Skip to content

Dope security puts a new spin on secure web gateways

Need to secure non-human entities, leaky clouds, and complex environments? The companies included in our network security startups to watch series have bold ideas.

dope.security is one of Network World’s 7 network security startups to watch for 2024. It rearchitected the traditional secure web gateway (SWG) to avoid routing traffic through cloud data centers. By performing security directly on the endpoint instead of routing traffic through stopover data centers, dope.security says its SWG can boost network performance fourfold.

dope.security at a glance

  • Founded: 2021
  • What they do: Provide secure web gateways (SWG)
  • Funding: $20 million
  • Headquarters: Mountain View, California
  • CEO: Kunal Agarwal
  • Competitors include: Forcepoint (through its acquisition of Websense),
  • Netskope,Symantec (through its acquisitions of Blue Coat), and Zscaler
  • Customers include: Plansource and Success Academies

Why dope.security is a startup to watch:
Cloud security risks are numerous and growing. According to ICS2’s 2024 Cloud Security Report, 96% of organizations are worried about public cloud security, and more than half (55%) consider securing multi-cloud environments as their top challenge.

Many legacy security solutions don’t have the ability to fully investigate and respond to cloud and SaaS threats. Conversely, cloud-native security solutions tend to force enterprises to route traffic through cloud data centers, which sacrifices network performance.

dope.security intends to improve cloud security and performance by rethinking legacy secure web gateway (SWG) design, removing a stop between enterprise resources and end users. The startup uses airline terminology to drive home the point, calling its architecture “fly direct.” dope.security’s SWG architecture eliminates stopovers at cloud data centers, which the startup says improves performance up to fourfold.

Instead, dope.security’s SWG performs security directly on the endpoint, including URL filtering, SSL inspection, and cloud app control. Dope.security also provides AI-powered Cloud Access Security Broker (CASB) services, including Data Loss Prevention (DLP), SaaS Security Posture Management (SSPM), and contextual analysis of an organization’s publicly exposed data.

The startup has raised a total of $20 million in VC funding. Its most recent round closed in March 2023, a $16 million Series A round led by Google Ventures (GV), with participation from existing investors boldstart ventures and Preface.

About Dope Security
A comprehensive security solution designed to protect individuals and organizations from various cyber threats and vulnerabilities. With a focus on proactive defense and advanced technologies, Dope Security offers a range of features and services to safeguard sensitive data, systems, and networks.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Amazon passkey: What it is and how to set it up on your account

Welcome to the passwordless era

Passwords are on the brink of retirement. They have served us well as an authentication method for a long time, no doubt about that. But like all technologies, they are being replaced by the next best thing. Right now, that thing is password-free authentication, already adopted by companies like Amazon, Google, and Apple to allow their customers to log in to their services quickly and securely without passwords.

Other organizations are expected to follow in the footsteps of the big players, especially since they can use free tools like Authopia by NordPass to effortlessly add a passkey-based login option to their website or service. The term “passkey-based” is pivotal here. What exactly are passkeys, and why are they considered the successor to passwords? Let’s dive in and find out.

What are passkeys?

Simply put, passkeys are a new authentication method that allows users to log in to their accounts on websites or services without using passwords. It relies on cryptography to provide secure authentication—sets of cryptographic keys, to be exact. One key, known as the “public” key, is stored on a server, while the other, the “private” key, remains on the user’s device. During the login process, the key from the user’s device is verified against the key stored on the server. If the two keys match, the user is granted access to the account.

Since the keys are generated by the system, there’s no need to remember them, which makes the technology much more user-friendly compared to passwords. Moreover, because encryption is used, passkeys offer greater security than even the longest and most complex passwords can provide.

How to enable Amazon passkeys

Setting up passkeys on your Amazon account is a straightforward process that can be completed in just a few minutes. However, the steps vary slightly depending on whether you are using a desktop or a mobile device. Let’s now review the setup process for both options.

Setting up passkeys via the Amazon website (desktop)

  1. Open your web browser and go to amazon.com.

  2. Access your account settings and scroll down to the “Login & Security” section.

  3. Find the option for “Amazon Passkeys” or “Two-Step Verification.”

  4. Follow the on-screen instructions to set up your passkey settings.

  5. Confirm the setup by scanning a QR code displayed on your computer screen with your mobile device, and authenticate using your mobile device’s biometric features.

  6. To verify that everything is set up correctly, log out and log back in using your newly set passkeys.

Setting up passkeys via the Amazon app (mobile)

  1. Launch the Amazon app on your iPhone, iPad, or Android device.

  2. Tap the menu icon and navigate to “Account.”

  3. Select “Login & Security.”

  4. Click on “Set Up” next to the “Passkey” option.

  5. Follow the prompts on your device to authenticate using your fingerprint or facial recognition.

How to sign in with an Amazon passkey

Once enabled, using passkeys to log into your Amazon account is super easy. All you have to do is:

  1. Visit the Amazon website and open the account login form.

  2. Enter your email or mobile number.

  3. Instead of entering your password, click on “Sign in with Amazon passkey.”

  4. Enter your passkey, for example, by using a biometrics scanner on your device.

  5. You’re securely logged in!

How to delete your Amazon passkey

If for some reason you would like to delete your Amazon passkey, you need to go back to your account settings and navigate to the “Login & Security” section. Once there, select the active passkey and click on “Delete.” When you confirm your choice, your passkey will be removed and your account will revert to the traditional password login option.

Can you use Amazon passkeys on multiple devices?

As a matter of fact, yes, Amazon passkeys can be used on multiple devices. Once you enable a passkey, it’s stored in your cloud service account, so you can use it across all linked devices. Therefore, when you access Amazon from another device using the same cloud service account, the passkey should automatically appear as a login option.

Effectively store and manage your passkeys with NordPass

If you want to be passwordless and start using passkeys to log in to your Amazon and other accounts, you need a solution that will allow you to store and manage your passkeys effectively. One such solution is NordPass.

Although primarily known as a password manager, NordPass fully supports passkeys and was one of the first tools of its kind to do so. This means you can now use it to create, store, and manage your passkeys with ease, significantly improving your login experience in terms of both security and convenience.

In other words, NordPass allows you to keep all your passkeys in an encrypted vault accessible only to you. And since NordPass is available on Android and Apple devices, you can quickly access your passkeys anytime, from any device.

So, if you’re ready to move away from traditional passwords and embrace the latest passwordless technology, NordPass can help you get started. Give it a try and see the difference for yourself.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

Scale Computing Pumps Ease of Edge Computing into Convenience & Fuel Retail Industry, Announces New Customer Royal Farms

Scale Computing Pumps Ease of Edge Computing into Convenience & Fuel Retail Industry with Innovative Technology and Ecosystem Partners, Announces New Customer Royal Farms 

August 6, 2024 – INDIANAPOLIS, IN – Scale Computing, a market leader in edge computing, virtualization, and hyperconverged solutions, announced today its latest success in the convenience and fuel retail industry, with new customer Royal Farms. With a focus on innovation and collaboration, Scale Computing is revolutionizing the landscape of IT infrastructure in this sector by delivering a single platform for unparalleled performance, reliability, and ease of use for the deployment, management, and growth of on-premises applications like POS, IoT, pump monitoring, video surveillance, and customer experience.

Royal Farms is a renowned operator of fast and friendly neighborhood convenience stores with 260 locations throughout Maryland, Delaware, Virginia, Pennsylvania, West Virginia, and New Jersey. Most locations are open 24 hours, 365 days a year. To keep those stores open and productive at all times, Royal Farms wanted to run their applications in a fully integrated platform with the following industry-leading features:

  • High Availability: Scale Computing HyperCore (SC//HyperCore) technology ensures uninterrupted operations and optimal performance, introducing high availability even in the most demanding and remote environments.
  • Ease of Use: Scale Computing Fleet Manager (SC//Fleet Manager) simplifies IT infrastructure management tasks, providing retailers with a centralized interface to oversee their application infrastructure at the distributed edge effortlessly.
  • Speed of Deployment: Scale Computing Platform (SC//Platform) enables rapid deployment across hundreds and thousands of stores, streamlining operations and driving efficiency.
  • Scalability: Simply mix and match old and new hardware and applications on the same infrastructure for a future-proof environment that can scale up or down as needed.

Another reason Royal Farms selected Scale Computing is its Scale Computing Fleet Manager, the first cloud-hosted monitoring and management tool built for hyperconverged edge computing infrastructure at scale. It allows customers to quickly identify areas of concern using a single pane of glass, scaling from 1 to over 50,000 clusters. Zero-touch provisioning and Secure Link features allow administrators to centrally and securely monitor and manage hundreds or thousands of distributed edge infrastructure deployments, with few or no on-site IT personnel. This is exactly what Royal Farms needed.

“Our focus is to be available to our customers whenever they need us. Downtime is not an option, nor is having IT personnel available at our sites. We need to be able to centrally monitor and manage the applications at our stores so that we can deliver the experience our customers have come to expect,” said Jesse Wolcott, IT Infrastructure Manager, Royal Farms. “We were challenged with updating outdated IT infrastructures, fragmented systems, and manual processes and wanted a completely modern solution. Scale Computing is helping us optimize operations, enhance customer experiences, and achieve unparalleled scalability and adaptability in a rapidly evolving industry.”

SC//Platform is being delivered across all Royal Farms locations on small form factor NUC hardware provided by Simply NUC. The integration partnership between Simply NUC and Scale Computing provides ease of doing business for distributed enterprises on right-sized hardware for size constrained locations. Simply NUC is the leader in the small form factor hardware industry and continues to innovate alongside Scale Computing for expanded edge computing offerings.

Advancing growth in this industry vertical is Scale Computing’s strategic alliance partnership with Mako Networks to address easier edge networking and PCI compliance challenges for the distributed enterprise. Scale Computing and Mako Networks partner to offer edge computing and edge networking management with strong customer support that fuels bottom line growth for these locations. Mako Networks technologies helps bridge the gap and secure networking with features like:

  • Payment Card Industry Data Security Standard (PCI DSS)
  • Software-Defined Wide Area Network (SD-WAN)
  • Next-Generation Firewall (NGFW)
  • Intrusion Detection and Prevention (IDS/IPS)

Scale Computing has also established OEM partnerships with industry leader DUMAC, who is providing fully virtualized solutions for Point of Sale (POS) systems. With the knowledge, expertise and services teams that understand the convenience and fuel retail market, DUMAC is delivering a fully integrated, easy to use solution that supports thousands of stores and can be managed with minimal IT overhead. DUMAC partners with both Scale Computing and Mako Networks and continues to innovate for leading brands with these strategic technology relationships that have been developed.

“We are excited to bring our innovative technology and strategic partnerships to customers like Royal Farms in the convenience and fuel retail industry,” said Jeff Ready, CEO at Scale Computing. “With our platform’s unmatched capabilities and ecosystem partners, we are empowering distributed retailers to embrace the future of edge computing, driving efficiency, compliance, and profitability.”

For more information about Scale Computing’s solutions for the convenience and fuel retail industry, visit https://www.scalecomputing.com/scale-computing-for-convenience-and-fuel-retail-stores.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

10 steps to train employees on cybersecurity

Data breaches usually start with an employee mistake. Someone may click a dangerous link or send data via an unprotected connection. Soon, that error becomes a crisis. Websites fail, customer data spreads across the Dark Web, and regulators become involved.

Most of the time, all of this can be avoided. Proper cybersecurity training and cybersecurity tabletop exercise tools prepare staff to deal with threats.

The shocking thing is that almost one-third of US companies don’t provide cybersecurity training for employees. Worse still, over half of SMBs have no cybersecurity plan at all.

Don’t follow their example. Create a cybersecurity awareness training program that educates employees and puts security policies into action.

This article will explain how to raise cybersecurity awareness across your organization. So pull a chair up to the whiteboard as we deliver our 10-step cybersecurity training roadmap.

Key takeaways

  • Raising cybersecurity awareness is a vital business goal. Start by building a foundation. Create comprehensive cybersecurity policies and aim to ensure every employee is aware of their security role.

  • Cybersecurity training should focus on urgent data security threats. List relevant risks and train employees to identify and minimize them.

  • Device security awareness training is critical–especially in companies that rely on remote workers. Train employees to secure devices from digital and physical threats.

  • Educating employees on password security is a priority. Most cybersecurity breaches target weak credentials. Ensure staff know how to use strong passwords and access network assets safely.

  • Focus training on confidentiality and data protection. Define company data and instruct employees how to handle data securely. This includes regular backups, secure storage, and tools like Virtual Private Networks (VPNs).

  • Update training programs annually. Cybersecurity threats evolve, and training should keep pace. Refresh employee knowledge, taking advantage of free cybersecurity training when possible.

Cybercrime targets human error key stats

Step 1: Ensure employees understand their cybersecurity role

Cybersecurity training must include every employee, no matter how junior (or senior). Every network user must be aware of their security responsibilities. Communicate that one slip-up or policy breach can lead to data theft and regulatory action.

Guide employees on how to meet security requirements. For instance, you may require a VPN and Secure Remote Access for remote workers. Inform staff how to report security issues and reassure them. Reporting accidental policy breaches is a good thing–not something to fear.

Step 2: Create watertight data security policies

Cybersecurity training rests on comprehensive and easy-to-follow security policies. Create formal policies on handling confidential data, incident response, password management, remote work, and other relevant areas.

Security awareness training should cover employee knowledge of security policies. But one-time testing is not enough. Schedule regular meetings to discuss policies. Test knowledge annually to ensure staff remain aware of policy requirements.

Remember: policies are worthless if they are just documents. They need to be part of everyday professional practice. Make policies available in a central library for staff to access, and double-check the language to avoid technical jargon.

Step 3: Train employees to identify data security threats

Cybersecurity training can’t necessarily create an army of technical experts, but raising overall awareness is vital. Well-trained employees understand cyber threats and know how to prevent or mitigate them.

Train staff to identify email phishing, fake websites, insecure document transmission, and the risks of using unsecured public Wi-Fi. Make it clear that adding unauthorized software to the network is out of bounds.

Real-life examples help employees understand the nature of cyber threats. For example, sessions could include visual material on pop-ups, sudden device slow-downs, or unrequested browser extensions.

Above all, employee training must communicate the consequences of cyber-attacks and emphasize the need to follow security policies. By educating staff, you build a human firewall that adds an extra layer of defense against attackers.

This is a critical point and a key recommendation in Gartner’s 2024 Cybersecurity Trends Report. Human firewalls complement technology by changing employee behavior to mitigate potential threats. Properly-educated employees understand the threat reporting process. Training involves everyone in network protection efforts. A human firewall of engaged employees is much more likely to identify cybersecurity problems before a data breach occurs.

Gartner review

Step 4: Tighten up your password hygiene

Weak, rarely-changed passwords often expose businesses to information security threats. Robust password policies are the only reliable protection.

Don’t assume employees understand password risks. Two-thirds of Americans re-use passwords across accounts. Up to 80% of data breaches result from easily guessed or stolen passwords. People tend to be lazy about password hygiene. Don’t give them that option.

Instead, consider assigning passwords to employees and rotating these passwords regularly. Train staff and password managers to use strong passwords. Add multi-factor authentication to network logins and ensure employees know how to use it.

Step 5: Fine-tune device security

Training employees on cybersecurity must cover device security. Remote and off-site staff often rely on mobile devices. If a device contains sensitive data or allows network access, security policies apply.

Take action to minimize the risk of device loss. Mandate separate work and personal devices when cybersecurity risks are high. Include training modules explaining the difference between personal and business use.

Cybersecurity training should cover physically securing devices and protecting remote connections. It’s also wise to use remote monitoring tools and inform employees that their business accounts are transparent.

Step 6: Make sure employees backup critical data

Employees must back up company data, preferably every day. During employee training, make it clear that local backups are insufficient. Employee devices are vulnerable to theft or external attacks. Instead, use secure cloud storage systems to hold critical documents or customer data.

Step 7: Put in place authorization and access management systems

Authorization and authentication technology should always shield central data centers and cloud-hosted apps. However, it’s important to instruct employees in proper access security practices.

For instance, employees should never share work devices with colleagues or external individuals without authorization. Writing down passwords or authentication codes is out of the question. Adding new devices without agreement from network admins should also be prohibited.

Sometimes, employees complain about time-consuming authorization systems. Outflank those issues by explaining why MFA and VPNs are so important. When they know what is at stake, employees will quickly adopt secure access routines.

Step 8: Ensure secure web development and website updating

SQL and web application exploits are common security breach vectors, making secure coding a vital element of cybersecurity awareness training.

Deliver a secure training program to every staffer with access to web backends and coding tools. Even those without direct coding responsibilities can allow access to attackers. If employees update web assets in any way, they must do so safely.

Authorization is also important. Employees should know who is authorized to change web code or update websites and how to request permission to make changes.

Step 9: Make sure employees use email securely

Email is another critical weak point in business cybersecurity. Cybersecurity awareness training should help employees spot potential threats like phishing attempts and links to suspicious websites.

If necessary, test employee competence with phishing simulations that generate false social engineering emails. Simulations are great because they prove users can spot dangerous messages from authentic business communications.

Separate training applies if employees use email to transmit sensitive information. In these cases, ensure workers use VPNs and email encryption to safeguard data.

It should go without saying, but you should also test employees on what constitutes “sensitive data.” Many email users send confidential information via unsafe personal accounts, and that should end when they understand how you classify information.

Step 10: Update your training program regularly

Cybersecurity awareness tends to wane after a few months. Around 10% of employees say they remember all of their cybersecurity training. The other 90% have likely drifted back to unsafe passwords or unsecured remote connections.

Refreshing cyber security training is the only viable solution, but it can be challenging for businesses with a limited security awareness budget.

However, refreshing knowledge does not need to be expensive. Cybersecurity awareness training often costs virtually nothing if you know where to look.

Keep costs low by checking out free cybersecurity training listed at the National Institute for Science and Technology (NIST). For example:

  • The Cisco Networking Academy offers 6 hours of free cybersecurity training covering all core themes.

  • Evolve Academy provides free cybersecurity awareness training focused on practical technical skills.

  • Microsoft Technologies Training offers refresher courses to boost information security awareness when using Microsoft products.

These are just a few of many free or low-cost cybersecurity education options. You can also listen to podcasts about security awareness. Combine external courses with internal training to manage cybersecurity costs.

How can NordLayer help?

Companies are never alone when delivering cyber security awareness training, so don’t feel isolated. Instead, work with trusted partners like NordLayer to build internal knowledge and upskill your workforce.

NordLayer’s Learning Center is the perfect bookmark for trainers and employees. Use our accessible security checklists and in-depth explainers to understand concepts and tick off cybersecurity tasks. And stay on top of emerging threats thanks to cutting-edge intelligence.

It also helps to add video elements to training sessions. In that case, explore NordLayer’s YouTube channel. Our channel covers cybersecurity essentials like device posture security and secure remote access—supplementing tests and in-person training.

Whatever you do, don’t struggle alone. Share the cybersecurity challenge by enlisting expert assistance. If you’d like to find out more, get in touch with NordLayer today. We’ll help you find the right training and security solutions.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

Adapting to the Remote Work Era: Improving Efficiency and Strengthening Cybersecurity

Over the past few years, there’s been a major shift in how work gets done. Working from home is becoming the new normal, not just a rare exception. This shift has reshaped our views on efficiency and work-life balance, driven by advancements in technology and world-changing events like the COVID-19 pandemic.

Remote work offers numerous benefits:

  • Cost Savings: Firms reduce overhead with no need for large offices, saving on rent and utilities.
  • Greater Autonomy: Employees enjoy more control over their schedules, enhancing satisfaction.
  • Improved Work-Life Balance: Flexibility enables better management of personal and professional life.
  • Increased Productivity: Studies show remote workers are more productive in quiet, private settings.
  • Environmental Impact: Reduced commuting lowers carbon emissions, promoting sustainability.
  • Global Talent Access: Businesses can recruit top talent worldwide, expanding their reach.

However, the return to the office has been met with considerable friction from employees who have gotten used to remote work flexibility. Case in point: what Amazon is having to wrangle with right now is something dubbed ‘coffee badging.

More than a year ago, Amazon announced its new policy on #RTO (#returntooffice), requiring employee presence in the office for at least three days per week, after a period of remote work precipitated by COVID-19. The response of employees has been very fast and negative; at this moment, more than 30,000 people have signed a petition against this mandate.

The employees began to engage in a very creative form of resistance by ‘coffee badging’: they would scan their badges, check into the system, enter the office, drink a cup of coffee, and then leave. Since duration of office presence was not specified in the first policy, it made the company later update it to state that an employee has to spend at least two hours in the office during each visit

Of course, there are many individuals who are enthusiastic about returning to the office. However, the opinions of the 30,000 Amazon employees who signed the petition reflect a significant segment of the workforce that prioritizes the benefits of remote work.

In addition, the shift to remote work has introduced fresh challenges for businesses aiming to safeguard sensitive information. With employees operating beyond traditional office settings, companies face the task of securing data access effectively. The rise in cyber threats due to remote work settings has heightened cybersecurity risks associated with remote access to unprotected networks and personal devices. This necessitates implementing robust security measures to mitigate these cybersecurity risks. Risks emerge from employee devices, home Wi-Fi networks, and unfamiliar third-party applications, necessitating innovative approaches to monitoring and management. Maintaining robust security protocols is crucial amidst this evolving work landscape.


5 Cybersecurity Challenges of Remote Work and How to Overcome These Cybersecurity Challenges

1. Phishing Scams: Remote workers can easily fall for phishing scams, where scammers send fake emails to steal company data. These emails might trick employees into giving away login details or downloading malware. To keep your team safe, host regular training sessions that make learning how to spot these scams fun and engaging. Teach them to recognize sketchy emails and avoid risky actions.

2. Unprotected Connections: One big headache in any remote job is the risk of insecure networks. Public Wi-Fi is like a playground for hackers; that makes the important company data prone when an employee logs in to one of those. Solution: Always use a VPN to get company information; it’s like giving your data a secret passageway. Additionally, implementing multi-factor authentication (MFA) provides an extra layer of security, ensuring secure remote access and protecting accounts from unauthorized access.

3. Device Control: When remote workers use their personal devices to access company data, it can spell trouble for the organization’s security. Installing endpoint security software on these personal devices is crucial to identify and prevent malware infiltration. A proper device management strategy will go a long way to assist in the monitoring of which specific devices are plugging into company information, thus increasing the risks related to data breaches. Establishing robust security measures to monitor and manage these devices will be the foundation in making sure that the data will be safe and remain unexposed.

4. Lack of Monitoring: Remote employees are not physically present in the office, which makes it difficult to monitor their cyber activities. Without the necessary monitoring checks, it becomes challenging to detect any potential threats or attacks. Establish proper monitoring measures to ensure that all systems and networks are secure and are continuously monitored. Implementing a content filtering solution can also help by restricting access to potentially harmful websites and ensuring that employees adhere to company policies on internet usage. The unique risks associated with a remote work environment and remote work environments necessitate tailored security solutions to effectively protect sensitive information.

5. Cloud Safeguarding: Cloud security is another significant concern for remote workers. Cloud providers typically offer several security features and protocols, but it’s essential to ensure that these features are adequate to meet your data security standards. Evaluate cloud providers before making a choice to ensure that they have the necessary security protocols in place. Protecting sensitive data in the cloud is paramount, and organizations must ensure that robust security measures are in place to safeguard this information.

To enhance productivity and protect organizational data, we recommend using content filtering solutions. These tools help in safeguarding against malicious websites and online threats while managing internet usage within the company. By filtering out non-work-related content, content filtering solutions ensure that employees stay focused on their tasks, reducing distractions and increasing overall productivity.

Here’s how SafeDNS can help:

  • Strengthen Security: Help protect your company’s network and employees from all internet threats with our cloud-based content filtering solution. SafeDNS adds an important layer of web filtering to help manage human error and make your cybersecurity stronger.
  • Boost Productivity & Monitor Traffic: SafeDNS puts you in charge of internet access at your company. You can block unnecessary sites and limit access to just what your team needs to get their work done. This cuts down on distractions and keeps everyone following company rules.
  • Next-Generation Protection Using ML & AI: SafeDNS uses the latest in AI and Machine Learning to provide exceptional security. Since 2015, our solution has been updating its database continuously with new online threats and inappropriate content to block them as they appear. In this way, it keeps your data and network safe against ever-changing risks, always one step ahead.

Want to experience it yourself? Try SafeDNS with a free trial here.

To wrap up, remote work isn’t just a trend—it’s a massive shift in how business goes on. More people are working from home now, so the need to strike a balance between efficiency and cybersecurity has become very important. This very article was crafted by someone working remotely, which goes to show just how pervasive this change really is. The digital age of remote work requires modern tools and strategies for any business to remain safe and productive.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SafeDNS
SafeDNS breathes to make the internet safer for people all over the world with solutions ranging from AI & ML-powered web filtering, cybersecurity to threat intelligence. Moreover, we strive to create the next generation of safer and more affordable web filtering products. Endlessly working to improve our users’ online protection, SafeDNS has also launched an innovative system powered by continuous machine learning and user behavior analytics to detect botnets and malicious websites.

How runZero speaks to the TwinCAT 3 Automation Device Specification (ADS) Protocol

In the realm of industrial automation, communication protocols play a crucial role in ensuring seamless interaction between various components and systems. One such protocol in the TwinCAT 3 ecosystem is the Automation Device Specification (ADS) protocol. Developed by Beckhoff Automation, ADS is integral to the TwinCAT 3 software suite, facilitating robust and efficient communication between different automation devices.

What is ADS?

The Automation Device Specification (ADS) protocol is a communication protocol designed to enable interaction between TwinCAT 3 automation devices. ADS functions as a gateway for data exchange and command execution between software applications and hardware components. It operates over TCP/IP networks, ensuring reliable and real-time communication. Both TCP and UDP are supported by the protocol as well as a secure version called Secure ADS which uses TLSv1.2 to secure the TCP connection.

The Role of ADS in TwinCAT 3

TwinCAT 3 leverages ADS to connect its various components. Within this environment, ADS facilitates communication between the TwinCAT runtime, PLCs, and HMI systems. By providing a standardized interface for data exchange, ADS simplifies the integration of different elements within the TwinCAT ecosystem. This integration capability is instrumental in developing sophisticated automation solutions that require interaction between multiple devices and software modules.

runZero Speaks ADS

The runZero research team has been working hard to increase the OT protocols available in runZero. We recently added the ADS protocol for passive scanning to identify devices that speak ADS. We have a very good understanding of the OSI model so we have started layering in support for any of these Ethernet-based protocols.

After reviewing the ADS specification we discovered that it operates on TCP port 48898 and UDP port 48899. By adding these ports to our broader global ports list we can start to decode the new traffic and identify the communicating devices. Although we see all of the traffic on those ports, we are only interested in a very specific packet to identify devices. The ADS specification outlines a ReadDeviceInfo command (Figure 1) which would tell us the version, build, and name of the device.

FIGURE 1 – ReadDeviceInfo packet layout courtesy of Beckhoff Automation LLC

If the packet is successfully decoded into this command we can assert that it is a legitimate device since the packet originated on the documented ports above. This gives us a high degree of confidence to continue fingerprinting this device and place it into your asset inventory.

As industrial automation continues to evolve, so too will the ADS protocol. Future developments may include enhancements to support emerging technologies such as IoT and Industry 4.0. There is potential for increased integration with cloud-based systems and advanced analytics, further expanding the capabilities of ADS. Staying abreast of these trends will be essential for us to further improve our fingerprinting capabilities as this protocol makes its way into other domains outside of industrial automation.

Subscribe now to stay up to date on runZero support for discovery of OT protocols.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

MELT: Understanding Metrics, Events, Logs and Traces for Effective Observability

The infrastructure must be “invisible” to the user, but visible to IT strategists to ensure the performance and service levels required by the business, where observability (as part of SRE or site reliability engineering) is essential to understand the internal state of a system based on its external results. For effective observability, there are four key pillars: metrics, events, logs, and traces, which are summarized in the acronym MELT 

Next, define each of these pillars.

 

Metrics

What are Metrics?

They are numerical measures, usually periodic, that provide information about the state of a system and performance.

Examples of useful metrics

Response times, error rates, CPU usage, memory consumption, and network performance.

Advantages of using metrics

Metrics allow IT and security teams to track key performance indicators (KPIs) to detect trends or anomalies in system performance.

Events

What are Events?

They are discrete events or facts within a system, which can range from the creation of a module to the login of a user in the console. The event describes the problem, source (agent), and creation.

Event examples in systems

User actions (user login attempts), HTTP responses, changes in system status, or other notable incidents.

How events provide context

Events are often captured as structured data, including attributes such as timestamp, event type, and associated metadata, providing greater elements and information to the IT team to understand system performance and detect patterns or anomalies.

Logs

What are logs?

They are detailed records of events and actions that take place in a system. Also these collected data provide a chronological view of system activity, offering more elements for troubleshooting and debugging, understanding user behavior, and tracking system changes. Logs can contain information such as error messages, stack traces, user interactions, notifications about system changes.

Common log formats

Usually, logs use plain format files, either in ASCII type character encodings or stored in text form. The best known formats are Microsoft IIS3.0, NCSA, O’Reilly or W3SVC. In addition, there are special formats such as ELF (Extended Log Format) and CLF (Common Log Format).

Importance of centralizing logs

Log centralization ensures a complete and more contextualized system view at any time. This allows you to proactively spot problems and potential problems, as well as take action before they become bigger problems. Also this centralization allows to have the essential elements for audits and regulatory compliance, since compliance with policies and regulations on safety can be demonstrated.

Traces

What are Traces?

Traces provide a detailed view of the request flow through a distributed system. This is because they capture the path of a request as it goes through multiple services or components, including the time at each step. That way, traces help to understand dependencies and potential performance bottlenecks, especially in a complex system. Also traces allow to analyze how system architecture can be optimized to improve overall performance and, consequently, the end user experience.

Examples of traces in distributed systems

  • The interval or span is a timed, named operation that represents a portion of the workflow. For example, intervals may include data queries, browser interactions, calls to other services, etc.
  • Transactions may consist of multiple ranges and represent a complete end-to-end request that travels across multiple services in a distributed system.
  • The unique identifiers for each, in order to track the path of the request through different services. This helps visualize and analyze the path and duration of the request.
  • Spreading trace context involves passing trace context between services.
  • Trace display to show the request flow through the system, which helps identify failures or performance bottlenecks.

Also, traces provide detailed data for developers to perform root cause analysis and with that information address issues related to latency, errors, and dependencies.

Challenges in trace instrumentation

Trace instrumentation can be difficult basically because of two factors:

  • Each component of a request must be modified to transmit trace data.
  • Many applications rely on libraries or frameworks that use open source, so they may require additional instrumentation.

Implementing MELT in Distributed Systems

Adopting observability through MELT involves Telemetry; that is, automatic data collection and transmission from remote sources to a centralized location for monitoring and analysis. From the data collected, the principles of telemetry (analyze, visualize and alert) must be applied to build resilient and reliable systems.

Telemetry Data Collection

Data is the basis of MELT, in which there are three fundamental principles of telemetry:

  • Analyzing the collected data allows obtaining important information, relying on statistical techniques, machine learning algorithms and data mining methods to identify patterns, anomalies and correlations. By analyzing metrics, events, logs, and traces, IT teams can uncover performance issues, detect security threats, and understand system performance.
  • Viewing data makes it accessible and understandable to stakeholders. Effective visualization techniques are the dashboards, charts, and graphs that represent the data clearly and concisely. In a single view, you and your team can monitor system health, identify trends, and communicate findings effectively.
  • Alerting is a critical aspect of observability. When alerts are set up based on predefined thresholds or anomaly detection algorithms, IT teams can proactively identify and respond to issues. Alerts can be triggered based on metrics that exceed certain limits, events that indicate system failures, or specific patterns in logs or traces.

Aggregate Data Management

Implementing MELT involves handling a large amount of data from different sources such as application logs, system logs, network traffic, services and third-party infrastructure. All of this data should be found in a single place and aggregated in the most simplified form to observe system performance, detect irregularities and their source, as well as recognize potential problems. Hence, aggregate data management based on a defined organization, storage capacity, and adequate analysis is required to obtain valuable insights.
Aggregating data is particularly useful for logs, which make up the bulk of the telemetry data collected. Logs can also be aggregated with other data sources to provide supplemental insights into application performance and user behavior.

Importance of MELT in observability

MELT offers a comprehensive approach to observability, with insights into system health, performance, and behavior, from which IT teams can efficiently detect, diagnose, and solve issues.

System Reliability and Performance Improvements

Embracing observability supports the goals of SRE:

  • Reduce the work associated with incident management, particularly around cause analysis, by improving uptime and Mean Time To Repair (MTTR).
  • Provide a platform to monitor and adapt according to goals in service levels or service level contracts and their indicators (see What are SLAs, SLOs, and SLIs?). It also provides the elements for a possible solution when goals are not met.
  • Ease the burden on the IT team when dealing with large amounts of data, reducing exhaustion or overalerting. This also leads to boosting productivity, innovation and value delivery.
  • Support cross-functional and autonomous computers. Better collaboration with DevOps teams is achieved.

Creating an observability culture

Metrics are the starting point for observability, so a culture of observability must be created where proper collection and analysis are the basis for informed and careful decision-making, in addition to providing the elements to anticipate events and even plan the capacity of the infrastructure that supports the digitization of the business and the best experience of end users.

Tools and techniques for implementing MELT

  • Application Performance Monitoring (APM): APM is used to monitor, detect, and diagnose performance problems in distributed systems. It provides system-wide visibility by collecting data from all applications and charting data flows between components.
  • Analysis AIOps: These are tools that use artificial intelligence and ML to optimize system performance and recognize potential problems.
  • Automated Root Cause Analysis: AI automatically identifies the root cause of a problem, helping to quickly detect and address potential problems and optimize system performance.

Benefits of Implementing MELT

System reliability and performance requires observability, which must be based on the implementation of MELT, with data on metrics, events, logs, and traces. All of this information must be analyzed and actionable to proactively address issues, optimize performance, and achieve a satisfactory experience for users and end customers.

Pandora FMS: A Comprehensive Solution for MELT

Pandora FMS is the complete monitoring solution for full observability, as its platform allows data to be centralized to obtain an integrated and contextualized view, with information to analyze large volumes of data from multiple sources. In a single view, it is possible to see the status and trends in system performance, in addition to generating smart alerts efficiently. It also generates information that can be shared with customers or suppliers to meet the standards and goals of services and system performance. To implement MELT:

  • Pandora FMS unifies https://pandorafms.com/en/it-topics/it-system-monitoring/ regardless of the operating model and infrastructures (physical or SaaS, PaaS or IaaS).
  • With Pandora FMS, you may collect and store all kinds of logs (including Windows events) to be able to search and configure alerts. Logs are stored in non-SQL storage that allows you to keep data from multiple sources for quite some time, supporting compliance and audit efforts. Expanding on this topic, we invite you to read the Infrastructure Logs document, the key to solving new compliance, security and business related questions.
  • Pandora FMS offers custom dashboard layouts to display real-time data and multi-year history data. Reports on availability calculations, SLA reports (monthly, weekly or daily), histograms, graphs, capacity planning reports, event reports, inventories and component configuration, among others, can be predefined.
  • With Pandora FMS, you may monitor traffic in real time, getting a clear view of the volume of requests and transactions. This tool allows you to identify usage patterns, detect unexpected spikes, and plan capacity effectively.
  • With the premise that it is much more effective to visually show the source of a failure than simply receiving hundreds of events per second. Pandora FMS offers the value of its service monitoring, which allows you to filter all information and show only what is critical for making appropriate decisions.

Market analyst and writer with +30 years in the IT market for demand generation, ranking and relationships with end customers, as well as corporate communication and industry analysis.

Analista de mercado y escritora con más de 30 años en el mercado TIC en áreas de generación de demanda, posicionamiento y relaciones con usuarios finales, así como comunicación corporativa y análisis de la industria.

Analyste du marché et écrivaine avec plus de 30 ans d’expérience dans le domaine informatique, particulièrement la demande, positionnement et relations avec les utilisateurs finaux, la communication corporative et l’anayse de l’indutrie.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

24.6.7 Voyager released

Changes compared to 24.6.6

New Features

  • Added SMB Storage Vault option to the Comet Server Service Manager first use wizard

Bug Fixes

  • Fixed an issue with Microsoft 365 listing that caused processing to fail when SharePoint Sites are locked
  • Fixed an issue with operating system information being incomplete for Windows devices
  • Fixed an issue causing certain Gradient PSA failures to retry for an unnecessarily long time

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.