Skip to content

ESET Global Support Wins 2023 SC Awards in Excellence for Best Customer Service

BRATISLAVA, SAN DIEGO— August 22, 2023 — ESET, a global leader in cybersecurity, is proud to announce that the company has won a 2023 SC Award in the Excellence Award category for Best Customer Service.  The SC Awards program is cybersecurity’s most prestigious and competitive program, recognizing the solutions, organizations, and people driving innovation and success in information security. This award recognizes ESET for delivering best-in-class customer support and services and exceeding expectations to ensure that organizations are protected against threats launched by today’s savvy cybercriminals. 

“SC Awards are recognized worldwide by the cybersecurity community, and we are honored to take home the Best Customer Service award this year,” said Brent McCarty, President of ESET North America. “This award speaks to both the transformation already underway and continued investment in our customer service organization, which has expanded with the vision of providing high-touch, localized customer support across time zones, channels, and languages. We understand that it is our job to provide peace of mind to our customers as their cybersecurity partner, and this award speaks to the commitment and outstanding work being done by our teams locally and around the world.”

“This year’s SC Award winners reflected our industry in flux,” said Tom Spring, SC Media’s editorial director at CyberRisk Alliance. “Winners demonstrated uncanny market agility and brought innovative solutions to help their customers stay ahead of increasingly sophisticated adversaries and emerging threats. The innovative strategies and technologies demonstrated by all our SC Award participants truly encapsulated the remarkable innovation within the cybersecurity industry this year.”

ESET’s Global Support has continued to look for new ways to differentiate and expand its offerings in response to an increasingly complex cybersecurity threat landscape and to help customers to adopt robust cybersecurity postures. The company was recognized based on a range of services, including:

  • Commitment to local and easily accessible customer support when and where customers need it. The company has 162 worldwide partners who help provide customer service in the time zones and languages required. For example, in the United States, business customers talk to ESET’s local customer service team in San Diego, California.
  • Multi-channel support that aligns with customer preferences. ESET provides business customers with complimentary support via phone, email, and live chat. ESET also maintains an online support forum where customers can engage with company experts on trending topics and emerging product issues.
  • Comprehensive documentation, including Knowledgebase articles, FAQ documents within ESET Security Forum, and video tutorials that focus on deployment and maintenance, user scenarios, and troubleshooting. Additionally, online user guides are available for every product and provide installation, configuration, and feature overviews for the ESET product. This is bolstered by localized language resources for ESET’s international markets, including French-speaking Canada, Spanish, German, Japan, and more (i.e. 21 languages are available for ESET Protect Cloud, and up to 35 languages are available for Endpoint Antivirus for Windows).
  • Advanced Professional Services in ESET Services Hub, including ESET PROTECT MDR (Managed Detection and Response), Premium Support, and Security Services.
  • Broader awareness and educational resources, including a robust Cybersecurity Awareness Training program for employees to address the human element of cybersecurity, and public resources like WeLiveSecurity, one of the top corporate cybersecurity blogs in the world – available in five languages with written and video content.

“The cybersecurity market continues to mature – with companies looking for enterprise-grade cybersecurity solutions backed by premium managed services,” said McCarty. “Our commitment to best-in-class support sets ESET apart in a fiercely competitive landscape. With ESET PROTECT MDR, organizations can reap the full benefits of Extended Detection & Response (XDR) without having to build an in-house team of digital security experts or add additional resources to their existing team. This allows for advanced capabilities, like triage and investigation, file analysis, incident response, digital forensics, threat monitoring, and even proactive periodic threat hunting – backed by ESET expertise and support teams.”

Now in its 26th year, the 2023 SC Awards are highly coveted and draw a continued record of entries each year. The Excellence Awards included 15 categories and opened participation to cybersecurity startups, investors, and financial partners. Hundreds of entries for the Excellence Awards were judged by a world-class panel of independent industry leaders from sectors including healthcare, financial services, manufacturing, consulting, and education.  Winners are featured on SC Media’s website, with a week of editorial coverage that celebrates the innovative technologies and solutions that support the ongoing efforts of the cybersecurity community.

View ESET coverage and the full list of winners here.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

23.6.12 ‘Voyager’ released

Changes compared to 23.6.11

Enhancements

  • Improved performance of cleaning up Object Lock delete markers during retention passes for S3-compatible Storage Vaults
  • Improve initial startup performance of browsing files to restore from a disk image

Bug Fixes

  • Fixed an issue with errors during a retention pass on an S3-compatible Storage Vault causing the entire retention pass to hang indefinitely
  • Fixed an issue with missing JPEG image format support for custom branding images in the Comet Backup desktop app on Windows
  • Fixed an issue with counting effective group membership for Office 365 Protected Items
  • Fixed an issue with Microsoft 365 batch retry logic not using fallback method when limit is reached
  • Fixed an issue with a crash when browsing files from a Hyper-V backup
  • Fixed an issue with Hyper-V backup where browsing file(s) at the time of restore could crash if a directory name ended in “.vhdx”
  • Fixed a cosmetic issue with the Comet Server web interface homepage widgets if Comet Server Storage Role is backed by unlimited cloud storage
  • Fixed a cosmetic issue with padding around the restore queue section when performing a Disk Image restore from the Comet Server web interface
  • Fixed a cosmetic issue with some missing language translation strings
  • Fixed a cosmetic issue with incorrect spelling for some WebDAV fields

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

CyberLink Launches FaceMe® Platform 5.4, a Complete API Solution for Facial Recognition

Taipei, TAIWAN – August 23, 2023 – CyberLink Corp. (5203.TW), a pioneer in AI and facial recognition technologies, today announced the latest release of FaceMe® Platform.  An on-premise and server based facial recognition API system, supporting various operating systems (Windows, Red Hat, CentOS) and accessible through any web browser, FaceMe® Platform 5.4 further improves the process for developers to add facial recognition to applications for ID verification, such as secure system login, and access control.

FaceMe Platform 5.4 released

Built for Developers 

The FaceMe® Platform’s extensive facial recognition API set – including face template extraction, 1:1 face match (comparison), 1:N face search, video analytics, image quality check, and anti-spoofing – addresses the facial recognition needs of any use case. FaceMe® Platform’s accuracy is top ranked in both NIST (National Institute of Standards and Technology) FRVT 1:1 and 1:N, providing up to 99.83% TAR (true acceptance rate) at 1E-6 FMR(false match rate). It is also iBeta Level 2 Compliant, ensuring liveness detection anti-spoofing functionality when used with phone and tablet cameras.

Already developer-friendly, with tools to quickly test or benchmark the installed API’s, all with little coding needed, FaceMe® Platform 5.4 now offers even more support with a new Developer Resources page. Easily accessible from the management console, all developer needs are now available in a well-organized layout including a Demo System, Test Tool, Documents, Sample Code, and more.

For convenience during setup of new Workstations, FaceMe® Platform 5.4 now includes auto-detection of other Central servers in the same LAN. Users can simply select from a list of Central servers connected to the same LAN without typing in their IP address, saving time, and reducing the potential for error.

Scalable Architecture

FaceMe® Platform’s architecture is fully scalable. As businesses grow and add workstations, the system automatically detects the new unit’s computing power and re-balances workloads to maintain optimal performance. Deploying or replacing workstations in existing systems becomes a quick and painless process – and even more so now for developers using Red Hat Linux. FaceMe® Platform 5.4 supports Docker, enhancing the process for quicker and easier installation, accelerating deployment when expanding systems.

Applications for FaceMe® Platform

FaceMe® Platform can be applied to many applications, especially in banking, financial services, and insurance (BFSI) industries. FaceMe® Platform enables BFSI customers with precise biometric identity verification for customer log in or account creation for secure transactions and protection against fraud. Banks and insurance companies can apply 1:1 biometric verification to ensure their client matches their ID card.  Specific to Taiwan, a new eKYC feature has been added in Version 5.4 that now supports Taiwan ID documents OCR and ID document anti-spoofing via FAuth Web SDK and HTTP API.

Enterprises can also utilize FaceMe® Platform for employee identity verification. Because it is server based, FaceMe® Platform can enable facial recognition from any company laptop, tablet, or smartphone camera, without the need to install software on individual devices. This provides for a simple and secure facial verification ID process for employee login.

“We understand that each customer’s needs are unique. By enhancing the capabilities of the FaceMe® Platform, we’re giving our customers greater flexibility to create their own personalized facial recognition solutions,” said Dr. Jau Huang, CEO of CyberLink. “With the addition of the Developer Resource page, developers now have an easier path to design, test, and implement facial recognition solutions that perfectly match their organization’s requirements.”

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About CyberLink
Founded in 1996, CyberLink Corp. (5203.TW) is the world leader in multimedia software and AI facial recognition technology. CyberLink addresses the demands of consumer, commercial and education markets through a wide range of solutions, covering digital content creation, multimedia playback, video conferencing, live casting, mobile applications and AI facial recognition.  CyberLink has shipped several hundred million copies of its multimedia software and apps, including the award-winning PowerDirector, PhotoDirector, and PowerDVD.  With years of research in the fields of artificial intelligence and facial recognition, CyberLink has developed the FaceMe® Facial Recognition Engine. Powered by deep learning algorithms, FaceMe® delivers the reliable, high-precision, and real-time facial recognition that is critical to AIoT applications such as smart retail, smart security, and surveillance, smart city and smart home. For more information about CyberLink, please visit the official website at www.cyberlink.com

A glimpse into the day-to-day life of a software monitoring expert

Working in the field of software monitoring may seem boring or too technical, but let me tell you that there is more fun and excitement than one might imagine at first.

Not that we’re all day doing barbecues and celebrating, but once we almost did our very own Olympics in the office! Kind of like The Office, you know.

*Long live Michael Scott.

Anyway, join me on this journey for a day in the life of a software monitoring expert, where code lines mingle with laughter and soluble coffee.

Our protagonist, whom we will affectionately call “Captain Monitor”, will face in this pseudo-documentary of flora and fauna, a day full of technical challenges and unexpected surprises.

From the moment he opens one of his lazy, rheum-covered eyes to the moment he closes his latest generation laptop, his life is a roller coaster ride of hilarious emotions and situations.

Early morning

Let’s start with the morning rush hour, exactly when Captain Monitor faces the dreaded flood of alerts in his inbox.

While trying to classify and prioritize alerts, he comes across one that says:

“The main server has become an orchestra of mariachis who just got completely wasted, from the Tenampa Hall to Plaza Garibaldi!”

Yes, you read that right:

It turns out that a “fellow” prankster decided to play a little joke on him and change the alert tones to Lucha Reyes rancheras.

But the surprises don’t end there!

Late morning

During a team meeting, Captain Monitor discovers that his charming cubicle companion has turned his desk into a jungle of cables, pins, modems and other electronic devices…

Between the giant monitor and the stacks of hard drives, the Captain seems to be lost in a kind of modern version of Alan Parrish’s Jumanji.

No matter how much he insists that monitoring modern software doesn’t actually require a work environment of such high technological sophistication, his partner continues and continues to pull plugged-in tinkerers to mock up his particular digital fantasy world.

Early afternoon

In the midst of testing and system tweaks, Captain Monitor also faces the challenges of dealing with “forgetful users.”

Yes, that user who calls all the time with problems that could be solved with a simple reboot.

But our hero doesn’t give up easily and becomes the master of basic reset instructions.

Sometimes he even dreams, as he sleeps in the toilet at nap time, of a life where he doesn’t have to say:

“Have you tried to reboot your device yet?”

Deep Afternoon

But it’s not all chaos and micro-ulcers in the world of software monitoring. Captain Monitor, who as you guessed works in the Support Department, also has his moment of glory when he manages to detect and solve a critical problem of global scale before it causes a collapse in the system of the floral commissioning company he monitors.

In that moment of triumph he feels like he’s on the main stage of a rock concert, with the crowd cheering and the fireworks bursting on top.

“Yes, this is the life I have chosen and I like it!,” exclaims to himself.

Just before the end of the day

At the end of the day, when not all danger is over, but he starts just ignoring it anyway out of pure exhaustion, Captain Monitor relaxes and shares some funny anecdotes with his colleagues in the break room.

They all laugh their asses off and share similar stories of technical madness and tense situations with customers.

It is, more than ever, in those shared moments when Captain Monitor realizes that, despite the challenges and the three thousand crises he suffers daily, there is a special camaraderie among the experts in software monitoring.

They are a close-knit, adventurous, cool community!

Here we go again

And so, the next morning, we are confident that Captain Monitor will rise and shine with renewed energy, ready once again to face another challenging day in the exciting world of software monitoring.

Because while there may be times of frustration and stress… There is nothing quite like the satisfaction of discovering and solving problems to look good with the boss!

Dimas P.L., de la lejana y exótica Vega Baja, CasiMurcia, periodista, redactor, taumaturgo del contenido y campeón de espantar palomas en los parques. Actualmente resido en Madrid donde trabajo como paladín de la comunicación en Pandora FMS y periodista freelance cultural en cualquier medio que se ofrezca. También me vuelvo loco escribiendo y recitando por los círculos poéticos más profundos y oscuros de la ciudad.

Dimas P.L., from the distant and exotic Vega Baja, CasiMurcia, journalist, editor, thaumaturgist of content and champion of scaring pigeons in parks. I currently live in Madrid where I work as a communication champion in Pandora FMS and as a freelance cultural journalist in any media offered. I also go crazy writing and reciting in the deepest and darkest poetic circles of the city.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

Key webinar takeaways: Cybersecurity trends to look out for

Modern security needs are constantly changing, so keeping an eye on emerging trends and evaluating them critically is key. As the attackers are getting better, faster, and stronger by utilizing the emerging technologies, so should the organizations.

Gerald Kasulis, VP of Business & Channel Operations, North America at Nord Security, recently hosted a webinar featuring Matt Lee, Senior Director of Security and Compliance at Pax8, and Frida Kreitzer, IT Consultant at FridaIT. Together they shared insights on the tech trends that are shaping cybersecurity into the near future.

Topics discussed included the shift towards Zero Trust architecture, ransomware’s surging menace, and the growing momentum in passwordless authentication.

Watch the full recording below, or keep reading this blog for some of the key takeaways we took from the webinar.

Cybersecurity landscape

Matt Lee believes that changing market conditions demand a heightened focus on cybersecurity: “what changed drastically is that we actually started feeling the pains of threat actors’ endeavors. But the big shift that I think took place is that people are actually trying to solve the cybersecurity problem at the SMB and mid-market level.”

Frida Kreitzer gave a quick overview of the situation on the ground for IT teams in the current threat landscape, where more than 80% of cyberattacks are made possible by human error. For her, the primary concern is: “How can we be as proactive as possible without “breaking” the company?”

Zero trust, but more security

Never trust, always verify

A Zero Trust architecture assumes that all network traffic is untrustworthy, regardless of origin. It’s become an increasingly significant area of interest for business leaders, as it minimizes risk by dividing your assets into walled-off sections.

“Zero Trust is a world where I know the device’s posture is healthy.” Matt suggests not even allowing network connections to be attempted if certain criteria aren’t reached: “If it’s got the right [security] tools, it’s using a layer for access, and it’s coming from the right IP address, then I’ll let someone try a password. Why would I even [allow an attempt] if they’re not meeting those conditions?”

Perimeter model

Matt draws a comparison between fortified castle walls and the perimeter model which has been “the mainstay of network security for decades. In both scenarios, the fortified area has a single gateway for access. But when cannons are rolled up or spies sneak through the gate, the perimeter can no longer adequately protect its inhabitants.

When new means of attack are developed, defenses must adapt. “Business email compromises and social engineering have grown extremely large,” Matt says, referring to the most common methods used by hackers to gain access. “It’s a different world now, that [requires changing] to a different policing model.”

Verify first, then trust

Matt sees Zero Trust as a shift from the attitude of trust first, then verify.

quote bubble

IoT security risks

Security leaders should consider more than just end users when addressing security concerns, Frida observes. With every additional device on your network, your potential attack surface expands. Internet of Things (IoT) devices can be particularly risky:

Ransomware: Not going anywhere

State of ransomware

Ransomware attacks have been surging in recent years. Matt observes that ransomware groups have become so efficient as to resemble legitimate businesses:

Matt explains that ransomware has become a fully-fledged economy unto itself, with various personas, services, and markets operating within. “I could be a bloke that just breaks into companies – that’s an initial access broker. You’ve heard of SaaS or software as a service. Well, now there’s RaaS – ransomware as a service. I can go to a marketplace and not only find a victim. The marketplace has all the infrastructure, all the capabilities to fully enact a ransomware scheme.” The problem has escalated to the point that law enforcement agencies worldwide and the recent US National Cybersecurity Strategy prioritize the dismantling of ransomware gangs.

Should you pay?

Gerald poses a controversial question on the topic – should you pay the ransom?

For Matt, “It depends. For me, it’s typically a balance of the greater good. And I think that that’s where I would try to make that decision of what’s in the best interests of everyone involved: the company, the customers, the patients. So it’ll come down to the sensitivity of the data, the impact, the gravitas of it. All of those things come into the conversation. Each one is a business by business decision.”

Frida suggests that pay or not, companies won’t be guaranteed safety from other attacks in the future. “They will get blackmailed again and again… Now you’re a target. We know that you’re vulnerable.” Frida says baking security into your software in early development should be a priority, but the real challenge is staying proactive on an ongoing basis.

Avoiding complacency is a big point for Matt as well: “Just like any business risk, you’re going to have to deal with it on a continuous basis. This is a continuous improvement model.”

Security leaders should be particularly vigilant when dealing with external contractors or consultants. Frida outlines the risks: “Someone who doesn’t know policy, someone who doesn’t have a company computer, someone who doesn’t use a password manager. Someone who’s easily susceptible to social engineering.”

Frida warns smaller companies not to assume they’ll fly under the radar:

Promises of passwordless: What’s the benefit?

The future of authentication – passwordless

The humble password, used since the early days of the internet, represents an increasingly outdated means of authentication, compromised with growing ease by social engineering or brute force attacks. As Matt says, “Passwords can be tricked or coerced from you.” The golden term for forward-looking, security-conscious organizations is “passwordless”.

Frida Kreitzer weighs in: “Most simply, [passwordless] means you’re not having to type in a password or use a password manager for authentication. That’s very exciting – you’re skipping that portion and just going straight to MFA (Multi-factor authentication, where multiple criteria have to be reached in order for the user to be authenticated). It’s a key that’s being sent to a device – usually a phone.”

Passkeys – a simpler and safer sign-in

Passkeys, digital credentials generated by a device, are invisible to the user, and represent a big step forward for the passwordless future. By removing the need for passwords and relying on user devices or biometrics for authentication, passwordless essentially circumvents the risk of password-related attacks.

Built on public-key cryptographic algorithms, passkeys are virtually impossible to phish or hack. Matt explains: “A [passkey] is a cryptographic representation of you that’s very hard to beat – it’s really large math.”

Closing comment

Getting your cybersecurity into a resilient posture is no mean feat. Matt points out that helpful frameworks exist that can support getting the ball rolling. “Stop trying to be the smartest guy or gal in the room. CIS (Center for Internet Security) has 153 little “do this” statements… if you do each of those you’ll greatly reduce your risk and reduce overspending because you won’t duplicate efforts. Be pragmatic.”

Important to remember is not to exaggerate or overstate security concerns when communicating with stakeholders. This can cause diminishing returns, according to Frida:

quote bubbleAs technology continues to evolve, so do the threats that emerge alongside it, shaping the cybersecurity landscape and the strategies needed to navigate it. Understanding these ever-changing trends is vital for any business aiming to build robust defense mechanisms. They can embrace security strategies like Zero Trust architectures, prepare for the relentless threat of ransomware, and explore cutting-edge authentication methods, such as passwordless systems. Through these strategic measures, organizations can enhance their digital security, preserving trust and ensuring continuity in an era marked by swift technological changes.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

ESET Research: Mass campaign aimed at stealing Zimbra email users’ credentials under way, European countries top targets

  • ESET researchers have uncovered a mass-spreading phishing campaign aimed at collecting Zimbra account users’ credentials, active since at least April 2023 and still ongoing.
  • Targets include a variety of small and medium businesses and governmental entities.
  • According to ESET telemetry, the largest number of targets are located in Poland; other European and Latin American countries were also hit.
  • The campaign observed by ESET relies only on social engineering and user interaction.

BRATISLAVA — August 17, 2023 — ESET researchers have uncovered a mass-spreading phishing campaign aimed at collecting Zimbra account users’ credentials. The campaign has been active since at least April 2023 and is still ongoing. Zimbra Collaboration is an open-core collaborative software platform, a popular alternative to enterprise email solutions. The campaign’s targets are a variety of small and medium businesses and governmental entities. According to ESET telemetry, the largest number of targets are located in Poland; however, victims in other European countries such as Ukraine, Italy, France and the Netherlands are also targeted. Latin American nations were hit too; Ecuador tops the list of detections in that region.

Despite this campaign not being particularly technically sophisticated, it is still able to spread and successfully compromise organizations that use Zimbra Collaboration.  “Adversaries leverage the fact that HTML attachments contain legitimate code, with the only telltale element being a link pointing to the malicious host. In this manner, it is much easier to circumvent reputation-based antispam policies, especially compared to more prevalent phishing techniques, where a malicious link is directly placed in the email body,” explains ESET researcher Viktor Šperka, who discovered the campaign.

“Target organizations vary; adversaries do not focus on any specific vertical – the only thing connecting victims is that they are using Zimbra,” adds Šperka. The popularity of Zimbra Collaboration among organizations expected to have lower IT budgets ensures that it stays an attractive target for adversaries.

Initially, the target receives an email with a phishing page in the attached HTML file. The email warns the target about an email server update, account deactivation or similar issue and directs the user to click on the attached file. After opening the attachment, the user is presented with a fake Zimbra login page customized according to the targeted organization. In the background, the submitted credentials are collected from the HTML form and sent to a server controlled by the adversary. Then, the attacker is potentially able to infiltrate the affected email account. It is likely that the attackers were able to compromise the victim’s administrator accounts and created new mailboxes that were then used to send phishing emails to other targets. The campaign observed by ESET relies only on social engineering and user interaction; however, this may not always be the case.

For more technical information about campaign against Zimbra, check out the blogpost “Mass-spreading campaign targeting Zimbra users” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

Countries hit by the campaign, according to ESET telemetry

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Capitalizing on threats & opportunities – now is the time to venture into cybersecurity

In our rapidly digitizing world, the role of cybersecurity cannot be overstated. The increase in online platforms and the adoption of digital solutions by businesses of all sizes have led to a surge in cyber threats. While the scope of online risks is expanding, the need for cybersecurity grows exponentially.

A challenge for some is a golden opportunity for others. Thus, this growing need for cybersecurity solutions presents a lucrative business prospect for Managed Service Providers (MSPs) and resellers to partner with cybersecurity firms and offer their clients robust protection.

Cybersecurity market: threats and opportunities

Despite the escalating cyber threats, virtual work setup offers immense potential for businesses and enterprises. To better understand the risks and, paradoxically, their advantages, let’s review the current cybersecurity setting.

Luring risk of cyber attacks

According to Statista, projected from 2023 to 2028, the total global cost of cybercrime is anticipated to surge by 5.7 trillion U.S. dollars, showcasing a notable rise of 69.94%. The latest estimates indicate that by 2028, global expenses related to cybercrime will soar to 13.82 trillion U.S. dollars.

Year after year, data breaches and ransomware attacks have wreaked havoc on the digital landscape. Recent cybersecurity threats research revealed that phishing attacks and malware are top risks businesses of all sizes are exposed to the most. Yet due to the dynamic cyber climate, leading threats constantly evolve, shifting their positions.

For instance, small- and medium-sized businesses (SMBs) are the most vulnerable, as companies with fewer than 1,000 employees bear the brunt of 46% of all cyber breaches. These statistics emphasize that no business is too small to ignore the importance of cybersecurity.

Moreover, analysis shows that ransomware attacks will reach an astounding 620.5 million cases in 2023, eventually costing approximately $265 billion U.S. dollars by 2031. Although it’s only a glimpse into the future digital ecosystem perceptions, the need for fortified cybersecurity solutions is more pressing than ever.

Possibilities dictated by the digital landscape

The silver lining in this situation lies in a boom in the cybersecurity market. This creates an opportune moment for MSPs and resellers to venture into cybersecurity. The global cybersecurity market size is predicted to grow exponentially in the coming years, and those prepared to seize the opportunity now stand to gain immensely.

This opportunity emerges as a prediction for MSP industry revenue to reach €21.18bn in 2023. The anticipated annual growth rate (CAGR 2023-2028) is 2.84%, culminating in a market volume of €24.36bn by 2028.

According to cybersecurity investments research, 59% of companies plan to purchase cybersecurity solutions, services, or applications. 52% of those who plan to invest in cybersecurity solutions and services are small– and medium–sized enterprises.Companies 1400x764

In addition, research gives an overview of major markets like the U.S., Canada, and the United Kingdom, revealing that approximately 22% of enterprises outsource their cybersecurity expertise. On average, almost 12% of companies don’t have in-house or outsourced cybersecurity professionals.

Regarding company size, a majority (52%) of small businesses don’t have and don’t outsource skilled cybersecurity staff, while 29% of medium-sized companies tend to outsource these functions.

Challenges faced by most MSPs & resellers

Like every sector has its own challenges, managed service providers and resellers encounter various obstacles in outsourcing business. According to Statista, in 2022, the most prominent impediments were coping with advanced and sophisticated security threats and acquiring more customers.

MSPs business challenges worldwide in 2022 1400x840

In 2022, 30–40% of respondents in EMEA (Europe and Middle East Africa), Americas, and APAC (Asia-Pacific) regions saw gaining new customers as a challenge. By 2023, 29% of service providers still cited the acquisition of new clients as their biggest challenge, followed by revenue growth and profitability.

Besides the struggle to find more clients, handling cybersecurity threats is an issue for a significant number (approximately 20%) of MSP and reseller companies in 2022. Service providers are directly exposed to digital threats like their customers and any other modern company.

NordLayer: your trusted cybersecurity partner

Navigating the cybersecurity landscape might seem daunting for many MSPs and resellers. That’s where NordLayer comes into play.

NordLayer offers a comprehensive partner program to help you tap into this booming cybersecurity market, enhancing your business performance and increasing your profits.

Boost your business performance

With NordLayer, your business can gain a competitive edge through an accessible software-defined solution. Our remote security solution ensures your clients stay safe online, allowing you to stay ahead of the game.

Grow your profits

NordLayer’s easy-to-adapt software eliminates the need for expensive hardware, saving your clients significant costs. By opting for a subscription-based SaaS model, you can enjoy a steady stream of recurring revenue, greatly amplifying your financial gains.

No tech expertise is needed

NordLayer simplifies the process of selling cybersecurity solutions. This means you don’t need a deep understanding of tech and network knowledge or invest in human resources education or competencies to start selling.

24/7 support

We believe that partnership goes beyond selling solutions. With NordLayer, you gain access to a committed, caring, and proficient technical support team available round the clock, helping you identify and close deals and propelling you toward success.

Efficiency is our priority

At NordLayer, we prioritize efficiency. With our solutions, you can onboard clients in under 10 minutes and scale rapidly. No minimum order requirement makes NordLayer ideal for SMBs. Network deployment and administration are simplified, without the need for complex hardware or tedious configurations, saving time and resources while boosting productivity.

Afterword

The time is ripe for MSPs and resellers to seize the opportunities in the cybersecurity market. With NordLayer as your partner, you will be well-equipped to navigate this booming sector and take your business to new heights. The cyber threats are real, but so are the opportunities. Now is the perfect time to start selling cybersecurity solutions.

Future partner, become an enabler securing all ways of working by joining forces with NordLayer.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

23.6.10 ‘Voyager’ released

Changes compared to 23.6.9

New Features

  • New design for the Comet Backup desktop app.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

Leading SaaS Data Protection Provider Keepit Launches Backup and Recovery for Microsoft Azure DevOps

New Service Offers Unrivaled Protection for Azure DevOps Users

COPENHAGEN, DENMARK  – June 29, 2022 – Keepit, the market leader in cloud data protection and management, today announced the launch of its new backup and recovery service for Microsoft Azure DevOps. Keepit is the world’s only independent, vendor-neutral cloud dedicated to software-as-a-service (SaaS) data protection with a blockchain-verified solution, and the Azure DevOps service adds to the company’s already industry-leading coverage for Microsoft’s cloud services.

“Azure DevOps has limited disaster recovery coverage. If a company loses its Azure DevOps data, it loses access to development operations, which means it loses the ability to track, document and deliver what software it’s building. Those losses can have a severe impact on the development team’s productivity and ability to deliver to its customers,” said Paul Robichaux, Keepit’s senior director of Product and a Microsoft Most Valuable Professional (MVP).  

  

DevOps is a set of practices that combines software development (Dev) and IT operations (Ops) and is characterized by key principles of shared ownership, rapid and continuous deployment, workflow automation, and rapid feedback. It is a way of thinking, collaborating and driving effectiveness and efficiency in software development, with a goal of delivering software more quickly while maintaining high quality. 

  

Azure DevOps (ADO) is Microsoft’s solution for implementing DevOps and supports a culture and set of processes that bring together developers, project managers, and individual contributors. Tools available as part of the Azure DevOps suite include Azure Boards, a standalone service that helps teams plan, track and discuss work across the entire software development process, and Azure Pipelines, which provides build and release services to support continuous integration and delivery of applications. With its simple, fast and flexible Azure DevOps backup and recovery service, Keepit safeguards these workloads against large-scale disasters and provides its customers with the following: 

  

  • The most comprehensive protection and quickest recovery for Azure DevOps Boards and Pipelines data and metadata​ 

    -Protection for Azure boards, including work items, boards, backlogs, team sprints, queries, and delivery plans 

    -Restoration with full metadata, including comments, custom fields, and attachments 

    -Rapid restoration of critical continuous integration and continuous development/deployment (CI/CD) automations and Pipelines to a known-good state​ 
  • Immutable storage of data in Keepit’s ISO 2700-certified private cloud, providing​ long-term archive or escrow copy of sensitive ADO data 
  • Granular protection that delivers speedy recovery, including for accidental deletions or changes, to minimize disruption to mission-critical activities. 
  • Compliance with various data protection regulations. 

  

 

Robichaux added, “Keepit’s fine-grained, incremental coverage protects against both ‘Oops’ scenarios and large-scale incidents. Our Azure DevOps backup and recovery service will enable businesses to protect their software development operations as an add-on to the coverage we offer for Microsoft’s cloud services. We are excited to include this in our already robust stable of offerings for our clients.” 

 

With its unmatched ease of use, fast restore features that minimize downtime, and cost-effectiveness, Keepit continues to be the solution that organizations rely on to protect their cloud-based data. For more information on Keepit’s backup and recovery for Azure DevOps, visit keepit.com

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

Essential cybersecurity measures when scaling your business

As businesses grow and expand in the digital era, their security must also advance. Business expansion brings more cybersecurity risks, including cyber attacks and data breaches. Because the cost of data breaches is currently very high, businesses face a challenge: as they grow, they become more attractive to hackers.

This is why it’s vital to consider boosting cybersecurity as your business grows. Let’s explore how a strong cybersecurity plan can safeguard intellectual property, sensitive data, and other crucial business resources.

Key takeaways

  • As businesses grow and expand, their cybersecurity risks also increase

  • To safeguard against increasing threats, a scalable cybersecurity policy should be developed

  • Conducting an internal cybersecurity audit helps identify system strengths and  weaknesses

  • Strengthening IAM ensures users have appropriate access privileges based on their roles

  • Encryption and VPNs safeguard sensitive data, making it unreadable to unauthorized individuals, and prevent data interception

  • Aligning with compliance requirements helps businesses avoid legal complications

  • Network segmentation limits the extent of damage a cyber attacker can cause

Understanding cybersecurity for business growth

Ensuring your business runs smoothly involves giving your team access to networks and IT systems. But as you do this, you also make your business a bigger target for problems. When you have more devices to keep safe and lots of data to handle each day, the chances of a cyberattack increase as your business grows.

Related articles

 

What is Security Compliance Management

In Depth

What is Security Compliance management?

And it’s not helping that cybercrime is on the rise. Different kinds of attacks can slow down or even stop your business. This can hurt how much your customers trust you, how people see your brand, and how much money you make.

When the key to doing well in business is being able to bounce back, you can’t forget about cybersecurity. These days, keeping your business safe from online problems is just as important as any other basic part of your business. The people who handle IT and the ones who run the business need to work together. If they don’t, your business can’t keep growing because it won’t be safe from new kinds of problems.

What are cybersecurity threats that businesses may face when scaling up?

Expanding a business means making it bigger online, which can lead to more cybersecurity problems. Here are some specific security issues that a business might have while growing:

Cloud problems: When businesses get bigger, they use more cloud services. But these can be weak against cyberattacks. For instance, outsiders might access private data if cloud settings aren’t set up right.

Increased attack surface: When a business grows, its networks, systems, and data increase. Attackers get more chances to break in, causing data leaks.

Insider threats: With more employees, there’s a bigger chance of trouble from insiders. Some might want to intentionally harm the company (like unhappy workers), while others might accidentally cause problems (by clicking on bad links).

Phishing and social engineering: These types of attacks go up as businesses get bigger. Bad actors try to fool employees into sharing secret info.

Third-party vulnerabilities: Growing companies often work with more outside vendors. But these vendors might not have great security. They could open the door to attackers.

Advanced Persistent Threats (APTs): Some attacks never stop and keep trying to break in for a long time. Big companies are often targets for these attacks because they can lead to big rewards.

Distributed Denial-of-Service (DDoS) attacks: Bigger companies might get hit with attacks that flood their systems, causing them to crash.

More complications: Expanding often means adding new tech and software, making things more complex. This can make it tough to keep everything safe and organized.

Regulatory compliance: As businesses get larger, they usually need to follow more rules, especially if they operate in many places. They could expose data and get fined if they don’t follow these rules.

Scaling security: the key to successful growth

When the number of threats increases and their techniques become increasingly sophisticated, this calls for a cybersecurity framework encompassing a scalability and growth plan. This means aligning with current requirements while considering infrastructure modernization for businesses.

Creating a scalable security system ensures that your cybersecurity program can grow with it as your business grows, not lag behind. A scalable security system can anticipate the changing landscape and proactively address potential security risks before they become an issue. Therefore, investing in scalable security is critical to sustainable business growth security.

Scaling your business safely: essential online security measures

As your business grows, it’s important to approach cybersecurity carefully. This helps protect your company from online threats, keep your data private, and follow rules and regulations.

1. Conduct an internal cybersecurity audit

Associative visual for a cybersecurity audit 1400x800

Conducting an internal audit is a crucial first step toward scaling cybersecurity. It helps an organization gain a comprehensive understanding of its existing cybersecurity posture. This includes identifying strengths, weaknesses, and vulnerabilities within the system. Without a clear picture of the current state, it’s challenging to determine where improvements are needed.

The audit also helps to identify potential risks and threats. This involves analyzing the security infrastructure, data handling processes, employee practices, and more. The critical areas that need the most attention can be prioritized by knowing the risks. It ensures that resources are allocated effectively to maximize security.

2. Educate employees

A “human firewall” refers to the idea that employees, through their awareness, knowledge, and actions, can play a crucial role in preventing and mitigating cybersecurity incidents. Employees who are educated about cybersecurity threats, best practices, and policies are better equipped to recognize and respond to potential attacks.

Regular cybersecurity training can help them understand the latest tactics used by cybercriminals and how to avoid falling victim to scams, phishing attempts, and social engineering attacks.

Creating a strong cybersecurity culture within an organization instills the belief that every employee has a role in protecting the company’s data and systems. The organization’s overall security posture improves when cybersecurity is everyone’s responsibility.

3. Strengthen Identity and Access Management (IAM)

As an organization grows, the complexity and scale of its operations also increase. This growth leads to more employees, contractors, partners, and customers accessing various resources and systems within the organization. As a result, the need for effective identity and access management (IAM) becomes paramount.

Different roles and departments have varying access requirements. Therefore, effective IAM ensures that users have appropriate access privileges based on their roles and responsibilities. This avoids granting excessive permissions and reduces the risk of unauthorized access. It’s a fundamental component of any cybersecurity strategy.

4. Use encryption and virtual private networks

Using encryption and virtual private networks (VPNs) is a crucial cybersecurity measure. Encryption helps to safeguard sensitive data by converting it into an unreadable format that can only be decrypted with a specific key or password. This prevents unauthorized access to data, even if it’s intercepted during transit or at rest. Without encryption, sensitive information such as passwords, financial details, and personal details would be vulnerable to theft or unauthorized use.

Meanwhile, a business VPN creates a secure tunnel between the user’s device and a remote server, encrypting all data transmitted. This prevents hackers and cybercriminals from eavesdropping on the data being exchanged. It’s particularly important when using public Wi-Fi networks, where data can be easily intercepted without proper security measures.

5. Step up your organization’s compliance alignment

Aligning with compliance requirements is a non-negotiable aspect of scaling cybersecurity. Laws, regulations, and industry standards dictate compliance requirements. Failure to comply leads to legal consequences, including fines, penalties, and lawsuits.

Compliance frameworks are designed to address specific risks and vulnerabilities in the cybersecurity landscape. Regulations like GDPR and HIPAA set certain data privacy and security standards that businesses must adhere to. By meeting these compliance requirements, your business avoids legal complications and demonstrates to clients and customers that you prioritize their data’s security.

6. Implement network segmentation

Associative visual for network segmentation 1400x800

Network segmentation involves dividing your network into multiple segments, each with its security controls. These segments are then isolated, creating barriers that restrict unauthorized access and the lateral movement of attackers within the network. It limits the extent of damage a cyber attacker can cause if they manage to breach your system. It’s vital to a scalable security strategy, protecting your business scales.

Even if hackers access a segmented network, they cannot move laterally across the network. This means that the hackers are trapped within the network segment, giving companies more time to respond to threats and contain the damage.

Protect your business with NordLayer: your cybersecurity partner

As your business expands, keeping it secure becomes crucial. You can take simple steps to ensure your growth is safe. Educating your employees and organizing your network are some of these steps. Working with partners who can grow with you is also smart.

NordLayer is here to help when your business is growing fast. No matter what is your business size or work model, you can keep your network security up to standard.

With NordLayer, you can enable secure access to your cloud platforms. Additional controls and ZTNA-focused contextual checks can be implemented to improve the organization’s security posture further.

Organizations using NordLayer can set up resource access policies with SSO, network segmentation, site-to-site tunnels, and more. There is an audit log for all actions completed within the Control Panel, including gateway connection timestamps helping to keep track of what’s happening within your network.

NordLayer makes your business more secure. Want to know more? Get in touch with our sales team to learn more about our offerings.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Nord Security
The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.