATA[ Wrestle back control of your company's network ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o7WBLNiHJe7zERx2JcPKjt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6vKyKkXVcvfwzD5n25baST-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Mar 2016 10:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6vKyKkXVcvfwzD5n25baST-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6vKyKkXVcvfwzD5n25baST-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kerio's Control is a long-term player in the SMB UTM market and for good reason as it has always offered a fine range of security measures at affordable prices. The company made the switch to software, hardware and virtual appliances a few years ago and its next generation Control products offer a boost in performance and features.</p><p>Kerio has launched three new hardware appliances with the top-dog NG500 on review aimed at head offices or large remote sites. Powered by a 3.6GHz Core i5 processor and 4GB of DDR3 RAM, this 1U rack appliance claims decent firewall and UTM speeds of 975Mbps and 280Mbps respectively.</p><p>It provides a solid foundation of SPI firewall, deep packet inspection, IPsec VPNs, IPS and bandwidth management. Kerio builds on this with Sophos' gateway anti-virus and its own Control Web Filter services, but anti-spam is not available.</p><p>The unlimited-user model costs 2,459 but you can save over 400 and go for a 100 user restriction. Ongoing costs aren't unreasonable as software maintenance charges for subsequent years are around 842 per year and include upgrades and updates to the Control, Sophos AV and web filter services.</p><h2 id="swift-deployment">Swift deployment </h2><p>The NG500 is very easy to install as the tidy web interface fires up an activation wizard which runs through setting up Internet access, registration and creating a base set of firewall rules. Port options are versatile as the appliance defaults to assigning the first Gigabit Ethernet port to Internet duties with the other five grouped together as a LAN switch with DHCP services.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="foDFbnpJ6k9WhFWxNQEELS" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/foDFbnpJ6k9WhFWxNQEELS.png" mos="https://cdn.mos.cms.futurecdn.net/foDFbnpJ6k9WhFWxNQEELS.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Kerio's tidy dashboard provides plenty of information about network activity</em></p><p>The NG500 supports failover and load-balanced Internet links and a handy wizard takes the strain. Both modes only use the first two ports for these duties. For load balancing, you can assign weightings to prioritise the link with the highest bandwidth.</p><p>If you wish, you can break selected ports out of the switch group and designate them as standalone. These can provide dedicated DHCP services and have their own security and firewall policies applied.</p><h2 id="security-detail">Security detail </h2><p>For custom firewall rules, we chose from a fine selection of predefined services, added sources and destinations and decided whether to block or allow the traffic. Rules are placed in a list in order of priority and colour coded so we could easily see which were blocking or allowing traffic. </p><p>Along with HTTP and FTP traffic, the Sophos anti-virus scanner can be applied to SMTP and POP3 too, so some email protection is provided. Kerio's Web Filter service offers 150 URL categories to block or allow and supports multiple rules so we could apply a wide range of browsing controls.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZETML54aQrFDMyuvZHkmdW" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZETML54aQrFDMyuvZHkmdW.png" mos="https://cdn.mos.cms.futurecdn.net/ZETML54aQrFDMyuvZHkmdW.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Kerio's Web Filter service offers 150 URL categories to choose from and performed very well</em></p><p>Kerio's intrusion prevention shouldn't be sniffed at as this is handled by the well-respected Snort. It's enabled for all traffic with a single click, uses three threat severity levels to decide whether to allow, log or block dubious incoming traffic. Its signature database can be updated automatically as often as every hour.</p><h2 id="vpn-choices">VPN choices </h2><p>VPN support extends to the IPsec, PPTP and L2TP varieties. Unlike most of the competition however, Kerio doesn't support SSL VPNs. The proprietary VPN server is remarkably easy to configure though, which makes up for this surprising absence.</p><p>All we needed to do was enable the Kerio VPN Server service, choose the default certificate and activate the predefined firewall rule to allow inbound VPN access from the Internet. Kerio provides Control VPN clients for Windows, OS X and Linux. We tested the Windows version, which just required the eternal address or FQDN of the NG500 and user credentials.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uCtHwSJTXLowZerGBtafdL" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/uCtHwSJTXLowZerGBtafdL.png" mos="https://cdn.mos.cms.futurecdn.net/uCtHwSJTXLowZerGBtafdL.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Kerio's proprietary VPN server is a cinch to set up and client connections are equally pain free</em></p><p>Performance is good, too. Copying a 2.5GB test file over the Kerio VPN link to a desktop on the LAN returned good sustained transfer rates of around 16.5MB/sec with appliance CPU utilisation never going above 21 percent.</p><h2 id="users-and-guests">Users and guests </h2><p>Kerio supports transparent and non-transparent HTTP proxy operations, while user authentication can be carried out locally or via Active Directory. Kerio's license only applies to user authentication so you can have as many unauthenticated users as you like. </p><p>This is handy for setting up a guest network as we could break out an interface from the LAN switch group and use it for this purpose. After providing it with a fixed IP address, the appliance automatically assigned DHCP services and a firewall rule to allow guest Internet access and it's hardcoded to block them from the LAN.</p><p>Users connecting to our guest network were automatically redirected to a welcome web page which can be customised with a company logo and AUP. You can assign custom firewall rules and request they enter a shared password, but you can't apply Kerio's Web Filter services to guest traffic.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zrkwuuNNBrvm43yBzXTnbV" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/zrkwuuNNBrvm43yBzXTnbV.png" mos="https://cdn.mos.cms.futurecdn.net/zrkwuuNNBrvm43yBzXTnbV.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The NG500 can be cloud managed with a MyKerio account and provides good local reporting as well</em></p><h2 id="conclusions">Conclusions</h2><p>The Control NG500 is pleasantly simple to deploy and offers a good range of security measures for the price. It's also easy to manage and you get free access to the MyKerio web portal for remotely monitoring and configuring multiple appliances.</p><p>Anti-spam would have rounded the NG500 out nicely, but it can't be faulted for its firewall, Sophos gateway AV or web content filtering features. Secure guest access is also a bonus as are Kerio's VPN services which delivered comparatively good performance.</p><h2 id="verdict-4">Verdict</h2><p>The Control NG500 delivers a good set of network security measures in an affordable and easily managed appliance</p><p>Chassis: 1U rack</p><p>Processor: 3.6GHz Intel Core i5-4570S</p><p>Memory: 4GB DDR3</p><p>Storage: 32GB SSD</p><p>Network: 6 x Gigabit Ethernet</p><p>Other ports: 2 x USB 2, RJ-45 serial port</p><p>Power: Fixed 220W PSU</p><p>Management: Web browser, MyKerio</p><p>Warranty: One year standard </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Uber launches bug bounty programme with $10k prize ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/26256/uber-launches-bug-bounty-programme-with-10k-prize</link>
                                                                            <description>
                            <![CDATA[ Keen bug tracers will need to find five genuine bugs to receive their first payout ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2EBfmAvQuL4yPWZ94hCYFt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EoN4fAypkarxjMpe2xbbuN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Mar 2016 11:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Aaron Lee ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EoN4fAypkarxjMpe2xbbuN-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A red padlock with a binary code label surrounded by circuits.]]></media:description>                                                            <media:text><![CDATA[A red padlock with a binary code label surrounded by circuits.]]></media:text>
                                <media:title type="plain"><![CDATA[A red padlock with a binary code label surrounded by circuits.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EoN4fAypkarxjMpe2xbbuN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Uber has launched an official bug bounty programme, and is offering cash rewards of up to $10,000 (7,049) for the discovery of errors in its systems.</p><p>The transport company ran a trial programme with 200 security researchers last year who found almost 100 bugs, which Uber said it has already fixed.</p><p>The success of that trial is why it has chosen to launch a public bug bounty programme now.</p><p>In addition to up to the monetary reward for the discovery of "critical issues", Uber said it is creating a "first-of-its-kind loyalty reward programme" to incentivise the security community to help quash bugs in its systems.</p><p>"Even with a team of highly-qualified and well trained security experts, you need to be constantly on the look out for ways to improve," said Joe Sullivan, chief security officer at Uber.</p><p>"This bug bounty program will help ensure that our code is as secure as possible. And our unique loyalty scheme will encourage the security community to become experts when it comes to Uber."</p><p>Uber's first reward programme season will commence on 1 May and will last 90 days.</p><p>Bug tracers will be eligible for the reward programme once they have found four issues that have been accepted by Uber as genuine bugs.</p><p>If they then find a fifth issue within the 90-day session, they will get a bonus payout equivalent to 10 per cent of the average payouts for all the other issues found in that session.</p><p>Uber has put together a <a href="https://eng.uber.com/bug-bounty" target="_blank">rolling guide</a> to show researchers how to find different classes of bug across its codebase.</p><p>More information about the programme can be <a href="https://hackerone.com/uber" target="_blank">found here</a>.</p><p>Bug bounty programmes are a fairly common part of the ecosystem for large tech businesses today, with Microsoft recently adding <a href="http://www.cloudpro.co.uk/collaboration/5882/microsoft-adds-onedrive-to-bug-bounty-programme" target="_blank">OneDrive to its bug bounty programme</a>.</p><p>Although Uber's technical presence has set an example for others, the company has been fighting court battles over its car sharing networks. Most recently two Uber executives in French <a href="https://www.itpro.com/public-sector/26042/trial-of-two-french-uber-executives-begins" target="_blank" data-original-url="https://www.itpro.com/public-sector/26042/trial-of-two-french-uber-executives-begins">denied their involvement in what has been deemed an "illegal" taxi service</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Panda GateDefender e250 review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/unified-threat-management/25382/panda-gatedefender-e250-review</link>
                                                                            <description>
                            <![CDATA[ This Panda security appliance is faster than ever, yet hasn't risen in price ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wVdtGVUbk37rrjhga4bfvY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/J7xEggUDQx7sdnMWQHBuKF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Oct 2015 06:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/J7xEggUDQx7sdnMWQHBuKF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/J7xEggUDQx7sdnMWQHBuKF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Although best known for its endpoint security software, Panda Security has always offered a solid range of business security appliances that have been nothing if not keenly priced. Unfortunately, performance has not been a strong point but the new GateDefender e250 aims to remedy this.</p><p>Taking over from <a href="https://www.itpro.com/security/23714/panda-gatedefender-performa-e9100lite-review" target="_self" data-original-url="https://www.itpro.com/security/23714/panda-gatedefender-performa-e9100lite-review">the e9100lite</a>, it claims to boost UTM throughput from the meagre 95Mbits/sec of its predecessor to a much more impressive 590MBits/sec. Even better, it does it at the same price as its predecessor.</p><p>It's easy to see how Panda has achieved this as the e9100lite only had an elderly 2.6GHz dual-core Pentium E5300 and just 2GB of DDR2 memory. The e250 has been beefed up with a quad-core 2GHz Intel Core i5-4590T alongside 4GB of DDR3 RAM.</p><p>As with the e9100lite, we found the cooling fans excessively noisy. With a tiny 35W TDP, the Core i5 processor is a cool customer so we can't see why it needs a massive heatsink and three fans all running as high as 8,000rpm.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aSVcmGEscr6SqYtEtFaTgE" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/aSVcmGEscr6SqYtEtFaTgE.png" mos="https://cdn.mos.cms.futurecdn.net/aSVcmGEscr6SqYtEtFaTgE.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The web console dashboard shows all wired and wireless activity along with appliance utilisation</em></p><h2 id="security-features">Security features </h2><p>We like Panda's simplified licensing scheme as you pay a single yearly subscription for everything. Along with an SPI firewall and support for IPsec and SSL VPNs, the subscription activates anti-virus, IPS, anti-spam, web content filtering and application controls. </p><p>Internal hard disks are unusual at this price. The e250 uses mirrored 320GB SFF SATA drives to provide a spam quarantine area and web cache.</p><p>Another feature that adds even more value is built-in wireless network management and unlike many other vendors that offer this, the e250 will work with any access point (AP). You connect the AP or a switch carrying wireless traffic to any port on the appliance, apply security policies and create a wireless hotspot with login portal and billing scheme.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="g3qtECYNMq5PFvFLzrjrRj" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/g3qtECYNMq5PFvFLzrjrRj.png" mos="https://cdn.mos.cms.futurecdn.net/g3qtECYNMq5PFvFLzrjrRj.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The e250 allowed us to set up wireless hotspots with billing schemes and Internet access restrictions</em></p><h2 id="colour-by-numbers">Colour by numbers</h2><p>The e250 provides eight Gigabit Ethernet ports which can be assigned to LAN, WAN, DMZ or wireless network duties. A quick-start wizard made light work of installation as it guided us through configuring trusted and uplink ports and applied a base set of firewall security policies to provide immediate protection.</p><p>Panda employs colour codes for ports and uses green, red, orange and blue zones for trusted, Internet, DMZ and wireless services respectively. This helps when configuring the firewall as security policies can be swiftly applied by selecting the zone colours for source and destination networks.</p><p>WAN failover is available as we could define multiple ports as uplinks in the red zone and use static or DHCP addressing. Each extra uplink can be set so they are only activated if another specific uplink port goes down.</p><p>This colour zoning method does have limitations for defining different trusted network segments though. Essentially, you can only have a single trusted network subnet as the green zone is assigned one IP address and a DHCP server.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Jtup3RKVbXp5w6kJSzzJXJ" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/Jtup3RKVbXp5w6kJSzzJXJ.png" mos="https://cdn.mos.cms.futurecdn.net/Jtup3RKVbXp5w6kJSzzJXJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Ports are assigned colour-coded zones</em></p><h2 id="web-filtering-and-anti-spam">Web filtering and anti-spam</h2><p>The e250 provides proxies for controlling HTTP, HTTPS, SMTP, POP3 and FTP traffic. The HTTP proxy can be transparent or non-transparent and we used the former as this didn't require any changes made to our users' browser settings.</p><p>The HTTP proxy can have AV scanning applied. For web filtering, Panda provides five general URL categories covering themes such as productivity and security and within these are a total of 83 sub-categories. Proxy authentication can also be applied using the local appliance, Active Directory, LDAP or RADIUS.</p><p>The POP3 proxy uses the SpamAssassin service to scan inbound mail. We used it to tag the subject line of suspect messages but they can't be moved to the quarantine area.</p><p>Quarantining is available with the SMTP proxy which uses the CommTouch hosted service and requires details of your internal mail server. It provides spam checks plus virus scanning and will move suspect messages to the appliance's quarantine store.</p><h2 id="performance-and-reporting">Performance and reporting</h2><p>For performance testing, we used the lab's Ixia Xcellon-Ultra NP load modules and IxLoad control software. The IxLoad software was configured for two client/server streams with requests for 1MB web page sizes.</p><p>With AV enabled in the HTTP proxy, we recorded a maximum steady throughput of 900Mbits/sec 35% lower than Panda's claimed 1.4Gbit/s. This was the best we could achieve as increasing the load further maxed out all four CPU cores at 100% causing traffic throughput to fluctuate wildly.</p><p>There were no such problems with the IPS service enabled. We recorded a steady throughput of 590Mbits/sec which is exactly what Panda's claims for full UTM performance.</p><p>On-board reporting tools are good as we could keep an eye on firewall activity, view graphs for proxies and services and check on traffic flows. MSPs can take advantage of Panda's Perimetral Management Console (PMC) which provides a central point of administration for all their Panda appliances with facilities for status monitoring and tools for remote firmware upgrades.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tqFj792f9oRAuFNbx8csLj" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/tqFj792f9oRAuFNbx8csLj.png" mos="https://cdn.mos.cms.futurecdn.net/tqFj792f9oRAuFNbx8csLj.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Our Ixia IxLoad test shows the e250 delivering a steady 590Mbits/sec UTM performance</em></p><h2 id="conclusions-2">Conclusions</h2><p>The GateDefender e250 delivers a solid range of security measures and teams them up with some useful wireless hotspot management features. Its port-zoning feature isn't as versatile as that used by Watchguard's Firebox appliances but the e250 is still good value and just as easy to deploy. </p><h2 id="verdict-5">Verdict</h2><p>The e250’s hardware upgrade delivers superior UTM performance and combines this with a fine range of network security measures including wireless hotspot management</p><p>Chassis: 1U rack</p><p>CPU: 2GHz Intel Core i5-4590T</p><p>Memory: 4GB 1,600MHz DDR3</p><p>Storage: 2 x 320GB Hitachi SATA SFF mirrored hard disks</p><p>Network: 8 x Gigabit Ethernet (LAN, WAN, DMZ, Wireless)</p><p>Other ports: 4 x USB 2, RJ-45 serial, VGA</p><p>Power: Internal power supply</p><p>Management: Web browser, PMC</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watchguard Firebox M300 review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/unified-threat-management/25376/watchguard-firebox-m300-review</link>
                                                                            <description>
                            <![CDATA[ WatchGuard is on a mission to bring enterprise-level security to SMBs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">w4W9nPdkzSsmyye7Bqw4sS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hkecSvwwaCBfMRWinPtHg6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Oct 2015 11:04:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hkecSvwwaCBfMRWinPtHg6-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hkecSvwwaCBfMRWinPtHg6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>High prices for UTM security appliances mean many SMBs aren't getting the protection they need which leaves them potentially vulnerable to cyber-criminals who are increasingly targeting smaller companies. Watchguard's latest Firebox appliances aim to put this right by delivering a wealth of security measures at a price SMBs can afford.</p><p>Clothed in Watchguard's customary fire-engine red chassis, the Firebox M300 has eight Gigabit Ethernet ports and claimed raw firewall speeds of 4Gbits/sec. Enabling its HTTP proxy plus IPS and gateway AV services drops this to 800Mbits/sec - still very respectable for an appliance at this price point.</p><p>A Standard Support subscription (formerly called Live Security) includes the appliance, hardware warranty, updates plus tech support and costs 2,117 for 3 years. This also includes Watchguard's System Manager and Dimension management software.</p><p>A Standard Support subscription only includes firewall and VPN capabilities. A 3-year Security Suite subscription pushes the price to 3,610 and augments the SPI firewall with web filtering, anti-spam, gateway anti-virus, IPS, application controls and WatchGuard's 'reputation enabled defence'. The M300 also supports Watchguard's optional data leak prevention (DLP) and advanced persistent threat (APT) blocker services.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="EHhqEPsCRssRBxS6KY5RJ6" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/EHhqEPsCRssRBxS6KY5RJ6.png" mos="https://cdn.mos.cms.futurecdn.net/EHhqEPsCRssRBxS6KY5RJ6.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The appliance's well-designed web interface makes management a simple process</em></p><h2 id="simple-deployment">Simple deployment</h2><p>Deployment was quick as we followed the web console's wizard which helped set up the first two network ports with Internet and LAN access. It enabled DHCP services on the LAN side and applied a base set of security policies.</p><p>It defaults to the mixed routing mode which is our preferred mode of operation. This allowed us to configure each port on the M300 as separate interfaces each with their own IP address and DHCP services if required.</p><p>When configuring the remaining ports, we could designate them as external, trusted, optional or custom and give each one an alias. It's worth taking a moment to get this right as it'll make creating firewall policies a lot easier.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZmCawoLR76fnbUngneRrG5" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/ZmCawoLR76fnbUngneRrG5.png" mos="https://cdn.mos.cms.futurecdn.net/ZmCawoLR76fnbUngneRrG5.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The new wizards made light work of creating proxy actions for the WebBlocker filtering service</em></p><h2 id="new-features">New features</h2><p>Watchguard's proxies are employed by all the security services but this is one feature we've always griped about as new users will find them complex to set up. You have proxies for HTTP, HTTPS, FTP, SIP, H.323, POP3 and SMTP.</p><p>It's now a lot quicker as a setup wizard handles cloning the predefined proxy actions and applying them to your security policy. For the WebBlocker filtering service, we gave the new HTTP Client action a meaningful name, browsed the 130 categories on offer and decided whether to block or allow them.</p><p>Anti-spam measures were equally quick to apply as the wizard helped us create a new action for the SpamBlocker service set to tag spam, suspect and bulk messages. It applies transparent scanning so there's no need to define internal mail servers plus we could add exceptions for specific mail senders and activate the virus outbreak detection feature. </p><p>Gateway AV can be enabled on selected proxies and set to decompress and scan archives. The APT service is available for the HTTP, FTP and SMTP proxies where it scans incoming files and checks their MD5 hash with the LastLine cloud service to see if they're known malware.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="K5DDvUcHzxL7y22ik6Jfb" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/K5DDvUcHzxL7y22ik6Jfb.png" mos="https://cdn.mos.cms.futurecdn.net/K5DDvUcHzxL7y22ik6Jfb.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Watchguard's Dimension provides slick Firebox monitoring and reporting tools</em></p><h2 id="management-choices">Management choices</h2><p>Our preferred method for managing a single appliance is via its well-designed web interface but Watchguard's System Manager program comes in handy if you have loads to administer. After connecting to an appliance, we could manage its security policies or network settings and call up the Firebox System Manager utility to view all network activity.</p><p>Available as a free Hyper-V or VMware virtual machine, Watchguard's Dimension collects and analyses security information from multiple appliances. We tested the VMware version and simply pointed our M300's Log Server address at the Dimension VM which automatically discovered it.</p><p>The home page lists all monitored appliances along with details of their operational status and current firmware version. Selecting our appliance took us directly to the Executive Dashboard which provided a wealth of data about user activity.</p><p>The Security Dashboard shows essential information about clients, web sites and protocols being blocked. The Threat Map provides a global map showing regions where threats are coming from and clicking on the city's associated IP address loads a Google Map of the area which could be potentially useful information for law enforcement.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gtZccPkGhNefZwRPDhmAKU" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/gtZccPkGhNefZwRPDhmAKU.png" mos="https://cdn.mos.cms.futurecdn.net/gtZccPkGhNefZwRPDhmAKU.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>Our Ixia tests showed the M300 delivered 600Mbits/sec with UTM services enabled on the HTTP proxy</em></p><h2 id="proxy-performance">Proxy performance </h2><p>For real world performance testing we hooked the M300 up to the lab's Ixia Xcellon Ultra-NP network load modules and configured the IxLoad control software to generate 512KB HTTP web pages. We created three client/server streams and set a load objective of 1Gbits/sec for each stream. </p><p>With the HTTP packet filter enabled, we recorded a top speed of 2.6Gbits/sec which dropped to 1.7Gbits/sec with IPS enabled in the firewall policy. During this test, IxLoad confirmed there were no TCP retries or resets.</p><p>With WatchGuard's HTTP proxy on the case, we saw an average throughput of 1.1Gbits/sec and with IPS enabled, this fell to 800Mbits/sec. With gateway AV and IPS enabled in the policy, throughput averaged 600Mbits/sec 25% less than WatchGuard's claims.</p><h2 id="conclusions-3">Conclusions </h2><p>Proxy performance didn't quite meet our expectations but compared with <a href="https://www.itpro.com/server/21211/dell-sonicwall-nsa-2600-review" target="_self" data-original-url="https://www.itpro.com/server/21211/dell-sonicwall-nsa-2600-review">Dell SonicWALL's more costly NSA-2600</a>, the Firebox M300 is still twice as fast. Combine this with its superb range of features and you have an ideal gateway security appliance for cost-conscious SMBs.</p><h2 id="verdict-6">Verdict</h2><p>The Firebox M300 delivers a superb range of security features at a price SMBs will approve of. Overall performance is good and the price includes some quality management and monitoring tools.</p><p>Chassis: 1U rack</p><p>CPU: 1.8GHz quad-core Freescale</p><p>Memory: 4GB DDR3</p><p>Network: 8 x Gigabit Ethernet</p><p>Other ports: 2 x USB2, RJ-45 serial port</p><p>Management: Web browser, Watchguard System Manager</p><p>Warranty: Advanced hardware replacement with support subscription</p><p>Options: 3-year subscriptions: APT, £1,207; DLP, £583 (all ex VAT)</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ZyXEL USG60W UTM review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/unified-threat-management/23085/zyxel-usg60w-utm-review</link>
                                                                            <description>
                            <![CDATA[ ZyXEL’s affordable USG60W could be the perfect all-in-one security appliance for SMBs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rWFjHJ5v6kmxU19xpj6FF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4QGcGGvv2qwfTQgShVhvhP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Sep 2014 15:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4QGcGGvv2qwfTQgShVhvhP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4QGcGGvv2qwfTQgShVhvhP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ZyXEL's next generation of UTM appliances offer small businesses a one-stop shop for all their gateway security needs. Along with an SPI firewall and support for IPsec and SSL VPNs, they can be beefed up with web content filtering, anti-virus, anti-spam, IDP and ZyXEL's own application patrol.</p><p>The USG60W on review goes one step beyond as it provides dual band 5GHz and 2.4GHz wireless services and can manage up to 10 wireless APs. The USG60W supports 60 users although this is more a limitation of the hardware as ZyXEL doesn't employ a per-user licensing scheme.</p><p>It hits the spot for value as the base appliance with firewall and support for 2 SSL VPNs costs a shade under 300. A full one year bundle with all security services pushes this to only 348.</p><p>The appliance has Gigabit all round with four LAN ports and two for WAN connections where it can perform load balancing or failover. The two USB ports support storage devices for storing logs on or mobile broadband adapters which can be used for failover.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FmdrLVGNDEm9TunxXpYte3" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/FmdrLVGNDEm9TunxXpYte3.png" mos="https://cdn.mos.cms.futurecdn.net/FmdrLVGNDEm9TunxXpYte3.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The dashboard uses status widgets which can be easily moved around as required</em></p><p><strong>Easy deployment</strong></p><p>To deploy the USG60W just point a web browser at its default address and follow the quick start wizard. This is designed to get Internet access up and running first so it can download the latest firmware.</p><p>ZyXEL's web console opens with a tidy dashboard using widgets for various status readouts. You can decide which widgets you want to see and customise the dashboard by dragging them around to suit.</p><p>The four LAN ports can be grouped into one of three zones each with their own DHCP server. The appliance defaults to having all ports as members of the LAN1 zone but it's easy enough to change them.</p><p>It's worth sorting out your network objects next as these define things such as users, groups, services, schedules, applications and wireless AP profiles. When creating security policies you'll find objects are referenced in most of them.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KvR3Tuv49L69hCMutujivB" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/KvR3Tuv49L69hCMutujivB.png" mos="https://cdn.mos.cms.futurecdn.net/KvR3Tuv49L69hCMutujivB.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The UTM components include anti-spam which is configured using profiles and rules</em></p><p><strong>Security policies</strong></p><p>Each port zone is assigned a security policy with firewall rules defining inbound and outbound routes, time schedules, users and services. UTM profiles are enabled within policies and for web content filtering you can create multiple profiles and choose from over 60 URL categories to block or allow. </p><p>For IDP profiles you have preconfigured rule sets which can be tweaked to suit. Kaspersky handles anti-virus duties but there isn't much to do here as you just decide whether to have it destroy infected files, log all activities and peer into ZIP and RAR archives.</p><p>The USG60W functions as a transparent gateway so it can scan email straight from the box. First, you enable the sender reputation, mail content analysis and virus outbreak detection global features and then create profiles that log, drop or tag suspected spam messages.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hLbvrfPduKXA8zjVjFPC2i" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/hLbvrfPduKXA8zjVjFPC2i.png" mos="https://cdn.mos.cms.futurecdn.net/hLbvrfPduKXA8zjVjFPC2i.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The appliance can send web filtering data to ZyXEL's web portal for use in graphical reports</em></p><p><strong>Application patrol and wireless</strong></p><p>The application patrol feature controls a wide range of apps and ZyXEL provides details of over 3,000. These include apps such as IM, P2P, VoIP, media streaming, file transfer and mail.</p><p>You define application objects first where you search by category though the list and choose those you want to control. Now you can add the objects to a profile and decide whether to allow or deny this traffic.</p><p>There are some useful management tools for social networking with both Facebook and Twitter on the list. For the latter you can decide whether to allow users to tweet, follow or post messages while for Facebook you only have options to block users logging in or accessing media.</p><p>Separate objects are used to control the 2.4GHz and 5GHz radios and each can present up to 8 SSIDs. Profiles defining a security scheme are assigned to each SSID and you can block users on one SSID from seeing those on another. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wumhystiEadW2cBpgbEjpf" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/wumhystiEadW2cBpgbEjpf.png" mos="https://cdn.mos.cms.futurecdn.net/wumhystiEadW2cBpgbEjpf.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em>The lab's Ixia Xcellon-Ultra NP blades recorded an average of 65Mbits/sec with AV and IDP enabled</em></p><p><strong>Ixia performance tests</strong></p><p>We tested performance with the lab's Ixia XM2 chassis and its two Xcellon-Ultra NP blades. ZyXEL claims a raw firewall throughput of 1,000Mbits/sec but this test doesn't give an indication of real world speeds as it only uses lightweight UDP packets.</p><p>With an IxLoad test configured for 512KB HTTP web pages, we saw firewall throughput of around 180Mbits/sec. With AV enabled in our policy, this fell to 70Mbits/sec 20Mbits/sec less than ZyXEL claims.</p><p>UTM performance stayed fairly steady as with IDP also enabled, performance dropped marginally to 65Mbits/sec. We can't argue with ZyXEL's 40,000 concurrent connection (CCs) claim as with 1byte web pages and a 50,000 CC load objective, IxLoad reported a tidy 39,998 CCs.</p><p><strong>Reporting and conclusion</strong></p><p>The console's monitor tab provides statistics tables on all UTM components, interfaces and traffic plus managed wireless APs and clients. It also sends web content filter data to ZyXEL's web portal where you can pull up graphical reports on blocked or allowed categories and URLs.</p><p>Small businesses may struggle with the complex relationship between the numerous security policies and profiles but it's worth persevering as they offer a versatile range of security measures. The price for a 1-year bundle is remarkably low and made all the more tempting by the integral dual-band wireless and AP management features.</p><h2 id="verdict-7">Verdict</h2><p>The USG60W offers an impressive range of security measures and tops them off with dual-band wireless. Configuration can get complicated but small businesses will be hard pushed to find better value elsewhere.</p><p><strong>Chassis:</strong> Desktop/rack mount chassis</p><p><strong>Network:</strong> 6 x Gigabit (2 x WAN, 4 x LAN/DMZ)</p><p><strong>Wireless:</strong> Concurrent 5GHz and 2.4GHz - 802.11a/b/g/n</p><p><strong>Other ports:</strong> 2 x USB2, serial port</p><p><strong>Power:</strong> External PSU</p><p><strong>Management:</strong> Web browser</p><p><strong>Warranty:</strong> 5 years</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fortinet FortiGate 3140B review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/641077/fortinet-fortigate-3140b-review</link>
                                                                            <description>
                            <![CDATA[ The FortiGate 3140B is a feature-laden UTM appliance which comes with a 64GB SSD, 10GbE port and an average throughput of 8.2Gbps. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ddy4ccdjGD11CQHiKBxZY3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MeV4uQ3EXFGP8UqRy8PZCn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Jun 2012 12:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MeV4uQ3EXFGP8UqRy8PZCn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Fortinet FortiGate 3140B - Performance]]></media:description>                                                            <media:text><![CDATA[Fortinet FortiGate 3140B]]></media:text>
                                <media:title type="plain"><![CDATA[Fortinet FortiGate 3140B]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MeV4uQ3EXFGP8UqRy8PZCn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure role="gallery"><figure><img src="https://cdn.mos.cms.futurecdn.net/MeV4uQ3EXFGP8UqRy8PZCn.jpg" alt="Fortinet FortiGate 3140B" /><figcaption>Fortinet FortiGate 3140B</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/VGDdw3kmmGFc2KkwmggNkk.png" alt="Fortinet FortiGate 3140B - Performance" /><figcaption>Fortinet FortiGate 3140B - Performance</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/bDJMDjhf7gpHCAHyeG2uik.png" alt="Fortinet FortiGate 3140B - Reporting" /><figcaption>Fortinet FortiGate 3140B - Reporting</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/mWNCHvxZw5StkSdRCKof4H.png" alt="Fortinet FortiGate 3140B - Profiles" /><figcaption>Fortinet FortiGate 3140B - Profiles</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/nJSdgtqZEQkheuPd3fjNKA.png" alt="Fortinet FortiGate 3140B - Dashboard" /><figcaption>Fortinet FortiGate 3140B - Dashboard</figcaption></figure></figure><p>The latest FortiGate 3140B is part of a family of products offering enterprises high performance along with a selection of 10GbE and Gigabit ports.</p><p>As with all FortiGate appliances, the 3410B uses the firm's ASIC-based FortiOS operating system and offers a range of port permutations. You have eight 10GbE SFP ports to the left, ten Gigabit ports in the middle and two more 10GbE SFP ports to the right. The latter port pair links up with Fortinet's FortiASIC-SP2 CPU which provides additional services including IPS signature analysis, application controls and DOS protection.</p><p>The appliance includes a 64GB SSD for high speed web caching, logging, DLP archiving plus quarantining and there's room for three more for a total capacity of 256GB. Standard features start with an SPI firewall plus IPSec and SSL VPNs but the price we've shown includes a full one year security bundle.</p><p>This adds extra security measures comprising IPS, anti-virus, anti-malware, anti-spam, web filtering, P2P app controls plus data leak prevention (DLP). The appliance can also provide centralised management of Fortinet's FortiAP wireless access points.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nJSdgtqZEQkheuPd3fjNKA" name="" alt="Fortinet FortiGate 3140B - Dashboard" src="https://cdn.mos.cms.futurecdn.net/nJSdgtqZEQkheuPd3fjNKA.png" mos="https://cdn.mos.cms.futurecdn.net/nJSdgtqZEQkheuPd3fjNKA.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Fortinet FortiGate 3140B - Dashboard </span></figcaption></figure><p><em>The console's home page provides a dashboard offering plenty of information and options to customise the views using widgets</em></p><h2 id="easy-deployment">Easy deployment</h2><p>An advantage of the FortiGate products is all their security services are developed in-house so there's no reliance on third party providers. Installation is simple as you choose either NAT or transparent modes from the intuitive web interface and for testing we opted for the latter.</p><p>The console's dashboard provides a wealth of information about real-time activity and its use of widgets means it can be customised. These include graphs for traffic history, top applications and sessions, system resources, SSD usage and quick access to the CLI.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mWNCHvxZw5StkSdRCKof4H" name="" alt="Fortinet FortiGate 3140B - Profiles" src="https://cdn.mos.cms.futurecdn.net/mWNCHvxZw5StkSdRCKof4H.png" mos="https://cdn.mos.cms.futurecdn.net/mWNCHvxZw5StkSdRCKof4H.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Fortinet FortiGate 3140B - Profiles </span></figcaption></figure><p><em>A choice selection of UTM profiles can be added to firewall policies and includes versatile web content filtering</em></p><h2 id="utm-profiles">UTM profiles</h2><p>Firewall policies control traffic and services between selected interfaces and port zones. Each can also contain various UTM profiles. For web filtering, Fortinet's own service provides eight main URL categories and nearly eighty subcategories.</p><p>For each category and subcategory you can opt to log, block, allow or warn as well as specify user authentication. Options are also provided for enforcing web usage quotas, activating the Safe Search feature and scanning HTTPS traffic.</p><p>The FortiGuard anti-spam measures are managed using profiles which define the mail protocols to scan and how to handle spam. We've always found this service to be very efficient, delivering detection rates of up to 99 per cent during testing with low false positives.</p><p>Anti-virus profiles define which protocols are to be scanned and gives the option of removing or quarantining viruses. DLP sensor profiles are used to look out for file types, file sizes, fingerprints, conditions or expressions such as credit card numbers.</p><p>Vulnerability scans use asset definitions based on IP addresses and ranges and can include Windows and Unix authentication details. Scans can be run on-demand or to a schedule and the results viewed from the web console.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bDJMDjhf7gpHCAHyeG2uik" name="" alt="Fortinet FortiGate 3140B - Reporting" src="https://cdn.mos.cms.futurecdn.net/bDJMDjhf7gpHCAHyeG2uik.png" mos="https://cdn.mos.cms.futurecdn.net/bDJMDjhf7gpHCAHyeG2uik.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Fortinet FortiGate 3140B - Reporting </span></figcaption></figure><p><em>Fortinet's FAMS is worth getting for its extensive hosted reporting services</em></p><p>Fortinet claims a high performance for the 3140B and for testing we hooked it up to the lab's Ixia XM2 chassis equipped with two Xcellon-Ultra NP load modules. We connected a 10GbE port to each load module and ran a range of HTTP throughput tests for IPS and anti-virus profiles.</p><p>With the default IPS profile enabled, we recorded an average throughput of 8.2Gbps for 128KB web page sizes which confirmed Fortinet's IPS rate. With IPS turned off and the anti-virus proxy profile enabled we recorded a throughput of 1.8Gbps for 128KB web pages which increased to 2.35Gbps for a 256KB page size.</p><p>Fortinet also offers flow based virus scanning which is less effective but faster than the proxy mode as it only uses the IPS engine to scan files without buffering them. With this profile selected, the Ixia system recorded higher throughputs of 5.6Gbps for 64KB pages and 8.6Gbps for 128KB pages.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VGDdw3kmmGFc2KkwmggNkk" name="" alt="Fortinet FortiGate 3140B - Performance" src="https://cdn.mos.cms.futurecdn.net/VGDdw3kmmGFc2KkwmggNkk.png" mos="https://cdn.mos.cms.futurecdn.net/VGDdw3kmmGFc2KkwmggNkk.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Fortinet FortiGate 3140B - Performance </span></figcaption></figure><p><em>The lab's Ixia performance testing system reported a tidy 8.2Gbps throughput with IPS enabled</em></p><h2 id="reporting-features">Reporting features</h2><p>Impressive logging and reporting features are provided by the FortiOS software and these can be used to create detailed web reports on areas such as bandwidth, web, email, application and VPN usage. The software can generate graphical reports revealing the top blocked sites, bandwidth hogging users and the most used applications. These findings can be exported to PDFs allowing them to be stored or emailed to colleagues.</p><p>For more detailed reporting we recommend the optional FortiGuard Analysis and Management Service (FAMS). The appliance can be set to upload selected logs regularly to your account on this hosted service which are used to present an extensive range of reports on all areas of user activity.</p><p>Overall, we found the FortiGate 3140B delivers an unbeatable range of security measures making it an ideal single product for enterprise network security. Performance is good with a high 10GbE port count, it's a cinch to deploy and reporting features are extensive.</p><h2 id="verdict-8">Verdict</h2><p>Fortinets’ strengths lie in its ability to pack more security measures into its appliances than anyone else and the FortiGate 3410B is no exception. It’s simple to deploy and our Ixia tests show it delivers the claimed throughput performance. For enterprises to get the best value from this appliance it needs to be deployed as a complete replacement for existing security equipment.</p><p>Chassis: 2U rack CPU: Fortinet FortiASIC Network, Content and Security processors Network: 10 x 10GbE SFP, 10 x Gigabit SFP Storage: 64GB SATA SFF SSD (max. 4) Ports: 2 x USB, RJ-45 console, 2 x Gigabit management Power: 2 x 300W hot-plug supplies Management: Web browser, CLI Software: Fortinet FortiOS 4.0 Other: 2 x 10GBase-SR SFPs included</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gartner: Worldwide UTM revenues top $1bn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/640219/gartner-worldwide-utm-revenues-top-1bn</link>
                                                                            <description>
                            <![CDATA[ Analyst hails firewall refresh cycles and growing interest from SMB and mid-sized firms for market growth. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2M9qFQ36FgdRdeWSBxaVMr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uGyv4FGqDCEVLq4kexyB3N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Apr 2012 14:07:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uGyv4FGqDCEVLq4kexyB3N-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graph]]></media:description>                                                            <media:text><![CDATA[Graph]]></media:text>
                                <media:title type="plain"><![CDATA[Graph]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uGyv4FGqDCEVLq4kexyB3N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The value of the worldwide unified threat management (UTM) market surpassed the $1bn mark last year, buoyed by the growing demand for the technology in North America and Western Europe.</p><p>According to figures released by analyst Gartner, global revenues for the UTM market rose from $972m in 2010 to $1.2bn last year.</p><p>Lawrence Pingree, research director at Gartner, said the market's growth could be attributed to firewall refresh cycles and the SMB market's growing interest in UTM.</p><p>"Many UTM vendors delivered new products during the last several years with some vendors performing product refresh efforts to their UTM portfolios," he said.</p><p>"Others worked to expand their small or midsize business (SMB) and wireless UTM offerings."</p><p>North America emerged as the largest consumer of the products, accounting for nearly half of the UTM market's worldwide revenues ($431 million) last year. This was up 15.5 per cent in 2010 when revenues peaked at $373 million.</p><p>Gartner said UTM's success in North America had been driven by the payment card industry's demand for firewalls and intrusion prevention products, and the growing interest of mid-sized firms in protecting themselves against network-based attacks.</p><p>Western Europe is the second-largest market for UTM products, with revenues up from $266 million in 2010 to $310 million last year.</p><p>Meanwhile, the Asia-Pacific UTM market was reportedly the fastest growing, with year-on-year expansion of 31.8 per cent to $204 million.</p><p>The analyst house said the region's growth had been driven by Korean UTM vendor SECUI, who specialises in selling its products there.</p><p>The vendor also grew the most in 2011, with year-on-year revenues up 59 per cent to $52 million.</p><p>Fortinet held on to its position as market leader with 19.6 per cent share and revenues of 228 million.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IBM Pulse 2012: IBM and Toshiba unveil power-savvy business laptos ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/639397/ibm-pulse-2012-ibm-and-toshiba-unveil-power-savvy-business-laptos</link>
                                                                            <description>
                            <![CDATA[ The two tech giants have worked together to create new software to aid power management and security. It'll be included in Toshiba's next-gen enterprise laptops. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x1Lct572RhRYzrW6ciNE9A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hURVzQdArx4aUtye8V73RL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 Mar 2012 20:42:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Maggie Holland ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hURVzQdArx4aUtye8V73RL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IBM Pulse logo]]></media:description>                                                            <media:text><![CDATA[IBM Pulse logo]]></media:text>
                                <media:title type="plain"><![CDATA[IBM Pulse logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hURVzQdArx4aUtye8V73RL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Toshiba has confirmed the next generation of its enterprise-class laptops will feature built-in software designed to better protect data and significantly reduce energy consumption.</p><p>The tech giant's future lineup will come bundled with IBM software, which will reduce power usage by 47 per cent, according to Nori Nakamura, one of Toshiba's managers in its business PC unit, who announced the new partnership at IBM's Pulse event in Las Vegas.</p><p>What's more, the new solution also provides beefed-up security to help prevent sensitive corporate data from falling into the wrong hands.</p><p>"This solution is a core development between Toshiba and IBM and provides users with advanced power management and security," Nakamura said.</p><p>The in-built software blends together IBM's Tivoli Endpoint Manager with Toshiba's BIOS functionality, allowing IT managers to apply their organisations' security and energy policies across their fleet of laptops.</p><p>Security-wise, patch management is handled much more efficiently and in the background, preserving vital network bandwidth for other business uses.</p><p>"As endpoint devices such as laptops proliferate inside and outside an organisation, it's important that the right security and management policies are in place no matter where the device is located," said Danny Sabbah, general manager of IBM's Tivoli software division.</p><p>"IBM software embedded into Toshiba laptops allows organisations to easily oversee these devices to help manage energy efficiency and security of the data that resides on them."</p><p>The new line-up will be available worldwide from the middle of the year, according to Toshiba.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Mac OS X Lion password-changing flaw uncovered ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/636235/mac-os-x-lion-password-changing-flaw-uncovered</link>
                                                                            <description>
                            <![CDATA[ Changing passwords looks awfully simple for anyone who has acquired access to a Mac OS X Lion machine. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">abXca6bB8PRnM3UJ5VPvWC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YXVo7fYB3aJLwDoQPPVJV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Sep 2011 10:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YXVo7fYB3aJLwDoQPPVJV-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password]]></media:description>                                                            <media:text><![CDATA[Password]]></media:text>
                                <media:title type="plain"><![CDATA[Password]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YXVo7fYB3aJLwDoQPPVJV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A flaw in <a href="https://www.itpro.com/633994/apple-launches-mac-os-x-lion" target="_blank" data-original-url="https://www.itpro.com/633994/apple-launches-mac-os-x-lion">Apple's new OS</a> lets those with access to a Mac running Lion change passwords without knowing the user's login details, a researcher has claimed.</p><p>In previous versions of the Apple OS, users wanting to change passwords had to enter their login information before making alterations.</p><p>Why crack hashes when you can just change the password directly?</p><p>Now that step is not needed, thanks to insecure permissions in the Mac OS X Lion's local directory service, researcher Patrick Dunstan said, writing on the Defense in Depth <a href="http://www.defenceindepth.net/2011/09/cracking-os-x-lion-passwords.html" target="_blank">blog</a>.</p><p>"Why crack hashes when you can just change the password directly?" Dunstan said. "It appears Directory Services in Lion no longer requires authentication when requesting a password change for the current user."</p><p>Dunstan also claimed it was possible to access other users' password hashes and therefore steal their login information.</p><p>In previous versions of Mac OS X, only those with root access were allowed to view so-called shadow files, which contain hashes and salts used to encrypt passwords.</p><p>Although non-root users cannot access the shadow file directly, they can still gain access to information in it by extracting data from the directory services on the OS. All that needs to be done is type in the right command into Terminal to get that information, the researcher claimed.</p><p>"The interesting thing about this? Root privileges are not required," Dunstan added. "All users on the system, regardless of privilege, have the ability to access the ShadowHashData attribute from any other user's profile."</p><p>A brute force attack could be used to crack passwords once the hash and salt are acquired.</p><p>Comments on the blog showed some claiming to have exploited the flaw successfully, whilst others were unable to do so.</p><p>At the time of publication, <a href="https://www.itpro.com/636082/apple-motorola-has-no-legal-standing-in-two-cases" target="_blank" data-original-url="https://www.itpro.com/636082/apple-motorola-has-no-legal-standing-in-two-cases">Apple</a> had not responded to a request for comment on the alleged vulnerability.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Netgear ProSecure UTM150 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/636043/netgear-prosecure-utm150</link>
                                                                            <description>
                            <![CDATA[ Netgear is better known for its network routers and switches than its security appliances. Karl Wright takes a look under the hood of the ProSecure UTM150 to see if the new unified threat management appliance is right for you. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">f6YqxmTFrxn9Ahz6pTF7PQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fSB6JyZrXNUSjfbdri6ga9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Sep 2011 13:44:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Karl Wright ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fSB6JyZrXNUSjfbdri6ga9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Using the content blocking options you can easily prevent all or only certain users from viewing particular categories of con]]></media:description>                                                            <media:text><![CDATA[The Netgear ProSecure UTM150]]></media:text>
                                <media:title type="plain"><![CDATA[The Netgear ProSecure UTM150]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fSB6JyZrXNUSjfbdri6ga9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure role="gallery"><figure><img src="https://cdn.mos.cms.futurecdn.net/fSB6JyZrXNUSjfbdri6ga9.jpg" alt="The Netgear ProSecure UTM150" /><figcaption>The Netgear ProSecure UTM150</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/USNJbHeoTYmCE7mfGjTFz.jpg" alt="Using the content blocking options you can easily prevent all or only certain users from viewing particular categories of con" /><figcaption>Using the content blocking options you can easily prevent all or only certain users from viewing particular categories of con</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/aeV2GaeqaN3tBwdK3ad3tJ.jpg" alt="By segmenting devices on the LAN into groups, by IP address, it’s easy to apply different settings to different users, or gro" /><figcaption>By segmenting devices on the LAN into groups, by IP address, it’s easy to apply different settings to different users, or gro</figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/xvufeq5teWCrNEDRZFGuH9.jpg" alt="The UTM handles https communications by inserting itself between the secure site and the client on your network, checking whe" /><figcaption>The UTM handles https communications by inserting itself between the secure site and the client on your network, checking whe</figcaption></figure></figure><p>The Netgear UTM 150 is a unified threat management device: an internet gateway, with a built-in stateful firewall and subscription web and email filtering. It sits between your broadband connection, or connections, and the internal network.</p><p>Set up is instantaneous; simply plug in your broadband device. The UTM150 has four WAN ports: so if one internet connection goes down, it switches immediately to a backup. Alternatively, you can configure it to load balance across all available bandwidth, helping to get the highest speeds and best return on investment from your broadband.</p><p>The firewall's basic configuration is to allow all outgoing connections, but only let incoming connections that have been requested by a client behind the firewall. You can easily customise this using the web interface, allowing or blocking specific services. We tried blocking and allowing a range of services, for the whole network, for certain device groups on the network and by schedule with perfect results every time.</p><p>Web- and email- and spam-filtering only works when you subscribe to the online filter services bundled with the product. A year's free subscription is included with the UTM, after that you pay $1062 (approximately 660) for a 1-year account and $2710 (approximately 1,685) for a 3-year account.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="USNJbHeoTYmCE7mfGjTFz" name="" alt="Using the content blocking options you can easily prevent all or only certain users from viewing particular categories of con" src="https://cdn.mos.cms.futurecdn.net/USNJbHeoTYmCE7mfGjTFz.jpg" mos="https://cdn.mos.cms.futurecdn.net/USNJbHeoTYmCE7mfGjTFz.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Using the content blocking options you can easily prevent all or only certain users from viewing particular categories of con </span></figcaption></figure><p>Content filtering worked well, but sometimes threw up false positives. It's easy enough to remedy using whitelists though.</p><p>URL filtering worked all the time, without any exception. Content filtering worked well, but sometimes threw up false positives. For instance, it classified an online human resources booking system as a "computers and technology" site, which was therefore blocked under the filtering scheme we had set up. Overall, however, the number of false positives was low, and it's easy to put a site on a whitelist if you want to make an exception for it but still keep your general rule.</p><p>Email antivirus filtering efficiently stripped out .exe and other suspicious files, as we'd specified, and scanned all outgoing messages without noticeably delaying their being sent. We did, however, have to remove the [MALWARE FREE] notice that the device, by default, adds to all outgoing mails it scans.</p><p>As well as being a switch, internet gateway and a security appliance, the UTM150 is also a VPN gateway, with support for both IPSEC and browser-based SSL VPNs. Setup is relatively easy, using the built-in VPN wizard. The SSL VPN is particularly useful, allowing users to access the local network from any computer with an internet connection and a browser, no client software required. We used the VPN to remotely access our network over the course of a week, working remotely with all the machines on our server accessing files and taking over some of the systems using Remote Desktop Connection. The VPN connection was reliable throughout.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aeV2GaeqaN3tBwdK3ad3tJ" name="" alt="By segmenting devices on the LAN into groups, by IP address, it’s easy to apply different settings to different users, or gro" src="https://cdn.mos.cms.futurecdn.net/aeV2GaeqaN3tBwdK3ad3tJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/aeV2GaeqaN3tBwdK3ad3tJ.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">By segmenting devices on the LAN into groups, by IP address, it’s easy to apply different settings to different users, or gro </span></figcaption></figure><p>By segmenting devices on the LAN into groups, by IP address, it's easy to apply different settings to different users, or groups of users, on your network.</p><p>One of the things we liked most about the UTM150 was its flexibility. With it, you can block or allow access to content for everyone on your network or for certain groups only. In the Network Configuration screen, you simply arrange devices by IP address into groups. Then apply to each group the appropriate level of content filtering. You can also apply different schedules to different groups, for instance allowing a group of machines restricted access to the internet during the week. but unrestricted at the weekend. This level of specificity was very useful, making it possible to prevent some users on our network gaming and using certain websites except at the weekends.</p><p>We did have trouble with the appliance's handling of SSL certificates. Even when we had installed the UTM's root certificate in our client browsers and told the UTM to trust some of our test sites' certificates, we still had problems accessing the sites, with some content not displaying properly. There was no reason we could see for this and we couldn't find a way around it.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xvufeq5teWCrNEDRZFGuH9" name="" alt="The UTM handles https communications by inserting itself between the secure site and the client on your network, checking whe" src="https://cdn.mos.cms.futurecdn.net/xvufeq5teWCrNEDRZFGuH9.jpg" mos="https://cdn.mos.cms.futurecdn.net/xvufeq5teWCrNEDRZFGuH9.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">The UTM handles https communications by inserting itself between the secure site and the client on your network, checking whe </span></figcaption></figure><p>Managing access to SSL sites can be time consuming.</p><p>Thankfully, the web interface itself is fairly well organised, so even when you can't remember where something is, you tend to find it fairly quickly because it's in the place you'd logically expect it to be. For larger networks there's also LDAP integration particularly useful for creating VPN users. You can also use the device's own database, but you need to make sure that you don't try and associate the same account with more than one function. For instance, if you have an IT admin who's also a VPN user, that person will need two user accounts.</p><p>Compared to a conventional router, the UTM150 is expensive. But for that price, you get the built-in switch, the firewall and the web and email filtering capabilities. Of course, you don't get integrated wireless. We used a Netgear WNAP320 wireless access point during our test. Given, however, the free bundling of the filtering services for the first year and the good price thereafter (a subscription to the Spamhaus spam blacklist alone costs around $370 a year) the UTM150 is still good value.</p><p><a href="https://www.itpro.com/636043/netgear-prosecure-utm150" target="_blank" data-original-url="https://www.itpro.com/636043/netgear-prosecure-utm150">So what's our verdict?</a></p><h2 id="verdict-9">Verdict</h2><p>It's not perfect, but the Netgear ProSecure UTM150 provides comprehensive cover against the security threats faced by most small business networks, giving you the tools you need to manage both your users and the risk that comes with exposing your systems to the internet.</p><p>Chassis: Desktop Performance: 400Mb/s firewall; 130Mb/s UTM Memory: 1GB RAM Network: 8 x Gigabit Ethernet (4 x WAN, 4 x LAN) Wireless: None Ports: 1 x USB2 Management: Web browser</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Which? says Nationwide is safest online bank ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/635674/which-says-nationwide-is-safest-online-bank</link>
                                                                            <description>
                            <![CDATA[ Nationwide scores highly, but no bank is able to protect from all forms of fraud. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ffud1dZ4XHNrtBgQDwz3Ao</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oUEyyepikH63VLMocaXgpg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Aug 2011 11:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oUEyyepikH63VLMocaXgpg-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bank security]]></media:description>                                                            <media:text><![CDATA[Bank security]]></media:text>
                                <media:title type="plain"><![CDATA[Bank security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oUEyyepikH63VLMocaXgpg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nationwide has been ranked as the safest online bank, ahead of Natwest in second and Barclays in third place.</p><p>Which? gave Nationwide an overall <a href="https://www.itpro.com/635671/facebook-issues-guide-to-security" target="_blank" data-original-url="https://www.itpro.com/635671/facebook-issues-guide-to-security">security</a> score of 69 per cent, six per cent ahead of Natwest and seven points in front of Barclays.</p><p>Which? tested banks' security by recruiting 12 volunteers, who tested the banks' customer-facing security measures such as passwords and preventative measures for high risk tasks. They also used a keylogger to see how much information could be captured.</p><p>We were alarmed to find significant flaws in the online security of some of the UK's biggest banks.</p><p>Nationwide scored well in most areas, apart from in allowing users to visit other sites whilst banking online. This could lead to users downloading viruses during banking session, and is dangerous if they share computers with others.</p><p>The results showed that whilst no bank was so bad users should stop banking online altogether, none were able to protect from all fraud.</p><p>Some major banks were found low down the list as well, with Lloyds in eight, Santander 10th and Halifax 11th. The latter bank was described as having "surprisingly poor" security.</p><p>The smallest provider tested, Norwich & Peterborough Building Society, came in last with the weakest security.</p><p>"We were alarmed to find significant flaws in the online security of some of the UK's biggest banks. For example, Santander was the only bank to ask for a full password, which could leave accounts vulnerable to keyloggers, while Halifax scored poorly for logout security," said Which? executive director Richard Lloyd.</p><p>"With so many of us doing our banking online these days, it's important that banks' security is up to scratch."</p><p>Bank users aren't just at risk from lax provider behaviour. Earlier this month, 800 records with bank account details were <a href="https://www.itpro.com/635422/hundreds-of-bank-account-details-left-at-london-pub" target="_blank" data-original-url="https://www.itpro.com/635422/hundreds-of-bank-account-details-left-at-london-pub">left on an unencrypted USB stick in a London pub</a> by a housing company contractor.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malicous spam hits ‘epic’ levels ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/635623/malicous-spam-hits-epic-levels</link>
                                                                            <description>
                            <![CDATA[ This month has seen a serious rise in malicious spam, according to M86 data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tkUjeGcb2wfJmMNo9PoQDd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/va9rAh3s4efjheZytzv7Fk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Aug 2011 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/va9rAh3s4efjheZytzv7Fk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spam]]></media:description>                                                            <media:text><![CDATA[Spam]]></media:text>
                                <media:title type="plain"><![CDATA[Spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/va9rAh3s4efjheZytzv7Fk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/633604/spam-down-65-per-cent-year-on-year" target="_blank" data-original-url="https://www.itpro.com/633604/spam-down-65-per-cent-year-on-year">spammers</a> have returned with a vengeance as malicious spam hit "epic" levels in August, according to security experts.</p><p>M86 Security said it saw a "huge surge" in malicious spam which has far exceeded anything it has seen in the past two years.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9caCGkrqNCEaQoKBDpNU2k" name="" alt="Spam chart" src="https://cdn.mos.cms.futurecdn.net/9caCGkrqNCEaQoKBDpNU2k.jpg" mos="https://cdn.mos.cms.futurecdn.net/9caCGkrqNCEaQoKBDpNU2k.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The majority of the spam was put out by the notorious Cutwail botnet, with the Festi and Asprox botnets showing themselves to be significant contributors too.</p><p>Last week, 13 per cent of the overall spam volume consisted of malicious spam, marking an "unusual" jump, according to M86. On Monday, that proportion increased to 24 per cent.</p><p>"Four of the campaigns, which we identified as originating from the Cutwail botnet are mostly recycled spam themes Fedex, credit card, changelogs and invoices," M86 explained in a <a href="http://labs.m86security.com/2011/08/massive-rise-in-malicious-spam" target="_blank">blog post</a>.</p><p>"The malware is attached within a compressed ZIP archive and is a Trojan that downloads additional malware including Fake AV, SpyEye and the Cutwail spambot itself."</p><p>Spammers used typical tricks, such as telling users there credit card had been blocked, promising more information in an attached file. Anyone opening the attachment would risk infecting their machines.</p><p>It seems spammers have returned from a holiday break and are enthusiastically back to work.</p><p>Other spam offered rebates on purported accidental charges from hotels, as well as messages appearing to confirm UPS deliveries.</p><p>"This is an epic amount of malicious spam. After multiple recent botnet takedowns, cyber criminal groups remain resilient, clearly looking to build their botnets and distribute more fake AV in the process," M86 added.</p><p>"It seems spammers have returned from a holiday break and are enthusiastically back to work."</p><p>Spam had seen a significant drop earlier this year, largely thanks to a <a href="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown" target="_blank" data-original-url="https://www.itpro.com/632014/microsoft-takes-credit-for-rustock-shutdown">Microsoft-led operation taking on the Rustock super spammer botnet</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Panda risks labelling LulzSec stupid ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/634729/panda-risks-labelling-lulzsec-stupid</link>
                                                                            <description>
                            <![CDATA[ Blasting hacktivist groups can backfire, but that hasn't stopped Panda Security having a pop at LulzSec and Anonymous. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5eDcTygQz3j9YtacxejLY1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JG4XL66YZDznWsxLYCyE46-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Jul 2011 10:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JG4XL66YZDznWsxLYCyE46-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker]]></media:description>                                                            <media:text><![CDATA[Hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JG4XL66YZDznWsxLYCyE46-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Panda Security has attacked LulzSec's hacking activities, saying the group was a proponent of "stupidism" rather than "hacktivism."</p><p>In past cases, when so called hacktivist groups receive criticism, they have responded by fighting fire with fire.</p><p>If you took the most irresponsible and brainless members of Anonymous and put them all together, they would be considered the most refined gentlemen compared to LulzSec.</p><p>When security firm HBGary claimed it had gained the identities of a number of key members of Anonymous, the <a href="https://www.itpro.com/631042/anonymous-empire-strikes-back-against-hbgary" target="_blank" data-original-url="https://www.itpro.com/631042/anonymous-empire-strikes-back-against-hbgary">hacktivist group struck back</a> by stealing tens of thousands of emails and posting them online.</p><p>In its cyber crime report for the second quarter of 2011, Panda chose to criticise LulzSec and the way it operates.</p><p>"If you took the most irresponsible and brainless members of Anonymous and put them all together, they would be considered the most refined gentlemen compared to LulzSec," Panda said.</p><p>Panda said LulzSec suffered from a "lack of coherence," claiming the hack of Sega was a case in point. In that particular episode, LulzSec was linked to the attack, but subsequently came out to say it was not responsible and offered to help find the perpetrators.</p><p>"It seems pretty clear that Lulzsec thinks it is perfectly OK to commit a crime as long as they are the perpetrators, otherwise it is clearly wrong and the competitor' must be destroyed," Panda said.</p><p>LulzSec has now disbanded, but Panda had some harsh words for fellow hacktivist group Anonymous too.</p><p>"It seems that the only way the Anonymous group has to protest is by committing illegal acts. However, if the members of the group were smart enough, they would realize that their constant breaking of the law undermines the legitimacy of their protests," the company added.</p><p>"Moreover, they claim that their activities are 'peaceful protests', despite their actions are purposefully enacted to cause economic loss and completely illegal. They say they represent everyone's best interest' but are not brave enough to appear publicly, hiding instead behind their pseudonyms."</p><p>Last month, <a href="https://www.itpro.com/634132/anonymous-warns-of-spain-arrest-revenge" target="_blank" data-original-url="https://www.itpro.com/634132/anonymous-warns-of-spain-arrest-revenge">Anonymous responded to arrests in Spain</a> of its alleged members by hitting the website of the national police force with a distributed denial of service (DDoS) attack.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IMF suffers ‘major’ data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/634147/imf-suffers-major-data-breach</link>
                                                                            <description>
                            <![CDATA[ The International Monetary Fund (IMF) confirms it was hacked, with suggestions the attack was state sponsored. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ubRrC3i5BpJVQffk2FfK4P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/khfmrCJpY9jTFcKRum4Tr9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jun 2011 10:42:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/khfmrCJpY9jTFcKRum4Tr9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber crime]]></media:description>                                                            <media:text><![CDATA[Cyber crime]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber crime]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/khfmrCJpY9jTFcKRum4Tr9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The International Monetary Fund (IMF) has admitted it was hit by a serious, sophisticated cyber attack recently.</p><p>The IMF told employees about the compromise last Wednesday, but did not make any public announcement, the <a href="http://www.nytimes.com/2011/06/12/world/12imf.html?_r=2&hp" target="_blank">New York Times</a> reported.</p><p>One official revealed the <a href="https://www.itpro.com/634090/ico-slaps-surrey-county-council-with-120000-fine" target="_blank" data-original-url="https://www.itpro.com/634090/ico-slaps-surrey-county-council-with-120000-fine">data breach</a> occurred over the past few months, starting before former managing director and French politician Dominique Strauss-Kahn was arrested on sexual assault charges.</p><p>"We are investigating an incident, and the fund is fully functional," said IMF spokesperson David Hawley.</p><p>The hackers reportedly attempted to establish a fake "digital insider presence."</p><p>The IMF, which has not revealed any further details on the nature of the attack, holds plenty of important data, including market information and communications between world leaders.</p><p>State sponsored?</p><p>Stolen data included documents and emails, according to <a href="http://www.businessweek.com/news/2011-06-13/imf-state-backed-cyber-attack-follows-hacks-of-atomic-lab-g-20.html" target="_blank">Bloomberg</a>, citing a security expert who was "familiar with the incident."</p><p>The expert, who wished to remain anonymous because he was not authorised to speak on the subject, said the intrusion was state sponsored.</p><p>"The IMF has revealed very little about this incident but with the FBI now involved, and the World Bank cutting its network connection to the organisation, we can safely assume that the attack is of a serious nature," said Ross Brewer, vice president and managing director for international markets at LogRhythm.</p><p>"As yet another high profile organisation falls victim to a data breach we are once again forced to question whether it is actually possible to protect data from hackers. The sheer number of headline grabbing incidents suggests that attempts to prevent cyber attacks from occurring in the first place may be ineffective and that a new approach is required."</p><p>Mark Darvill, director at trusted security firm, AEP Networks, said the attack was "of significant concern."</p><p>"The attempt to establish a fake "digital insider presence," whether it is another state or a malicious individual, needs to be looked at extremely carefully," Darvill added.</p><p>"Once something is digitally signed', it is essentially assumed legitimate and given roaming rights. The possibility of a large-scale cyber attack disrupting our power, finance, security and governmental systems is becoming more and more of a possibility in today's world."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous warns of Spain arrest revenge ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/634132/anonymous-warns-of-spain-arrest-revenge</link>
                                                                            <description>
                            <![CDATA[ Spanish police arrest three men suspected of being involved in the Anonymous hacking group, which has told the world to expect a response. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fBXaQDDwGGvahaksPaGRk5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UqBMn5w5q57nyE29LmgjxM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Jun 2011 17:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UqBMn5w5q57nyE29LmgjxM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Anonymous]]></media:description>                                                            <media:text><![CDATA[Anonymous]]></media:text>
                                <media:title type="plain"><![CDATA[Anonymous]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UqBMn5w5q57nyE29LmgjxM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anonymous has warned about repercussions following arrests of three individuals suspected of being key members of the hacking group.</p><p>Arrests of the unnamed men were made in three Spanish cities - Barcelona, Valencia and Almeria - earlier this week.</p><p>AnonOps, the hacking group, referencing events in Spain, simply wrote "Expect us" on both a <a href="http://anonops.blogspot.com/2011/06/v-for-spain.html" target="_blank">blog</a> post and a <a href="https://twitter.com/#!/anonops" target="_blank">Twitter</a> status update.</p><p>Spain's Technological Investigation Brigade (BIT) alleged the men had operated a cell of Anonymous, helping run attacks against notable firms like Sony as well as on websites run by Governments of various nations, including Egypt and Iran.</p><p>BIT also posted images on Twitter of IRC conversations appearing to show plans to attack Spanish police websites and the electoral board with DDoS attacks.</p><p><a href="https://www.itpro.com/630424/police-make-anonymous-arrests" target="_blank" data-original-url="https://www.itpro.com/630424/police-make-anonymous-arrests">Arrests of people suspected of Anonymous involvement</a> have been made across the world, including in the UK.</p><p>How long is it going to take before they retaliate? It's not if, but when.</p><p>On previous occasions when Anonymous has been targeted, it has responded by fighting fire with fire.</p><p>When security firm HBGary said it had acquired details on senior members of the hacking collective, <a href="https://www.itpro.com/631042/anonymous-empire-strikes-back-against-hbgary" target="_blank" data-original-url="https://www.itpro.com/631042/anonymous-empire-strikes-back-against-hbgary">Anonymous acted ferociously by hacking the company</a> and dumping tens of thousands of corporate emails on the web.</p><p>Luis Corrons, technical director of PandaLabs, said it was just a matter of time before Anonymous would respond.</p><p>"How long is it going to take before they retaliate? It's not if, but when," Corrons told <em>IT PRO</em>.</p><p>"They usually react in the same way, so DDoS against who? Well, the website of the Spanish police probably."</p><p>The arrests came thanks to legal changes in Spain made in December last year, which made DDoS attacks illegal in the country, Corrons said.</p><p>"There is a lack of law in some fields, especially in cyber security," Corrons added.</p><p>As for how to deal with hacking groups like Anonymous and suspected spin off LulzSec, there is no consensus in the industry.</p><p>"The security industry is really worried," Corrons added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GhostMarket cyber crime teens sentenced ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/633547/ghostmarket-cyber-crime-teens-sentenced</link>
                                                                            <description>
                            <![CDATA[ The teenagers hacked a range of online casinos, betting companies and web hosting firms. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2NGPwuVMebozLk11h5iGmy</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ivBNXPhA6cPZLZZrruNpNo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 May 2011 14:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ivBNXPhA6cPZLZZrruNpNo-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber crime]]></media:description>                                                            <media:text><![CDATA[Cyber crime]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber crime]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ivBNXPhA6cPZLZZrruNpNo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two British teenagers involved in the GhostMarket <a href="https://www.itpro.com/633496/osborne-treasury-hammered-by-hackers" target="_blank" data-original-url="https://www.itpro.com/633496/osborne-treasury-hammered-by-hackers">cyber crime</a> forum have been sentenced for a variety of offences.</p><p>Brighton residents Zachary Woodham, 19, and Louis Tobenhouse, 18, were arrested last year following an investigation by the Metropolitan Police Service's Police Central e-Crime Unit (PCeU).</p><p>Woodham, currenly a law student at Sussex University, received a suspended prison sentence of 18 months imprisonment and 360 hours of community service. Tobenhouse was slapped with 400 hours of unpaid community work.</p><p>Woodham, who went by the alias Colonel Root, hacked into a web hosting company named Punkyhosting, eventually causing it to cease trading.</p><p>The youngster even left a taunting email to the firm boasting about his actions, but the hack was to land him in trouble.</p><p>Once the offence came to the attention of PCeU, the police discovered a list of criminal activities Woodham had been involved in. Further inquiries implicated Tobenhouse's involvement too.</p><p>The PCeU discovered the pair had infiltrated a number of online casinos and betting companies, as well as other web hosting firms, acquiring thousands of credit card details.</p><p>Woodham used the details partly to pay for access to a number of premium rate chat lines which he owned, thereby earning him a tidy profit.</p><p>As for their GhostMarket work, Woodham and Tobenhouse posted tutorials on the site, providing tips on hacking and how to avoid capture.</p><p>In March, <a href="https://www.itpro.com/631594/cyber-crime-teens-jailed-in-ghostmarket-bust" target="_blank" data-original-url="https://www.itpro.com/631594/cyber-crime-teens-jailed-in-ghostmarket-bust">four individuals were given prison sentences for their involvement in GhostMarket</a>. Two of them were teenagers.</p><p>"Woodham and Tobenhouse chose to abuse their computer skills causing a considerable amount of financial loss and anxiety to a number of innocent people," said Detective Constable Stuart Hosking of the PCeU.</p><p>"Woodham in particular has shown himself to be a vindictive hacker with no sign of remorse towards any of his victims."</p><p>Those who want to get into the IT industry may want to keep in mind what Tobenhouse said on his arrest: "I will never get a job in IT now."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sophos buys Astaro in hardware play ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/633283/sophos-buys-astaro-in-hardware-play</link>
                                                                            <description>
                            <![CDATA[ The UK-based security firm makes a security hardware play in buying Astaro. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dxvTm4hrAJTx23v9DEvEWi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UmfLfq7gbzZ57so3UjuSiM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 May 2011 14:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UmfLfq7gbzZ57so3UjuSiM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sophos]]></media:description>                                                            <media:text><![CDATA[Sophos]]></media:text>
                                <media:title type="plain"><![CDATA[Sophos]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UmfLfq7gbzZ57so3UjuSiM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sophos has agreed to acquire network security company Astaro as it looks to move into the appliance market.</p><p>Astaro offers unified threat management boxes, which bring together a range of protection capabilities, including firewall, intrusion prevention and URL blocking.</p><p>The terms of the deal announced today were undisclosed.</p><p>"The combination of Astaro's comprehensive portfolio of network security solutions alongside our endpoint, mobile, and email and web threat and data protection capabilities will enable us to continue to deliver on our vision of providing complete security without complexity wherever the user and company data resides," said Steve Munford, chief executive (CEO) at Sophos.</p><p>Astaro enjoyed 30 per cent year-on-year growth in 2010.</p><p>Sophos believes the acquisiton will cater to businesses' desire for "coordinated protection and policy between endpoint and network."</p><p>"Demand for network security solutions with more comprehensive and high-quality protection is accelerating fast, and yet companies are struggling with the complexity of multiple security solutions to serve these needs," stated Jan Hichert, Astaro CEO.</p><p>"Together, we will deliver to customers the ability to apply consistent security and web and application controls regardless of where the user is or where the network boundary may lie."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Second Sony breach hits 25 million users ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/633157/second-sony-breach-hits-25-million-users</link>
                                                                            <description>
                            <![CDATA[ A breach on Sony's Online Entertainment arm, separate from the PSN hack, sees 25 million customers' data placed in danger. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bXWo2yJT6vCR4BYrCLtNLV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w7ozh78SWuKWndEVpkq2yj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 May 2011 11:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w7ozh78SWuKWndEVpkq2yj-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Sony]]></media:description>                                                            <media:text><![CDATA[Sony]]></media:text>
                                <media:title type="plain"><![CDATA[Sony]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w7ozh78SWuKWndEVpkq2yj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sony has confirmed a hack on its Sony Online Entertainment (SOE) division may have seen personal data of around 24.6 million users stolen.</p><p>The revelation of the second hack came after Sony recently apologised for another compromise affecting 77 million Playstation Network (PSN) customers.</p><p>SOE, an online gaming network like PSN but for PC gamers, was shut down as soon as the company became aware of the <a href="https://www.itpro.com/632047/data-breach-cost-hits-19-million" target="_blank" data-original-url="https://www.itpro.com/632047/data-breach-cost-hits-19-million">data breach</a>, it said today.</p><p>Sony, which came under fire for not being quicker in notifying customers of the PSN breach, said it was "making this disclosure as quickly as possible after the discovery of the theft."</p><p>Sony said the SOE hack may have taken place on 16 and 17 April before the PSN attacks.</p><p>Financial data was compromised as hackers were able to steal 2,700 credit or debit card numbers and 10,700 direct debit records of non-US SOE customers from "an outdated database from 2007."</p><p>Other data at risk included names, addresses, telephone numbers, email addresses, gender, date of birth, login ID and hashed passwords.</p><p>Unlike with the PSN hack, Sony did not confirm credit card numbers of SOE customers were encrypted.</p><p>The total number of Sony customers affected now surpasses 100 million, which F-Secure chief research officer Mikko Hypponen said "must be some sort of a record."</p><p>"This is pretty big. For example, we have scores of employees at F-Secure who are affected," Hypponen said in a <a href="http://www.f-secure.com/weblog/archives/00002148.html" target="_blank">blog</a> post.</p><p>Sophos senior security advisor Chester Wisniewski was shocked the data was taken from an outdated database.</p><p>"It is just unfortunate that Sony had not taken a few preventative measures to be sure our information was safe," Wisniewski said on a <a href="http://nakedsecurity.sophos.com/2011/05/03/sony-admits-breach-larger-than-originally-thought-24-5-million-soe-users-also-affected/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+nakedsecurity+%28Naked+Security+-+Sophos%29" target="_blank">blog</a>.</p><p>"It is important to remember that Sony is a victim as well, not just the 101.5 million customers whose personal information have been disclosed. Malicious attacks like this are a serious crime."</p><p>This week should see the return of PSN, as Sony announced it will begin a phased restoration by region.</p><p>Sony said it has also worked with external firms to introduce "significant security measures," whilst confirming it will create a chief information security officer position at the company.</p><p>On top of improved data protection and encrytption, Sony said it had added automated software monitoring and configuration management to help defend against new attacks.</p><p>Extra services for customers concerned about security were also launched.</p><p>"We have learned lessons along the way about the valued relationship with our consumers," said Kazuo Hirai, executive deputy president at Sony.</p><p>"We will be launching a customer appreciation programme for registered consumers as a way of expressing our gratitude for their loyalty during this network downtime, as we work even harder to restore and regain their trust in us and our services."</p><p>The Playstation creator said it was collaborating with the FBI to investigate the breaches as it works to restore all affected services.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Week in Review: All about the ICO, DEA lives on ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/633028/week-in-review-all-about-the-ico-dea-lives-on</link>
                                                                            <description>
                            <![CDATA[ This week, the ICO dominates security headlines, the judicial review of the Digital Economy Act is thrown out and research shows Apple could be tracking its users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bDQetXuDaXziNvkz2sEoS1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xh66QiWmdbTfWPJ2i9Wkze-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Apr 2011 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xh66QiWmdbTfWPJ2i9Wkze-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Week in review]]></media:description>                                                            <media:text><![CDATA[Week in review]]></media:text>
                                <media:title type="plain"><![CDATA[Week in review]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xh66QiWmdbTfWPJ2i9Wkze-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ICO dominates InfoSec</p><p><a href="https://www.itpro.com/633013/infosec-2011-the-big-themes" target="_blank" data-original-url="https://www.itpro.com/633013/infosec-2011-the-big-themes">InfoSec 2011</a> may have been filled to the brim with vendors and had numerous debates going on, but the centre of the security world's attention fell on the ICO this week.</p><p>A freedom of information (FoI) request showed the organisation had <a href="https://www.itpro.com/632971/ico-fines-less-than-one-per-cent-of-dpa-breaches" target="_blank" data-original-url="https://www.itpro.com/632971/ico-fines-less-than-one-per-cent-of-dpa-breaches">fined less than one per cent of all cases referred to it</a>, and only taken action on a mere 36.</p><p>However, deputy commissioner, David Smith, claimed the <a href="https://www.itpro.com/632977/infosec-2011-ico-wants-larger-fining-powers" target="_blank" data-original-url="https://www.itpro.com/632977/infosec-2011-ico-wants-larger-fining-powers">figures were false</a> and the ICO went back and forth with numerous numbers in a confusing effort to prove its effectiveness.</p><p>An interesting reaction considering it is the ICO which is tasked with ensuring the smooth running of FoI requests</p><p>Digital Economy Act lives on</p><p>Fans of the Digital Economy Act (DEA) were celebrating this week, whilst critics licked their wounds.</p><p><a href="https://www.itpro.com/632974/isps-lose-digital-economy-act-judicial-review" target="_blank" data-original-url="https://www.itpro.com/632974/isps-lose-digital-economy-act-judicial-review">BT and TalkTalk lost their judicial review</a> of the DEA when the presiding judge, Kenneth Parker, deemed the legislation proportionate.'</p><p>Obviously the Government and groups like the BPI were very pleased with the results, but the ISPs and rights groups are already planning their appeal, with the possibility of heading to the European courts.</p><p>We are pretty sure this isn't the last we will hear of the DEA trials.</p><p>We're watching you</p><p>The almighty Apple was revealed to be wielding even more power this week when <a href="https://www.itpro.com/633010/apples-iphone-tracking-users" target="_blank" data-original-url="https://www.itpro.com/633010/apples-iphone-tracking-users">research unveiled its flagship smartphone could track user's movements</a>.</p><p>The study found hidden files within iOS 4, used on the iPhone 4, which stored location data unencrypted on the device and passed it on when syncing with a PC.</p><p>Although Apple's terms and conditions technically say it is allowed to gather user data, the technology within the device has been hidden for some time and the reaction against the so-called tracking' has been negative.</p><p>Maybe more users will scarper off to alternative operating systems but we have a feeling the Apple fan boys are happy with the company knowing what they are doing anytime of day.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Skype Android app flaw places data in danger ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/632911/skype-android-app-flaw-places-data-in-danger</link>
                                                                            <description>
                            <![CDATA[ Skype says it is looking into a flaw which could allow hackers to acquire user data including contacts and instant message logs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8cwgnftXk1hmqjxuabh7i8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WFy2RzxqNo6i4vCw7M2TyX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Apr 2011 14:14:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WFy2RzxqNo6i4vCw7M2TyX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Skype]]></media:description>                                                            <media:text><![CDATA[Skype]]></media:text>
                                <media:title type="plain"><![CDATA[Skype]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WFy2RzxqNo6i4vCw7M2TyX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A vulnerability in the Skype app for Android could be exploited by hackers wanting to get hold of user profile and contact information, according to a report.</p><p>Skype did not encrypt files within the app containing data such as contacts and instant message logs, leaving them accessible to third-party sources, the <a href="http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more" target="_blank">Android Police</a> claimed.</p><p>"Skype mistakenly left these files with improper permissions, allowing anyone or any app to read them. Not only are they accessible, but completely unencrypted," the Android Police said.</p><p>"But how do we find this directory from another app if we don't know the username? Well, Skype stored the username in a static location, we can parse this file, get the username and find the path to Skype's stored data."</p><p>In theory, a rogue developer could create an application so when it is installed on a Skype user's Android phone, it will pilfer the data. The Android Police created a proof of concept to test the theory.</p><p>"This means that a rogue developer could modify an existing application with code from our proof of concept (without much difficulty), distribute that application on the Market, and just watch as all that private user information pours in," the Android Police added.</p><p>"While the exploit can't steal your credit card info, the data it's harvesting is still clearly very private (chat logs linked back to your real name, address, and phone number)."</p><p>Skype said it was aware of the issue and was looking at how to protect its users.</p><p>"It has been brought to our attention that, were you to install a malicious third-party application onto your Android device, then it could access the locally stored Skype for Android files," said Adrian Asher, chief information security officer at Skype, in a <a href="http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html" target="_blank">blog</a> post.</p><p>"We take your privacy very seriously and are working quickly to protect you from this vulnerability, including securing the file permissions on the Skype for Android application."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CEOP unencrypted website places data at risk ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/632689/ceop-unencrypted-website-places-data-at-risk</link>
                                                                            <description>
                            <![CDATA[ CEOP admits a form on its website is unencrypted, but claims no data appears to have been compromised. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8b3Y8VdoCSfDvPRRgP3iea</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YGx9dXCaMphN38rdQCRz6J-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Apr 2011 12:16:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tom Brewster ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YGx9dXCaMphN38rdQCRz6J-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CEOP]]></media:description>                                                            <media:text><![CDATA[CEOP]]></media:text>
                                <media:title type="plain"><![CDATA[CEOP]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YGx9dXCaMphN38rdQCRz6J-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Child Exploitation and Online Protection Centre (CEOP) has admitted its website contained an unencrypted form, potentially placing user data at risk.</p><p>A member of the public was responsible for highlighting the unencrypted form, which related to the CEOP button <a href="https://www.itpro.com/625081/facebook-teams-with-ceop-for-panic-button" target="_blank" data-original-url="https://www.itpro.com/625081/facebook-teams-with-ceop-for-panic-button">integrated into Facebook</a> last year, a spokesperson told <em>IT PRO</em>.</p><p>"The day we were made aware of the problem we rectified it. The issue isn't a problem anymore," the spokesperson said.</p><p>CEOP chief executive (CEO) Peter Davies said the risk "was a hypothetical one."</p><p>"We thank the member of the public who brought this issue to our attention and have rectified the problem so people can continue to report any concerns they have to us, with the reassurance that their report will remain secure," Davies added.</p><p>Despite reassurances no user data appeared to have been taken, the Information Commissioner's Office (ICO) said it would be launching an investigation.</p><p>"We are making enquiries into the circumstances of this alleged breach of the Data Protection Act before deciding what action, if any, needs to be taken," an ICO spokesperson said.</p><p>The CEOP button, which became known as the ClickCEOP panic button, was made live on Facebook in July 2010 after plenty of back and forth between the social network and the campaign group.</p><p>The button offers advice on staying safe online and lets users report any cases of suspected grooming or improper sexual behaviour.</p><p>Although CEOP moved to fix the problem on its own website quickly, anyone with malicious intent and the know-how could hijack a user's unencrypted web session on a non-HTTPS site.</p><p>There has been much talk about the value of HTTPS recently, with <a href="https://www.itpro.com/631954/twitter-boosts-security-with-https" target="_blank" data-original-url="https://www.itpro.com/631954/twitter-boosts-security-with-https">Twitter adding the security layer</a> last month.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Intel’s McAfee acquisition gets EU thumbs up ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/630412/intels-mcafee-acquisition-gets-eu-thumbs-up</link>
                                                                            <description>
                            <![CDATA[ The $7.68 billion deal gets the go ahead from the EU’s competition commission. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sxnCp5fnjz6ZeNxH6UcS6q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/npG4J8K4LNtEkMJ9kvqKyi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Jan 2011 11:11:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/npG4J8K4LNtEkMJ9kvqKyi-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Acqusition]]></media:description>                                                            <media:text><![CDATA[Acqusition]]></media:text>
                                <media:title type="plain"><![CDATA[Acqusition]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/npG4J8K4LNtEkMJ9kvqKyi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="http://www.intel.com" target="_blank">Intel's</a> proposed acquisition of security heavyweight <a href="http://www.mcafee.com" target="_blank">McAfee</a> has been signed off by the European Union (EU).</p><p>The EU's competition commission had "serious concerns" around the issue of competitors in the security space still being able to access Intel's processors, but gave its blessing to the deal after the chip maker pledged to remain open to rival vendors.</p><p>"The commitments submitted by Intel strike the right balance, as they allow preserving both competition and the beneficial effects of the merger," said Joaqun Almunia, the commission's vice president in charge of competition policy.</p><p>"These changes will ensure that vigorous competition is maintained and that consumers get the best result in terms of price, choice and quality of the IT security products."</p><p><a href="https://www.itpro.com/626215/intel-to-acquire-mcafee-in-768-billion-deal" target="_blank" data-original-url="https://www.itpro.com/626215/intel-to-acquire-mcafee-in-768-billion-deal">Intel first announced the acquisition back in August</a>, putting $7.68 billion (4.81 billion) on the table for arguably one of the best known names in the security sector.</p><p>McAfee will become part of the software and services group at Intel, led by Renee James, and bring over about 6,000 employees to the company.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SAP boosts security with SECUDE acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/630022/sap-boosts-security-with-secude-acquisition</link>
                                                                            <description>
                            <![CDATA[ One of the world’s leading business software vendors has added another string to its bow with the acquisition of a security company. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3kj3on6paA9SBS6K7uacmM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eed2c4mCeNN4TDAH6FnafW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Jan 2011 11:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Unified Threat Management]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jennifer Scott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eed2c4mCeNN4TDAH6FnafW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Acqusition]]></media:description>                                                            <media:text><![CDATA[Acqusition]]></media:text>
                                <media:title type="plain"><![CDATA[Acqusition]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eed2c4mCeNN4TDAH6FnafW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/625066/qa-timo-elliott-bi-evangelist-at-sap" target="_blank" data-original-url="https://www.itpro.com/625066/qa-timo-elliott-bi-evangelist-at-sap">SAP</a> has confirmed it is set to acquire Swiss security firm <a href="http://www.secude.com/html/index.php?id=1185" target="_blank">SECUDE</a> for an undisclosed sum.</p><p>The business software leader claimed the move would allow it to incorporate more <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security">security</a> solutions into its own offerings, removing the need for customers to seek out third-party vendors.</p><p>As part of the deal, SAP will take ownership of SECUDE's two flagship products, Secure Login and Enterprise Single Sign-On, and include them in its own portfolio. A basic version of Secure Login will also come as standard in SAP's entire product range at no extra cost.</p><p>A joint statement from the companies confirmed SECUDE would still operate as an independent company and put its attention into its range of data protection products, coming under the FinallySecure brand.</p><p>"I am very pleased that SECUDE's deep expertise as a world leader in the field of security technology will now be available to SAP's vast customer base," said Dr Heiner Kromer, founder and chief executive (CEO) of SECUDE.</p><p>"This deal is a significant one, especially considering the role security plays in ensuring compliance and strict governance for businesses."</p><p>The deal is expected to complete by 1 February, with Secure Login beginning to ship with SAP products in the second quarter of 2011.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>