Skip to content

How to Password-Protect Your Folders

Securing Your Data: How to Password-Protect a Folder

Using public Wi-Fi networks exposes your sensitive documents and personal media to potential interception. Password-protecting specific folders creates a vital barrier against unauthorized access. While macOS includes native utilities for this task, Windows requires external software to achieve true cryptographic security. Regardless of your operating system, locking down your directories is a straightforward process.

Key Takeaways:

  • macOS: Utilize the built-in Disk Utility to convert folders into encrypted, password-protected disk images (AES-256).
  • Windows: Rely on trusted third-party archiving tools like 7-Zip or WinRAR, as Windows lacks native folder-locking capabilities.
  • Recovery Risk: Forgetting an encryption password results in permanent data loss. Use a secure password manager to retain access.

Password-Protecting a Folder on macOS

Mac users can secure folders natively by converting them into encrypted disk images using Disk Utility.

  1. Navigate to Applications > Utilities and launch Disk Utility.
  2. In the top menu, select File > New Image > Image from Folder.
  3. Locate and select the folder you wish to secure.
  4. Under the Encryption dropdown, select 256-bit AES encryption (recommended for optimal security).
  5. Enter and verify your new password.
  6. Change the Image Format to read/write so you can modify the folder’s contents later.
  7. Click Save and allow the system to generate the encrypted disk image (a .dmg file).

Note: Once you verify that your new encrypted disk image opens correctly, permanently delete the original unprotected folder.

Password-Protecting a Folder in Windows

Unlike macOS, Windows does not feature a built-in mechanism to password-protect standard folders. The native Encrypting File System (EFS) ties folder access to your Windows user account rather than a specific password, making it unsuitable for general sharing or isolated protection.

To achieve true password protection, you must use archiving software like 7-Zip or WinRAR.

  1. Download and install your preferred archiving tool (e.g., 7-Zip).
  2. Right-click the target folder and select Add to archive.
  3. Select your preferred archive format (e.g., .zip or .7z).
  4. Locate the Encryption section and enter your desired password.
  5. Ensure the encryption method is set to AES-256.
  6. Click OK to generate the locked archive.
  7. Delete the original, unencrypted folder.

Password Protection vs. Encryption

Understanding the distinction between simply locking a file and actually encrypting it is crucial for evaluating your security posture.

MethodHow It WorksSecurity Profile
Password ProtectionActs as a digital gatekeeper. It prevents the interface from opening without the correct credential, but the underlying data remains in its raw state.Vulnerable. Can often be bypassed by malicious software or direct data extraction.
EncryptionMathematically scrambles the raw data into unreadable ciphertext. It cannot be decoded without the precise cryptographic key.Highly secure. Useless to attackers without the decryption key.
Combined (Best Practice)Uses your password to generate a complex encryption key (like AES-256) that actively scrambles the folder’s contents.Maximum security. Both tools mentioned above utilize this combined approach.

Managing Your Access Credentials

True encryption is unforgiving. If you forget the password to your secured archive or disk image, there is no “forgot password” link—your data is permanently inaccessible. To prevent accidental data loss, utilize a dedicated password manager.

Tools like NordPass safeguard your credentials inside a vault secured by XChaCha20 cryptography. By utilizing a password manager, you only need to memorize a single Master Password. Furthermore, these applications can generate highly complex, unguessable passwords for your folders on the spot and automatically sync them across your desktop and mobile devices.

Frequently Asked Questions

How do I open a folder once it is password-protected?

Locate the encrypted archive (Windows) or disk image (Mac) on your device. Double-click the file to initiate the opening process. A prompt will appear requesting your password; enter your credentials, and the system will decrypt and display your folder’s contents.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

The AI Governance Gap: Why MSPs Are Lagging Behind

The AI Governance Gap: Why MSPs Are Lagging Behind

AI agents are already executing active workloads in 72% of modern organizations, yet fewer than 40% of these digital workers are managed under standard identity and access protocols. More alarmingly, JumpCloud’s Agentic IAM Pulse Report reveals that 83% of teams lack a designated security owner to hold accountable when an AI agent makes an error.

Your clients are running AI agents within your managed environments right now. Whether you have formalized a service around this reality or not, the operational exposure exists. The reluctance of Managed Service Providers (MSPs) to build formal AI governance practices rarely stems from a lack of interest. Instead, it is driven by three distinct, solvable barriers.

1. The Ownership Vacuum

The proliferation of machine identities has vastly outpaced the strategic frameworks needed to govern them. Currently, only 17% of organizations assign AI agent accountability to a dedicated security leader. Nearly half (47%) simply dump the problem onto IT by default, while a mere 6% utilize cross-functional governance committees. Ultimately, 83% of organizations operate without clear security ownership over AI.

Because AI agents represent an entirely new operational category, businesses remain paralyzed over whether governance belongs to IT, security, or compliance. However, fundamentally, this is an Identity and Access Management (IAM) challenge. AI agents operate as Non-Human Identities (NHIs) and require the exact same foundational controls as human users: unique identification, linkage to a human owner, strict least-privilege access, and defined lifecycles. With NHIs now outnumbering human employees in 53% of organizations—and hitting a 6:1 ratio in 23% of them—every agent requires an owner. MSPs can bridge this gap by claiming the ownership territory that clients have left vacant.

2. Tool Stack Saturation and Alert Fatigue

MSP technicians already operate at maximum capacity. Navigating between RMM, PSA, EDR, and DLP platforms forces engineers to pivot across four to seven distinct security consoles daily. Consequently, over 75% of MSPs report experiencing alert fatigue every month. Teams burdened by high false-positive rates face a 2.7x higher probability of debilitating daily burnout.

Attempting to sell your team on AI governance by introducing yet another standalone console to license, monitor, and maintain will face immediate rejection. The solution is not bolting on a new tool; it is extending your existing IAM capabilities. When AI agent governance is routed through the exact same platform used to manage human identities and endpoints, technicians do not have to learn a new system. They simply apply familiar controls to a new identity class.

3. The Perception of Legal Liability

Assuming governance over a client’s AI agents—especially those built by third parties or driven by unknown prompts—feels like an open invitation to legal liability. However, turning a blind eye offers zero protection. If an unmonitored agent triggers a data breach or executes a catastrophic workflow within your client’s environment, the operational and reputational damage will inevitably strike the MSP, regardless of contract specifics.

The current lack of baseline controls exacerbates this risk: 55% of organizations lack a centralized kill switch to sever an agent’s access during an incident, and 59% fail to maintain comprehensive audit trails of agent activity. If an incident occurs and you can instantly produce audit logs detailing the agent’s owner, its access scope, and the exact moment its privileges were revoked, you demonstrate reasonable oversight. Failing to provide any documentation makes you the scapegoat.

Capitalizing on the AI Governance Opportunity

Addressing ownership, tool fatigue, and liability does not require pivoting your entire business model. It simply demands applying your existing identity and access discipline to the autonomous workers already operating inside your clients’ networks.

MSPs that establish an AI security and governance practice today will secure long-term client dependency and capture significant margins for years to come. To explore tiered pricing strategies, position yourself as a strategic AI advisor, and deliver robust agentic security without bloating your tool stack, consult The MSP Guide to Securing and Selling Agentic AI. Download the full playbook today to transform these three perceived barriers into a highly profitable, scalable service line.

About JumpCloud
At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Unmasking the Hidden Server: Out-of-Band Infrastructure Exposed

Unmasking the Hidden Server: Out-of-Band Infrastructure Exposed

Baseboard Management Controllers (BMCs) represent a formidable, shadow attack surface embedded within conventional rack-mounted servers. Engineered with independent processors, isolated firmware, and dedicated network interfaces, these out-of-band (OOB) devices wield profound administrative control over their host machines. While the security community has scrutinized BMCs since at least 2013, the discourse intensified in August 2026 when HD Moore publicly spotlighted runZero’s deep-dive investigations into OOB infrastructure. Today initiates our structured rollout of vulnerability disclosures, following responsible coordination with affected hardware vendors and technology providers.

This initiative originated from a hybrid methodology: leveraging off-the-shelf AI tools and advanced prompting to surface hundreds of potential candidates. Refining this list to roughly 40 verified vulnerabilities, however, demanded exhaustive, traditional security research. This meant navigating the unglamorous realities of hardware hacking—extensive trial and error, reverse-engineering firmware virtualization, and enduring agonizingly slow physical reboots to validate exploits.

We extend our sincere gratitude to Gadi Evron, Dan Farmer, Fabien Perigaud, Sn0rkY, Solar Designer, and the dedicated teams at NetRise, Dragos Threat Intelligence, and runZero. Their invaluable guidance, testing, and peer review underscore that cybersecurity research is fundamentally a collaborative endeavor.

September 15, 2026 Update: Critical OpenBMC Vulnerabilities

Our inaugural disclosure targets the IPMI implementation within OpenBMC’s phosphor-net-ipmid component. These vulnerabilities were validated against both the OpenBMC reference architecture and downstream products deploying equivalent code bases, notably the NVIDIA BlueField-3 DPU BMC and the H3C HDM3.

It is crucial to highlight the pervasive white-labeling of OpenBMC. Without a robust Software Bill of Materials (SBOM), organizations remain dangerously unaware that OpenBMC is powering the “server inside their server,” regardless of the OEM branding stamped on the exterior chassis.

Vulnerability Mechanics & Exploit Chaining

CVE IdentifierVulnerability TypeMechanism & Impact
CVE-2026-16141Authentication BypassLocated in the RMCP+ session setup pathway. An attacker with network line-of-sight to IPMI can exploit a default key alongside a stale challenge state to establish an authenticated session without possessing the account password. This grants initial foothold access to the BMC’s IPMI interface.
CVE-2026-16140Privilege EscalationAn authenticated, low-privilege IPMI user can maliciously relabel an active session, mapping it to an enabled administrator account. This bypasses the need for the administrator’s password entirely.

When weaponized in sequence, these two vulnerabilities can transform basic network access to an exposed IPMI service into total administrative dominance over the BMC. However, a successful exploit chain requires a “perfect storm” of prerequisites:

  • The target must execute the vulnerable phosphor-net-ipmid code.
  • The IPMI service must be network-reachable.
  • An enabled account name must be known or guessable by the attacker.
  • For CVE-2026-16141, the stale challenge value must be predictable on that specific build (a factor heavily influenced by heap layout, allocator reuse, and precise session creation timing).
  • For the privilege escalation (CVE-2026-16140), an administrator account must already be enabled on the device.

If these complex variables align, a threat actor gains the capacity to rewrite management configurations, manipulate core hardware functions, and infiltrate OOB console and storage mechanisms.

The Imperative of Deep Asset Discovery

Quantifying your exposure to these flaws is rarely straightforward. Standard server inventories typically record top-level vendor and model data, entirely missing the granular, embedded components driving the hardware. This highlights the critical necessity of comprehensive asset discovery.

A fundamental runZero query—such as (protocol:ipmi OR type:=BMC)—delivers immediate visibility into how many BMCs are actively listening for IPMI traffic across your environments. Following our Rapid Response release in August, running a broader IPMI diagnostic query is highly recommended. For teams with dedicated testing environments, runZero’s open-source oobscan toolchain is available to safely probe for these specific vulnerabilities.

Once assets are inventoried, runZero’s network topology and attack path mapping (introduced in version 4.9) become vital. These tools visualize the routing pathways to vulnerable devices, verifying whether your intended network segmentation holds up against reality. Fundamentally, IPMI interfaces should never be accessible from standard user subnets, production application segments, and certainly not the public internet.

Strategic Roadmap: The Month Ahead

This OpenBMC disclosure represents the first wave in a planned series of five technical releases. Over the ensuing weeks, culminating at the end of October, we will publish comprehensive technical details concerning vulnerabilities across several other vendor ecosystems (all of whom have been engaged via coordinated disclosure).

This post will serve as a living document, updated with links to our official advisories as subsequent disclosures go live. Our overarching mission is to eliminate informational asymmetry. The cybersecurity ecosystem remains fragile if deep attack surface knowledge is restricted to a minority of actors. We are committed to educating defenders, implementors, and researchers about the severe risks posed by untracked management interfaces. OOB devices like KVM emulators and BMCs are ubiquitous, frequently bleed outside of isolated management networks, and represent a critical blind spot that demands daily operational vigilance.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Demystifying Managed Broadband Services

The Strategic Guide to Managed Broadband Services

Stop wrestling with ISP outages and disjointed network contracts. Managed broadband transfers the daily burden of network oversight—from security and provisioning to monitoring and failover—from your internal IT team to a dedicated, specialized partner. For multi-site enterprises, this operational shift translates directly to fewer dropped connections, zero ISP headaches, and a single point of accountability. With SC//AcuVigil™ managed network solutions, IT leaders gain unprecedented, centralized control over every location’s connectivity.
What is Broadband Network Management? It is the ongoing discipline of overseeing a network’s reliability, performance, and security, rather than treating internet access as a “set it and forget it” utility. It rests on three core pillars: proactive monitoring to intercept issues, bandwidth optimization for smooth traffic flow, and unified security to thwart emerging threats.

The Cost of the Status Quo: Unmanaged vs. Managed

When organizations handle their own broadband internally, IT staff are constantly pulled away from high-value projects to extinguish connectivity fires. Managed broadband offloads these technical hurdles entirely.
The DIY Approach (Unmanaged) The SC//AcuVigil Approach (Managed)
Juggling multiple ISPs and points of contact. One accountable provider for every single site.
Blind spots: problems are only found when users complain. 24/7 proactive monitoring catches issues before they escalate.
No centralized visibility across locations. A live, unified dashboard tracks uptime globally.
Drowning in separate invoices from various carriers. Consolidated billing streamlines everything into one invoice.
Sites go offline entirely if a primary link fails. Automated WAN failover keeps locations running seamlessly.
Internal IT absorbs every tedious escalation call. The provider handles all ISP break-fix interactions directly.

Core Benefits and Key Features

Transitioning to a managed service empowers distributed organizations—like those in retail, hospitality, and manufacturing—to operate efficiently and securely across all outposts.
  • Uncompromising Reliability: A dedicated Network Operations Center (NOC) monitors connections around the clock, resolving bottlenecks before they become outages.
  • Predictable OpEx: Say goodbye to emergency truck rolls and reactive break-fix fees. Consolidated billing and proactive maintenance stabilize your IT budget.
  • Standardized Security & Compliance: Consistent protections are applied globally, preventing individual sites from improvising their own defenses. Granular reporting provides the historical data needed to prove compliance with frameworks like PCI DSS.
  • Reclaimed Time: By offloading vendor research, provisioning, and troubleshooting, internal teams are freed to focus on strategic, revenue-driving initiatives.

The SC//AcuVigil™ Managed Network Solution

Scale Computing’s SC//AcuVigil platform removes the friction of multi-site connectivity. It provides a comprehensive, end-to-end service suite designed to maximize uptime and simplify operations:
  • Research & Selection: Procures the fastest, most cost-effective broadband for each specific geographic location.
  • Turnkey Provisioning: Manages the complete ordering, configuration, and deployment lifecycle.
  • ISP Break-Fix Management: The SC//AcuVigil team bypasses your IT desk, working directly with ISPs to restore connectivity during service degradation.
  • Uptime Transparency: A cloud-native dashboard delivers crystal-clear visibility into the health of every site.

Bulletproof Resilience: WAN Failover Service

Downtime is not an option. SC//AcuVigil’s WAN Failover service—often referred to as Managed Internet Access (MIA)—guarantees high availability by automatically shifting traffic to a secondary internet connection (such as cellular backup) the moment a primary link drops. This nearly undetectable transition is governed by highly customizable parameters to suit each location’s specific needs. Key capabilities include:
  • Live Connection Status & Dual-Source Monitoring: Instantly see which connection is handling traffic, with real-time health metrics for both primary and secondary sources.
  • Configurable Thresholds: Tailor the exact conditions that trigger a failover or failback event.
  • Automated Logging & Alerting: The system immediately generates a support ticket and notifies stakeholders when a failover occurs.
  • Trend Analysis: Historical reporting helps identify chronic ISP issues, allowing you to refine your long-term connectivity strategy.

Enhance Your Network Infrastructure Today

Investing in managed broadband means choosing business continuity over technical complexity. Partner with Scale Computing to experience unparalleled network reliability, and let our specialists ensure your distributed enterprise stays connected, secure, and efficient.

About Scale Computing
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Demystifying Enterprise Browser Management

The Strategic Guide to Enterprise Browser Management

Executive Summary: The modern workspace is entirely browser-centric. Effectively managing this digital workspace is no longer optional—it is a critical requirement for mitigating cyber risks and safeguarding corporate assets.

The 80% Reality: According to research by Omdia, today’s workforce spends over 80% of their day operating inside browser-based applications. While this highlights the browser’s role as the ultimate productivity tool, it also paints a massive target on its back for cybercriminals.

Because the browser is the primary gateway to your company’s data, it must be rigorously configured and fortified before touching a corporate network. This is the fundamental purpose of enterprise browser management.

Decoding Enterprise Browser Management

Enterprise browser management is the overarching, centralized practice of configuring, updating, and monitoring web browsers across your entire organization. It acts as a command center where IT teams can enforce strict security protocols—ranging from blocking malicious extensions to establishing Data Loss Prevention (DLP) rules that restrict illicit copying, downloading, or uploading of sensitive files.

It is important to clarify a common point of confusion: Enterprise browser management is not synonymous with an enterprise browser.

  • An Enterprise Browser is a specialized software product purpose-built for corporate use, arriving with native security and management controls baked in.
  • Enterprise Browser Management is the broader discipline of centrally administrating any browser fleet within your environment—whether that includes purpose-built corporate browsers or consumer staples like Google Chrome, Mozilla Firefox, and Microsoft Edge.

Why Centralized Management is Non-Negotiable

When the vast majority of your employees rely on browsers to access sensitive data and cloud applications, leaving those browsers unmanaged creates an unacceptable compliance and security hazard.

Without centralized oversight, every individual browser devolves into a blind spot. Unmanaged environments make it incredibly difficult to detect risky behaviors, leaving your data exposed. A user might unknowingly install a rogue extension that scrapes confidential data, run an obsolete browser riddled with unpatched vulnerabilities, or upload proprietary code to an unapproved generative AI tool.

Furthermore, centralized management empowers IT and security teams with the visibility required to accelerate incident response. When you have a panoptic view of your browser fleet, you can instantly pinpoint the origin of a threat, trace its lateral movement, and swiftly execute containment protocols.

The 5 Pillars of Browser Management

A comprehensive management strategy must address several critical vectors to ensure browsers are secure and enterprise-ready:

1. Total VisibilityContinuously track active browsers across your network, logging their versions, configurations, and installed extensions. This prevents outdated software and unauthorized add-ons from compromising your perimeter.

2. Policy & Configuration ControlAbandon device-by-device setups. IT should centrally mandate foundational settings, such as default search engines, homepage destinations, and authorized password management behaviors.

3. Extension GovernanceTake control of the add-on ecosystem. Allow-list essential extensions, block known risky plugins, and forcefully deploy required tools across the organization without user intervention.

4. Data Loss Prevention (DLP)Dictate exactly how users interact with sensitive data. Establish granular rules for copy/pasting, downloading, and uploading based on the specific applications or websites being accessed, drastically reducing the risk of data exfiltration.

5. Regulatory ComplianceEnsure browser usage aligns strictly with internal security mandates. Monitor in-browser activities to generate the audit trails required to prove compliance with strict frameworks like the GDPR.

Tangible Business Benefits

  • Minimized Data Leakage: Strict, browser-level DLP controls act as a formidable barrier against both malicious data theft and accidental oversharing.
  • Accelerated Incident Response: Deep visibility allows security operations to detect anomalies instantly, shrinking the dwell time of threats and minimizing potential blast radiuses.
  • Reduced IT Overhead: By applying policies globally, IT teams eliminate the tedious task of manual, endpoint-by-endpoint configuration, freeing up cycles for high-impact strategic initiatives.
  • Frictionless User Experience: Employees enjoy a standardized, reliable browsing experience regardless of their physical location, with heavy-lifting security protocols operating silently in the background.

Secure Your Fleet with NordLayer Browser

The NordLayer Browser is a purpose-built enterprise solution designed to make mass management effortless while preserving a flawless user experience. Equipped with native, enterprise-grade security tools, it grants IT teams total sovereignty over SaaS applications, AI tool usage, and network downloads.

With NordLayer, you can audit extension usage, enforce stringent data loss prevention policies, and implement Zero Trust browsing architectures that authenticate every single session, user, and request.

Experience frictionless enterprise browser management exactly as it was meant to be. Try NordLayer Browser today, backed by a risk-free 14-day money-back guarantee.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

The Ultimate MSP Client Security Onboarding Checklist

The Ultimate MSP Client Security Onboarding Checklist

When an MSP takes on a new client, they inherit an environment built by someone else. From mailboxes and SaaS connections to random vendor permissions, these systems were likely set up by previous providers or business owners. If inherited vulnerabilities aren’t caught during transition, they become your liability during regular service.

Security onboarding shouldn’t depend on a technician’s individual habits. A standardized, documented process ensures every client receives the same rigorous baseline protection, leaving a clear record of their starting security posture.

Core Takeaways

  • Establish a Firm Baseline: Document all inherited assets, risks, controls, and responsibilities before normal service kicks off.
  • Standardize to Reduce Variance: A consistent workflow ensures every client gets identical core protections.
  • Assess Before Deploying: Always inventory devices, identities, and vulnerabilities before you start installing tools.
  • Continuous Monitoring: Onboarding is just the beginning. Verify your alerts and conduct recurring reviews to catch configuration drift.

Why Bake Security into Onboarding?

Security isn’t a step you can afford to skip during onboarding. It directly impacts client retention, mitigates third-party risks, and prepares businesses for cyber insurance scrutiny.

Onboarding FactorThe ContextThe MSP Strategy
Retention & StructureData shows MSPs with structured onboarding experience lower churn. Only 36% of MSPs currently utilize a formal onboarding process.Treat onboarding as a core service metric. Define milestones, assign owners, and set clear review dates.
Third-Party VulnerabilitiesAlmost half (48%) of all breaches involve third parties, often starting with software vulnerabilities.Map all vendors, remote access pathways, and legacy software before assuming the environment is secure.
Cyber Insurance ReadinessInsurers heavily scrutinize baseline security controls during the underwriting process.Provide concrete documentation of deployed controls and accepted risks to aid clients in insurance discussions.
The “Clean Slate” AdvantageTransitions offer unprecedented access to contracts, legacy controls, and administrators.Record the initial posture so you can measurably prove the value and improvements your MSP has delivered over time.

The 4-Phase Security Onboarding Checklist

A resilient checklist mirrors the order in which you gain control over the client’s environment. Assign clear ownership and completion criteria for every step.

Phase 1: Pre-Onboarding Logistics

  • Map the Hierarchy: Identify technical contacts, security decision-makers, and after-hours escalation paths. Know exactly who can authorize drastic measures like device isolation.
  • Validate Integrations: Confirm that your PSA and RMM tools route correctly. Test tenant naming conventions, alert workflows, and escalation rules.
  • Workspace Setup: Create the client tenant, assign precise technician permissions, and verify access capabilities.
  • Document Third-Party Access: Record all existing SaaS providers, legacy IT vendors, backup services, and remote-access tools. Flag stale accounts for immediate removal.

Phase 2: Discovery and Risk Assessment

  • Comprehensive Inventory: Cross-reference data from the client, RMM, identity providers, and external scans to find unmanaged devices and shadow IT.
  • Identify Critical Assets: Determine which systems, mailboxes, and applications would cause the most damage if compromised.
  • Audit Access Hygiene: Review privileged accounts, MFA enforcement gaps, and shared credentials. Hunt down legacy authentication paths.
  • Vulnerability Scanning: Search for leaked credentials, unpatched software, and public-facing weaknesses that demand immediate remediation.

Phase 3: Baseline Security Deployment

  • Endpoint & EDR Rollout: Deploy protection across all devices. Verify that tamper protection is active and alerts successfully reach your MSP workflow.
  • Universal MFA Enforcement: Lock down every user, admin, and remote access point. Document any rare, approved exceptions with a strict remediation timeline.
  • Email Defense: Configure anti-phishing, impersonation controls, and quarantine behaviors.
  • Identity Threat Detection: Connect workspace sources to monitor for suspicious logins, privilege escalations, or abnormal account activity.

Phase 4: Documentation and Handoff

  • Posture Documentation: Record everything protected, known exceptions, and unresolved risks. Capture approvals for accepted risks.
  • Deliver the Baseline Report: Provide a clean summary of control coverage that the client can share with executives or insurers.
  • Verify Live Monitoring: Test that incident alerts route to the correct queues and after-hours escalations actually fire.
  • Schedule Reviews: Book 30-day and 90-day check-ins to catch newly discovered assets, user changes, and unresolved transition items.

Where Onboarding Processes Derail

Most failures are process-oriented, not tool-oriented. Avoid these common traps to prevent early mistakes from turning into long-term security debt.

Common MistakeResulting RiskThe Better Approach
Deploying tools before assessing riskMissing inherited exposures or protecting the wrong assets first.Finish discovery and prioritize critical systems before rolling out deployments.
Caving to MFA pushbackLeaving privileged or remote accounts wide open to credential theft.Make MFA a non-negotiable baseline. Time-bound any rare exceptions.
Failing to document the starting baselineInability to prove what you inherited vs. what you fixed.Create a dated record of the starting posture and maintain an audit trail of changes.
Treating onboarding as a finish lineConfiguration drift and new vulnerabilities quickly degrade security.Treat onboarding as the launchpad for continuous monitoring and regular reviews.

How Guardz Streamlines MSP Onboarding

Guardz provides MSPs with a unified platform that bridges the gap between initial risk assessment and continuous protection, eliminating the need to duct-tape multiple point solutions together.

  • Pre-Onboarding Prospecting: Scan a prospect’s public-facing assets and compromised credentials to highlight gaps before they even sign.
  • Automated Discovery: Identify high-risk users, shadow IT, and exposed external domains the moment the environment connects.
  • Unified Signal Correlation: Bring endpoint, email, cloud, and identity signals into a single dashboard, mapping full attack chains effortlessly.
  • Multi-Tenant Control: Push global configurations across your entire customer base to standardize protection and slash setup times.
  • Client-Ready Reporting: Generate data-backed security posture reports on demand to hand off to clients at the end of the onboarding phase.

Security onboarding is your opportunity to set the standard. By leaning into structured phases, strict baselines, and comprehensive documentation, your MSP can turn a chaotic IT inheritance into a secured, manageable environment.

About Guardz
Guardz is on a mission to create a safer digital world by empowering Managed Service Providers (MSPs). Their goal is to proactively secure and insure Small and Medium Enterprises (SMEs) against ever-evolving threats while simultaneously creating new revenue streams, all on one unified platform.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Beyond Shadow AI: The Imperative for a Unified Identity Architecture

Beyond Shadow AI: The Imperative for a Unified Identity Architecture

Managing digital access shouldn’t feel like an operational nightmare, yet modern IT teams are navigating unprecedented chaos as the definition of a “user” rapidly evolves.

The Evolution of the Digital Workforce

The modern enterprise workforce has expanded far beyond human employees logging into SaaS platforms. Today, autonomous AI agents, automated workflows, and custom scripts operate at machine speed, frequently accessing core networks and querying databases. Often, these digital entities handle sensitive customer data completely under the IT department’s radar, creating massive governance blind spots.

The Danger of Fragmented Security

Treating human and machine identities as entirely separate problems is a failing strategy. According to JumpCloud’s Agentic IAM Pulse Report, tool fragmentation prevents 92% of organizations from securely scaling their AI agents. When identity and access management (IAM) systems remain siloed, unmanaged “zombie” agents proliferate. Without a direct link between an automated task and a verified user account, IT cannot confirm if an agent’s actions actually align with human intent. Relying on disjointed tools for access, compliance, and security leaves dangerous gaps, allowing over-privileged bots to compromise sensitive corporate data in seconds.

Overcoming Legacy Limitations

Legacy IAM platforms were designed exclusively for human logins, not for governing dynamic, autonomous code. Left unchecked, third-party AI services can spread across endpoints, maintain elevated privileges indefinitely, and open backdoors into your infrastructure. However, outright banning AI or locking down systems stunts business growth. The organizations that will thrive in the agentic era are those that implement robust governance, enabling secure and rapid innovation rather than stifling it.

JumpCloud’s Unified Control Framework

To safely scale automation, JumpCloud delivers a cohesive identity infrastructure purpose-built for the age of AI:
  • Assign Agent Identities: Provision verifiable digital identities to all AI-driven services, ensuring autonomous actions are strictly privileged, secure, and fully auditable.
  • Mitigate Non-Human Identity (NHI) Risk: Connect AI agents directly to core IT systems—from legacy applications to cloud infrastructure—and govern them via a single control plane to eradicate shadow automation.
  • Maintain Continuous Monitoring: Gain 24/7 oversight of device health, corporate data access, and third-party agent permissions across your entire hybrid ecosystem.
Embracing the agentic era means treating AI agents as primary identities right alongside your human workforce, ultimately securing your entire hybrid organization on a single platform.

About JumpCloud
At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Day Zero Support: Scalefusion Prepped for Apple’s 2026 OS Releases

Day Zero Support: Scalefusion is Ready for iOS 27, iPadOS 27, macOS 27 & tvOS 27

The annual Apple update cycle has arrived. With the rollout of iOS 27, iPadOS 27, macOS 27, and tvOS 27, Apple has introduced sweeping changes to device configuration, security protocols, authentication, and compliance. Crucially, this release cycle underscores Apple’s accelerating pivot toward Declarative Device Management (DDM), fundamentally altering how IT administrators oversee enterprise fleets. At Scalefusion, we guarantee Day Zero readiness. We have proactively tested our applications against the latest operating systems and integrated new DDM-based configurations, profile settings, and Automated Device Enrollment (ADE) enhancements. This ensures your IT teams can seamlessly transition to the new OS versions without a hitch in your daily management workflows.
Accelerated Application Readiness We have rigorously tested the entire Scalefusion app suite across iOS 27, iPadOS 27, macOS 27, and tvOS 27. Necessary underlying updates have been applied to guarantee that device and policy management functions operate flawlessly on day one.

Device Profile Modernization: The DDM Shift

Apple Intelligence Settings Migrate to DDM

Beginning with iOS 26.4 and macOS 26.4, Apple officially deprecated traditional MDM restriction keys for controlling Apple Intelligence, migrating these configurations directly into DDM declarations. Scalefusion now natively routes Apple Intelligence restrictions through the DDM channel for supported versions, while maintaining legacy MDM key support for older OS versions. For iOS 26.4 and newer, the following are now DDM-controlled:
  • Allow Genmoji
  • Allow Image Playground
  • Allow Image Wand
  • Allow Writing Tools
  • Allow Personalized Handwriting Result
  • Allow Mail Summary
  • Force On-Device Only Dictation
  • Force On-Device Only Translation
Scalefusion has also introduced new DDM-exclusive controls:
  • Allow Apple Intelligence Report
  • Allow Visual Intelligence Summary
  • Allow Safari Summary
  • Allow Mail Smart Replies
  • Allow Notes Transcription (and Transcription Summary)
  • Allow Calendar Natural Language Editing (Exclusive to iOS 27.0+)
Note for macOS: The same DDM migration applies to macOS 26.4+, excluding mobile-specific features like Image Wand and Personalized Handwriting Result. Calendar Natural Language Editing requires macOS 27.0.

External Intelligence & Siri Settings

Controls for External Intelligence Integrations and External Intelligence Integrations Sign-in are now exclusively delivered via DDM on iOS 26.4+ and macOS 26.4+. Administrators can also configure the new Allowed External Intelligence Workspace ID on both platforms. Similarly, core Siri restrictions—including Allow Siri, Force Siri Profanity Filter, and Allow Assistant while Locked—have migrated to DDM. A new restriction, Allow Siri User-Generated Web Content, is now available for supervised devices.

Fresh Granular Restrictions

New iOS 27 Controls

  • Default App Modification: Lock down the default calling and messaging apps to maintain corporate workflows.
  • Satellite Connection: Toggle satellite connectivity based on organizational compliance.
  • Proximity Setup: Prevent users from utilizing proximity-based configurations when setting up new hardware.

New macOS 27 Controls

  • Captive Portal on Lock Screen: Force users to authenticate via captive portals before bypassing the lock screen.
  • Wi-Fi on Lock Screen: Allow Wi-Fi configuration directly from the lock screen if pre-login network access is necessary.
  • Rosetta Usage Awareness: Toggle user notifications regarding apps utilizing Rosetta to maintain performance awareness.

Advanced OS Update Management (iOS)

The iOS OS Update module has been completely overhauled to offer superior, granular control over patching:
  • Enforce Policies & Deferrals: Strictly enforce update policies or defer them by 1 to 90 days.
  • Automated Configurations (iOS 18+): Control auto-installs, auto-downloads, and the silent deployment of system data files and security patches.
  • Recommended Cadence: Select between deploying All, Oldest, or Newest updates.
  • Rapid Security Responses (iOS 18+): Authorize the installation or rollback of critical Rapid Security Response patches.

Deprecations to Watch

AUE iOS Profiles: The Allow Siri and Allow Assistant while Locked settings now display deprecation warnings. No immediate action is required; existing configurations will continue to function normally. macOS PPPC Deprecations: Apple has deprecated Privacy Preferences Policy Control (PPPC) for the Camera, Microphone, and Speech Recognition in macOS 27. Scalefusion will display a deprecation indicator; these permissions will no longer be pushed to devices running macOS 27+, regardless of your dashboard configuration.

Apple Configuration Enhancements

Platform SSO: OpenID & New Keys

macOS 27 introduces OpenID authentication for Platform SSO. Scalefusion will support OpenID alongside existing methods, allowing you to configure FileVault, Login, and Unlock policies (including grace periods and Apple Watch fallbacks). Furthermore, we are rolling out support for Sync Password from Web Login and Allowed Web Login URLs (mandatory when utilizing OpenID).

Automated Device Enrollment (ADE) Upgrades

Streamlined Setup Assistants

Administrators can now skip new setup screens. iOS skip options now include Liquid Glass, multitasking, and the OS showcase. macOS setup can bypass Apple Watch unlock, Accessibility, Liquid Glass, OS showcase, and software updates.

Auto Advance (macOS & tvOS)

Breeze through the Setup Assistant automatically on macOS and tvOS. On macOS, Scalefusion automatically triggers the Do not create Primary Account setting when Auto Advance is active, enabling a truly zero-touch deployment.

FileVault During Setup (macOS 14+)

Rolling out the week of September 15, a new Force Enable During Setup Assistant option will be available. When active, ADE pauses the Setup Assistant via the Await Device Configured command, installs the FileVault profile, and seamlessly resumes setup.

mSCP 2.0 Compliance Benchmarks

The macOS Security Compliance Project has launched version 2.0, featuring a redesigned schema. Scalefusion’s backend has been upgraded to support this new mSCP 2.0 architecture, delivering CIS Level 1 and Level 2 compliance benchmarks for iOS 27, iPadOS 27, and macOS 27.

Navigate the Future of Apple Management with Scalefusion

Apple’s 2026 OS updates represent a massive leap in configuration control, authentication, and the DDM framework. By leveraging Scalefusion’s Day Zero support, your enterprise can confidently deploy iOS 27, iPadOS 27, macOS 27, and tvOS 27 with cutting-edge management capabilities fully operational.

Rethinking Edge IT: Why Physical Visits Expose Unmanaged Infrastructure

Rethinking Edge IT: Why Physical Visits Expose Unmanaged Infrastructure

Most organizations have thoroughly mapped out their data center virtualization strategies. Yet, when it comes to their distributed edge locations, that strategic clarity vanishes.

Ask an IT leader for a device count at a remote clinic, branch, or retail store. You will receive a number. Now, dispatch an auditor to walk that same facility and count the hardware manually. The physical count is almost universally higher.

This discrepancy is not a product of poor record-keeping. It is the natural consequence of how distributed IT environments are constructed: piecemeal. A POS system arrives with its own server. The security vendor installs a camera DVR. A backup appliance is bolted on. Digital signage requires an independent controller. Each isolated purchasing decision made sense at the time.

No organization sets out to manage 14,000 disparate devices. They simply make a dozen localized decisions, and their total footprint multiplies the complexity.

The Edge Requires a Dedicated Strategy

For the past decade, enterprises obsessed over data center optimization. That was the first major IT decision, and it was necessary. The second major decision dictates how an enterprise runs hundreds or thousands of remote sites—places devoid of server racks, dedicated IT staff, or traditional infrastructure budgets. Success here is not measured by rack density; it is measured by truck rolls eliminated, administrative scale, and localized uptime.

Scale Computing was engineered exclusively for this second decision. We did not build a stripped-down version of a centralized data center platform. We built a system inherently designed for the rugged, unstaffed realities of the edge.

The Devastating Multiplier Effect

Consider the true operational burden of your edge deployments. Take a standard branch location, count the devices, and multiply that by your total number of sites. Now, multiply that figure by the hidden obligations tied to every piece of hardware: firmware updates, support renewals, security patching, and on-site troubleshooting.

If an enterprise operates 1,200 locations with 12 devices each, that is over 14,000 independent infrastructure points. If each device requires manual updates just twice a year, the organization burns tens of thousands of administrative hours annually. You are essentially funding an entire department just to manually touch hardware that a unified platform could manage automatically.

Add the cost of physical dispatch. When hardware drifts or fails, someone must travel to the site. Every truck roll consumes technician time, vehicle costs, and operational downtime. This massive operational bleed is hidden because it spans a dozen different departmental budgets.

The Core Distinction: Managed infrastructure features a unified control plane. You can monitor, patch, and recover systems across your entire footprint simultaneously from a single console. If an infrastructure setup requires a human to travel to the hardware, it is not being managed. It is merely being visited.

Many enterprises falsely categorize their distributed environments as “managed” simply because helpdesk tickets eventually close. But if a Saturday evening failure at a remote plant requires a four-hour drive for a technician, that site is unmanaged. The IT teams are not at fault; they are trapped by an architecture consisting of thousands of independent boxes lacking a shared foundation or central control plane.

Engineered for the Edge, Not Exported from the Core

General-purpose data center platforms struggle at the edge because they expect pristine environments. They demand excessive hardware, flawless connectivity, and on-site expertise. Scale Computing approached the problem from the opposite direction.

Our integrated platform was built for multi-site constraints from day one. It operates flawlessly amid legacy equipment, fluctuating bandwidth, tight physical spaces, and zero on-site technical support. We standardize security, visibility, and management across the enterprise while integrating seamlessly with your existing hardware and carriers. We deliver modernization without demanding a disruptive rip-and-replace overhaul.

Converging Compute, Security, and Connectivity

At the edge, compute, network connectivity, and security are not isolated disciplines. They fail in tandem, yet the industry continues to sell them as separate products with distinct consoles and support numbers. Treating these as three separate problems guarantees operational friction.

Scale Computing unifies edge compute, SD-WAN, and managed network security into a single platform. We process mission-critical AI workloads locally while delivering cloud-managed, multi-link connectivity and continuous security monitoring. It is a single platform providing an infinite edge.

Strategic Modernization on Your Terms

Adopting a true edge platform does not require an immediate, total system overhaul. Capabilities can be layered in over time. You might modernize your edge compute today and roll in managed network services next year. The critical factor is that each new capability lands on the same unified control plane, rather than becoming yet another isolated box requiring physical visits.

Proven at Global Scale

This is not theoretical. Scale Computing powers over 70,000 active sites for more than 7,000 customers across 30 countries. We run the infrastructure for global retailers, healthcare networks, manufacturing plants, and restaurants—locations where the nearest IT pro is hours away, but the systems must remain online.

The urgency for edge platforms is accelerating. AI inference is shifting from the cloud to local clinics and stores to minimize latency and protect privacy. Site digitization—from computer vision to IoT—is creating massive local data footprints. IT labor remains scarce, and localized downtime means immediate lost revenue.

To determine if your organization actually possesses a distributed IT strategy, ask yourself one question: What happens when the business needs to deploy a new application to every single location?

If your answer involves hardware procurement, shipping manifests, and a rollout schedule spanning several quarters, you do not have a platform. You have a physical supply chain. If your answer is that you deploy the application globally via a central console, you have a platform.

Your data center received its deliberate, strategic architectural choice years ago. The locations where you actually conduct business and interact with customers demand that exact same intentionality.

About Scale Computing
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Keepit Shatters $100M ARR Milestone

Keepit Shatters $100M ARR Milestone, Unveils AI Truth Cloud for Enterprise Data Integrity

Keepit has officially crossed the $100 million Annual Recurring Revenue (ARR) threshold. This nine-figure milestone aligns with the rapid market adoption of its AI Truth Cloud—a strategic evolution that transforms SaaS data protection from a passive insurance policy into the verified, immutable foundation required for enterprise AI operations.

$100M+
Annual Recurring Revenue
13x
Growth Since Sept 2020
>55%
Compound Annual Growth Rate

From Passive Backup to the Bedrock of AI

As enterprise AI systems become deeply embedded in daily workflows, the integrity of underlying corporate data has escalated from a technical footnote to a critical business risk. Because AI models are probabilistic, any modifications an AI agent makes to enterprise data are inherited by subsequent processes. If the foundation is flawed, the entire automated ecosystem is compromised.

Keepit’s AI Truth Cloud addresses this vulnerability head-on. By maintaining data in an immutable, highly verifiable state that is strictly separated from primary SaaS providers, organizations gain an absolute source of truth. Whether recovering from a ransomware strike or rolling back an AI-induced data corruption, companies can instantly restore a single item or an entire environment to a guaranteed known-good state.

“Historically, backups simply answered whether you could recover lost files. Today, AI forces a more profound question: Do we inherently trust the data driving our business? Protection has evolved from a baseline operational cost to the bedrock of corporate trust.”

— Frederik Schouboe, Co-founder and Chief Visionary Officer

True Independence Drives Sovereign Trust

Keepit’s accelerated growth is heavily fueled by its refusal to build on hyperscalers like AWS, Google Cloud, or Microsoft Azure. Operating entirely on its own vendor-neutral cloud infrastructure across seven global data center regions, Keepit ensures structural independence. Customers retain unfettered access to their backups even during catastrophic outages at their primary SaaS provider.

This architectural separation is increasingly mandatory for organizations navigating complex data sovereignty laws, conflicting jurisdictional residency requirements, and strict regulatory frameworks.

“Crossing $100 million in ARR proves that the market demands data protection independent of the hyperscalers hosting their primary environments. We scaled this company by prioritizing data sovereignty, immutable storage, and absolute independence. As our AI initiatives accelerate, this growth trajectory is locked in.”

— Morten Felsvang, Co-founder and CEO

Global Scale and Enterprise Adoption

Supported by a 700-person workforce across the Americas and Europe, Keepit orchestrates data protection for a massive portfolio of SaaS applications, including Microsoft 365, Google Workspace, and Salesforce. Delivered through an expansive network of MSPs, aggregators, and resellers, the platform scales effortlessly from single-user setups to global conglomerates.

Keepit currently serves as the trusted data foundation for industry leaders worldwide, including:

  • Porsche Holding Salzburg
  • Carlsberg
  • Saxo Bank
  • Oxford University Innovation
  • KU Leuven
  • Luminus, HDI, freenet, and Emmi

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.