Skip to content

HIPAA: Five Tips for Complying with The Certificate

What is HIPAA? Currently, this is one of the most frequently asked questions by many professionals working in the healthcare industry, especially in times of the Covid-19 pandemic.

But why is it so important and what are its benefits for healthcare companies? First, it is critical to comply with HIPAA to ensure that more secure procedures are in place regarding the handling of some critical information.

However, it must be emphasized that this law is North American. Based on this, there is no document or certificate in Brazil capable of attesting that your company is working following HIPAA.

Thus, working following HIPAA means working in accordance with the standards established by foreign law.

But following these guidelines is a movement that, fortunately, has been gaining many followers in Brazil.

It must be taken into account that HIPAA is extremely important, as it aims to ensure information security in all companies operating in the healthcare industry.

With that in mind, we have prepared an article with five fundamental tips to help your company work in compliance with this law. Check it out!

1. Know HIPAA in Detail

Why is it important to know all the details of HIPAA? To make sure all its points are met.

As mentioned, the Health Insurance Portability and Accountability Act (HIPAA) is a law of foreign origin and applicable in the United States.

So, it can be described as a group of standards aimed at companies in the healthcare industry.

The aim is to ensure data protection. Although HIPAA is legally applicable to the North American territory, this law has inspired many entities around the globe that are part of the healthcare universe.

These companies use various resources to adapt to the rules and guidelines set forth by this law.

The intention is to practice the procedures that guarantee enhanced security in relation to information that circulates in the healthcare sector.

As a result, customers are more confident in doing business with companies that adapt to this foreign law.

Therefore, you can increase the credibility of your brand in a market that is increasingly competitive.

Requirements to Be HIPAA Compliant

Certain requirements must be followed by all companies that aim to comply with HIPAA.

After all, they indicate the standards necessary to protect the electronic medical records of doctors and patients.

Based on this, one could say this law was created to cover several objectives, such as:

  • Offer improvements to the healthcare industry;
  • Ensure a high level of security of patient information and privacy;
  • Determine that healthcare companies provide medical records to patients whenever requested;

2. Assess Your Company’s Infrastructure According to HIPAA

One of the key issues for companies looking to comply with HIPAA standards is a thorough analysis of their IT structure.

For that, they must have a broad vision of the possible vulnerabilities and risks that may appear during the activities.

In this way, it will be possible to identify sensitive loopholes to fully comply with this law.

Another interesting aspect is to assess the information security practices present in the organization and understand if the level of security provided by them is within the ideal.

Thus, analyze whether these practices are capable of guaranteeing the confidentiality of health information, as well as the security of data considered more sensitive.

An effective tip is to observe the procedures being performed to obtain the resources capable of correcting current threats, thus conforming to HIPAA guidelines.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

Absolutely no one is safe from security attacks

Software developers and manufacturers around the world are under attack by cybercriminals. It is not like we are in a time of the year in which they spread more and they barricade themselves in front of the offices, with their evil laptops seeking to blow everything up, no. They are actually always there, trying to violate information security, and in this article we are going to give you a little advice on the subject.

No one is safe from all threats

Whether it is a middling attack or sophisticated and destructive (as it happened to our competitors Solarwinds and Kaseya) evil never rests. The whole industry faces an increasingly infuriating threat landscape. Almost every day we wake up with some news of an unforeseen cyber attack that brings with it the consequent wave of urgent and necessary updates so that our system is safe… Nobody is spared, real giants have fallen over. The complexity of the current software ecosystem means that a vulnerability in a small library affects hundreds of applications. It happened in the past (openssh, openssl, zlib, glibc…) and it will continue to happen.

As we pointed out, these attacks can be very sophisticated or they can be the result of a combination of third-party weaknesses that make the client vulnerable, not because of the software, but because of some of the components in its environment. That’s why IT professionals should demand that their software vendors take security seriously, both from an engineering standpoint and from vulnerability management.

We repeat: No one is safe from all threats. The software vendor that took others out of business yesterday may very likely be tomorrow’s new victim. Yes, the other day it was Kaseya, tomorrow it could be us. No matter what we do, there is no 100% security, no one can guarantee it. The question is not to prevent something bad from happening, the question is how to manage that situation and get out of it.

Pandora FMS and ISM ISO 27001

Any software vendor can be attacked and each vendor must take the necessary additional measures to protect itself and its users. Pandora FMS encourages our current and future clients to ask their suppliers for more consideration in this matter. We include ourselves.

Pandora FMS has always taken security very seriously, so much so that for years we have had a public policy of “Vulnerability disclosure policy” and Artica PFMS as a company, is certified with the ISO 27001. We periodically employ code audit tools and maintain some modified versions of common libraries locally.

In 2021, in face of the security demand, we decided to go one step further, and make ourselves CNA of CVE, to give a much more direct response to software vulnerabilities reported by independent auditors.

Decalogue of PFMS for better information security

When a client asks us whether Pandora FMS is safe, sometimes we remind them of all this information, but it is not enough. Therefore, today we want to go further and prepare a decalogue of revealing questions on the subject. Because some software developers take security a little more seriously than others. Relax, these questions and their corresponding answers are valid for both Microsoft and Frank’s Software or whatever thing you may have. Since security does not distinguish between big, small, shy or marketing experts.

Is there a specific space for security within your software life cycle?

At Pandora FMS, we have an AGILE philosophy with sprints (releases) every four weeks, and we have a specific category for security tickets. These have a different priority, a different validation cycle (QA) and of course, a totally different management, since they involve external actors in some cases (through CVE).

Is your CICD and code versioning system located in a safe environment and do you have specific security measures to ensure it?

We use Gitlab internally, on a server in our physical offices in Madrid. People with name and surname, and unique username and password have access to it. No matter what country they are in, their access through VPN is individually controlled and this server cannot be accessed any other way. Our office is protected by a biometric access system and the server room with a key that only two people have.

Does the developer have an ISMS? (Security Incident Management System)

Artica PFMS, the company behind Pandora FMS, is certified with ISO 27001 almost from its beginnings. Our first certification was in 2009. ISO 27001 certifies that there is an ISMS as such in the organization.

Does the developer have a contingency plan?

We not only have one, we have had to use it several times. With COVID, we went from 40 people working in an office in Gran Via (Madrid) to each and everyone of them working at home. We had power outages (for weeks), server fires and many other incidents that put us to the test.

Does the developer company have a security incident communication plan that includes its customers?

It has not happened many times, but we have had to release an urgent security patch, and we have notified our clients in a timely manner.

Is there an atomic and nominal traceability on code changes?

The good thing about code repositories, like GIT, is that these kinds of issues have been solved for a long time. It is impossible to develop software professionally today if tools like GIT are not fully integrated into the organization, and not only into the development team, but also into the QA, support, engineering… teams.

Do you have a reliable update distribution system with digital certifications?

Our update system (Update Manager) distributes packages with digital certificates. It is a private system, duly secured and with its own technology. 

Do you have an open public vulnerability disclosure policy?

In our case, it is published on our website.

Do you have an Open Source policy that allows the customer to see and audit the application code if necessary?

Our code is open, anyone can review it at https://github.com/pandorafms/pandorafms. In addition, some of our customers ask us to audit the source code of the Enterprise version and we are delighted to be able to do so.

Do the components/third-party purchases meet the same standards as the rest of the parts of the application?

Yes they do, and when they do not comply, we maintain them ourselves.

BONUS TRACK:

Does the company have any ISO Quality certification?

ISO 27001 

Does the company have any specific safety certification?

National Security Scheme, basic level.

Conclusion

Pandora FMS is ready for EVERYTHING! Just kidding, as we have said, everyone in this sector is vulnerable, and of course the questions in this decalogue are elaborated with certain cunning, after all, we had solid and truthful answers prepared in advance for them, however, the real question is: Do all software vendors have answers to those questions?

Would you like to find out more about what Pandora FMS can offer you? Find out clicking here . If you have to monitor more than 100 devices, you can also enjoy a FREE 30-day Pandora FMS Enterprise TRIAL. Installation in Cloud or On-Premise, you choose !! 

Last but not least, remember that if you have a reduced number of devices to monitor, you may use Pandora FMS OpenSource version. Find more information here .

Do not hesitate to send your questions. The great team behind Pandora FMS will be happy to assist you! And if you want to keep up with all our news and you like IT, release and, of course, monitoring, we are waiting for you in our blog and in our different social networks, from Linkedin to Twitter through the unforgettable Facebook . We even have a YouTube channel , and with the best storytellers. Ah well, we also have a new Instagram channel ! Follow our account, we still have a long way to go to match that of Billie Eilish.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

How Does The LGPD Impact Companies?

Due to the growing technological development in the market, we can clearly see how much how consumers tend to buy products and services has changed. Through more practical technologies, such as cellphones, laptops, and tablets, for example, they are just a click away to connect with companies over the internet.

Realizing this new consumer behavior, brands uncovered the need to ensure a digital presence in order to conquer new audiences. As a result of this migration, there was a need to have digital marketing strategies to capture customers, and the collection of user information is among the most used strategies to generate conversions.

However, the LGPD was sanctioned in 2018 to make sure that this data collected by companies — whether an email, CPF, or telephone number — was stored and used securely and transparently.

Do you want to learn more about it? So, check out our post until the end and answer all your questions about the LGPD and how it can impact your business.

After All, What Is The LGPD?

Law 13.709/2018, popularly known as LGPD — an acronym for General Data Protection Law — ended up entering into force in 2018. Therefore, it was created so that the personal data users make available to companies become even more secure, that is, efficiently collected and stored.

In a practical way, it is known that this law offers users power over their data. In other words, it can define how companies can dispose of their sensitive data, and how it should be treated. Furthermore, these users can also simply deny sharing their information as they are not obligated to do so.

There is also a European law, popularly known as GDPR. It was from there that the LGPD based its main premises regarding the security of data and shared user information.

Following the LGPD’s practical line, users must be aware of how their personal information will be used and handled by the companies that collected it. Also, users can choose to remove their data from the database of such companies.

Do you want to stay on top of this subject? Download our free e-book right now and get access to exclusive information.

How Does The LGPD Impact Companies?

Looking at the business side, these new processes guided by the Law will insist that businesses be extremely careful and meticulous about the terms of use of the respective data. Therefore, brands need to explain very well all forms of use in relation to the information provided by users. Not to mention that these businesses must also promote actions so that the user can manage their information.

For these activities to be carried out efficiently, and above all, following the guidelines imposed by the LGPD, each company must pay attention to the main rules it guides regarding the collected data.

What has happened a lot in the business world is that brands have hired professionals to deal specifically with these processes, making the internal sectors that need personal data of customers and leads can work even more securely, and within the law.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

Looking to protect a fleet of Windows on ARM PCs? Look no further than ESET Endpoint Security

The new ESET Endpoint Security v.9 brings a stable build for Windows 10 on ARM and Windows 11 on ARM-powered devices

After half a year of beta testing, ESET has released a stable build of ESET Endpoint Security ready to help businesses protect their investments into Windows on ARM-based devices. Unlike simpler applications that may only require recompiling the source code for the new hardware platform, reengineering ESET’s endpoint protection technology for ARM-powered devices required intense effort from our development teams. A key contribution to this project was the invaluable feedback of beta product testers and Qualcomm, whom ESET would like to thank.

Starting with version 9, the ARM64 builds of both ESET Endpoint Security and ESET Endpoint Antivirus are now available alongside the x86 (32-bit) and x64 (64-bit) builds. The new builds come with an ARM64 build of ESET Management Agent, making the management and deployment of endpoint protection for a fleet of ARM-based devices easy via the ESET PROTECT console.

ESET PROTECT offers IT admins a unified endpoint management solution that now extends to the ARM64 platform with the same powerful management capabilities and experience. Current ESET business customers can use their existing subscriptions to license the new ARM64 builds.

While the current ARM builds are stable and fully supported by ESET, a few features are currently unsupported compared to the x86 and x64 builds. ESET is working on adding these features in future releases. Nevertheless, thanks to its multi-layered approach to protection, ESET Endpoint Security for ARM still offers a slew of prevention and detection technologies. These range from real-time file system protection that scans files for malicious code whenever they are created, opened, or run, to web access protection that monitors HTTP and HTTPS traffic for malicious software, all the way to anti-phishing protection that detects illegitimate websites attempting to steal passwords or other sensitive data.

Businesses looking to migrate employees to an “Always On, Always Connected PC” model should be prepared for the accompanying risks of employees being always connected to the internet and able to access sensitive data from anywhere—hence the importance of a mature security suite. The pursuit of business effectiveness and an improved customer experience with ARM-powered hardware in employees’ hands entails a twofold dependency:

  • a sufficient growth of an ecosystem of high-performing native ARM applications; and
  • a reconfiguration of security policies and system hardening for “always on, always connected” employees.

Thus, whatever your use case for adopting or experimenting with ARM-based devices—from real-time GPS tracking, to running mobile point-of-sale software, to enabling anywhere access to data for essential services workers—a critical component of your move to ARM should undoubtedly be endpoint security.

For consumers on the lookout for a security solution compatible with their Microsoft Surface Pro X, HP Elite Folio, Lenovo Flex 5G, or other ARM-powered device, ESET provides a beta version available in the ESET Forum.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Securing the hybrid workplace demands dynamic defense

Advanced preventive protection for cloud email, collaboration and storage

With the massive shift to working from home and large numbers of workers entering a hybrid workplace, cloud-based collaboration and productivity tools have become ubiquitous at businesses around the globe. Although long envisaged, the hybrid model has exposed the complexity of securing the workplace on a practical level.

Protocols, business processes and IT tools now have much more impact on good security, both for home and business networks, not to mention for mitigating increased risks from devices crossing between personal and business use.

The year 2021 saw plenty of news around the large-scale hack of business platforms like SolarWinds Orion and intrusion campaigns targeting IT services companies that ran outdated versions of the Centreon IT monitoring tool. For many businesses, these events should have driven home the point that cyberthreats are increasingly targeting cloud-based systems, collaboration platforms, their users and the IT admins tasked with making it all run smoothly. These have been the very means that enable businesses to find additional efficiencies throughout the pandemic.

While clearly critical, what few IT admins and budget holders may have counted on was the scale of risks unleashed when entire service platforms were targeted by threat actors. In March 2021, the exploitation of Microsoft Exchange, in which ESET researchers identified more than 10 different threat actors or groups that likely leveraged the vulnerability, became a feast on unpatched internet-facing servers that sent shock waves across the IT industry.

Are these large-scale threats distracting from threats closer to home?
ESET’s T2 2021 Threat Report demonstrates that employees working remotely and using remote access tools like Remote Desktop Protocol (RDP) to access company data, tools and IT help are at high risk. In T2 (May-August) 2021, ESET detected 55 billion new brute-force attacks (+104% compared to T1 2021) against networks with public-facing RDP services. This is a sign of how critical RDP has become in the home and hybrid workplace.

This also demonstrates how critical security practices are when setting up, configuring, and using collaboration tools, servers and other business systems. Security is a twofold responsibility: the first on the part of IT admins, who set the rules and monitor activity, and the second on the part of a business’s staff, who use the tools but may waver in their security practices.

Cybercriminals cannot always be stopped from knocking at the door with their false wares. Thus, it is no surprise that phishing and fraudulent messages dominated the T2 2021 email threat scene, with the most heavily impersonated brands being Microsoft, followed by logistics company DHL, electronic signature service DocuSign and file sharing service WeTransfer. However, in their defense, security solutions can be deployed to detect and block these threats.

Enterprise grade security for SMBs
With the security burden only increasing in the second half of 2021, ESET has upgraded ESET Cloud Office Security with a powerful enterprise grade tool, ESET Dynamic Threat Defense (EDTD), which directly addresses the problem of unknown threats with its zero-day threat prevention technology, including cloud sandboxing analysis. The threat landscape is not static, and new threats arise every day; employees need to stay productive without their machines being slowed down by heavy processing tasks from security solutions. Once EDTD is set up, there is no need for admins or users to take any further action. EDTD decides whether a suspicious or unknown sample is benign or malicious by sending it to a cloud-based sandbox for analysis.

The cloud-based sandbox is precisely where this solution can immediately show its value because it off-loads the processing power needed to detect new or unknown threats from employee machines to the cloud. Once in the cloud sandbox, suspicious samples are subjected to multiple machine learning models and robust detection techniques to determine a definitive outcome.

In the face of ever-present threats like phishing and malicious email attachments, organizations should keep track of news on the latest campaigns targeting corporate accounts and share this news with employees.

They should also deploy a cloud sandbox solution that provides a robust layer of protection, even against never-before-seen threats.

Image 1. ECOS dashboard view for ESET Dynamic Threat Defense

With EDTD engaged, ESET Cloud Office Security (ECOS) provides user-friendly administration and flexibility that is backed by enterprise grade protection.

New behaviors require new security 
Rewinding to just prior to the pandemic, when businesses were hunting for additional security solutions, we would find ESET introducing ECOS. Bolstering security for Microsoft 365, including OneDrive and Exchange Online, ECOS proved easy to implement and manage for SMB and enterprise customers alike. Within weeks of its launch, MSPs also offered ECOS in managed environments, simplifying security provision and reporting for cloud customers. 

ECOS has now been put through its paces, securing the very solutions intended to address operating costs, improve productivity and ensure business continuity. While the pandemic has cemented the use of many of these tools, increasing attention must be paid to securing them. Specifically, ECOS extends protection to Microsoft Teams and SharePoint Online. This is a big plus for SMBs which are operating in the cloud because it hardens protection for business continuity via the very tools that allow distributed work and collaboration. 

Try our interactive demo

What can ESET Cloud Office Security with EDTD do for SMBs?
While the onus of properly configuring and securing infrastructure like Teams, SharePoint Online and Outlook lies on both service providers and their clients, these tools impact any and all of their users. When security incidents do occur on large platforms, which are now heavily used even at SMBs, we can expect super blooms of ransomware and other malicious campaigns seeking to leverage extensive periods of vulnerability and access exposed networks.

If you use powerful tools like Teams, SharePoint and Exchange Online, you have signed up for a role in securing your environment. While not all attacks and disruptions faced by organizations have stemmed from large-scale events, mitigating the impacts mirrors practices employed against common threats, and comes down to addressing the “what can be controlled” in a business’s own environment. Considering the near-universal uptake of productivity tools, a product like ECOS goes a long way in adding immediate protections for the most popular tools.
 
Spam and malware 
For the benefit of IT admins who need to manage protection for 25 seats or more, ECOS delivers an effective multitenant and scalable service, protecting all major Microsoft 365 cloud services against malware, phishing and spam emails.  

ECOS checks all incoming emails delivered to a customer’s Microsoft 365 inbox. Our award-winning antispam technology works as the first layer, filtering out spam messages with near-100% accuracy. The second layer is our malware scanner, which detects malicious or suspicious attachments. The third layer protects against phishing (anti-phishing). Learn more about these features here. 

Every file that is uploaded to OneDrive, shared via SharePoint or transferred via Teams is checked using our powerful malware detection engine, which leverages the same technology as ESET’s endpoint solutions. If the engine detects a dangerous file, it is placed in quarantine, where it is accessible only by administrators; the user remains protected. 

To back that up, admins benefit from ECOS’s easy-to-use cloud console, which gives an overview of quarantined items and immediately notifies them when a detection occurs.

Images 2-3. ECOS dashboard views of detections and quarantined items

What else has ESET Cloud Office Security seen in its first year? 
Many businesses that have onboarded these indispensable productivity tools have enjoyed the confidence of knowing that the built-in security provided by Microsoft is sufficient to maintain business continuity, and, more broadly, to keep their systems safe. By Microsoft’s own account, a lot of “us” are on Microsoft 365 and Teams. As of Q3 2020, Microsoft reported 258 million monthly active Microsoft 365 business users and 75 million daily active Teams users. That’s on top of the 1.2 billion active users of Microsoft Office. 

Their success also means the platforms are targeted in various ways from malicious macros in Word documents sent via Outlook emails to incidents of exploitation of Microsoft Exchange servers. Neither security by design nor Microsoft’s native security have completely stopped these security challenges. This is to be expected for such large infrastructure and their outsized user numbers.  As such, use of these key Microsoft products strongly warrants users adding further security measures. ECOS is cost-effective, rapid to deploy and scalable across the entire range of business and institutional sizes.

Images 4-6. ECOS dashboard views for Exchange, Teams and SharePoint

In 2021, via ECOS’s many dashboards, IT admins were able to see threat types that slipped by Microsoft’s native security: 

  1. HTML/Fraud: A detection name covering a diversity of HTML-based content, distributed with the aim of gaining money or other profit from the victim’s involvement. This includes scam websites, as well as HTML-based emails and email attachments. 
  2. HTML/Phishing.Agent: A detection name for malicious HTML code often used in a phishing email’s attachment. When such an attachment is opened, a phishing site is opened in the web browser, posing as an official banking, payment service or social networking website. The website requests credentials or other sensitive information, which is then sent to the attacker.  
  3. DOC/Fraud: A detection name mainly covering Microsoft Word documents with various types of fraudulent content, primarily distributed via email. The goal of this threat is to profit from the victim’s involvement, often by persuading the victim to disclose online account credentials or sensitive data. Documents often contain links to websites where victims are asked to fill in personal data. 

While malicious documents vectoring from email and malicious websites still comprise the largest proportion of threats to business ecosystems, we shouldn’t forget that these also track to newer SharePoint-based features that mushroomed in popularity under COVID-19. These files can and do make their way to SharePoint. 

ECOS for hybrid work
Security culture, IT admin skills and  system settings are critical to address the security demands brought by both hybrid work and the large uptick in collaboration and productivity platforms, as well as RDP. These realities mean more security is essential. The addition of EDTD now ensures immediate protection via additional cloud technology to protect not only computers within the company perimeter, but also employees connecting from home offices or other remote locations. Via the analysis of unknown samples by EDTD, not only does the PC encountering the sample remain better protected, but all endpoints within the company perimeter proactively receive the same detection and protection.

If a company requires improved security now, but its IT department is overwhelmed with work, simple automation of security is a key requirement. ECOS + EDTD supplies that.

To find out more, try our interactive demo of ECOS here. 

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research analyzes malicious frameworks targeting air-gapped networks; dissects 15 years of nation-state efforts

  • ESET researchers revisit 17 malicious frameworks used to attack air-gapped networks. The frameworks comprise all those known to date.
  • An air-gapped network is one that is physically isolated from any other network. As air-gapping increases security, such networks are commonly used for the most sensitive systems, such as industrial control systems that run pipelines, power grids, and nuclear centrifuges, and voting systems.
  • These critical systems are of high interest to APT groups that are typically sponsored or part of nation-state efforts. Ultimately, if an air-gapped system is infiltrated, these threat actors can intercept confidential data and spy on countries and organizations.
  • In the first half of 2020 alone, four malicious frameworks designed to attack air-gapped networks were detected and publicly revealed, bringing the total number to 17.
  • ESET Research offers security tips to improve air-gapped network defenses.

BRATISLAVA, MONTREAL — December 1, 2021 — ESET researchers present their analysis of all malicious frameworks used to attack air-gapped networks known to date. An air-gapped network is one that is physically isolated from any other network in order to increase its security. This technique can help protect the most sensitive of networks: industrial control systems (ICS) running pipelines and power grids, voting systems, and SCADA systems operating nuclear centrifuges, just to name a few. Naturally, systems that run critical infrastructure are of high interest to numerous attackers, including any and all APT groups. APT groups are typically sponsored by or part of nation-state efforts. Ultimately, if an air-gapped system is infiltrated, these threat actors can intercept confidential data in order to spy on countries and organizations.

In the first half of 2020 alone, four previously unknown malicious frameworks designed to breach air-gapped networks emerged, bringing the total number to 17.

Discovering and analyzing this type of framework poses unique challenges as sometimes there are multiple components that all have to be analyzed together in order to have the complete picture of how the attacks are really being carried out. Using the knowledge made public by more than 10 different organizations over the years, and some ad hoc analysis to clarify or confirm some technical details, ESET researchers led by Alexis Dorais-Joncas put the frameworks in perspective to see what history could teach cybersecurity professionals and, to a certain extent, even the wider public about improving air-gapped network security and our abilities to detect and mitigate future attacks. They have revisited each framework known to date, comparing them side by side in an exhaustive study that reveals several major similarities, even within those produced 15 years apart.

“Unfortunately, threat groups have managed to find sneaky ways to target these systems. As air-gapping becomes more widespread, and organizations are integrating more innovative ways to protect their systems, cyber-attackers are equally honing their skills to identify new vulnerabilities to exploit,” says Alexis Dorais-Joncas, who leads ESET’s security intelligence team in Montreal.

“For organizations with critical information systems and/or classified information, the loss of data could be hugely damaging. The potential that these frameworks have is very concerning. Our findings show that all frameworks are designed to perform some form of espionage, and all the frameworks used USB drives as the physical transmission medium to transfer data in and out of the targeted air-gapped networks,” explains Dorais-Joncas.

With the risks identified, ESET has put together the following list of detection and mitigation methods to protect air-gapped networks against the main techniques used by all the malicious frameworks publicly known to date:

  • Prevent email access on connected hosts — Preventing direct access to emails on connected systems would mitigate this popular compromise vector. This could be implemented with browser/email isolation architecture, where all email activity is performed in a separate, isolated virtual environment.
  • Disable USB ports and sanitize USB drives — Physically removing or disabling USB ports on all the systems running in an air-gapped network is the ultimate protection. While removing USB ports from all systems may not be acceptable for all organizations, it might still be possible to limit functional USB ports only to the systems that absolutely require it. A USB drive sanitization process performed before any USB drive gets inserted into an air-gapped system could disrupt many of the techniques implemented by the studied frameworks.
  • Restrict file execution on removable drives — Several techniques used to compromise air-gapped systems end up with the straight execution of an executable file stored somewhere on the disk, which could be prevented by configuring the relevant Removable Storage Access policies.
  • Perform regular analysis of the system — Performing a regular analysis of the air-gapped system to check for malicious frameworks is an important part of security in order to keep data safe.

In addition, it is worth noting that endpoint security products are generally able to detect and block several exploit classes, so having such technology not only deployed but also kept up to date could have a positive impact.

“Maintaining a fully air-gapped system comes with the benefits of extra protection. But just like all other security mechanisms, air gapping is not a silver bullet and does not prevent malicious actors from preying on outdated systems or poor employee habits,” comments ESET researcher Alexis Dorais-Joncas.

For more technical details about malicious frameworks used to attack air-gapped networks, read the white paper “Jumping the Air Gap: 15 years of nation-state effort” and the accompanying blogpost on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

What Is the Difference Between IAM and PAM?

It is important to know the differences between IAM (Identity & Access Management) and PAM (Privileged Access Management). However, this theme still raises doubts for some people.

First, it is necessary to understand that the need to obtain an identity is essential. 

After all, it is important to know that it is not defined only based on personal documents anymore. 

In fact, identity is constituted through several characteristics capable of affirming who we are and the types of activities we perform.

Thus, several issues make up our identification such as name, biometrics, among other attributes that help build a unique identity.

Based on this, without detecting these characteristics, it would be impossible to recognize a person among the large number of individuals that inhabit planet Earth.

Regarding this aspect, have you ever imagined what would be the routine of an online system in which all users had the same identity?

So, imagine the following situation: Leo owns a company. When logging into the system, he seeks access to information relating to all employees in the organization.

Laura, who also works at the company, needs to enter the same platform to obtain information about the work she will perform, without necessarily seeking information regarding the clients.

But how will the system be able to provide the necessary information if it cannot recognize the identity of each one?

And how will the platform be able to identify authentic access?

This reality would also make it impossible to select the people who can have access to certain functions within the system in question.

Interesting, isn’t it?! So, I invite you to keep reading this article.

IAM: What Is It?

Based on the concern regarding identity issues, IAM has emerged, which can be understood as Identity and Access Management.

This system makes it possible to manage the most diverse identities and accesses related to company resources.

These resources can be understood as devices, environments, applications, network files, among other possibilities.

In other words, through IAM, it is possible to have optimal management and definition of the activities each user will be able to perform within the system.

These users can be clients, internal employees, third-party workers, or some applications.

One can see that, regardless of the type of user, IAM systems defend the concept that each individual must have their own virtual identity.

Therefore, it must be unique and needs to be monitored based on its life cycle, thus considering its creation, use, and exclusion stages.

From this perspective, the virtual identity presents the username, a password, and the activities carried out virtually.

IAM contains certain application models. One of the most common is the system as a service.

It is called IDaaS (Identity as a Service).

This process occurs when the authentication infrastructure is supported and managed by third parties.

Generally speaking, there are many application models today. However, every IAM system must have:

  • An efficient database to store information from the most diverse users.
  • Tools that provide the ability to enable and disable accounts.
  • Features capable of granting and revoking access rights to users.

In other words, IAM systems can manage digital identities.

The goal is to ensure access permission to users who, in fact, have authorization.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

Global pandemic accelerates innovation in the public sector

Having an open, safe and efficient digital administration is the new objective of every Government these years. Although the recent pandemic may have hampered any master plan for system evolution and optimization, there is still some hope. The hybrid Cloud reaches the public sector, among other advances. We’ll tell you all about it in our blog!

The pandemic strengthens the hybrid cloud in the public sector

“The Cloud”, that abstract fantasy, has made possible large-scale government teleworking (so much so that “IDC ensures that 74% of government organizations worldwide will switch to remote work in the future”), in addition to giving institutions the opportunity to test new applications and experiment with them. Being the advantages of scalability and the safety benefits the first objectives.

The public sector, like so many others, got down to work when the shackles of Covid-19 fell on them. Like concert halls or gyms, they had to get reinvented, and soon after new online platforms arrived and heavy investments were made in Artificial Intelligence, Cloud-based management systems and other transformative solutions that give a break to organisms collapsed by difficult conditions. In fact, IDC Research Spain has confirmed that “40% of the public sector already works in a hybrid cloud environment compared to 90% of private companies”. This shows, indeed, that Public Administrations are heading towards new models.

The Hybrid Cloud in the public sector

So, we can say that damn Covid-19 accelerated not only masks sales, but also the adaptation of the most cutting-edge technologies to governments. They were suddenly aware, for example, as we say, of the possibilities of the Hybrid Cloud. Due, of course, to the rising popularity of hybrid IT environments; that although we know that they can be difficult to manage at high scale, and that they require specific capacities, they will always be welcome from now on.

What caused the skepticism regarding Hybrid Cloud in the public sector? Well, surely it was because the governmental institutions throughout the planet faced several and notorious obstacles related to the subject. Ensuring a high-performance infrastructure is no easy task, for example. Certain types of traditional monitoring technologies do not work in such heterogeneous ecosystems. In addition, sometimes, the speed at which some tools are deployed in the Cloud can lead to security problems.

Optimize Hybrid Cloud Management in the public sector

But is it all over? Do governments have nothing to say in the face of these “different and notorious obstacles”? Relax, as the highest paid coaches and cartoon heroes show us, there is always hope, even to optimizehybrid Cloud management in the public sector.

A new approach

From Pandora FMS, a company devoted to delivering the best monitoring software in the world, we tell you: NOT ALL MONITORING TECHNOLOGIES WORK THE SAME.. Many are either designed for local data centers or for the Cloud, but not both. This is where lots of improvements can be made and IT experts must intervene, especially to prioritize a plan for monitoring hybrid environments. Always with a vision of the general state of the systems, the performance and the security of the network, the databases, the applications, etc. It seems that no one had the time or the necessary skills for this task, which ends up exposing organizations, especially regarding security.

The hybrid network

After being aware that investing time and efforts in Cloud services is necessary, the idea that connectivity and network performance are a key factor will come hand in hand, at least to guarantee the provision of quality services.

So we must address issues such as network latency, increased cloud traffic, interruption prevention, and any other problem, before they affect us and the end user.

It goes without saying that Software-defined wide-area network (SD-WAN) technologies play an obvious role in hybrid technologies and can help simplify network management tasks and avoid network overload.

Beware of identity and access control

No, it is not crazy to monitor who has access to what. We do it here and call it “Standard Security Practice”. However, when everything becomes a hodgepodge of employees/users/everyone having access, and you interact with data from a large number of sources, things get a bit complicated.

Indeed, rushing is not good at all, and the implementation of the Cloud is wished right away, “immediately”, so access controls sometimes bear the brunt and remain a vulnerable point. So, you only have to take your chances on multi-factor authentication, as an improved official replacement for passwords for digital access.

Zero-trust frameworks, network segmentation, and new security practices for the provider are other healthy practices to better be safe than sorry and help protect the assets hosted in our hybrid environment.

New skills, new mindset

Big changes need small changes. The capabilities and skills that are necessary for managing the hybrid Cloud are far from those that are needed for a local infrastructure. The data center is already an abstraction of what it was and what IT teams know well. Technology is the future, but also the most current present, and if government institutions do not develop the adequate and necessary capacities to support such technology, there will be neither a well-managed hybrid cloud, nor anything to do in areas such as monitoring and security.

Conclusions

As we started saying, the global pandemic of Covid-19 has justified and potentiated the modernization of technology, and accelerated adaptation to the Cloud and IT environments, but there is still a long way to go for these services to be really used by institutions and their citizens. And this should be a priority, as well as its good performance, accessibility and security. At the appropriate time, supported by the necessary investment and work, I am sure the Cloud will reveal itself in all its splendor showing us its full potential.

Would you like to find out more about what Pandora FMS can offer you? Find out clicking here . If you have to monitor more than 100 devices, you can also enjoy a FREE 30-day Pandora FMS Enterprise TRIAL. Installation in Cloud or On-Premise, you choose !! Get it here.

 

Last but not least, remember that if you have a reduced number of devices to monitor, you may use Pandora FMS OpenSource version. Find more information here .

 

Do not hesitate to send your questions. The great team behind Pandora FMS will be happy to assist you! And if you want to keep up with all our news and you like IT, release and, of course, monitoring, we are waiting for you in our blog and in our different social networks, from Linkedin to Twitter through the unforgettable Facebook . We even have a YouTube channel , and with the best storytellers. Ah well, we also have a new Instagram channel ! Follow our account, we still have a long way to go to match that of Billie Eilish

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

ESET presents plans for ESET Campus; innovation and technology hub in the heart of Europe

Bratislava, November 29, 2021 – ESET, a global leader in cybersecurity, unveiled its plans for the previously announced ESET Campus – an innovation and technology hub based in its headquarters’ city, Bratislava, Slovakia. The 55,000 m2 campus designed by world-renowned architectural studio BIG-Bjarke Ingels Group will house the company’s new headquarters and will become a center of excellence, creating a strong cybersecurity, AI and innovation ecosystem for Slovakia and Central Europe.

Reflecting the shifting post-pandemic working patterns and the wishes of its employees, ESET Campus is being built to be fit-for-purpose for employees, customers and partners, and their business needs. The Campus’ core function for being a welcoming work environment is going to be supported by a whole array of facilities and amenities for ESET and the local community. Richard Marko, Chief Executive Officer for ESET, said: “I envision the ESET Campus as a creative hub where bold cybersecurity solutions come to life so that we all can enjoy the vast potential of advanced technologies. By building an inclusive, diverse, green and collaborative workplace fit for the future, we are addressing the pressing needs of our employees, customers, partners and our communities. We will continue our strong alignment with societal needs in order to support science, education and innovation.”

ESET campus will be built on the principles of functionality and ecology by being sustainably built, sustainably operating and responsibly reporting on its results. The business has already taken the first step towards reporting on its carbon footprint which has seen a 40 per cent decrease in carbon emissions in 2020. Palo Luka, Chief Operating Officer for ESET, said: “We believe it’s crucial for ESET to lead by example in innovation and technology. We will ensure that our Campus houses the latest technologies, clever and efficient solutions to achieve the highest levels of sustainability. We will aim for a carbon neutral campus operation, but we’ve got an ambition to also reduce the embodied carbon by building it in the most sustainable way possible, and we believe our partnership with BIG will help us achieve this.”

Bjarke Ingels, founding partner of BIG, presented the finalized plans to the city officials and the public in Bratislava on Wednesday 24th November at a press conference. Ingels said: “The new ESET HQ materializes the brief and challenge we got from the ESET leadership as literally as possible – the architecture is not only ecologically and economically sustainable, it is also socially sustainable: rather than a single hermetic entity, we have dissolved the new campus into a series of buildings framing a central square. An abundance of public spaces, pathways, and human-scale pavilions welcome ESET employees, university students and citizens of Bratislava to gather, exchange knowledge and enjoy. The architecture of the campus can expand organically over time but also feels as a single unified identity that is open, integrated and accessible to the community from day one. We’re excited for the new ESET HQ to be part of the city’s transformation towards a more engaging public realm and we believe the new ESET HQ has the true potential to become the seed for a new innovation district the city deserves.”

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About BIG – Bjarke Ingels Group
BIG-Bjarke Ingels Group is a Copenhagen, New York, London, Barcelona, and Shenzhen-based group of architects, designers, urbanists, landscape professionals, interior and product designers, researchers and inventors. The office is currently involved in projects throughout Europe, America, Asia and the Middle East. BIG’s architecture emerges out of a careful analysis of how contemporary life constantly evolves and changes. By hitting the fertile overlap between pragmatic and utopia, architects once again find the freedom to change the surface of our planet, to better fit contemporary life forms.

ISO 27001: 4 Reasons to Implement It in Your Company

Leaving data unprotected ends up putting business continuity and your clients at risk.

Therefore, it is necessary to implement standards that aim to make information more secure.

One of the best known among them is ISO 27001 , responsible for dealing with Information Security aspects of several companies.

There are many advantages to following this high standard of quality, with the benefits going far beyond security.

Optimization of procedures and increase in company profit are just some of them.

Do you want to know 4 reasons to implement this in your company? So check out this article.

It Reduces Costs in Your Company

The ISO 27001 standard also helps in implementing policies to organize and improve business processes.

This ends up causing a reduction in costs , resulting from the implementation of a good security and management system.

By having a clear vision of strategic management, it is possible to reduce risks considerably.

Therefore, resources that would be spent on repairs are saved by the company.

This directly influences the company’s cash, reducing costs with this type of situation, especially considering that the expenses to resolve any data security issue are always very high.

Thus, eliminating the risk of spending on this issue also makes the situation more comfortable for the company.

Given this scenario, it becomes a no-brainer to see why ISO 27001 is so important to companies.

Having more efficient management improves the company as a whole, and this has a direct influence on cash.

As we will see below, this is also important even for attracting potential new clients.

Showing that your company follows good market practices can be the missing difference to leverage your business.

ISO 27001 Gives Greater Credibility in The Market

Having an ISO 27001 certification shows that your company is seeking total security in its procedures and total commitment to Information Security , which is reflected as a great advantage in the market.

Showing potential clients that your company values data security demonstrates seriousness.

The chances of being able to close a deal increase when you have ISO certification.

When compared to a company that does not have certification, for example, the one that has certification will definitely stand out.

Data preservation is essential for large companies, and for this reason, ISO 27001 is seen as a differentiator.

Passing trust and credibility to potential clients is a way to be able to stand out from your competitors.

Given that data is now considered the new oil, it is critical to ensure no data is stolen.

Companies not dedicating resources to this area run serious risks, in addition to putting their clients at risk.

And because of that, companies that seek to meet the requirements of the ISO standard are standing out in the market.

Efficiency and security are essential for closing deals, regardless of a market niche.

But since we are talking about Information Security, be sure to check out this article that addresses the pillars of the area.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.