Skip to content

How to find CrushFTP installations on your network

Latest CrushFTP vulnerability: CVE-2025-54309 #

CrushFTP disclosed a vulnerability in certain versions of their file transfer product, which fails to protect the alternate channel AS2 (Applicability Statement 2) data transfer protocol via HTTP(S) when a DMZ proxy instance is not used. The mishandling of AS2 validation allows a remote adversary to bypass the intended security measures, and obtain administrative access via HTTP(S). This vulnerability has been designated CVE-2025-54309 and has been rated critical with a CVSS score of 9.0. There is evidence that this vulnerability is being actively exploited in the wild.

The following versions are affected:

  • CrushFTP versions 10.x prior to 10.8.5
  • CrushFTP versions 11.x prior to 11.3.4_23

What is the impact? #

Successful exploitation of this vulnerability would allow an adversary to execute administrative functions within the CrushFTP service without authentication, potentially leading to complete system compromise and data integrity issues.

Are updates or workarounds available? #

Users are encouraged to update to the latest version as quickly as possible.

  • CrushFTP release 10.x upgrade to version 10.8.5 or later
  • CrushFTP release 11.x upgrade to version 11.3.4_23 or later

How to find potentially vulnerable systems with runZero #

From the Software Inventory, use the following query to locate systems running potentially vulnerable software:

vendor:=CrushFTP AND product:CrushFTP

April 2025: (CVE-2025-31161) #

CrushFTP disclosed that a vulnerability in their file transfer product allows an unauthenticated remote attacker to bypass authentication on some HTTPS interfaces. Since the original disclosure, a CVE was assigned, CVE-2025-2825, and later, CVE-2025-31161. This vulnerability is being exploited in the wild.

What is the impact? #

Successfully exploiting this vulnerability would allow an attacker to execute administrative functions within the CrushFTP service without authentication. Versions of CrushFTP 11 prior to 11.3.1 and CrushFTP 10 prior to 10.8.4 are vulnerable.

Are updates or workarounds available? #

CrushFTP has released versions 11.3.1 and 10.8.4 to address this issue. The vendor has also indicated that enabling the DMZ setting in the CrushFTP configuration will mitigate this issue. CrushFTP administrators are advised to update at their earliest opportunity.


Previous CrushFTP vulnerability (April 2024) #

CrushFTP disclosed that a vulnerability in their file transfer product allows an unauthenticated attacker to access the host’s file system. No CVE has yet to be assigned for this issue and CrowdStrike has indicated that this issue is being actively exploited in the wild. Additional details can be found in this article by Sergiu Gatlan at BleepingComputer.

What is the impact? #

This issue affects all CrushFTP versions prior to 10.7.1 and CrushFTP 11 releases prior to patch 11.1.0. An unauthenticated attacker can abuse this issue to read files from the host’s file system. 

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Hackers Now Use AI: Evolving Cyber Attacks and Emerging AI Security Threats

The AI-Powered Heist: How Artificial Intelligence is Arming the Next Generation of Cybercriminals 

In Hong Kong, a finance officer transferred $25 million after receiving instructions on a video call from his CFO. The only problem? The CFO was an AI-generated deepfake. This isn’t science fiction; it’s a stark example of a new era in cybersecurity, where Artificial Intelligence is both a powerful tool and a formidable weapon.

As AI weaves itself into society, it is reshaping the threat landscape on two fronts: by supercharging traditional hacking methods and by creating entirely new ways to attack.

The Old Playbook, Supercharged by AI

Adversaries are now using AI to refine and automate age-old attack methods with terrifying efficiency.

  • Hyper-Personalized Social Engineering: Forget typos and generic greetings. AI-powered phishing emails now perfectly mimic human communication, using a target’s social media data to craft deeply personal and convincing messages that bypass traditional filters. Deepfake technology takes this further, allowing attackers to clone executives’ voices and faces for video calls, making fraudulent requests for funds or data alarmingly persuasive.
  • Automated, Large-Scale Attacks: AI algorithms can operate 24/7, scanning thousands of systems for vulnerabilities and cracking passwords with an intelligence that surpasses brute-force methods. By analyzing behavioral patterns, AI can predict and test highly probable passwords, undermining conventional security policies at an unprecedented scale.

Attacking the Brain: The New Frontier of AI-Specific Threats

Beyond enhancing old methods, entirely new threats are emerging that target the AI models themselves.

  • Model Integrity Attacks: Adversaries are learning to fool AI systems. An adversarial attack might use a strategically placed sticker to make a self-driving car misread a stop sign. Model poisoning involves corrupting an AI’s training data to create hidden backdoors, such as teaching a security system to recognize a specific virus as “safe.”
  • Unprecedented Privacy Risks: AI’s ability to process massive datasets poses a severe privacy threat. Model inversion attacks can reconstruct sensitive personal data (e.g., medical records) from an AI’s public outputs. Furthermore, by correlating anonymized data points—like location history and credit card use—AI can infer sensitive personal traits, effectively de-anonymizing individuals.
  • The “Black Box” Dilemma: Our growing dependence on AI is risky because we often don’t understand why it makes certain decisions. This “black box” nature complicates incident response, as demonstrated by historical examples like Microsoft’s chatbot turning hateful or Amazon’s recruitment AI developing a gender bias.

A New Call for Holistic Security The rise of AI-driven threats means purely technical defenses are no longer sufficient. To stay resilient, organizations must adopt a holistic strategy that treats AI not just as a tool to be defended, but as a potential attack vector in its own right—one that requires a new framework of legal, ethical, and security governance.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

8 Essential Kafka Security Best Practices

About Perforce
The best run DevOps teams in the world choose Perforce. Perforce products are purpose-built to develop, build and maintain high-stakes applications. Companies can finally manage complexity, achieve speed without compromise, improve security and compliance, and run their DevOps toolchains with full integrity. With a global footprint spanning more than 80 countries and including over 75% of the Fortune 100, Perforce is trusted by the world’s leading brands to deliver solutions to even the toughest challenges. Accelerate technology delivery, with no shortcuts.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Install Pandora ITSM from Pandora FMS Console

Until now, deploying Pandora ITSM required a standalone installation, manual database configuration, and later integration with Pandora FMS. With the new NG 783 version, that entire process has been simplified: Pandora ITSM can now be installed directly from the Pandora FMS web console, no additional servers, no external steps, and with integration already configured.

A Single Workspace, No Middle Steps

The new installer automatically detects whether an ITSM database already exists. If not, it creates one and applies all necessary setup (table structure, initial data load, access setup, and authentication configuration). There’s no need to enter credentials or perform extra configurations—the installation automatically adapts to the available permissions in the environment.

Integrated Authentication and Synchronized Users

Once the installation is complete, Pandora FMS administrator users are automatically synchronized with ITSM, without the need to manage separate accounts. ITSM is ready to authenticate directly using the main system’s users, following the same logic already used for LDAP or Active Directory integrations.

Additionally, any pre-existing users in ITSM are removed to avoid license conflicts and ensure that access control remains centralized within Pandora FMS.

Native Integration with Contextual Access

Pandora FMS console now includes a dedicated ITSM menu, with direct links to the incident and change management environment. This native integration enables work within a unified interface, where monitoring alerts can automatically generate incidents in ITSM—without switching contexts or duplicating tools. It strengthens the connection between the alert and notification system and operational management.

Once the process is complete, a summary is displayed showing the generated access points and the full URL of the ITSM environment, already integrated and ready to use.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

Penta Security is Named Company of the Year for Excellence in WAF Technology

Prestigious Recognition by Frost & Sullivan

Penta Security has been named the 2025 South Korea Company of the Year in the Web Application Firewall (WAF) industry by Frost & Sullivan for the third consecutive year.

This award recognizes excellence in leadership, innovation, customer service, and product strategy. Penta Security earned this honor for its robust, secure solutions and commitment to meeting customer needs in the evolving cloud security landscape.

WAPPLES - Intelligent WAAP Solution

WAPPLES is a cloud-native Web Application and API Protection (WAAP) solution offering scalable, high-performance security across on-premise and cloud environments. Powered by the COCEP engine, it provides real-time threat detection and has led Korea’s WAF market for 17 years.

Logic-Based Detection : COCEP™ Engine

WAPPLES’ COCEP™ engine uses 39 predefined rules to block known and zero-day attacks without relying on signature updates.

Advanced Protection for Web Applications, APIs, and Mobile Apps

As API-based applications grow, so do related threats. WAPPLES blocks these using a dedicated API parser and COCEP™ engine schema.

Effective Protection Against Automated Malicious Bots and DoS

WAPPLES blocks malicious bots and anonymous attacks using fingerprinting, CAPTCHA, and behavior detection to protect websites and applications effectively.

Exceptionally Low False Positive Rate

WAPPLES’ COCEP™ engine blocks known and unknown attacks while avoiding benign traffic, achieving near-zero false positives for optimal security and performance.

Intelligent Web Application and API Protection

Discover how we can help your business

Hotline (65) 6296 4268 | Email: sales@version-2.com.sg
Website: www.version-2.com.sg | www.v2catalog.com

SMB IT at a Breaking Point: Only 12% Have Mature ITSM Frameworks to Deal with Increasing IT Complexity

New global benchmark study reveals sharp gaps in tools, talent, and integration

Despite knowing they need to modernize, small and medium-sized businesses (SMBs) are falling behind on IT maturity, leaving themselves exposed to rising cyber risks, inefficiencies, and productivity losses. This is according to a new global benchmark study, “The State of SMB IT for 2026,” released today by EasyVista and OTRS Group. The report reveals that just 12% of SMBs have implemented a fully mature, proactive IT Service Management (ITSM) framework, even though more than half (56%) recognize it as a strategic opportunity to improve efficiency and drive business success. Nearly 40% of organizations still operate without well-defined or consistent ITSM processes, relying instead on basic ticketing systems, spreadsheets, or manual workarounds.    

Based on responses from more than 1,000 SMB IT leaders and practitioners, the report offers insights into the operational realities shaping IT strategies for organizations worldwide. It highlights a growing urgency among SMBs to modernize fragmented systems, improve security, and leverage emerging technologies like AI to drive business value.  

Pain Points Holding Back SMB IT  

According to the report, 67% are still relying on manual work or spreadsheets to bridge ITSM and ITAM processes and just 39% report full integration between infrastructure monitoring and ITSM workflows. SMBs name talent shortages (40%), budget constraints (40%), and security and compliance pressures (37%) as the top obstacles preventing them from advancing IT operations.  

AI Momentum is Building, But Still in the Discovery Phase  

The report shows that AI adoption is growing but SMB teams face cost and expertise barriers:  

  • 71% of respondents say AI is rather or very important to ITSM success.  
  • Early adoption is focused on asset tracking and reporting (35%), automating repetitive tasks (34%), and IT trend analysis for better decision making (33%).  
  • Cost, data privacy and security, and a lack of expertise are the biggest obstacles in deploying Generative AI.  

SMB Priorities Point Toward Modernization  

Looking ahead, the top IT priorities for the next twelve months are:  

  • 41% plan to prioritize IT security improvements. 
  • 31% aim to automate IT workflows.  
  • 30% plan to introduce AI to improve efficiency.  

However, delivering on these goals will require more than just new technology:  

  • 62% say they need training and education to improve ITSM practices.  
  • 56% want easy-to-use AI and automation capabilities.  
  •  48% want access to affordable tools and software.  

“SMBs clearly understand that ITSM and ITAM aren’t just back-office functions anymore, they are critical to how the business runs,” said Keith Andes, Head of Product Marketing at EasyVista. “But our data confirms that too many teams are still stuck with fragmented, outdated systems that slow them down and open up risks. What they need are affordable solutions that are easy to integrate and built with automation and AI at the core. That’s how IT can ‘do more with less’ while helping the business grow.”  

Andreas Bender, Senior VP Business Transformation and Innovation, OTRS Group, added: “As IT systems become more critical to business operations, SMBs risk falling behind larger competitors if they cannot modernize effectively. To make the shift from reactive to proactive ITSM, SMB leaders must empower their IT teams with clear priorities, consistent processes, the right technologies, and continuous training. Proactive ITSM isn’t just a technical change – it’s a leadership-driven transformation that starts with strategic commitment.”  

Download the report at this link to learn more: https://info.easyvista.com/the-state-of-smb-it-in-2026

About EasyVista  
EasyVista is a leading IT software provider delivering comprehensive IT solutions, including service management, remote support, IT monitoring, and self-healing technologies. We empower companies to embrace a customer-focused, proactive, and predictive approach to IT service, support, and operations. EasyVista is dedicated to understanding and exceeding customer expectations, ensuring seamless and superior IT experiences. Today, EasyVista supports over 3,000 companies worldwide in accelerating digital transformation, enhancing employee productivity, reducing operating costs, and boosting satisfaction for both employees and customers across various industries, including financial services, healthcare, education, and manufacturing.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Understanding the Business Continuity Plan (BCP) and Its Importance

What is a business continuity plan?

These days, cybercrime is rampant. It’s no longer a matter of “if” you’re going to suffer an attack but “when” it will happen. All companies want to be ready for any crisis – that’s where a business continuity plan comes into play.

Setting up a strategy helps understand the next steps during and following a potential cyber incident. So what is a business continuity plan, exactly? What does it encompass? And what makes it so important to organizations? Today, we’re exploring all these questions in-depth.

A business continuity plan (BCP) is a document that sets guidelines for maintaining or quickly resuming business operations during and after a disruption. Disruptions may include fires, floods, other natural disasters, cybersecurity incidents, or service outages. A BCP is a proactive strategy that aims to help organizations resume operations without significant downtime, safeguard resources, and maintain customer trust.

Despite their utility for business security, BCPs are not as common as expected. According to ZipDo, 57% of organizations that experience a business disruption don’t have a business continuity plan in place.

Business continuity vs disaster recovery plan: What’s the difference?

Sometimes, people use the terms disaster recovery plan (DRP) and business continuity plan (BCP) interchangeably. However, these are two separate types of plans. A business continuity plan helps organizations stay prepared to deal with a potential crisis and, hence, usually encompasses a disaster recovery plan. Although the two overlap and are often set into motion to optimize procedures during crisis events, their purposes differ.

The key difference between BCPs and DRPs is their goal. Business continuity plans aim to reduce downtime during the incident to a minimum. Disaster recovery plans focus on reducing any faults or abnormalities in the system caused by the event and returning things back to normal. They also tend to be more extensive, including additional steps like containing, examining, and restoring operations and covering employee safety measures.

In terms of functionality, a disaster recovery plan focuses on operational steps to restore data access to business as usual following an incident. On the other hand, a business recovery plan is set in place while the incident is still ongoing, ensuring that the operations proceed despite the circumstances.

Benefits of business continuity planning

The number of news headlines announcing data breaches has numbed us to the fact that cybercrime is very real and frequent and poses an existential risk to companies of all sizes and industries.

According to the 2023 Data Breach Investigations report, ransomware is present in 24% of all breaches and is among the top four most common types of cyberattacks. In fact, 24% of breaches involved ransomware, with damages costing businesses an average of $4.82 million.

Most cyberattacks are financially motivated, as the global cost of cybercrime exceeded $8 trillion in 2022 and is expected to exceed $13 trillion by 2028. The picture is quite clear — cybercrime is a lucrative venture for bad actors and potentially disastrous for those on the receiving end.

The importance of business continuity plans cannot be understated, as to thrive in these unpredictable times, organizations go beyond conventional security measures. Many companies develop a BCP parallel to secure infrastructure and consider it a critical part of the security ecosystem. The purpose of a business continuity plan is to significantly reduce the downtime in an emergency and, in turn, reduce the potential reputational damage and — of course — revenue losses.

 

Business continuity plan template

Business Continuity Plan Example

[Company Name]

[Date]

I. Introduction

  • Purpose of the Plan

  • Scope of the Plan

  • Budget

  • Timeline

The initial stage of developing a business continuity plan starts with a statement of the plan’s purpose. It explains the main objective of the plan, such as ensuring the organization’s ability to continue its operations during and after a disruptive event.

The Scope of the Plan outlines the areas or functions that the plan will cover, including business processes, personnel, equipment, and technology.

The Budget specifies the estimated financial resources required to implement and maintain the BCP. This includes costs related to technology, personnel, equipment, training, and other necessary expenses.

The Timeline provides a detailed schedule for developing, implementing, testing, and updating the BCP.

II. Risk Assessment

  • Identification of Risks

  • Prioritization of Risks

  • Mitigation Strategies

The Risk Assessment section is an essential part of the business continuity plan that identifies potential risks that can disrupt an organization’s critical functions.

The Identification of Risks involves identifying potential threats to the organization, such as cybersecurity breaches, supply chain disruptions, or power outages. This step is critical to understand the risks and their potential impact on the organization.

Once the risks have been identified, the Prioritization of Risks follows, which helps determine which risks require the most attention and resources.

The final step in the Risk Assessment section is developing Mitigation Strategies to minimize the impact of identified risks. Mitigation strategies may include preventative measures, such as system redundancies, data backups, and cybersecurity measures, as well as response and recovery measures, such as emergency protocols and employee training.

III. Emergency Response

  • Emergency Response Team

  • Communication Plan

  • Emergency Procedures

This section of the plan focuses on immediate actions that should be taken to ensure the safety and well-being of employees and minimize the event’s impact on the organization’s operations.

The Emergency Response Team manages the response to an emergency or disaster situation. This team should be composed of individuals trained in emergency response procedures who can act quickly and decisively during an emergency. The team should also include a designated leader coordinating the emergency response efforts.

The Communication Plan outlines how information will be disseminated during an emergency situation. It includes contact information for employees, stakeholders, and emergency response personnel, as well as protocols for communicating with these individuals.

The Emergency Procedures detail the steps during an emergency or disaster situation. They should be developed based on the potential risks identified in the Risk Assessment section. The procedures should be tested regularly to ensure their effectiveness.

IV. Business Impact Analysis

The Business Impact Analysis (BIA) section of a business continuity plan is a critical step in identifying the potential impact of a disruption to an organization’s critical operations.

The BIA is typically conducted by a team of individuals who understand the organization’s critical functions and can assess the potential impact of a disruption. The team may include representatives from various departments, including finance, operations, IT, and human resources.

V. Recovery and Restoration

  • Procedures for Recovery and Restoration of Critical Processes

  • Prioritization of Recovery Efforts

  • Establishment of Recovery Time Objectives

     

The Recovery and Restoration section of a Business Continuity Plan (BCP) outlines the procedures for recovering and restoring critical processes and functions following a disruption.

The Procedures for Recovery and Restoration of Critical Processes describe the steps required to restore critical processes and functions following a disruption. This may include steps such as relocating to alternate facilities, restoring data and systems, and re-establishing key business relationships.

The Prioritization of Recovery Efforts section identifies the order in which critical processes will be restored based on their importance to the organization’s operations and the overall mission.

Recovery time objectives (RTOs) define the maximum amount of time that critical processes and functions can be unavailable following a disruption. Establishing RTOs ensures that recovery efforts are focused on restoring critical functions within a specific timeframe.

VI. Plan Activation

  • Plan Activation Procedures

The Plan Activation section is critical in ensuring that an organization can quickly and effectively activate the plan and respond to a potential emergency.

The Plan Activation Procedures describe the steps required to activate the BCP in response to a disruption. The procedures should be clear and concise, with specific instructions for each step to ensure a prompt and effective response.

VII. Testing and Maintenance

  • Testing Procedures

  • Maintenance Procedures

  • Review and Update Procedures

This section of the plan is critical to ensure that an organization can effectively respond to disruptions and quickly resume its essential functions.

Testing Procedures may include scenarios such as natural disasters, cyber-attacks, and other potential risks. Clear objectives, testing scenarios, roles and responsibilities, and evaluation criteria to assess the plan’s effectiveness are also part of the procedural structure.

The Maintenance Procedures detail the steps necessary to keep the BCP up-to-date and relevant.

The Review and Update Procedures describe how the BCP will be reviewed and updated regularly to ensure its continued effectiveness. This may involve reviewing the plan regularly or after significant changes to the organization’s operations or threats.

What should a business continuity plan checklist include?

Organizations looking to develop a BCP have a lot to consider. Variables such as the organization’s size, its IT infrastructure, personnel, and resources all play a significant role in developing a continuity plan. Remember, each crisis is different, and each organization will have its own view on handling it according to all the variables in play. However, all business continuity plans include a few fundamental elements.

  • Clearly defined areas of responsibility

    A BCP should define specific roles and responsibilities for emergencies. You must detail who’s responsible for what tasks and clarify what course of action a person in a specific position should take. Clearly defined roles and responsibilities in an emergency event allow you to act quickly and decisively and minimize potential damage.

  • Crisis communication plan

    In an emergency, communication is vital. It is the determining factor in crisis handling. Establishing clear and effective communication pipelines is critical. Alternative communication channels should not be overlooked either. Make sure to outline them in your business continuity plan.

  • Recovery teams

    A recovery team is a collective of professionals who ensure that business operations are restored as soon as possible after the organization confronts a crisis.

  • Alternative site of operations

    Today, when we think of an incident in a business environment, we usually think of a cybersecurity-related event. However, as discussed earlier, a BCP covers many possible incidents. In a natural disaster, determine potential alternate sites where the company could continue to operate.

  • Backup power and data backups

    Whether a cyber event or a real-life physical incident, ensuring that you have access to a power source is crucial to continue operations. A BCP often contains lists of alternative power sources like generators, locations of such tools, and who should oversee them. The same applies to data – regularly scheduled backups can significantly reduce potential losses incurred by a crisis event.

  • Recovery guidelines

    If a crisis is significant, a comprehensive business continuity plan usually includes detailed guidelines on how the recovery process will be carried out.

Business continuity planning steps

Business continuity plan steps

Here are the 3 main business continuity plan pillars that an organization looking to develop a BCP should consider:

Risk assessment and impact analysis

Any business continuity planning process should start with the identification of potential threats and vulnerabilities. All threats and vulnerabilities should be prioritized and systematized so that the organization can take steps to mitigate and manage them.

Once risks are identified, they should be followed by an assessment of the potential impact of these disruptions on critical business functions and resources. The analysis phase should also include assessing different levels of risk. This will help determine the most essential services or systems that have to be maintained during a crisis and how long they can stay offline before causing significant damage to the business.

Recovery strategies and plan development

Once you have a clear overview of the potential risks your company could face, start developing a plan. Create a draft and reassess it to see if it accounts for even the smallest of details, including alternative locations, communication plans, and how to restore critical functions.

Implementation, testing, and maintenance

A business continuity plan cannot be completed without regular implementation, testing, and maintenance:

  • Implement the BCP within the organization by providing staff with training sessions to familiarize them with the plan.

  • Run through a variety of scenarios in training sessions to assess the plan’s overall effectiveness. By doing so, everyone on the team will be closely familiar with the business continuity plan’s guidelines.

  • Tune your continuity plan to recent developments to ensure the plan remains relevant as the business and landscape change.

Business continuity planning standards

Business continuity plans don’t just appear out of thin air. They must strictly adhere to industry standards, including ISO and regional standards, to ensure that business is sufficiently prepared for a crisis scenario.

Following a standard is advantageous to businesses as the relevant information and the requirements are continuously being updated. This ensures that the implemented strategies don’t fall behind the security requirements. The ISO 223XX standard series, in particular, aims to provide a clear and internationally recognized framework for continuity planning.

ISO 22301

ISO 22301, or the Security and Resilience Standard, provides organizations with a framework to plan, operate, improve, and otherwise maintain response and recovery strategies. The business continuity plan acts as the documented management system (known as a business continuity management system, or BCMS) that aims to prevent disruptive incidents and, if they occur, ensure a full recovery. It goes hand in hand with ISO 22313.

ISO 22313

This business continuity plan standard provides guidance on implementing the ISO 22301 requirements. It details the precise steps on how the business continuity management system should be implemented in an organization.

ISO 27001

ISO 27001 provides a framework for managing information security. This standard ensures that an organization implements the right risk assessment and controls to upkeep the development, improvement, and protection of information management systems (ISMS). The NordPass ISMS is certified according to ISO 27001.

ISO/IEC 27031

These guidelines cover the principles of how ready an organization’s information and communication technology (ICT) infrastructure should be for business continuity. It covers all potential events and incidents that may impact the infrastructure, leading to the implementation of a BCP.

ISO 31000

ISO 31000, or the Risk Management Standard, exists to help all organizations handle potential risks. Its main purpose is to allow organizations to compare their internal risk management practices to the global standards. However, ISO 31000 can’t be used for certification purposes.

Level up your company’s security with NordPass Business

A comprehensive business continuity plan is vital for the entire organization’s security posture. However, in a perfect world, you wouldn’t have to use it. That’s is where NordPass Business can help.

Weak, reused, or compromised passwords are often cited among the top contributing factors in data breaches – unsurprising, considering that an average user has around 170 passwords. Password fatigue is real and significantly affects how people treat their credentials. NordPass Business counters these issues.

With NordPass Password Manager for IT Teams, your team will have a single secure place to store all work-related passwords, credit cards, and other sensitive information. Accessing all the data stored in NordPass is quick and easy, which allows your employees not to be distracted by the task of finding the correct passwords for the correct account.

NordPass Enterprise helps keep your corporate credentials secure at all times. Everything stored in the NordPass vault is secured with advanced xChaCha20 encryption, which would take hundreds of years to brute force.

If you’are interested in learning more about NordPass Business and how it can help fortify corporate security, do not hesitate to book a demo with our representative.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How Traceloop protected its LLM dev workflow and met SOC2 compliance

Summary: Learn how Traceloop locked down AWS access, passed SOC 2 compliance, and saved hours with NordLayer’s dedicated IP.

Results at a glance. 1 year of using NordLayer. 100% of employees secured. IT hours saved weekly. SOC 2 compliance support. Secured access to AWS cloud environments

Established in 2022, Traceloop is a seed-stage startup based in Israel. It creates platforms that help companies worldwide build and improve their large language model (LLM) apps. The team consists of eight on-site employees and one remote worker based in Ukraine.

Focus features: Server with a dedicated IP. 2022 Year of establishment. Service scale: Global. Team presence: Tel-Aviv, Israel, Ukraine. Work policy On-site, Remote. Industry sector: Software that helps build and manage Al-powered apps

Before NordLayer, Traceloop didn’t have any security solution in place. And like many early-stage startups, its team focused exclusively on building products.

Knowing that their SOC 2 compliance audit was fast approaching, they needed a reliable and scalable solution that:

  • Helps secure access to their AWS-managed Kubernetes clusters
  • Supports SOC 2 compliance

The challenge: Securing access to DevOps environments

We spoke with Gal Kleinman, CTO and co-founder of Traceloop, about when security became a priority.

“We’ve always cared about security, but SOC 2 made us realize we needed tighter access controls to our cloud environments.”

The biggest issue was that their Kubernetes clusters were accessible from anywhere using AWS Command Line Interface (CLI), with no IP restrictions. Manually restricting access would’ve slowed down the team and introduced bottlenecks for developers.

They needed a solution that offers a server with a dedicated IP, works seamlessly with AWS, and could be set up in minutes, not days.

How NordLayer helped Traceloop

Traceloop needed a fast, reliable way to secure access to its cloud environments without adding unnecessary cost or complexity. As Gal Kleinman explains:

“With NordLayer, our team can now securely access our cloud resources, and I don’t have to spend much time managing it.”

Traceloop deployed NordLayer’s server with a dedicated IP, which was assigned to the company through a Virtual Private Gateway.

NordLayer Control Panel Network Gateways

Benefit 1: Fast NordLayer’s deployment

Traceloop was looking for a solution that was easy to use and set up. NordLayer’s deployment was simple:

  • Log in to NordLayer.
  • Invite the team members.
  • They click the link, download the app, and it installs automatically.
  • Within minutes, they’re securely connected.

“Everything took four or five minutes—start to finish.”

Benefit 2: Secure cloud access with a dedicated IP

To secure AWS access and meet SOC 2 compliance, Traceloop assigned a server with a dedicated IP to the Virtual Private Gateway. This ensured the whole team could connect through the same IP address, regardless of where they were.

Popup of NordLayer Control Panel Network Gateways

For a small team managing security themselves, this simplicity was a huge benefit. Setup was fast and straightforward. And they met all SOC 2 requirements without disrupting workflows or slowing down product development.

Results

After one year of using NordLayer, Traceloop achieved the following results:

  • Locked-down cloud access: Secure access to staging and production environments.
  • SOC 2 compliance support: Fast, compliant access controls for audit readiness.
  • Scales with the team: 8 out of 9 team members use NordLayer daily, and the setup is quick and effortless.
  • Many IT hours saved: NordLayer is easy to use and streamlines Traceloop’s workflows.

“NordLayer gave us a simple way to secure AWS access with a dedicated IP. The whole team connects through the gateway, and I can control access without touching our workflows.”

 

Why NordLayer works for Traceloop

NordLayer was the perfect fit for Traceloop because it delivered exactly what the team needed: simplicity, security, and zero disruption to developer workflows.

As a small startup without a dedicated IT team, Traceloop needed a solution that just worked, right out of the box:

  • Secure access with a dedicated IP. Locked down staging and production, eliminating open endpoints.
  • Set-up in minutes. NordLayer was fully deployed in under five minutes.
  • Works with existing tools. Integrated seamlessly with AWS Command Line Interface (CLI), so the team didn’t have to change how they work.

Pro cybersecurity tips

Gal Kleinman, CTO and co-founder of Traceloop, shared a few cybersecurity tips with us:

  • Keep it simple. Choose security tools that are easy to implement and use. Avoid overcomplicated setups that drain time and energy.
  • Protect without disrupting. Security measures should work quietly in the background, not block workflows or frustrate developers.
  • Balance security and speed. The best tools protect your systems and let your team move fast.
Quote: "Keep it simple. Choose security tools that are easy to implement and use. Avoid overcomplicated setups that drain time and energy."

Conclusion

Traceloop chose NordLayer to secure its AWS access and streamline SOC 2 compliance without disrupting the team’s daily work.

“NordLayer gave me exactly what I needed—a dedicated IP, fast setup, and no disruption to how our team works.”

With NordLayer, Traceloop gained secure cloud access and an easy way to scale security as the team grows.

Need to secure your cloud workflows without slowing your team down? Learn how NordLayer can help you with that.

Talk to our sales team to find the right plan for your team.

 

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.