Q&A: Ransomware Settlements and Cyber Insurance

FortiGuard Labs Perspectives

Ransomware is top of mind for many organizations. According to a FortiGuard Labs Threat Landscape Report, ransomware incidents increased nearly eleven-fold from 2020 to 2021. Not surprisingly, as a result, more organizations are looking into cyber insurance, which covers certain types of losses suffered from a cyberattack and pays out settlements to the attackers.

FortiGuard Labs’ Derek Manky and Jim Richberg, Fortinet Field CISO for the Public Sector, offer their perspectives on current ransomware trends, cyber insurance, and how organizations can better defend against and recover from attacks. 

Can you give us an overview of what is happening with ransomware today?

Derek Manky: Ransomware offers a low-investment, high-profit business model that’s irresistible to cybercriminals. It is a growth industry in part due to the increase in Ransomware-as-a-Service (RaaS). In addition to customizing ransomware toolkits for business affiliates, some operators have also begun selling access to compromised corporate networks, making it that much easier for less-technical criminals to get involved. What is worse is that they are actively targeting insiders by offering compensation for access to networks.

Another alarming trend we’ve seen at FortiGuard Labs is an increase in the volume of attacks. For example, the percentage of organizations detecting botnet activity jumped from 35% to 51% by the mid-year mark. In addition to the increase in volume, attacks are also becoming more aggressive. Cybercriminals have been adding levels of extortion to get victims to pay, including combining traditional ransomware file encryptors with threats of publicly exposing internal data, adding a DDoS attack to create additional confusion and panic, and reaching out to a victim’s customers and stakeholders. We also predicted that destructive wiper malware threats will be added to the list of extortion strategy.

How do these trends relate to cyber insurance?

Jim Richberg: Cyber insurance is growing as an industry, and I think part of it is because ransomware has become so prolific. Insurance can sound like an easy answer to the problem of ransomware. Getting insurance in order to pay a settlement if you fall victim to ransomware is a lot easier for boards to understand than going into the various reasons why your cybersecurity efforts aren’t working to thwart attacks. Cyber insurance is particularly attractive to small and medium-sized organizations that don’t have the means to self-insure and are not confident that their security is likely to withstand attack. Many large enterprises do what it takes to bring their level of risk down to a level they can live with and afford. Going under the assumption that eventually they’ll be targeted, they may even include ransomware settlements in the incident response budget.

How do settlements play a role in ransomware?

Derek Manky: Cybercriminals are preferentially targeting companies that have cyber insurance because if the insurance company is paying out the ransomware settlement, it’s more likely the attackers will get the money. The classic approach to reconnaissance is that cybercriminals blueprint the network and organization, looking for vulnerabilities and other points of entry. But now, they’re not just scanning your networks; they’re scanning public records. With government, the budget is part of public record, so it’s easy for bad actors to determine whether or not the agency has insurance.

With private sector organizations, it’s a little different. But often there is public information and social media that cybercriminals can use to perform reconnaissance. It’s becoming yet another tool in their toolset. Because cybercrime has become a more organized enterprise model with affiliates (RaaS), cybercriminals are going where the money is. Ransomware negotiation is a growing business fueled by payment and insurance. It is part of why ransomware is becoming more prevalent than other types of attacks like distributed denial-of-service (DDoS).

What should you do to protect yourself?

Jim Richberg: Organizations need to take an architectural approach to security to protect themselves across their ever-expanding and evolving attack surface and defend against increasingly sophisticated tactics. Because no single technology can protect an entire network, Fortinet brings together all the necessary technologies to provide the right level of protection where it’s needed, using a cybersecurity mesh platform called the Fortinet Security Fabric. The mesh concept has gained a lot of attention over the past year, but Fortinet has been defending organizations through its integrated and automated Fabric since 2016.

It’s important for organizations to control who and what can connect to the network through zero-trust access, defend endpoints using endpoint detection and response (EDR), and protect the converged physical network through security-driven networking, and the virtual extension of the network into the public cloud with adaptive cloud security. 

In addition to technology, organizations need to invest in cybersecurity training. People are a significant potential threat vector to organizations. To prevent intrusions, employees need to be educated about the risks of phishing, so they can better recognize fake websites and suspicious emails.

Another side effect of robust security is that if you can demonstrate that you have a strong security posture, you might get better rates when you start looking into cyber insurance. Much like having a smoke alarm makes it less likely that a fire will spread and burn down your house, implementing best practices in terms of security reduces the potential for an intrusion to turn into a devastating breach. In both situations, you’re less of a risk to the insurer, and this is likely to be reflected as lower insurance premiums.

Is insurance a panacea?

Jim Richberg: The big warning here needs to be that just because you have cyber insurance doesn’t mean you’ve got nothing to worry about. Insurance doesn’t make your organization bulletproof or absolve you from needing to have the type of robust security I mentioned.

I think of cyber insurance as a double-edged sword. Although it’s good to have cyber insurance, as Derek pointed out, it can make you more of a target for cybercrime. And beyond that, you’re not transferring all of the risk to the insurance company. Yes, the insurance pays the ransomware settlement, but it doesn’t compensate you for the damage to your company reputation, intellectual property losses, or the reduction in sales from publishing your data publicly or contacting customers to tell them their data was compromised.

Derek Manky: For cybercriminals, ransom settlements from insurers can be a more predictable revenue stream than they’ve had before. It may be a reason we’re seeing the ecosystem become faster, more robust, and cohesive. Cybercriminals are going to keep coming back for more. They know that companies that have insurance can net them a nice quick payout. We knew that this cybercrime ecosystem existed, but now they’re negotiating and setting up customer support centers. With toolkits for affiliates, they’re setting up an enterprise model, versus the more ad hoc attacks we saw in the past.

Jim Richberg: I think another thing to consider is that cyber insurance isn’t like car insurance where you’re insuring against an accident. With car insurance, the people around you want to avoid an accident just as much as you do; another driver usually isn’t trying to hit you on purpose! But cybercriminals are specific and malicious. Ransomware is never an accident. 

Learn more about how Fortinet Security Fabric solutions protect the entire organization against ransomware attacks as well as from infection and spread.

Sourced from Fortinet

7 Best Practices for Social Media Security and Privacy

How to Protect Against Threats on Social Media Platforms

Social media provides a world of opportunities for an organization or individual to promote and expand a brand. A powerful form of communication that uses the internet, social media can provide any organization with a strong global presence.

Most organizations believe they must have a social media presence because these platforms and apps have billions of users and an audience that could have millions of potential prospects, customers, partners, employees, and advocates.

Social media platforms enable an organization’s representatives and its followers to have interactions that involve sharing information, exchanging feedback, and creating content.

Balancing “Social” and Security

Social media can increase brand awareness and engagement with the public. It allows for a generally less-expensive form of advertising in a non-traditional way. There are many types of social media, from blogs to photo-sharing sites to instant messaging or video-sharing portals and more.

As with almost every form of new technology, social media comes with some challenges too. One drawback for those using social media is that it can put users at risk, because it can open pathways that are insecure or tunnel beneath traditional cybersecurity.

This blog explains how a lack of social media security can harm individuals and organizations. At the end is a list of seven social media security best practices that everyone should follow to protect themselves and others.

How Does Social Media Affect Security?

There are five social media-related cyber threats to be aware of and to protect against. They include the following:

1) Social engineering

Social engineering refers to a wide range of attacks that leverage human interaction and emotions to manipulate a target. Such an attack attempts to fool victims into giving away sensitive information or compromise corporate security.

A social engineering attack typically involves multiple steps. The attacker will research the potential victim, gathering information about them, and then use this newly acquired data to bypass security protocols. Then the attacker works on gaining the target’s trust before finally manipulating them into divulging sensitive information or violating security policies.

Obviously, social media provides a social engineer with an avenue to naturally engage with the potential victim or organization to push them for information that can then be used to help launch an attack.

2) Phishing

In a phishing attack, usually via an email or an online message, the cybercriminal baits the potential victim(s) by trying to entice them into clicking on a malicious link or open a malicious attachment. If the attacker uses social media to establish a rapport or relationship with their target, it will be easier to build the trust necessary to get them to click on malicious links or enter sensitive private information into an online form.

Cyber criminals also apply pressure on their potential victim(s) by creating a sense of urgency or appealing to their curiosity. “Act now before it’s too late…” is the epitome of the kind of encouragement an attacker uses on their target with the goal of getting them to either click on a malicious link or provide private information via a form.

3) Malware

The malicious links promoted in social media lead to malware. Malware is the portmanteau of malicious software. There are many different types of malware, such as viruses, trojans, spyware, and ransomware. Cyber criminals use malware to access devices and networks to steal data and take control of systems, create botnets, cryptojack, or damage systems.

4) Brand impersonation

Another risk created by social media is when an individual or group tries to impersonate a well-respected company or brand to trick victims (employees or individuals) into providing confidential and valuable information that can be used by social engineers to hack systems and networks. In addition to harming the victims who fall for such impersonation tactics, brand impersonation can also damage the reputation of the organization being impersonated.

5) Catfishing

When a person takes information and images from another to create a fake identity and then uses this false identity to victimize an individual on a social media platform, this is called catfishing. The catfisher usually uses a fake identity to trick targeted individuals into associating with them or doing business online. The goal is to steal from a victim or humiliate them, or often both.

Social Media Security Best Practices

The best practices for addressing social media threats include these seven strategies:

1) Enable MFA

Multi-factor authentication is a security measure that protects individuals and organizations by requiring users to provide two or more authentication factors to access an application, account, or virtual private network (VPN). This adds extra layers of security to combat more sophisticated cyberattacks even after credentials or identities have been stolen, exposed, or sold by third parties.

2) Do not re-use passwords

Use a different password for every account. This prevents other accounts from being easily accessed if one account is hacked. Use a password management tool to keep track of various passwords. Make sure passwords are not easy to guess.

3) Regularly update security settings across platforms

Stay on top of social media platform security options to ensure they are always current and set at the most stringent level.

4) Narrow down connections to reduce unknown threats

Be discriminating about the types of individuals and entities that you are connecting with on social medium platforms. Carefully review every connection, and don’t affiliate with those that appear disingenuous or suspicious.

5) Monitor social media for security risks

Stay aware of the threat news on specific social media platforms and respond accordingly. If you learn of vulnerabilities or hacking incidents, attend to your accounts and address issues that could lead to breaches or hacks.

6) Learn what a phishing attack looks like

Be diligent and educate yourself on the latest types of phishing attacks going around. Always be skeptical when someone reaches out to you uninvited via a social media platform or email.

7) Look out for spoofs of your account

Keep an eye out for brand impersonation attempts. Report violations to the social media platform administrators immediately and inform your followers as well.

Learn about how Fortinet’s Training Advancement Agenda (TAA) and NSE Training Institute programs, including the Certification Program, Security Academy Program and Veterans Program, are helping to solve the cyber skills gap and prepare the cybersecurity workforce of tomorrow.

Sourced from Fortinet

The Public Sector Threat Landscape in 2022

In the public sector, government must defend against the full spectrum of threat actors, whereas many in the private sector hope (often incorrectly) that they only need to be secure enough that intruders will go after easier targets. But government cannot make that excuse. Whether it is nation-state activity seeking intellectual property or criminals who want money or personal identifying information, cybersecurity is daunting for government organizations because they face attacks from threat actors of all levels of sophistication using a wide variety of techniques and tactics.

FortiGuard Labs’ chief, security insights and global threat alliances, Derek Manky, and Jim Richberg, Fortinet public sector CISO, offer their perspectives on the threat landscape the public sector is facing in 2022, and how to defend against these threats. For more details, read the Fortinet 2022 Threat Landscape Predictions.

In the FortiGuard Labs report, what threat landscape predictions specifically affect the public sector?

Derek Manky: In the public sector, we’re seeing a convergence of advanced persistent threats (APT) and cyber crime. When you think about what the acronym APT means, it hints at sophistication and a more pre-meditated, targeted type of attack cycle. We’re starting to see a lot more investment from cyber criminals in the reconnaissance and weaponization phases of an attack. And it’s literally an investment because of how much they’ve profited from ransomware over the years, particularly weaponization. We are calling this convergence of cyber crime like APTs “advanced persistent cyber crime” (APC).

One thing that’s concerning for the public sector in 2022 is aggressive attack code. Ransomware is one example, but we’ve also seen wiper malware that’s been put into ransomware campaigns. Another name for wiper malware is “killware,” and the basic idea is that it’s destructive. I have a sense that given the innovation by cyber criminals, that they’re going to blend these together. When they add killware into their strategy, some can destroy systems as an upfront message to show that they mean business, and then demand a high ransom payment in return in exchange for the rest of the systems being spared. In the past, we’ve seen these strategies affecting IT, and now that’s going to start hitting OT and the public sector too.

Jim Richberg: It’s always been cost effective for cyber criminals to keep using existing exploits that are known to work, even if they’re 10 years old. But now, large organizations and governments that do a decent job of defending themselves with security patches are going to have to stay closer to the bleeding edge of newly discovered vulnerabilities. In some cases, they may even have to do virtual patching to keep up.

Derek Manky: The other thing to look at is the infrastructure piece. The attack surface is connected now. In the past there was an air gap between IT and OT, but now everything is connected, so a lot of areas that were inaccessible before are now vulnerable. For example, modern remote terminal units (RTUs) out in the field for oil and gas are now becoming more and more connected through broadband and 5G. And now satellite broadband is being rolled out as well.

Jim Richberg: I think there’s going to be a paradigm shift for government. When you talk to some government organizations they’ll say, “I’m not a manufacturer; I don’t have OT.” But the fact is that they might have smart buildings, green infrastructure, security video cameras, or sensors linked to air filtration to safeguard employee and public health. That means there’s an OT presence and an IoT footprint, whether they realize it or not. So, governments need to understand that they have to defend against OT threats.

Derek Manky: Exactly. And in OT, the dominant platform is Linux, which is now in the crosshairs. Attackers are writing new malware code specifically for Linux because it’s widely deployed on IoT and OT devices. So that’s expanding the attack surface and attack capabilities (weaponization phase of APC). For example, Mirai was the number-one botnet that we observed in 2021, and it’s a Linux-based botnet. And this is just the tip of the iceberg. I think there are going to be a lot more.

How do these threats map against what is top of mind for government?

Jim Richberg: Here in the U.S., President Biden signed the $1.2 trillion infrastructure and jobs bill. Planning for implementation and setting standards will rely on government understanding the operational technology environment and security implications. Being a steward or regulator becomes exponentially more difficult because these government organizations are also busy implementing the tasks assigned to them by recent Executive Orders on areas such as implementing zero trust and accelerating cloud migration. So, I think cybersecurity is getting more difficult for government, not easier.

When we talk about threat activity targeting the public sector, I think it’s critical we remember that the public sector is not monolithic. National-level governments tend to have the most financial resources and expertise, although even they have trouble dealing with the skills gap and staying close to the leading edge of technology. When you look below the national level, entities such as local government or public utilities have fewer resources to deal with cybersecurity. Yet these are the levels of government that most people interact with in their daily lives.

What threat trends do you see affecting smaller public sector organizations?

Derek Manky: Cyber crime is a whole ecosystem, and the ransom-as-a-service model is part of it. Now there are cyber criminals paying affiliates commissions to wage attacks. So, there’s going to be more diversification in cyber crime operations with more horsepower, more weapons, and more people. If you consider all the elements that fall under cyber crime like money laundering, all of those networks are going to expand. And these threats just add to what public sector organizations already face like APT and nation-state threat actors.

But more attribution is helping. When it comes to threat intelligence and research, finding people is the ultimate goal; but even getting other data like learning why they’re attacking or what verticals or infrastructure they’re targeting can help disrupt campaigns and activity. Tracking down attackers and tactics makes it easier to know what to do about an attack. Attributing where funds are moving also helps, which includes crypto wallets and currency flows.

Find out how the Fortinet Security Fabric platform delivers broad, integrated, and automated protection across an organization’s entire digital attack surface to deliver consistent security across all networks, endpoints, and clouds.

Sourced from Fortinet

Public Sector Cybersecurity and Threat Trends

In the public sector, government must defend against the full spectrum of threat actors, whereas many in the private sector hope (often incorrectly) that they only need to be secure enough to drive intruders towards easier targets. But the public sector cannot make that excuse. Whether it is nation-state activity seeking intellectual property or criminals who want money or personal identifying information, cybersecurity is daunting for government organizations because they face attacks from threat actors of all levels of sophistication using a wide variety of techniques and tactics.

Public Sector Cybersecurity: Examining the 2022 Threat Landscape

To help shed light on this issue, Derek Manky, FortiGuard Labs’ Chief, Security Insights and Global Threat Alliances, and Jim Richberg, Fortinet Public Sector CISO, offered their perspectives on the threat landscape the public sector is facing in 2022, and how to defend against these threats. For more details, read the Fortinet 2022 Threat Landscape Predictions.

In the FortiGuard Labs report, what threat landscape predictions specifically affect the public sector?

Derek Manky: In the public sector, we’re seeing a convergence of advanced persistent threats (APT) and cyber crime. When you think about what the acronym APT means, it hints at sophistication and a more premeditated, targeted type of attack cycle. We’re starting to see a lot more investment from cyber criminals in the reconnaissance and weaponization phases of an attack. And it’s literally an investment because of how much they’ve profited from ransomware over the years, particularly weaponization. We are calling this convergence of cyber crime like APTs “advanced persistent cyber crime” (APC).

One thing that’s concerning for the public sector in 2022 is aggressive attack code. Ransomware is one example, but we’ve also seen wiper malware that’s been put into ransomware campaigns. Another name for wiper malware is “killware,” and the basic idea is that it’s destructive. I have a sense that given the innovation by cyber criminals, they’re going to blend these together. When they add killware into their strategy, some can destroy systems as an upfront message to show that they mean business, and then demand a high ransom payment in return in exchange for the rest of the systems being spared. In the past, we’ve seen these strategies affecting IT, and now that’s going to start hitting OT and the public sector too.

Jim Richberg: It’s always been cost-effective for cyber criminals to keep using existing exploits that are known to work, even if they’re 10 years old. But now, large organizations and governments that do a decent job of defending themselves with security patches are going to have to stay closer to the bleeding edge of newly discovered vulnerabilities. In some cases, they may even have to do virtual patching to keep up.

Derek Manky: The other thing to look at is the infrastructure piece. The attack surface is connected now. In the past, there was an air gap between IT and OT, but now everything is connected, so a lot of areas that were inaccessible before are now vulnerable. For example, modern remote terminal units (RTUs) out in the field for oil and gas are now becoming more and more connected through broadband and 5G. And now satellite broadband is being rolled out, as well.

Jim Richberg: I think there’s going to be a paradigm shift for government. When you talk to some government organizations they’ll say, “I’m not a manufacturer; I don’t have OT.” But the fact is that they might have smart buildings, green infrastructure, security video cameras, or sensors linked to air filtration to safeguard employee and public health. That means there’s an OT presence and an IoT footprint, whether they realize it or not. So, governments must understand that they have to defend against OT threats.

Derek Manky: Exactly. And in OT, the dominant platform is Linux, which is now in the crosshairs. Attackers are writing new malware code specifically for Linux because it’s widely deployed on IoT and OT devices. So that’s expanding the attack surface and attack capabilities (weaponization phase of APC). For example, Mirai was the number-one botnet that we observed in 2021, and it’s a Linux-based botnet. And this is just the tip of the iceberg. I think there are going to be a lot more.

How do these threats map against what is top of mind for government?

Jim Richberg: Here in the U.S., President Biden signed the $1.2 trillion infrastructure and jobs bill. Planning for implementation and setting standards will rely on government understanding the operational technology environment and security implications. Being a steward or regulator becomes exponentially more difficult because these government organizations are also busy implementing the tasks assigned to them by recent Executive Orders in areas such as implementing zero-trust and accelerating cloud migration. So, I think cybersecurity is getting more difficult for the public sector, not easier.

When we talk about threat activity targeting the public sector, I think it’s critical we remember that the public sector is not monolithic. National-level governments tend to have the most financial resources and expertise, although even they have trouble dealing with the skills gap and staying close to the leading edge of technology. When you look below the national level, entities such as local government or public utilities have fewer resources to deal with cybersecurity. Yet these are the levels of government that most people interact with in their daily lives.

What threat trends do you see affecting smaller public sector organizations?

Derek Manky: Cybercrime is a whole ecosystem, and the ransom-as-a-service model is part of it. Now, there are cyber criminals paying affiliates commissions to wage attacks. Because of this, there’s going to be more diversification in cyber crime operations with more horsepower, more weapons, and more people. If you consider all the elements that fall under cyber crime like money laundering, all of those networks are going to expand. And these threats just add to what public sector organizations already face like APT and nation-state threat actors.

However, more attribution is helping. When it comes to threat intelligence and research, finding people is the ultimate goal, but it is not the only goal. By gathering additional data centered on why cyber criminals are attacking or what verticals or infrastructure they’re targeting, security teams can disrupt campaigns and activity. Tracking down attackers and tactics makes it easier to know what to do about an attack. Attributing where funds are moving also helps, which includes crypto wallets and currency flows.

Find out how the Fortinet Security Fabric platform delivers broad, integrated, and automated protection across an organization’s entire digital attack surface to deliver consistent security across all networks, endpoints, and clouds.

Sourced from Fortinet

Make Work from Anywhere a Reality with ZTNA

The season of ice and snow has arrived in North America and after a year of confinement, when you see the typical photos related to working from anywhere, it’s easy to be jealous. The image of a person writing lines of code or peerless prose from a white sand beach in the Caribbean might seem like just a fantasy when you’re staring out the window at torrents of freezing rain.

Although your home office may not have an ocean view, hybrid and flexible work environments are becoming the new norm. Work-from-Anywhere (WFA) is quickly being adopted by many organizations as the new ideal work model because it improves employee productivity and overall work satisfaction. For many employees, one of the only silver linings of the pandemic is enhanced work flexibility.

However, implementing WFA isn’t easy without the security capabilities zero-trust network access (ZTNA) brings to the table. In fact, WFA is essentially the use case ZTNA was designed to support. ZTNA can make WFA a reality because it provides the same security no matter where someone is located, and it reduces the attack surface by hiding applications from the internet behind a proxy point.

Going Beyond Just Working from Home

Implementing WFA securely goes beyond simply working from home. The goal is to keep users productive and secure as they move to different locations. Whether they’re working from the road or a home office, they need secure access to applications and resources that may be located in the cloud or data center. The key to keeping everything consistent is to unify ZTNA, endpoint, and network security with a common set of APIs and integration points. From a security standpoint, the situation may be different depending on the location, but the user experience and protection need to be consistent no matter where the users are connecting from or what applications and services they need to access.

From Home

Employees who work remotely all or part of the time generally log in from a specific location, such as their home office. Their setup might include a home network and hardware, such as a monitor and webcam that facilitates their work. Connecting to a home network introduces risks from everything else that is connected to it, such as non-secure Internet-of-Things (IoT) devices or other users. Those users could be streaming video or gaming, which introduces potential vulnerabilities because their connections are generally outside corporate network security and control.

Because ZTNA creates a secure tunnel, it insulates the user from other issues that may plague their home network. The ZTNA client on the endpoint will make the secure tunnel, and can then provide the device identity and report on the status of that endpoint. This helps determine if that specific device should get access to the requested application.

On the Road

When employees travel, they often have to connect using unknown and potentially unsecured networks that are vastly less secure than a corporate office or remote workspace. Connecting to work applications and resources can introduce new threats, such as exposing communications to hackers and revealing exploitable devices that could be used to launch attacks. Because ZTNA only gives access to people and devices that should be accessing the network, it keeps out those that shouldn’t be there. Once entities are connected, it also provides visibility and control. By engaging in per-session device posture checks, ZTNA also makes sure that if a device is compromised while traveling, it will be detected quickly.

In the Office

Even in a corporate environment, consistent security is an important aspect of a layered defense. ZTNA provides seamless access to applications no matter where the user or the application may be located, including the office. Even in the office, users must provide access credentials such as multi-factor authentication (MFA) and endpoint validation. Once connected, they only receive the least-privileged access, which means they can access only the applications they need to perform their jobs and nothing else.

ZTNA Everywhere

Work-from-Anywhere demonstrates how important it is for organizations to have the same security protection and control no matter where someone may be physically located. Users at many organizations often need access to both cloud and non-cloud resources, and consistent protocols and policies need to be implemented across the entire network. To meet this need, organizations running hybrid networks need flexible ZTNA solutions that aren’t cloud-only. Even better if ZTNA and SD-WAN are integrated into the same solution (without additional licenses or fees) to also ensure a better quality of experience for users. Because it shouldn’t matter where a user is working. The same zero-trust security should apply everywhere and offer a consistent experience for users, whether they’re sitting in a lounge chair on a beach or at a desk in their home office.

Discover how Fortinet’s Zero-Trust Access framework allows organizations to identify, authenticate, and monitor users and devices on and off the network. Read more about why the Fortinet Security Fabric is the industry’s highest-performing cybersecurity mesh platform.

Sourced from Fortinet

Enabling Work from Anywhere with Zero-Trust Security

The season of ice and snow has arrived in North America and after a year of confinement, when you see the typical photos related to working from anywhere, it’s easy to be jealous. The image of a person writing lines of code or peerless prose from a white sand beach in the Caribbean might seem like just a fantasy when you’re staring out the window at torrents of freezing rain.

Although your home office may not have an ocean view, hybrid and flexible work environments are becoming the new norm. Work from Anywhere (WFA) is quickly being adopted by many organizations as the new ideal work model because it improves employee productivity and overall work satisfaction. For many employees, one of the only silver linings of the pandemic is enhanced work flexibility.

However, implementing WFA isn’t easy without the security capabilities zero-trust network access (ZTNA) brings to the table. In fact, WFA is essentially the use case ZTNA was designed to support. ZTNA can make WFA a reality because it provides the same security no matter where someone is located, and it reduces the attack surface by hiding applications from the internet behind a proxy point.

3 Scenarios Where ZTNA Bolsters Work-from-Anywhere Security

Implementing WFA securely goes beyond simply working from home. The goal is to keep users productive and secure as they move to different locations. Whether they’re working from the road or a home office, they need secure access to applications and resources that may be located in the cloud or data center. The key to keeping everything consistent is to unify ZTNA, endpoint, and network security with a common set of APIs and integration points. From a security standpoint, the situation may be different depending on the location, but the user experience and protection need to be consistent no matter where the users are connecting from or what applications and services they need to access.

From Home

Employees who work remotely all or part of the time generally log in from a specific location, such as their home office. Their setup might include a home network and hardware that facilitates their work, including a monitor and webcam. That said, connecting to a home network introduces risks from everything else that is connected to it, such as non-secure Internet-of-Things (IoT) devices or other users. Those users could be streaming video or gaming, which introduces potential vulnerabilities because their connections are generally outside corporate network security and control.

Because ZTNA creates a secure tunnel, it insulates the user from other issues that may plague their home network. The ZTNA client on the endpoint will make the secure tunnel, and can then provide the device identity and report on the status of that endpoint. This helps determine if that specific device should get access to the requested application.

On the Road

When employees travel, they often have to connect using unknown and potentially unsecured networks that are vastly less secure than a corporate office or remote workspace. Connecting to work applications and resources can introduce new threats, such as exposing communications to hackers and revealing exploitable devices that could be used to launch attacks. Because ZTNA only gives access to people and devices that should be accessing the network, it keeps out those that shouldn’t be there. Once entities are connected, it also provides visibility and control. By engaging in per-session device posture checks, ZTNA also makes sure that if a device is compromised while traveling, it will be detected quickly.

In the Office

Even in a corporate environment, consistent security is an important aspect of a layered defense. ZTNA provides seamless access to applications no matter where the user or the application may be located, including the office. Even when in the office, users must provide access credentials such as multi-factor authentication (MFA) and endpoint validation. Once connected, they only receive the least-privileged access, which means they can access only the applications they need to perform their jobs and nothing else.

ZTNA Secures Employees Working Everywhere

Work from Anywhere demonstrates how important it is for organizations to have the same security protection and control no matter where someone may be physically located. Users at many organizations often need access to both cloud and non-cloud resources, and consistent protocols and policies must be implemented across the entire network. To meet this need, organizations running hybrid networks need flexible ZTNA solutions that aren’t cloud-only. It’s even better if ZTNA and SD-WAN are integrated into the same solution (without additional licenses or fees) to also ensure a better quality of experience for users. 

Because it shouldn’t matter where a user is working. The same zero-trust security should apply everywhere and offer a consistent experience for users, whether they’re sitting in a lounge chair on a beach or at a desk in their home office.

Discover how Fortinet’s Zero Trust Access framework allows organizations to identify, authenticate, and monitor users and devices on and off the network. Read more about why the Fortinet Security Fabric is the industry’s highest-performing cybersecurity mesh platform.

Sourced from Fortinet

Data Privacy Day: What it Means for Your Organization

Data Privacy Day occurs annually on January 28 and is observed in many countries from North America to Europe to Africa. The purpose is to raise awareness about data privacy and best practices for data protection. This is a follow-on to Data Protection Day in Europe, which commemorates the January 28, 1981, signing of the Council of Europe treaty known as Convention 108. This treaty was the first legally binding agreement designed to protect an individual’s right to digital privacy, anticipating the increasingly automated processing and distribution of personal data.

Understanding the Significance of Data Privacy Day

While remarkably prescient, the original authors and signers of Convention 108 could not have possibly foreseen how data would be created, shared, processed, and stored today, or the volume of personal data that exists for virtually every human being on earth.

That original treaty has been enhanced by legally binding legislation over the years in nearly every country in the world. Despite all of these changes over recent decades, there is still education and work to be done in the realm of data protection. This is why Data Privacy Day is more crucial than ever.

Key Steps To Protect and Secure Data

There cannot be any data privacy without good data security. Therefore, below is a quick checklist of the things organizations should do to help protect and secure data.

1. Implement a Security Strategy Focused on a Platform Approach

The first step in protecting data is ensuring that any Personally Identifiable Information (PII) data your organization touches is secured from the moment it enters your network to the moment it leaves. This includes applying security measures and policies that can seamlessly identify, follow, and secure data as it moves between network domains and devices, including across multi-cloud or SD-WAN environments, as well as across the extended network. In addition, zero-trust access is vital. As users continue to work-from-anywhere and Internet-of-Things (IoT) devices flood networks and operational environments, continuous verification of all users and devices is crucial as they access corporate network resources, especially data.

Security plays a critical role in securing every bit of data as well as managing who and what has access to it. A cybersecurity mesh platform allows all security components to see other devices, share and correlate information between them, and participate in a coordinated threat response. It must be woven into and across every aspect of the evolving network to enable things like unified policy creation, centralized orchestration, and consistent enforcement. This mesh approach allows organizations to extend visibility deep into the infrastructure to see every device, track every application and workflow, and more importantly, see and secure all data. It also allows organizations to demonstrate compliance with regard to protected privacy requirements and the verification of its secure storage, use, and removal.

2. Change What and How You Collect PII Data

Privacy laws such as the General Data Protection Regulation (GDPR) define individuals as the sole owners of their data, not businesses or institutions. As a result, these individuals must be able to withdraw their consent to the collection of their data as quickly and easily as it was given. This requires organizations to collect only the minimum amount of data needed for a specific purpose and to then be able to completely remove it when it is no longer needed.

3. Ensure PII Can Be Easily Identified, Flagged, and Deleted

Organizations need to be prepared to demonstrate how to prevent specific data from being shared or sold to third parties and how to remove all instantiations of an individual’s PII regardless of where it is being stored or used. For example, the GDPR’s “right to be forgotten” (RTBF) means that data needs to be found and removed quickly and easily, rather than relying on humans to hunt for each instance of personal information scattered across a distributed network.

4. Encrypt PII To Ensure Less Risk

Consider encrypting data in transit and at rest in the network, as encryption negates the value of data if it is compromised. That said, encrypting large volumes of data is no easy task. Because of this, organizations should consider what is a priority based on the ability of encryption performance and any associated degradation of performance.

5. Training and Education Are Important

Encourage cybersecurity training for all employees and follow up with practice and drills. Good password hygiene along with multi-factor authentication (MFA) should be requirements to help add extra protection.

Summing Up

Data privacy legislation reflects concern about the protection and personal ownership of PII. Data Privacy Day is a reminder that every organization that touches personal data needs to evaluate its IT security infrastructure. Ask yourself:

  • Are IT security solutions able to effectively communicate, regardless of where they have been deployed, to optimally protect data and provide network-wide visibility?
  • Does the network include sophisticated data protection measures such as threat prevention and detection, pseudonymization of PII, and internal segmentation to isolate and track customer and employee data?
  • Is there a documented and tested data breach response plan?

Today’s organizations need to be able to answer “yes” to these questions to be prepared for existing data privacy regulations or others on the near horizon.

Discover how Fortinet’s Zero-Trust Access framework allows organizations to identify, authenticate, and monitor users and devices on and off the network.

Sourced from Fortinet

The Definition and Examples of Exploit Kits

In cybersecurity terminology, an exploit is a bit of code or a program that takes advantage of vulnerabilities or flaws in software or hardware. An exploit is not malware, but rather a way to deliver malware like ransomware or viruses. The goal of exploits is to install malware or to infiltrate and initiate denial-of-service (DoS) attacks for example.

The recent exponential growth of computer peripherals, software advances, and edge and cloud computing has led to a corresponding increase in vulnerabilities. Of course, cybercriminals love having more systems to attack with exploit kits.

What Is An Exploit Kit?

Exploit kits (EKs) are automated programs used by cybercriminals to exploit systems or applications. What makes an exploit kit very dangerous is its ability to identify victims while they browse the web. After they target a potential victim’s vulnerabilities, attackers can download and execute their malware of choice.

Examining How Exploit Kits Work

Exploit kits work silently and automatically as they seek to identify vulnerabilities on a user’s machine while they browse the web. Currently, exploit kits are the preferred method for the distribution of remote access tools (RATs) or mass malware by cybercriminals, especially those seeking to profit financially from an exploit.

EKs don’t require victims to download a file or attachment. The victim needs only browse on a compromised website and then that site pulls in hidden code that attacks vulnerabilities in the user’s browser.

The events that must occur for an exploit kit attack to be successful, include:

  • Targeting a compromised website, which will discreetly divert web traffic to another landing page
  • Running malware on a host, using a vulnerable application as the gateway
  • Sending a payload to infect the host, if and when the exploit is successful

Examples of Exploit Kits

Below is a list of exploit kits that have been used by cybercriminals in the past:

Angler

In the mid-2010s, Angler was one of the most powerful and frequently used EKs that enabled zero-day attacks on Flash, Java, and Silverlight. According to The Register, “At its…peak, the authors [of the Angler] were responsible for a whopping 40% of all exploit kit infections having compromised nearly 100,000 websites and tens of millions of users, generating some US$34 million annually.”

Blackhole

The origins of the Blackhole exploit kit go back to 2010. It was apparently the preferred tool by cybercriminals for running drive-by downloads for over three years until the 2013 arrest of its author. After finding a website that could be exploited, cybercriminals would plant the Blackhole exploit kit and expose visitors to Blackhole-powered attacks. Then the exploit kit downloaded malware (often ransomware) on the PCs of visitors by taking advantage of any browser, Java, or Adobe Flash plug-in vulnerability it found.

Fiesta

In 2014, the Fiesta exploit kit gained popularity after the decline of the Blackhole exploit kit due to its source code being leaked and its founder arrested. Like earlier EKs, Fiesta worked by compromising a vulnerable website. After the website was compromised, visitors were redirected to the Fiesta landing page controlled by cybercriminals. Then different exploits based on the computer’s characteristics were downloaded.

Flashpack

The Flashpack exploit kit was also popular with cybercriminals in 2014 when there were campaigns that abused advertising networks. Flashpack EK was used to distribute various pieces of malware, including the information-stealing malware Zeus, the Dofoil Trojan, and the Cryptowall ransomware.

Researchers found that the Flashpack EK used free ads to distribute the threats. An example: when users accessed a website that served malicious ads (a.k.a. malvertising), they were brought by way of multiple redirects to a Flashpack exploit kit page that served up ransomware.

GrandSoft

The GrandSoft exploit kit was another malvertising-based threat that redirected unsuspecting users and installed password stealing trojans, ransomware, and clipboard hijackers on their machines. In 2019, the GrandSoft EK was pushing the Ramnit banking trojan that attempted to steal victims’ saved login credentials, online banking credentials, FTP accounts, browser history, site injections, and more.

HanJuan

In 2015, the HanJuan exploit kit was popular and helped cybercriminals facilitate malvertising attacks. It used false ads and shortened URLs to trick users into landing on a webpage containing a HanJuan EK that targeted vulnerabilities in the Adobe Flash Player (CVE-2015-0359) and the Internet Explorer browser (CVE-2014-1776).

Hunter

Another exploit kit that was popular in 2015 with cybercriminals was the Hunter EK, which initially targeted Brazilians via a phishing email. When the victim’s machine was comprised, a variant of a Brazilian banking trojan generically known as “Bancos” launched. This was a Brazilian banking trojan that used man-in-the-browser (MITB) techniques to steal banking and other financial credentials. 

Magnitude

The Magnitude exploit kit, like other EKs, is a framework hosted by malicious actors to target browser vulnerabilities particularly for Internet Explorer. Because the popularity of IE has changed, the Magnitude exploit kits that target Microsoft’s browser have been much less active. Still, as recently as 2019, cybercriminals were using Magnitude EK in specific geographic regions where IE owned a sizable part of the market like in South Korea.

In the fall of 2021, SecurityWeek reported the Magnitude EK is “active” after it “added to its arsenal exploits for CVE-2021-21224 and CVE-2021-31956.”

Neutrino

According to Bank Info Security website, the Neutrino EK was “at one time [2016] ranked as one of the world’s most popular exploit kits. Also known as exploit packs, these tools enable anyone – no coding experience required – to run large-scale campaigns designed to infect massive quantities of PCs with malware, turning them into ‘zombie’ nodes in a botnet.”

Nuclear

The Nuclear exploit kit was another cybercriminal favorite in the mid-2010s. According to an April 2016 Ars Technica article, Nuclear EK had “a sophisticated multi-tier server architecture, with a single master server providing automatic updates to ‘console’ servers—the systems used by paying customers to access and customize their particular paid attack packages. Those console servers in turn manage a rotating stock of landing pages served up through malicious links, exploited web pages and malicious advertisements.”

RIG

In a November 2016 article on the ThreatPost website, the author says that at that time the “most prolific exploit kit is RIG, which has filled a void left by the departure of Angler, Neutrino and Nuclear.” The post goes on to outline the “unique” way “the RIG exploit kit combines different web technologies such as DoSWF, JavaScript, Flash and VBscript to obfuscate attacks.” Threat researchers add that “a RIG attack is a three-pronged attack strategy that leverages either a JavaScript, Flash, VBscript-based attacks as needed.”

Sundown

At the end of 2016, SecurityWeek ran a piece on its website about the Sundown exploit kit that used “a technique called steganography to hide its exploits in harmless-looking image files.” The practice of hiding information within a file become at this time “increasingly used by malicious actors, including malvertising campaigns.”

Analysis of Sundown EK forays revealed that attackers used PNG images to disguise various exploits, including ones targeting Internet Explorer and Flash Player vulnerabilities.

Sweet Orange

Sweet Orange exploit kit was also popular with criminals in the mid-2010s. It targeted the Windows operating systems Windows 8.1 and Windows 7 as well as web browsers Internet Explorer, Firefox, and Google Chrome. Sweet Orange EK’s authors tried to prevent the security community from getting access to the source code of the kit. They did this by limiting messages posted on invite-only cybercrime-friendly web communities and sell the kit to only those with a cybercrime reputation.

More to the Story

Today older kits have been leaked and are publicly available. Attackers have been taking these older kits and modifying them making them more resilient to newer security detection strategies. Also many of these kits are being advertised for sale online. Attackers offer these kits for rent on these sites and offer support and update contracts to guarantee they work against future updates. 

What should you do?

o  Protect Your Endpoints: Advanced, automated endpoint protection, detection, and response.

o  Web Security: Protection against web threats hidden in encrypted or non encrypted traffic.

o  Internal Segmentation: Segment network and infrastructure assets regardless of their location whether on-premises or on multiple clouds.

o  Zero Trust Access: As users continue to work from anywhere and IoT devices flood networks and operational environments, continuous verification of all users and devices as they access corporate applications and data is needed.  

Find out how Fortinet’s Endpoint Security and Device Protection Solutions protect every user and device on and off the network.

Sourced from Fortinet

SD-WAN Works Best as Part of a Platform

Business and work are evolving at breakneck speed, and networks need to be able to keep up. In addition to being flexible enough to adapt to changing business needs and new technology, networks now also need to provide a consistent user experience for employees who may be working from home, the office, or anywhere else. And they need to do it all securely. Many organizations are struggling to deploy a complete work-from-anywhere (WFA) solution because getting an array of separate networking and security products to work together can be difficult or even impossible.

If all of your security and networking solutions are designed to work together, they are more effective than if they operate in isolation. A cybersecurity mesh platform architecture tied to security-driven networking solutions can provide the unified visibility, automated control, and coordinated protection organizations need. This type of integration is particularly important for software-defined wide-area networking (SD-WAN).

The Rise of SD-WAN

Today, many organizations are distributed with users working from multiple locations. These people need access to applications, which may be located in still more locations. The need to manage such a complex spiderweb of connections is why the SD-WAN market continues to grow. SD-WAN makes it possible to use available WAN services more effectively and economically. It simplifies branch networking, improves application performance, and provides faster access to cloud-based applications and communications. It can also monitor and modify connections to maintain bandwidth and prevent latency, jitter, and packet loss that can affect bandwidth-intensive applications and services like digital voice and video.

The Security Limitations of SD-WAN

From a networking standpoint, SD-WAN has dramatically improved branch connectivity and the user experience; but from a security standpoint, not all SD-WAN solutions are the same. Most SD-WAN solutions don’t have integrated security, and direct internet access can lead to new threats.

Security solutions that are added on top of an existing SD-WAN solution often can’t keep up with the changes in a dynamic network and it can be almost impossible to track applications and workflows. Taking this type of security overlay approach can lead to gaps in protection. The network complexity that arises from a non-integrated SD-WAN architecture can make it difficult to manage and troubleshoot. Ideally, a solution should integrate networking, connectivity, and security functions into a single, centralized management console. But if it doesn’t, keeping security policies and enforcement consistent can be challenging or even impossible.

SD-WAN Works Best as a Platform

Instead of trying to bolt on security to SD-WAN after the fact, it makes more sense to take an integrated platform approach, so that the networking and security solutions work as a unified system. Integrated security then seamlessly adapts and scales with SD-WAN connectivity, which avoids the almost inevitable security gaps that can occur with an overlay security solution. SD-WAN works best as part of a holistic platform that incorporates the following elements:

1. Integrated ZTNA

As more organizations need to support WFA initiatives, they’re looking to zero-trust network access (ZTNA) for remote access. It provides secure, per-user and per-session access to specific applications, rather than the perimeter-based network access provided by traditional VPNs. ZTNA makes it easier to manage access to critical applications and maintain visibility into who has access to which resources. ZTNA that’s integrated with a next-gen firewall-based SD-WAN solution – that is, integrated into a single platform – allows organizations to eliminate device sprawl and solution management overhead because they can enforce one policy consistently across all edges to protect the entire attack surface.

2. SD-WAN for Multi-cloud Deployments

In a multi-cloud deployment situation, SD-WAN needs to be able to provide reliable access to cloud-based resources with granular controls, including dynamic failover, SLA-based application steering, and application availability, even during brownout or blackout conditions. It should support secure and high-performance connectivity between public cloud workloads running on multiple clouds without increasing cost and complexity. In addition to supporting seamless, reliable, and high-performance connectivity to the cloud and across clouds, an SD-WAN solution should also be able to route and secure workloads within the cloud on a single VM.

3. AIOps

Many SD-WAN solutions still rely on time-consuming and error-prone manual configurations. Adding AIOps to large and complex SD-WAN deployments enables automatic detection and response across all connections. It can identify issues and remediate them before an application or user is affected. AIOps can help find configuration errors and anomalies and aids in troubleshooting.

4. 5G/LTE

A 5G or LTE gateway that is tightly integrated with an SD-WAN solution can not only help ensure fast, inexpensive, and flexible broadband connectivity at the branch edge, but also support seamless management and operation and secure connectivity. The edge is a dynamic space and an effective SD-WAN gateway should offer dedicated cloud management dashboards that include simple out-of-band management (OBM) capabilities and provide support for multiple OBM console connections to serial cables and adapters.

5. SD-Branch

Branch technology is often made up of siloed appliances and consoles that manage wired access, wireless access, WAN, and security. An SD-WAN solution that can easily and seamlessly be extended into an SD-Branch solution can effectively reduce this complexity and appliance sprawl while maintaining a high level of performance.

6. Integration With a Cybersecurity Mesh Platform

Many organizations suffer from fragmented, complex infrastructures that make deploying new technologies and services difficult. An automated cybersecurity mesh platform is essential to reducing complexity and increasing overall security effectiveness across today’s expanding networks. This type of integrated platform offers centralized management and visibility and can automatically adapt to dynamic changes in the network.

SD-WAN that Supports Secure Digital Acceleration

Networks have to support new business needs while remaining protected against new security threats. If SD-WAN is a technology that is a part of your digital acceleration initiatives, the best solution is tied to a platform that enables a variety of use cases and interoperates across a vast ecosystem of solutions. Such an ecosystem matters because it gives organizations flexibility across their deployments while gaining the benefit of consolidated and converged operations, visibility, and security.

Take a security-driven networking approach to improve user experience and simplify operations at the WAN edge with Fortinet Secure SD-WAN.

Sourced from Fortinet

Five Cyber Threats to Watch Out for in 2022

In 2022, threats are unlikely to slow down. If your network and security tools were not up to the task of protecting your organization in 2021, it is not going to be any better in 2022. If you’re still struggling to integrate and manage a collection of single-purpose products, the resulting complexity and lack of visibility is likely to leave your organization at risk. Although no one can predict the future, here are five up-and-coming threats we’re keeping an eye on at FortiGuard Labs.

Five Cyber Threats To Watch Out For

1. Linux Attacks

Up until recently, Linux has been largely ignored by cybercriminals, but that’s changing. Because Linux runs the back-end systems of many networks and container-based solutions for IoT devices and mission-critical applications, it’s becoming a more popular target for attackers. At this point, attacks against Linux operating systems and applications running on those systems are as prevalent as attacks on Windows operating systems.

Many organizations are used to defending against Windows attacks but aren’t accustomed to keeping up with Linux from a defensive and malware analysis standpoint in comparison to Windows. Even worse, Linux environments often have valuable data like Secure Socket Shell (SSH) credentials, certificates, applications usernames, and passwords.

A malicious implementation of the Beacon feature of Cobalt Strike called Vermilion Strike can target Linux systems with remote access capabilities without being detected. Now that Microsoft is actively integrating Windows Subsystem for Linux (WSL) into Windows 11, it’s inevitable that malware will follow. WSL is a compatibility layer that is used for running Linux binary executables natively on Windows. An increase in botnet malware is being written for Linux platforms as well. Log4J is also a good example of a recent attack where we are seeing Linux binaries capitalize on the opportunity.

2. Satellite Network Attacks

As connectivity using satellite internet increases, the likelihood of new exploits targeting these networks will increase correspondingly. At this point, about a half dozen major satellite internet providers are already in place. The biggest targets will be organizations that rely on satellite-based connectivity to support low-latency activities, like online gaming or delivering critical services to remote locations, as well as remote field offices, pipelines, or cruises and airlines. This will also expand the potential attack surface as organizations add satellite networks to connect previously off-grid systems, such as remote OT devices, to their interconnected networks.

3. Attacks Targeting Crypto Wallets

Crypto Wallets are a new risk as more malware designed to target stored information means attackers can steal credentials such as a bitcoin private key, bitcoin address, crypto wallet address and other significant information. They then can drain the digital wallet. Attacks often start as a phishing campaign that uses the classic strategy of attaching a malicious Microsoft Word document to a spam email. The malware is delivered by a Word document macro that is designed to steal crypto wallet information and credentials from the victims’ infected devices.

Along the same lines, a new fake Amazon gift card generator targets digital wallets by replacing the victim’s wallet with that of the attacker. And a new remote access trojan (RAT) called ElectroRAT targets cryptocurrency. It combines social engineering with custom cryptocurrency applications and has the ability to perform keylogging, take screenshots, upload and download files, and execute commands.

4. Attacks on OT Systems

Ransomware attacks are increasingly targeting critical infrastructure and the phrase “killware” has been used to describe some of these incidents. Although the attacks don’t necessarily target human lives directly, the term is used because the malware that disrupts hospitals, pipelines, water treatment plants, and other critical infrastructure is different from regular exploits because of the direct impact they can have on people.

Cybercriminals may be moving away from smaller targets toward larger more public attacks that affect the physical world and a larger number of victims. The near-universal convergence of IT and operational technology (OT) networks has made it easier for attackers to access OT systems through compromised home networks and devices of remote workers. Adding to the risk is that fact that attackers no longer have to have specialized technical knowledge of ICS and SCADA systems because now they can buy attack kits on the dark web.

5. Attacks on the Edge

The increase in the number of people working remotely has exposed corporate networks to many of the threats to residential networks. The increase in network edges mean there are more places for “living off the land” type threats to hide. With this technique, attackers use malware made from existing toolsets and capabilities within compromised environments so their attacks and data exfiltration look like normal system activity. Living off the land attacks also may be combined with edge access trojans (EATs), so new attacks will live off the edge, not just the land.  While avoiding detection, the malware located in these edge environments can use local resources to keep an eye on activities and data at the edge and then steal, hijack, or even ransom critical systems, applications, and information.

Protect Against Threats New and Old

To prepare for 2022, organizations should certainly make it a priority to harden both Linux and Windows-based systems. And when adopting new technology, organizations should always take a security-first approach; so before adding new connections such as satellite-based connectivity, make sure it’s protected. But you also need to keep in mind the fact that cybercriminals keep using tactics as long as they keep working. Along with preparing for new threats, you can’t forget about what’s already out there. Defending against both new and existing threats requires an integrated approach to security. To fight today’s evolving threats, organizations should look into a security platform based on a cybersecurity mesh architecture with security solutions that are designed to work together.

Learn more about upcoming cyber threat trends in the full Threat Predictions perspective from Fortinet’s FortiGuard Labs team.

Sourced from Fortinet