Skip to content

Presenting The SCADAfence Cloud

A SCADAfence New Feature Report

SCADAfence now offers new advanced services via our cloud. We use the cloud to deliver continuous OT security updates, software upgrades and OT health monitoring.

Continue reading

Cutting Through the Hype of Securing the Zero Trust Edge

What is Zero Trust?

Zero trust is a strategic approach requiring all network users to be authenticated, authorized, and regularly validated. The framework covers the internal and external users of an organization’s network.  

As a cybersecurity concept, it requires full awareness of security policy based on established contexts rather than assumptions. A well-defined zero trust architecture results in simpler network infrastructure, improved defense mechanisms, and a better user experience.  

How Does Zero Trust Work?

Zero trust pretends there is no traditional network edge in the cloud or hybrid, whether local. Its maxim is to always verify, and trust no user or device. 

The core philosophy of zero trust security is to presume that every user or device is hostile by default. As a model, it responds to the fact that the perimeter security approach isn’t 100% secure. The ability of cyber criminals to breach data even with corporate firewalls is enough proof. Users also access networks from different devices and locations, making  it  harder to clearly define perimeters while increasing the risk of security breaches.  

The approach zero trust uses is to treat all traffic as hostile. For instance, workloads get validated by a set of attributes before they can communicate. It also involves using fingerprint or identity-based validation policies to attain stronger security.   

  Zero trust draws on technologies, calls on governance policies, and uses push notifications for effective security. Since protection is environment-agnostic, zero trust secures applications. Moreover, it securely connects devices and users via business policies over any network. That way, it can enable a safe digital transformation. 

Why is Zero Trust Important?

The primary reason for introducing zero trust is to reduce risks. However, it also helps to manage risks associated with remote work, insider threats, and third-party and cloud security . 

  • Zero trust protects  organizations in various ways  including: Giving visibility to potential threats while improving proactive remediation and response. 
  • Preventing cyber threats like malware from gaining network access. 
  • Simplifying the management of security operations centers through enhanced automation. 

The Benefits of a Zero Trust Edge

The cloud environment is a highly attractive opportunity for cyber actors to steal troves of sensitive data, financial information, and intellectual property.  

While no security strategy offers a perfect solution to data breaches, zero trust helps reduce the surface attacks and the severity of cybercrimes. This includes the reduced cost and time spent responding to  breaches. 

The approach of not trusting any connection without the necessary verification is a crucial factor. Furthermore, companies deal with many cloud, data sprawl, and endpoints, making  it only logical to adopt a system that guarantees security.  

Other highlighted benefits include:  

  • Reducing the reliance on point solutions designed to detect and stop threat activity. 
  • Limiting possible avenues for data exfiltration. 
  • Enhancing the authority and use of authentication 
  • Reducing the literal movements of attackers within an organization
  • A sneak peek into all user activity
  • It offers improvements in both on-premises and cloud-based security posture.  

Cutting Through the Zero Trust Hype

There’s no doubt that zero trust architecture gives a new face to trusted network-defining perimeters. However, it remains a theoretical concept in practice for many establishments. 

The challenge for these organizations becomes looking beyond the buzzwords of vendors. They need to put the possible outcomes of any security technology into consideration. One major point to note is that the designs of security solutions follow core principles. The zero trust edge security model also has principles that need evaluation before its adoption. 

According to Forrester’s research, the Zero Trust concept focuses on the integrated, dynamic ecosystem of security capabilities and technologies. Simply put, the principles highlight three areas access denial to applications and data by default. These include threat prevention by granting access to networks utilizing continuous and contextual organization policy, risk-based verification across users, and their associated devices. 

Any establishment wishing to integrate the zero trust model  must consider certain parameters such as: 

Internal Applications

An application lacking micro perimeter compatibility or Application Programming Interfaces (API) support to automation finds zero trust implementation impossible. Also, adding new security parameters to existing applications to make them zero trust-aware may not work. Furthermore, it may lead to an existing application’s inability to accommodate a zero-trust model.  

What becomes obtainable is a  good level of reliance on custom applications, while determining the effort and potential cost required. 

Transformation in the Digital Sphere

Adopting the zero trust edge security model could be challenging for organizations using Cloud, DevOps, IoT, and IIoT. These applications do not inherently support the zero trust model. One reason is that they require additional technology to enforce or segment the model. In addition, a straight migration of a raised floor to the cloud discourages zero trust integration. Nonetheless, to bypass this challenge, organizations must develop new cloud applications as a service. That way, it will embrace the zero trust architecture.  

Legacy Infrastructure

Some legacy infrastructure and network devices lack authentication models for modifications to contextual usage. It is the very reason they can’t be zero trust edge aware. In addition, all zero trust implementations require a layered approach to enable systems. 

Organizations must weigh their options carefully before venturing into a zero-trust architecture. Monitoring behavior within a non-compatible application comes with limitations. They only get to monitor external interactions of the legacy device. On the flip side, having an accurate infrastructure inventory comes with benefits. Zero trust expects that administrators have a handle on all corporate infrastructures, from users to devices, data, applications, and services. It also requires where these resources reside. With all these in place, center administrators possess the power to detect and respond to cybersecurity threats promptly.  

The best way to approach the zero trust architecture is to conduct a thorough investigation. IT and security teams need to ensure that the network technologies of the organizations comply with the architecture. Trust models work strictly on keys or passwords with no dynamic models for authentication modifications.  

Security teams also need to navigate through the aggressive claims of vendors, extensively testing against its use cases, and ensuring product verification is top-notch for integration without creating vulnerabilities. 

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

KIDS BACK AT SCHOOL. CHECK. DEVICES PROTECTED. CHECK.

 For many, a new school year symbolizes a new beginning. For kids it’s as much a celebration as New Year’s Eve for adults. New beginnings, a clean slate and starting over. No wonder we want to prepare for it as best we can, to set ourselves, and our children, up for success.
The preparation should not only include the purchase of school supplies and books, today a very important part is, digital security and privacy. We may omit this at times, but unfortunately the back-to-school season offers a great opening for phishing, ransomware and other scams to deceive both us and our children.

For many, a new school year symbolizes a new beginning. For kids it’s as much a celebration as New Year’s Eve for adults. New beginnings, a clean slate and starting over. No wonder we want to prepare for it as best we can, to set ourselves, and our children, up for success.
The preparation should not only include the purchase of  school supplies and books, today a very important part is, digital security and privacy. We may omit this at times, but unfortunately the back-to-school season offers a great opening for phishing, ransomware and other scams to deceive both us and our children.

Set yourself up for success

There are several threats to look out for, for example the aforementioned phishing scams or ransomware attacks. Make sure you watch out for the most common back to school scams, such as scholarship scams, tech support scams and other. However, using these tips you can prevent them from happening and have a cybersafe start of the new school year.

What to do?

  • Do not click unknown links or open suspicious emails
  • Avoid sharing personal information
  • Keep your operating system (OS) up to date
  • Never use unknown portable devices: USB sticks, other people’s smartphones
  • Watch out for bad grammar/generic openings
  • Use a strong password and don´t leave your device unlocked or unattended
  • Back up your data regularly
  • Ask your school or university about their privacy and security policy
  • If you are a parent, invest in efficient Parental Control

Secure your mobile device

Whether you are a parent, a teacher or a child, your phone is a powerful tool. It is certainly a great tool to keep in contact, stay on top of assignments and other school activities. But it is also a tool for malicious actors to invade your privacy and security. Keeping it safe is therefore one of the key things in ensuring a smooth and safe back to school transition.  

A great way to start is with ESET Mobile Security on your Android mobile devices. It is a solution that ensures security against a multitude of mobile threats while securing users’ data.  

ESET Mobile Security aims to provide a safe environment by leveraging its Anti-Phishing feature. The feature integrates with the most common web browsers (Chrome and many others) available on Android devices to provide protection to any and all online activities you want to carry out.  

We recommend you keep Anti-Phishing enabled at all times. All malicious websites, listed in the ESET malware and phishing database, will be blocked and a warning notification will be displayed informing you of the attempted attack. 

Other features of ESET Mobile Security include:  

  • Anti-Smishing – protects you from SMS and App notifications containing malicious links
  • Antivirus – protection against malware: intercepts threats and cleans them from your device   
  • Payment protection – lets you shop and bank safely online   
  • App lock – requires extra authentication to access sensitive apps; protects content when you’re sharing a device   
  • Anti-Theft – a powerful feature to help protect your phone and find it if it goes missing  
  • Network inspector – scans your network and all connected devices to identify security gaps   
  • Call filter – blocks calls from specified numbers, contacts and unknown numbers   
  • Adware detector – identifies and removes apps that display ads unexpectedly 
  • Real-time scanning – scans all files and apps for malware   
  • Scheduled scans – checks your device every time you charge it, or whenever you want   
  • Security audit – checks an app’s permissions   
  • Security report – provides an overview of how secure your device is   
  • USB on-the-go scanner – checks any connected USB device for threats   
  • Up to 5 devices – pay once, protect 5 devices associated with the same Google account  

ESET Mobile Security makes your Android phones and devices easy to find and harder to steal, and it helps to protect your valuable data. 

If you want to protect your phone with ESET Mobile Security, you’re in luck! From August 25 to September 7, the premium version of ESET Mobile Security will be 50% off. No need for a promotional code; the discount will automatically be added to your checkout! It couldn’t be easier.    

The most powerful tool

Your most powerful tool when trying to keep your children safe in the digital world is educating yourself, talking to them about healthy use of digital and the threats they may encounter. Have regular conversations with your children about privacy, security and proper online behavior. Make sure they feel safe to talk to you about anything that might make them feel uncomfortable in the digital world.

To better educate yourself and your children, visit saferkidsonline.eset.com.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research jointly presents Industroyer2 at Black Hat USA with Ukrainian government representative

  • ESET researchers Robert Lipovský and Anton Cherepanov recently presented their research on Industroyer2 at the Black Hat USA 2022 conference.
  • Joining the presentation was Deputy Director of Ukraine’s State Service of Special Communications and Information Protection Victor Zhora.
  • This is the first time that a Ukrainian governmental representative has taken part in such a high-profile cybersecurity conference.
  • ESET researchers pledged to continue working with CERT-UA to support its cyberdefenses.


BRATISLAVA, LAS VEGAS — ESET researchers Robert Lipovský and Anton Cherepanov recently presented  breakthrough research into Industroyer2 during a Black Hat conference in Las Vegas, along with Victor Zhora, the Deputy Director of Ukraine’s State Service of Special Communications and Information Protection (SSSCIP). This is the first time that a Ukrainian governmental cybersecurity expert has participated in one of the most prestigious cybersecurity research conferences in the world.

The “surprising” appearance of  Zhora during ESET’s presentation was an additional opportunity for research, expert, and media audiences alike to gain in-depth information on Ukraine’s capability to resist the cyber warfare waged by the Russian aggressor.

“The Industroyer2 attack was thwarted thanks to the swift response of Ukrainian defenders and CERT-UA. We provided the Ukrainian side with crucial analysis of this threat, which could have become the most substantial cyberattack since the beginning of the invasion had it succeeded. Our researchers are ready to continue to work with CERT-UA to support its cyber defenses,” says  Lipovský, ESET’s Principal Malware Researcher, who presented the Industroyer2 research at Black Hat with Cherepanov.

Earlier this year, ESET researchers responded to a cyber-incident affecting an energy provider in Ukraine. ESET worked closely with the Computer Emergency Response Team of Ukraine (CERT-UA) in order to remediate and protect this critical infrastructure network.

The collaboration resulted in the discovery of a new variant of Industroyer malware that ESET Research together with CERT-UA named Industroyer2. Industroyer is an infamous piece of malware that was used in 2016 by the Sandworm APT group to cut power in Ukraine. In this case, the Sandworm attackers made an attempt to deploy the Industroyer2 malware against high-voltage electrical substations in Ukraine. In addition to Industroyer2, Sandworm used several destructive malware families. These consisted of disk wipers for the Windows, Linux, and Solaris operating systems.

“Since the end of World War II, humankind has never faced such grave challenges as today, when Russia invaded Ukraine. However, the parallel war in cyberspace is an absolutely new challenge. The knowledge we have gained by this research should be part of a universal common knowledge that helps defend the civilized world from such threats. I’d like to express my gratitude to all our partners who keep supporting us in this unprecedented war and in our struggle for life,” added Zhora.

The State Service of Special Communications and Information Protection of Ukraine is a specialized executive authority whose key functions include provisioning secure government communications, the government courier service, information protection, and cyber defense.

For more technical information about Industroyer2, check out the blogpost Industroyer2: Industroyer reloaded, and for more about the Black Hat presentation, check out Black Hat 2022 – Cyberdefense in a global threats era on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.