Skip to content

Using runZero to verify network segmentation

What is network segmentation?

Network segmentation, in its simplest form, is the act or practice of dividing a computer network into smaller parts, subnetworks, or network segments. In recent years,it has evolved into a foundational enterprise control to improve network performance and security. However, without effective verification strategies like Cyber Asset Attack Surface Management (CAASM), network segmentation can be easily undermined by misconfigurations and multi-homed machines.

Let’s explore a practical comparison to network segmentation – a house with an open floor plan. This design ensures ease of movement and makes the space feel larger, but presents a challenge for achieving privacy and security. You likely don’t want everyone that enters your home to have unfettered access to all areas. Adding walls and changing the architecture of a home is much harder after it’s been built; however, doors and locks can help add security controls while maintaining the original functionality. For example, if a contractor is scheduled to work on the garage, doors and locks add a level of segmentation that ensures access is only granted for the area where the work needs to be done. Lateral movement into the house is unlikely and garage repair alone does not merit access to other areas. Essentially, network segmentation is akin to a house with defined areas of access to make safe and secure spaces when needed.

A simple example of network segmentation
A simple example of network segmentation

What are the benefits of network segmentation?

  • Better operational performance Segmentation reduces network traffic congestion.

  • Improved security:
    • Limit the damage done by cyber attacks: Segmentation improves cybersecurity postures by limiting how far an attack can spread by reducing lateral movement. For example, segmentation keeps a malware outbreak in one segment from spreading to systems in another.

    • Protect vulnerable devices: Segmentation can prevent harmful traffic from reaching devices that are unable to protect themselves. For example, on a factory floor that contains OT/ICS devices that were not designed with advanced security defenses, segmentation can stop harmful Internet traffic from reaching them.

  • Containing network problems: Segmentation minimizes the impact of local failures on other parts of the network. When localized problems arise, network segmentation helps to minimize production downtime and decrease corporate latency due to misconfigurations.

  • Controlling access: Access can be controlled by creating VLANs to segregate the network. For example, visitors can access a “guest network”, so they can access the Internet, but not the corporate network itself. Another example is separating networks during a corporate divestiture, so that employees only have access to the corporate network of their company and not the other.

  • Meet industry compliance standards Regulations are a driving factor in network segmentation. For example, businesses subject to Payment Card Industry Data Security Standard (PCI DSS) requirements must validate cardholder data environment (CDE) segmentation during the security audit process. The PCI guidance on scoping and segmentation describes a common CDE administration model.

How do you verify network segmentation is implemented correctly?

Verifying that segmentation is working correctly can be challenging, especially across large and complex environments. Common techniques to validate segmentation, such as reviewing firewall rules and spot testing from individual systems can only go so far, and comprehensive testing, such as running full network scans from every segment to every segment, can be time intensive and are rarely performed on a regular basis.

Verifying safe network segmentation with CAASM

Network bridge detection

Network bridge detection is a useful tool when validating the effectiveness of network segmentation and testing whether an attacker can reach a sensitive network from an untrusted network or asset. Examples of this include laptops plugged into the internal corporate network that are also connected to a guest wireless segment, or systems connected to an untrusted network, such as a coffee shop’s wireless network that also have an active VPN connection to the corporate network.

The runZero Platform detects network bridges by looking for extra IP addresses in responses to common network probes (NetBIOS, SNMP, MDNS, UPnP, and others) and only reports bridges when there is at least one asset identified with multiple IP addresses. Typical hardening steps, such as desktop firewalls and disabled network services are limiting factors that will usually prevent multi-homed assets from being detected by runZero; however, the click-through demo below shows how to use network bridge detection to search for multi-homed assets in the runZero inventory.

Identifying Potentially Risky Network Bridges

This runZero network bridge report is an interactive view of possible paths that can be taken through the network by traversing multi-homed assets. When detected, single IP addresses are omitted to keep the graph practical and actionable for defenders.

runZero enables you to click through asset and subnet details within the external (red) and internal (green) networks. Clicking a bridged node once will highlight the networks it is connected to and show a link which leads to the full asset details for that node. Alternatively, clicking a network once will highlight the connections to bridged nodes and show a link to the Asset Inventory page with a CIDR-based inventory search.

This report helps you see where segmentation may be broken, and can cut down on the number of surprises encountered in a future security audit.

The Asset Route Pathing Report

The runZero Platform also enables you to visualize potential network paths between any two assets in an organization by creating the asset route pathing report. This unique methodology identifies surprising and unexpected paths between assets that may not be accounted for by existing security controls or reviews.

The report generates a graph of multiple potential paths by analyzing IPv4 and IPv6 traceroute data in combination with subnet analysis of detected multi-homed assets – without requiring access to the hosts or network equipment.

With a view of potential paths between assets, security professionals can verify whether a low-trust asset, such as a machine on a wireless guest network, can reach a high-value target, such as a database server within a cardholder data environment (CDE). Another example would be an OT asset (such as an engineering workstation) being able to access the IT network. This feature highlights potential network segmentation violations and opportunities for an attacker to move laterally from one segment to another.

Summary

In summary, there are many benefits of network segmentation, and fact checking proper implementation can be a difficult, arduous task. runZero is here to help by reducing the burden of misconfigurations and/or improperly defined network boundaries, subnets and VLANS.

Not a runZero customer? Download a free trial today and achieve comprehensive asset inventory and attack surface visibility in minutes.

If you would like to read more about network segmentation and what runZero has found in the wild, check out Chapter 4 of the runZero Research Report that talks about the decay of segmentation.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

Guardz collects $18M to expand its AI-based security platform for SMBs

Thanks to advances in AI, small and medium businesses have become a significant target in the world of cybercrime, accounting for roughly half of all breaches worldwide by some estimates. Now, one of the companies building security tools for SMBs has raised a round of funding to expand its business, underscoring the demand in the market for better defenses.

Guardz, an Israeli startup that has built an all-in-one security and cyber insurance service for small and medium businesses, has raised another $18 million in a Series A round of funding.

 

The company emerged from stealth less than a year ago (at the end of January 2023), and since then it has had a bit of a pivot. It’s no longer selling directly to SMBs but is working with managed service providers that in turn sell and manage IT services for SMBs. MSPs, it found, were the primary route to getting their product to get used by SMBs (meaning direct business was not taking off). Now those MSPs are able to build their own offerings “powered” by Guardz.

“This is the journey. It’s a blended solution, powered by Guardz but with the logo of the MSP out in front,” said Dor Eisner, the CEO, in an interview.

The plan will be to use the funding to hire more engineering talent to continue evolving the Guardz product, which has been selling primarily to customers in the U.S., U.K. and Australia. It has around 200 MSPs on its books currently, which in turn are working with some 3,000 SMBs, which in turn represent some 36,000 seats overall using Guardz’s products. Security remains the main revenue driver, with cyber insurance an option add-on.

Glilot+, the early growth fund of Glilot Capital Partners, is leading the round, with ClearSky and previous backers Hanaco Ventures, iAngels and GKFF Ventures also participating.

The company is not disclosing its valuation, but Eisner — who co-founded the company with Alon Lavi — said that the figure has tripled since its last fundraise, a $10 million seed round that coincided with Guardz coming out of stealth mode.

 
 

 

To give some more context: The startup has now raised $28 million and alongside securing around 36,000 “seats” it is growing fast, within an interesting opportunity for more customers since there are around 150,000 MSPs globally serving the SMB market, Eisner said. That likely puts Guardz’s valuation comfortably above $100 million.

The gap in the market that Guardz is targeting is a big and urgent one. In the past, SMBs were overlooked by cybercriminals largely for the same reasons that they were mostly ignored by the most cutting-edge B2B technology developers: SMBs are too fragmented as a group, and they typically do not represent lucrative ROI compared to large enterprises.

However, developments in AI have made it very easy for malicious actors to develop, execute and scale campaigns exploiting vulnerabilities. That’s been an alarming development, because typically SMBs have lacked the in-house expertise, and the right tools, to defend against that.

Guardz’s aim has been to create a security platform for these customers that is just as robust as what larger organizations might use. The platform is provided as a managed service — meaning the customer does little to manage it directly — but within that managed service, there is a lot of AI-based automation built in: Guardz’s tools automatically detect malicious activity, provide remediation against it and write up activity reports that can be further triaged by the MSP. The MSP can also use Guardz to create security breach simulations — customized to the specific activity of the SMB in question — which can be used to help train the employees at their customers.

Part of the funding will be used to continue expanding the tools that its own team has at hand to match the increasing sophistication of bad actors.

 

“Every day we find a new method used by hackers,” Eisner said. A recent discovery, he said, involved a method to create automated forwarding rules for those using Microsoft 365, giving malicious actors a way to collect emails “in a silent way.”

“We found that people were talking about this attack on the dark web, so we decided to develop detection and remediation around it,” he said, adding that a technique like this would likely be used as part of a multivector attack, alongside phishing, for example.

SMBs have become a sharper target for tech companies building enterprise services not just because innovations in cloud services and AI have improved the unit economics. It’s also because they are a huge market segment, estimated at over 99% of all businesses globally. And that can mean big business in a variety of verticals. Payments and fintech business SumUp, which also targets SMBs, earlier this week announced more than $300 million in funding to expand its platform and grow its customer base. Guardz is also not the only one in the area of building cybersecurity for SMBs. Others in the long list of direct competitors include CyberSmart out of the U.K. as well as bigger players like CrowdStrike and Check Point.

“When we met the exceptional team at Guardz, which combines cybersecurity leaders with small business go-to-market experts, it became evident that they had built the ultimate solution for small business cybersecurity – a longstanding and rapidly growing market need we’ve been monitoring at Glilot for a while,” stated Lior Litwak, who is the managing partner heading up Glilot+, in a statement. “Guardz has developed an impressive, holistic, and user-friendly cybersecurity and cyber insurance risk-assessment platform that is cleverly tailored to MSPs, who serve the often-overlooked long-tail small business market. We are excited to lead this funding round and join the Guardz team on their journey to secure the digital world for those who today need it most.”

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Guardz
Guardz is on a mission to create a safer digital world by empowering Managed Service Providers (MSPs). Their goal is to proactively secure and insure Small and Medium Enterprises (SMEs) against ever-evolving threats while simultaneously creating new revenue streams, all on one unified platform.

Searching for a password manager? Discover the best review sites

 

Suppose you were Stefan Thomas, a San Francisco-based German programmer who is left with two guesses to figure out a decade-old password to access his $321M fortune. In that case, you’d probably be banging your head against the wall trying to figure out why you didn’t use a password manager back then.

These days password managers are an everyday essential. Choosing the right one for you — out of all available options — can be tricky, especially if you have no experience with password managers. And that’s when we often turn to review sites.

This post is your shortcut to understanding how to use review and comparison sites to your advantage so you can make the best possible decision.

What makes a reliable password manager comparison site?

Transparency of evaluation and methodology

The cornerstone of any reliable review site is openness about its editorial integrity and review criteria. Such sites should be transparent about what they value in a password manager or any other app in terms of features or functionalities. This also includes being frank about their evaluation methodologies and review timelines.

Up-to-date information

Any reputable comparison site should update its reviews to reflect how a product or service has changed. The reviewers should look to include the latest features or any other disclosures that may determine the user’s choice in either buying or avoiding the product.

Disclosure of conflicts of interest

A comparison site that wants to be taken seriously or considered as trustworthy should be open about its connections and relationships with various developers. Ultimately, the site stands more to gain than lose when it comes to disclosure of conflict of interest.

Key password manager features to consider

Not all password managers are created equal. When choosing the best fit for your needs, here are the essential features you should consider.

Encryption

The foundation of any password manager worth its salt is encryption. Put simply, encryption scrambles data into a code that only the correct key can decode. Strong encryption means that the likelihood of hackers accessing your passwords in the password manager’s vault is essentially zero.

Device sync

We live in a multi-device world, where switching between smartphones, tablets, and computers is a fact of life. A password manager that is worth your buck should offer seamless sync across devices and platforms.

Password generation

Weak passwords are the leading cause of unauthorized access. It’s no secret that we—humans are terrible at password creation. Machines, on the other hand, usually excel there. When considering a password manager, look for a built-in password generator.

Extra features

Password managers come packed with a variety of advanced security features. To get the best bang for your buck, look for a password manager that offers email mask creation, allows you to add emergency contact, and notifies you if your data ever appears in a data breach.

Secure sharing

There are times when you need to share a password with a family member or colleague. There’s no way around it. So be sure to look for a password manager that provides a secure way to share passwords and other sensitive information that you might keep in its encrypted vault.

Built-in Multi-factor authentication (MFA)

Multi-factor authentication (MFA) is another feature that you might want to look for in a password manager because it adds an extra layer of security. You likely already know what MFA is, but just to recap, it’s a security method that requires users to present multiple proofs of identity. So with MFA enabled along with a master password you’d need to enter an additional code that might be sent to you via text, email, or an authentication app.

User-friendly interface

Security tools are most effective when used consistently. And so that’s exactly where a clean, intuitive user interface can make or break a product—a good user interface will not dissuade you from using the app.

Top review sites for password managers

Here, we’ve presented you with some of what we consider leading review sites. Each of them offers unique insights that can help you decide on a password manager:

  • TechRadar is known for its balanced approach, offering detailed comparisons and honest takes on products that caters to both tech enthusiasts and everyday users. They focus on usability, security features, and the overall value.

  • CyberNews focuses more on cybersecurity. They tend to test encryption strength and privacy protections. It is an ideal comparison site for those who are more into the technical details of what’s going on behind the hood.

  • Forbes Advisor as the brand name suggests, blends financial and tech insights, assessing password managers through the lens of security and cost-effectiveness.

  • VPNOverview seems to emphasize user experience, ease of use, compatibility, and daily application. Their reviews offer readers straightforward, practical advice on choosing a password manager for their daily online routines.

  • All About Cookies focuses more on privacy and data protection. It also tends to explore how password managers handle and secure user data. Its reviews cater for the privacy-conscious.

  • The Wall Street Journal provides in-depth analysis of software utility with a consumer electronics spin to it. Their thorough reviews and comparisons are meant for readers seeking expert opinions.

  • How-To Geek is known for making technology accessible. They break down the features and functionalities of password managers and so many other apps into easy-to-understand reads. Their approach is perfect for those new to password manager or those looking for a down-to-earth explanation.

  • Engadget provides a variety of reviews, offering a broad overview of password managers on the market. Their generalist approach is ideal for readers starting their search and looking for a list of available options.

  • FrAndroid provides detailed reviews for the French-speaking audience, focusing on the user interface, features, and language support. Their reviews and comparisons are invaluable for French users seeking a password manager that meets their specific needs.

  • Tom’s Hardware Italia offers comprehensive coverage tailored to Italian users. Their reviews are meticulously crafted to address the unique things Italians value in password security.

Wrapping up

Choosing a password manager that’s right for you can be tricky. With so many options and opinions out there, we hope this article made it a little bit easier for you to make an informed choice on which reviews sites to consider.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

Vault doesn’t cut it: why you need a backup solution for Google Workspace

For organizations looking for an affordable, scalable productivity suite, Google Workspace is a great option. Designed with security in mind, it also has several features that promise to keep your organization’s most valuable asset – your data – safe.  

Your data is under constant threat – and the consequences can be costly

The safety of your data is under attack from many directions: cybercriminals as well as disgruntled users, accidental human error, programmatic errors and more pose a threat.  Cyberattacks especially are an ever growing challenge: incidents have doubled in some sectors due to the advances in AI enabling criminals to conduct increasingly sophisticated attacks. 

Data loss often comes with severe consequences for your business. The time and effort required to recover from the event and get critical operations running safely again can be significant. Being able to demonstrate business continuity in the event of a cyberattack is a legal requirement of regulations such as the Digital Operational Resilience Act (DORA) and the upcoming NIS 2 directive, and fines for non-compliance are hefty. Lastly, your reputation is on the line, too, especially when it is found that data security protection was lacking.

Google’s protection is not enough

Google’s safety mechanisms include end-to-end encryption and two factor authentication. However, Google’s built-in backup and recovery solution is insufficient, leaving you and your data at risk. There are two main reasons for this: 

  • Google’s built-in backup functionality provides only temporary and limited protection

Google constantly backs up your data to meet their service level agreements (SLA) in the event of a major service outage on their part. Your data is “sharded” (partitioned horizontally) and split between multiple regions and data centers so that in the event of a catastrophic failure or cyber attack on a single data center, your “live” data will still be available to you when you open up Google Workspace.

However, there are no automatic backups beyond 25 days, and only limited protection against accidental deletion and malicious users. 

  • Google Vault is not a backup solution

Some organizations use Google Vault, a protective layer to provide data retention and eDiscovery for compliance purposes, to backup their data, however Vault is not designed as a backup tool. It only stores the latest versions of your data and is not designed for recovery.

In fact, you are responsible if your data is lost or changed in many common circumstances such as:

  1. A user has modified content and you need to restore it back to a previous state.
  2. A malicious user has been able to modify and delete data because you have given them access to it through sharing and delegation policies.
  3. An admin has incorrectly set a policy or process (such as a Vault retention policy) leading to unwanted changes to your data such as pre-emptive deletion

Google Workspace and Google Vault lack basic backup functionality

Further limitations that disqualify Google Workspace and Google Vault as effective backup and recovery methods include:

  1. No mass restoration process – Google does not provide an easy, direct and effective method of restoring data in bulk. 
  2. Data restored may not be in the format required – For example, Google Vault will only allow you to restore emails in MBOX format with no label preservation.
  3. Limited time and no version control when restoring from Google Workspace Trash – Whilst you can retrieve deleted items from Trash, you only have a limited amount of time to do so (25 – 30 days) before it is permanently deleted. You will only be able to restore the latest version of the file or email with no granular version control.

How can you protect your data from the consequences of data loss?

In summary, relying on Google and Google Vault for backup and recovery exposes your organization to significant risk from data loss. Noncompliance, reputational damage and ultimately the cost of restoring your data and recovering from the loss further strengthen the case for implementing a robust backup and recovery solution.

CloudM Backup a simple yet powerful backup and recovery solution for Google Workspace that protects your data against accidental deletion and malicious users whilst providing quick and easy mass restoration should data loss occur.

Find out how CloudM backup can protect your organisation.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About CloudM
CloudM is an award-winning SaaS company whose humble beginnings in Manchester have grown into a global business in just a few short years.

Our team of tech-driven innovators have designed a SaaS data management platform for you to get the most from your digital workspace. Whether it’s Microsoft 365, Google Workspace or other SaaS applications, CloudM drives your business through a simple, easy-to-use interface, helping you to work smarter, not harder.

By automating time-consuming tasks like IT admin, onboarding & offboarding, archiving and migrations, the CloudM platform takes care of the day-to-day, allowing you to focus on the big picture.

With over 35,000 customers including the likes of Spotify, Netflix and Uber, our all-in-one platform is putting office life on auto-pilot, saving you time, stress and money.

ESET Research releases latest APT Activity Report, highlighting cyber warfare of Russia-, China-, and Iran-aligned groups

  • This ESET APT Activity Report summarizes notable activities of cyberthreat groups that were documented by ESET researchers from October 2023 until the end of March 2024.
  • Iran-aligned groups increased their activity against Israel after the Hamas-led attack on Israel in October 2023 and  throughout the ongoing  war in Gaza.
  • Russia-aligned groups focused on espionage within the European Union and continued attacks against Ukraine.
  • China-aligned threat actors exploited vulnerabilities in public-facing appliances, such as VPNs and firewalls, and software.
  • The main targets of most of the campaigns were government organizations.

BRATISLAVAMay 14, 2024 — ESET has released its latest APT Activity Report, which summarizes notable activities of selected advanced persistent threat (APT) groups that were documented by ESET researchers from October 2023 until the end of March 2024. The highlighted operations are representative of the broader landscape of threats ESET Research has investigated during this period, illustrating key trends and developments. After the Hamas-led attack on Israel in October 2023, and  throughout the ongoing war in Gaza, ESET has detected a significant increase in activity from Iran-aligned threat groups. Russia-aligned groups have focused their activities on espionage within the European Union and attacks against Ukraine. On the other hand, several China-aligned threat actors exploited vulnerabilities in public-facing appliances, such as VPNs and firewalls, and software, such as Confluence and Microsoft Exchange Server, for initial access to targets in multiple verticals. North Korea-aligned groups continued to target aerospace and defense companies and the cryptocurrency industry.

“The targets of most of the campaigns were government organizations and certain verticals: for example, those targeted in continued and relentless attacks on Ukrainian infrastructure. Europe experienced a more diverse range of attacks from various threat actors. Russia-aligned groups strengthened their focus on espionage in the European Union, where China-aligned threat actors also maintain a consistent presence, indicating a continued interest in European affairs by both Russia- and China-aligned groups,” says Jean-Ian Boutin, Director of Threat Research at ESET.

Based on the data leak from Chinese security services company I-SOON (Anxun), ESET Research can confirm that this Chinese contractor is indeed engaged in cyberespionage. ESET tracks a part of the company’s activities under the FishMonger group. In this latest report, ESET also introduces a new China-aligned APT group, CeranaKeeper, distinguished by unique traits yet possibly connected by the digital footprint with the Mustang Panda group.

In the case of Iran-aligned threat groups, MuddyWater and Agrius transitioned from their previous focus on cyberespionage and ransomware, respectively, to more aggressive strategies involving access brokering and impact attacks. Meanwhile, OilRig and Ballistic Bobcat activities saw a downturn, suggesting a strategic shift toward more noticeable, “louder” operations aimed at Israel.

Regarding Russia-aligned activity, the Operation Texonto campaign, a disinformation and psychological operation (PSYOP) uncovered by ESET researchers, has been spreading false information about Russian election-related protests and the situation in the eastern Ukrainian metropolis Kharkiv, fostering uncertainty among Ukrainians domestically and abroad.

The report also describes the exploitation of a zero-day vulnerability in Roundcube by Winter Vivern, a group ESET assesses to be aligned with the interests of Belarus. Additionally, ESET spotlights a campaign in the Middle East carried out by SturgeonPhisher, a group ESET researchers believe to be aligned with the interests of Kazakhstan.

ESET products protect our customers’ systems from the malicious activities described in this report. Intelligence shared here is primarily based on proprietary ESET telemetry data and has been verified by ESET researchers, who prepare in-depth technical reports and frequent activity updates detailing activities of specific APT groups. These threat intelligence analyses, known as ESET APT Reports PREMIUM, assist organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from criminal and nation-state-directed cyberattacks. This report contains only a fraction of the cybersecurity intelligence data provided to customers of ESET’s private APT reports.

You can read the full ESET APT Activity Report on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

24.3.9 Voyager released

Changes compared to 24.3.8

Bug Fixes

  • Fixed an issue with backup jobs to the il-central-1 AWS region always failing
  • Fixed an issue with the Constellation title in the Tenant dialog not showing in the Comet Server web interface
  • Fixed an issue with the Comet Server web interface violating the strict CSP policy
  • Fixed an issue causing a white background to show on some loading animations when using dark mode in the Comet Server web interface
  • Fixed an issue with missing branding images in Comet Backup desktop app for Linux
  • Fixed an issue with the message This Storage Vault was unlocked … appearing incorrectly when a backup job was experiencing network issues
  • Fixed an issue causing alternate data streams on NTFS metadata files to cause errors during granular restores
  • Fixed an issue with invalid filenames when switching from a custom-branded client installer to the pre-built Comet Backup-branded installer
  • Fixed an issue with inconsistent validation between configuring custom client branding at the top-level versus for a Tenant’s settings

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

Employee smartphones, a pack of risks in a pocket. How to minimize your business’ attack surface

With proactive prevention, companies can mitigate threats from mobile devices before they can do wider harm. 

When intelligence services were trying to infiltrate companies or institutions during World War II and the Cold War, they needed to come up with some very smart ideas. They disguised cameras as coat buttons, hid transceivers in suitcases, and even tried to create a robot dragonfly with a microphone!

Today, when people want to snoop and get around a company’s defenses, they just need to get inside your employees’ smartphones. Nearly everybody has one, and many are casual about their security. Though it’s true that it is rare to see malware spreading from a phone to company laptops, a compromised phone is still a threat if it is connected to the company’s internal network or when attackers steal an employee’s credentials, sensitive corporate data, or banking information.

Considering how small those devices are, the threat landscape they create is disproportionally huge: A single phone contains several devices, such as a camera, microphone, and GPS tracker, but what is even more serious is that these components and many of the applications hosted on the phone can be abused to steal sensitive information from employees and to serve as an initial attack vector for cybercriminals to further harm a company.

Some businesses deal with this by using mobile device management (MDM), imposing strict rules on their corporate devices and allowing employees to use only a handful of apps. However, most businesses are either small or midsize, and their security may struggle to keep enforcement tight.

ESET researchers could write books about malware that threatens smartphones and its potential harm to businesses. That is why ESET, a global leader in cybersecurity, has introduced ESET Mobile Threat Defense (EMTD) as a part of its latest B2B offering.  To improve their prevention capabilities, users of ESET PROTECT Advanced and higher can now enjoy one free mobile device seat per one paid seat for other devices.

Shortly after the successful launch of the ESET’s Mobile Threat Defense module, ESET was included in Forrester’s Mobile Threat Defense (MTD) Solutions Landscape report, Q1 2024. Forrester, a respected analyst firm, provides an overview of 16 vendors in the field, including ESET, which, in our opinion, makes ESET a valuable player in this established market.

What threats are out there?

From the beginning of 2020 until the end of 2023, Android malware detected by ESET telemetry rose by 222%.

For example, last year, ESET researchers discovered two active campaigns targeting Android users distributed across several app stores and dedicated websites.

The threat actors patched the open-source Signal and Telegram apps for Android with malicious code that ESET researchers have identified as BadBazaar. The malicious apps went by the name Signal Plus Messenger and FlyGram, and their purpose was to exfiltrate user data, such as contact lists, call logs, and the list of Google accounts.

Signal Plus Messenger is even more dangerous than FlyGram with its unique capability to spy on the victim’s communications in the original Signal app. Such sensitive information could be used for further spear phishing attacks against business officials.

 

A similar case was covered in June 2023, when ESET researchers identified an updated version of Android GravityRAT spyware. It was distributed within the malicious but functional messaging apps BingeChat and Chatico, which were both based on the OMEMO Instant Messenger app. This particular spyware can exfiltrate call logs, contact lists, SMS messages, the device location, basic device information, and files with specific extensions, such as jpg, PNG, txt, pdf, etc.

And this is just the beginning. Smartphones can be attacked in numerous ways that put companies’ finances and data in danger, such as through banking trojans, phishing, vulnerabilities, or physical theft.

A similar case was covered in June 2023, when ESET researchers identified an updated version of Android GravityRAT spyware. It was distributed within the malicious but functional messaging apps BingeChat and Chatico, which were both based on the OMEMO Instant Messenger app. This particular spyware can exfiltrate call logs, contact lists, SMS messages, the device location, basic device information, and files with specific extensions, such as jpg, PNG, txt, pdf, etc.

And this is just the beginning. Smartphones can be attacked in numerous ways that put companies’ finances and data in danger, such as through banking trojans, phishing, vulnerabilities, or physical theft.

SMBs are more vulnerable

Small businesses are often considered to be the backbone of national economies. In the United States, small businesses (defined as businesses with up to 500 employees) comprise 99.9% of all American businesses.

Authorities in the United Kingdom define small businesses as those with 10 to 49 employees and medium businesses as those with 50 to 249 employees. Similarly, more than 99% of all U.K. businesses are small and medium-sized businesses (SMBs).

Being cheaper and simpler to manage than issuing business devices, a Bring Your Own Device (BYOD) policy is often the number one option for SMBs. Some may also take a hybrid approach, providing corporate devices only to chosen employees. Without proper security, this comes with risks.

Of companies opting for BYOD, 48% say they have seen malware introduced through an employee’s personal phone, and just 4 out of 10 have MDM deployed, according to a Samsung 2023 survey.

And human error is a huge factor. Several recent studies show that more than 80% of data breaches involve a human element. Specifically, the most common mistakes contributing to cyber incidents are employees’ poor password hygiene and misuse of personal email.

However, we are not here to put the blame for every cyber incident on an average employee; after all, IT professionals can make some of the most common mistakes too. For example, half of them admitted to reusing the same password in a Ponemon Institute 2020 study.

Moreover, SMBs are less eager to invest in employee training, according to a survey conducted by the U.K. Department for Science, Innovation and Technology in 2023. For example, only 28% of surveyed small businesses conducted awareness training, in comparison with 77% of large businesses.

The same survey found that SMBs often also lack properly educated senior managers: “Although we have senior managers who are good at the role, they don’t have awareness in cyber security. I try to ensure they have a basic understanding, training, and knowledge in it. But they are focused on the day-to-day,” said one of the participating human resources administrators working for a medium business.

Target mobile threats to minimize attack surfaces

Considering these threats, implementing MDM is a huge step forward. For example, ESET Mobile Threat Defense gives administrators the option to monitor and control applications for both Android and iOS. EMTD is part of ESET’s cloud and on-premises unified management console ESET PROTECT, so no additional management console is needed.

With endpoint protection included, EMTD also provides antivirus and anti-phishing features, giving businesses more cyberattack prevention capabilities.

Both are also necessary when opting for a Zero Trust approach, an increasingly popular strategy in which the company verifies every account or device before allowing it to connect to its network.

See these ESET Mobile Threat Defense key capabilities and features:

  • Security: The security features range from anti-malware, anti-phishing, anti-theft, device security to control over web access, and much more.
  • Management: Management includes remotely wiping devices, restricting application installs, preconfiguring devices for users, and other items related to IT management.
  • Multiple OS: Mobile protection typically covers Android and Apple devices, the two most widespread mobile operating systems. As these operating systems are different, mobile protection capabilities can also vary between them.
  • Single pane of glass (SPOG): EMTD is natively integrated into the ESET PROTECT platform, and there is no need for another console or management platform.
  • Remote deployment: IT administrators simply selects employees with corporate devices, and they will automatically receive a QR code to then download ESET protection. Simple as that!
  • Seamless synchronization with cloud management platforms: For streamlined enrollment of mobile devices, ESET supports Microsoft Intune, Microsoft Entra ID, VMware Workspace ONE, and Apple Business Manager.

Investing in prevention to avoid crisis

According to the 2023 ITRC Business Impact Report, nearly half of the surveyed U.S. SMBs that experienced a data breach estimated their financial losses as being up to $250,000, another 26% calculated their losses as $250,000 to $500,000, and another 10% of SMBs estimated their losses could reach $1 million.

Seeing these numbers, it is clear that the phrase “an ounce of prevention is worth a pound of cure” also applies to cybersecurity. And that is not all: One-third of those companies also experienced loss of customer trust after a breach.

MDM with endpoint protection is always a great option to avoid such damage by decreasing your attack surface and possible risks, despite a lack of employee awareness training. Even better is that device management and protection can be operated from a single user-friendly platform, saving IT professionals precious time.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

24.3.8 Voyager released

Changes compared to 24.3.7

Enhancements

  • Added configuration to the Comet Server to set the maximum number of CPU cores that are allowed to be used when generating new builds of the Comet Backup client software
  • Added a new environment variable (COMETD_TMPDIR) to allow configuration of the temp directory used by the Comet Server when running in Linux

Bug Fixes

  • Fixed an issue which caused the SEVT_TENANT_UPDATED event to emit the tenant name instead of the tenant ID
  • Fixed an issue where the “Open Folder” button was not visible in the Comet Backup desktop app after a restore job had completed
  • Fixed an issue where the “Open Folder” button in the Comet Backup desktop app failed to open a file browser at the location of the restored files for UNC paths
  • Fixed an issue where S3 backups showed a Object Lock error about enabling Versioning on the S3 bucket instead of the real failure
  • Fixed an issue where audit logs would not be pruned if Authentication Role was set to keep logs indefinitely
  • Fixed an issue where setting “If the last job was Missed” on a schedule triggered extra backup jobs if the device’s live connection dropped while the scheduled job was still running

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

Saily Review: Evaluating the New eSIM App from Nord Security

Here at Nord Security, we take great pride in the fact that we offer a wide range of quality cybersecurity products and services, including NordPass and NordVPN. Each product we deliver has its own identity and is developed by a dedicated team, making it feel like each is a unique division within the company.

This actually allows us to try something a bit out of the ordinary — right now, the NordPass team will give an honest review of Nord Security’s latest product — Saily. Why? Because we’re not shy about critiquing our colleagues’ work. In fact, by sharing constructive criticism, we can all better understand where we stand, which helps us deliver an excellent experience for our users. So, let’s get started.

First things first — what is Saily?

Saily is an eSIM application that allows users to switch between mobile carriers and plans on their devices without dealing with any physical SIM cards. In other words, it enables you to activate a cellular data plan, just like with a traditional SIM card, but without having to buy or insert a new card.

Since no physical SIM cards are involved and everything happens in the app, Saily lets you quickly compare and select data plans from different vendors, so you don’t have to sort through a bunch of SIM card packages and plan details. Basically, it’s meant to be a quick and easy way to switch your mobile carrier whenever you like.

Why would you want to use this app?

While the description itself might already give you some ideas about how Saily could be helpful to you, we will now explore some of the key benefits in more detail.

Saily is designed for anyone traveling to a different country, but it’s especially useful for frequent travelers like business professionals and globetrotters. With Saily, you can keep your phone number and use the app to get as much cellular data as you need during your trip.

For those who need to stay connected while traveling, Saily eliminates the hassle of switching SIM cards or paying for costly international roaming plans. So, for global sales managers, for example, it’s an affordable way to stay in touch with clients and teams almost anywhere they are at the moment. For world travelers, it’s a way to get internet data for maps and guides, helping them make the most of their trips.

How does Saily work?

We were really impressed by how user-friendly the app is. Creating your account is incredibly simple and takes less than a minute. But the best part is how quickly you can switch mobile carriers and choose a plan — it’s just as fast!

The way it works is you browse the list of countries or use the search feature to find a specific one, compare the carriers and plans for that location, pick the one that suits you best, and you’re good to go.

Saily is compatible with both iOS and Android, so you can download the app from the AppStore or Google Play in no time. If you have any service-related questions, there’s a 24/7 customer support chat ready to help. However, the app is so intuitive and easy to use that you’ll probably never need customer support for app-related issues — perhaps only for specific carrier questions.

What about the price of Saily?

According to user feedback from multiple platforms, Saily is among the most cost-effective eSIM apps on the market, offering great value.

First, Saily is available in more than 150 countries and territories, including the United States, Brazil, Australia, Japan, Turkey, and China. Creating a Saily account is free, and the price of your plan depends on the country, carrier, and plan you choose. The most affordable plans start at just $2.49.

Speaking of data plans, Saily offers several options for the carriers in each country. You can choose anything from 1GB for 7 days to 20GB for 30 days, depending on your needs. For payment, you can choose from various options like credit or debit cards, Google Pay, Apple Pay, and PayPal.

Quick summary

  • Functionality

    Changing mobile carriers and selecting different data plans on a device

  • Plans

    Multiple data plans, ranging from 1GB/7 days to 20GB/30 days

  • Cost

    Starting at $1.99

  • Countries

    150+

  • Compatibility

    iOS, Android

  • Support

    24/7 live chat via the app

  • Payment method

    Credit or debit card, Google Pay, Apple Pay, and PayPal

  • Our score

    4.5/5

Saily is an app that does exactly what it is supposed to do. It lets you switch mobile carriers quickly and use data plans to avoid high roaming costs. This means you can access the internet without a hitch, wherever you are. The app is incredibly user-friendly and requires no expert knowledge to get started.

One drawback is that Saily doesn’t offer unlimited data plans for now, so if you’re traveling for more than 30 days or use a lot of data, you might need to buy additional cellular data plans. We hope this will be addressed in the future, but despite this limitation, Saily is an almost perfect app that delivers on its promise. We’re really proud of the team behind it and are excited to see Saily become the next big product in the Nord Security lineup.

Give it a try and form your own opinion

While our Saily review can give you quite a good understanding of what the app does and how it works, there’s nothing quite like experiencing it for yourself. That’s why we suggest you go to the App Store or Google Play, download and install the Saily app on your device, and try it on your next trip. We think you’ll be pleasantly surprised.

Also, while creating a password for your Saily account, remember to make it unique and strong. Consider using NordPass to generate the password and safely store it, along with all your other passwords and passkeys. For more information, visit www.nordpass.com.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

What is the Principle of Least Privilege (PoLP)?

In cybersecurity, the principle of least privilege (PoLP) is a concept that states that a user should have the least amount of access privileges possible to carry out. PoLP aims to squash risks associated with unauthorized access and improve the security perimeter generally.

Today, we’re taking a deeper look at the principle of least privilege. We’re showcasing why PoLP is important, how it relates to zero-knowledge principles and how it can help organizations to further improve their overall security posture.

How does the principle of least privilege work?

Technically speaking, the principle of least privilege, which is deeply embedded in the Zero Trust security philosophy, works by simply limiting a user’s (employees) access rights to certain data, applications, resources, and systems — leaving the user with the least amount of privileges that are needed to do their job. However, before the least access principle can be applied in a business setting, it is critical to first assess user roles and responsibilities, in other words, to pinpoint which access rights and privileges are essential for which users. Once the analysis is complete and users are assigned their appropriate access rights, the next step is the continuous management of these permissions. After all, employees come and go, roles change, and so access rights have to be adjusted accordingly.

Why is the principle of least privilege important?

Let’s look at a hypothetical situation. Say an HR employee has access to the human resources management system to update employee records. But if they also have access rights to access the IT infrastructure, which are not essential for their HR-related tasks, the risk of a full-blown data breach increases significantly in the event their account is compromised.

The hypothetical above showcases the principle of least privilege benefits, which include:

  • Reduce the potential attack surface: Limiting user access privileges means fewer opportunities for bad actors to exploit those privileges.

  • Minimize the impact of exploits: Even if a hacker can gain unauthorized access to the user’s account, the security principle of least privilege confines the possible damage.

  • Come closer to adhering to regulatory frameworks such as GDPR and HIPAA: Regulatory frameworks such as GDPR and HIPAA require strict access controls. By applying PoLP and ensuring users have access only to the information and system essential for their tasks, an organization can get closer to being compliant with various regulations.

  • Improve security within the hybrid work environment: In a hybrid work environment, where employees access systems remotely, maintaining strict access controls becomes even more important. Implementing the principle of least privilege ensures that the security risks associated with remote access are reduced significantly.

Zero Trust vs Least Privilege

Zero Trust is a cybersecurity concept built on another simple idea: never trust, always verify. Unlike the traditional security frameworks, Zero Trust Security assumes that threats can come from within as well as outside the network.

At its core, Zero Trust embodies the principle of least privilege by enforcing strict access controls and permissions. Every access or connection request, regardless of origin, is treated as untrusted until verified otherwise. This stringent verification process is an extension of PoLP’s main idea — to provide users with only the necessary access levels.

In practice, Zero Trust treats every access request as if it’s the first request coming from an untrusted network. Each request is always re-authenticated regardless of previous requests or connections. In this sense, you can think of Zero Trust as a dynamic framework while PoLP can be considered static because it provides users with specific access rights that remain the same unless adjusted.

To make the distinction between Zero Trust and PoLP clearer, let’s imagine a high-end office building. In this case, Zero Trust would be the foundation of the building’s security system, which requires employees, regardless of their position, to use an access card to enter the office building and other facilities. The principle of least privilege, in this scenario, could be likened to the specific programming of access cards based on the employee’s role: for instance, providing the IT staff with access to server rooms, while not granting the same privileges to, say, the marketing team.

What is Privilege Creep?

Privilege creep is a term that refers to a user that gradually accumulates more access rights than are required to execute their function. Privilege creeps most often come into being due to role changes that do not trig

ger an adjustment concerning access privileges. When thinking about organizational cybersecurity, privilege creeps pose a serious risk where unauthorized access to a single account could lead to an enterprise-wide data breach.

Here are best practices when it comes to the principle of least privilege, helping to prevent privilege creeps from materializing:

  • Implement role-based access controls: Clearly define roles and associated permissions to make sure access rights are granted based on the necessities of the job.

  • Conduct regular access reviews: Schedule periodic reviews of user privileges to identify and rectify any discrepancies or excessive access rights.

  • Enforce a Zero-Trust security approach: Adopt a zero-trust policy where no user is trusted by default. Verify every access request, regardless of the user’s position within the organization.

  • Make use of automated tools: Leverage automation for managing access rights. Tools like Privileged Access Management (PAM) systems can help in monitoring and controlling access rights efficiently.

  • Promote security awareness: Educate employees about the risks of privilege creep and the importance of adhering to cyber security protocols.

By proactively managing user permissions and educating employees, you can significantly mitigate the risk of privilege creep and enhance your organization’s overall security posture.

How to Implement the Least Privilege Principle in Your Organization

Adopting the principle of least privilege in your organization can be a lengthy process; however, the juice is well worth the squeeze. Once your organization operates under PoLP, the potential attack surface will shrink significantly. Here are a few best practices when it comes to the implementation of PoLP:

  • Define access requirements clearly: Before adopting the principle of least privileges in your organization, you need to have a clear understanding of the data access needs of various roles within the organization.

  • Implement Role-based access control (RBAC): Once you have a clear understanding of access requirements, setting up RBAC will be a lot easier. You’ll need to create roles based on job functions and assign permissions to these roles rather than for individual users.

  • Utilize Just-In-Time (JIT) privilege access: Enhance security by granting time-limited privileges on a need-to-use basis. Establishing JIT access privileges will restrict the window of opportunity for access to sensitive data, minimizing the risk of insider threats or external breaches that would exploit user access privileges.

  • Enforce Multi-factor authentication (MFA) and password policies: Strengthen the authentication processes by establishing MFA as an additional layer of security next to company-wide password policies. MFA ensures that even if the password of a critical account is compromised, the attackers will not have a chance to access it as they will not have another authentication factor required.

  • Implement system monitoring: Establish surveillance of system and user activities to quickly identify and respond to abnormal access patterns or potential security incidents.

How can NordPass help?

These days, when access points seem to multiply as fast as potential security threats, adopting the principle of least privilege within a business setting should be a no-brainer. PoLP implementation can reduce, quite significantly, the organization’s attack surface and generally improve overall cybersecurity. There’s also the added benefit of coming closer to compliance with various regulatory frameworks such as HIPAA or GDPR.

While the adoption of PoLP can be challenging, there are tools that can make this a lot easier and NordPass Enterprise is one of them. It’s an enterprise-grade password manager that’s built on the principle of the Zero-Knowledge architecture and is equipped with the XChaCha20 encryption algorithm.

But that’s just the tip of the iceberg. NordPass’s integration with Single Sign-On (SSO) is a key asset in adopting PoLP. By allowing users to use a single set of credentials to access multiple resources, SSO simplifies authentication and enhances security. NordPass Enterprise is compatible with major identity providers such as Microsoft Azure AD, MS ADFS, and Okta. This centralized management system is effective in preventing unauthorized access and minimizing potential security breaches by assigning user access based on specific roles.

NordPass also helps organizations in managing user access effectively. It allows administrators to assign, revoke, or modify user access to login credentials, personal information, payment card data, and other sensitive data according to specific needs. This flexibility, powered by the Activity log feature, is critical when adopting PoLP. Thanks to this functionality, you can easily adjust access rights in response to changes in roles or employment status.

Learn more about how NordPass Enterprise can benefit your organization’s overall security strategy by visiting the official NordPass Enterprise website.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.