Skip to content

遠端工作新常態造成的內部資安威脅

自COVID-19危機爆發以來,遠端工作可能是未來新的工作常態,即使員工將來可能會回到疫情大流行前的生活。部分人因為防疫而在家工作,部分辦公室可能因為人數與空間效率考量,朝向比以往更加偏遠地區改租。同時也發現居家異地辦公,可能會節省空間和通勤成本、提高生產率和提高員工滿意度等好處。

雖然是因為大流行而在被迫異地工作,但即使公共防疫限制取消或緩和下來,他們仍然寧願繼續遠端工作。但這種轉變也帶來了與硬體、軟體和網路連接等相關挑戰。除了Zoom、Teams 等這類視訊會議工具可以讓團隊面對面會議,許多協同作業和溝通方案也都會依賴於高性能的網路。

 

來自遠端工作的內部威脅

異地遠端工作不太可能很快消失,基於場地設備限制,在異地辦公的環境中,並非可以輕易達成資安上的要求。這些軟硬體設施也成為IT管理,資安管理上最難顧全的一環。過往在傳統上,傾向投資網路基礎建設,注重邊境防禦等,實務建置偏向企業網路安全。這時候關注的內部威脅可以比較明白的劃分,威脅可能來自心懷不滿的員工,企圖擾亂運營;取得客戶資料以獲得利益的員工,或者忽視公司政策的粗心同事。當端點及移動用戶不在辦公現場時,這個問題就變得複雜多了,因為我們須要防衛的insider threats 分散在世界各地。

從技術上來說,內部威脅是內部人員利用其被授予的存取權限,或者是利用對組織專業領域的理解來破壞或損害業務。內部人員不僅僅限於員工,他們可以是有權存取內部的系統或資訊的人。這可能包括前僱員、承包商、供應商甚至董事會成員。即使是與異地遠端工作員工同住的家庭成員,也有可能看到或存取他們不應該看到系統。

 

內部威脅防禦

當涉及內部威脅時,防禦目標必須包含嚇阻、偵測和阻斷。嚇阻始於為所有員工、承包商和其他被授權人員制定明確的政策和安全意識訓練,在內部和外部建立保護性安全措施。與此同時,異地遠距工作的員工更有可能在使用的裝置上,混合使用個人事務和工作專業;從而將組織敏感資訊置於風險之中,面臨潛在的隱私洩漏或員工監管違規行為。因此組織需要密切管理,種存取,優先考慮端點上的活動監視控管與連接裝置控管,而非僅僅考量網路安全。

引用 IBM 最新內部威脅成本報告中,調查的 4,716 起內部威脅案例中,員工疏忽這個因素佔其中 2,962 起。簡之,公司不能依賴員工自行決定他們的網路安全措施。相反的,他們需要為工作的端點做好安全準備。應該使用員工活動監控、內部威脅檢測和其他系統來執行這些安全規則,以保持與現企業環境內相同的安全防護等級。

 

異地工作適用端點零信任方案

要能夠將安全防護措施適用到各種Work From Home, Remote Workforce, 或是 Distributed Workforce,由於地點不一,使用裝置也沒辦法在中央監控之下,端點安全防護方案要比網路安全方案來的適合。在端點上可以強固的遵循公司的安全規則,在零信任架構之下涵蓋這幾個方面:

 

使用者活動監視

與網路行為監視相比,端點的活動監視更貼近人的實際行為。所獲的稽核記錄軌跡,也具備較好的資訊內容清晰度。在網路端看到的是封包活動交易事件,不容易還原成人的實際操作活動,還可能受限於所支援的通信協定。在端點上,不論是網頁瀏覽,檔案的使用活動歷程,軟體的執行,通訊軟體的操作傳輸等,都可以有效保留記錄證據,甚至保留實體檔案證據。

 

端點裝置控管

由於端點上可以連接各式裝置,須確保限制使用信任的裝置。封鎖所有可用外接裝置可能是方案之一,但會嚴重危害業務運作。而現今的端點的連接裝置具備各種生產力所需的功能,不能為了資安防護而妨礙工作。套用零信任裝置的概念,組織可以註冊認可的信任裝置納入白名單;其他裝置則阻擋存取。信任的裝置則加以限制存取控制,例如讀、寫、記錄與備份的控制;一方面保護了端點不會造成洩漏的破口,一方面也顧及了工作需求。

 

應用程式控管

除了傳統以黑名單方式控管應用程式的執行,白名單機制能夠更有效的落實零信任,除了被核准清單之外,一律不允許執行;阻擋不想要的應用程式,不預期的程式被執行,可以有效降低被勒索或惡意利用的攻擊風險。組織也可能會基於軟體授權的因素,管制使用者在端點上安裝、執行軟體。

 

動態適應政策

靜態政策通常以True / False 決定允許或拒絕,但現實世界的工作不會這麼單純。很多組織採取分流A/B組輪流到辦公室上班。除了以人的角色為主的安全政策外,因應上班位置、上班時間判斷自動切換政策。為了解決靜態規則無法應對變動的環境,主動適應政策根據不同環境條件,建立不同對應行動計畫;可簡化團隊管理複雜度,並減低對使用者工作的干擾。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於精品科技
精品科技(FineArt Technology) 成立於1989年,由交大實驗室中,一群志同道合的學長學弟所組合而成的團隊,為一家專業的軟體研發公司。從國內第一套中文桌上排版系統開始,到投入手寫辨識領域,憑藉著程式最小、速度最快、辨識最準等優異特性,獲得許多國際大廠的合作與肯定。歷經二十個寒暑,精品科技所推出的產品,無不廣受客戶好評。

Preview of Scale Computing at SpiceWorld: How Edge Computing is Fueling Innovation Today

Edge Computing represents one of the most transformative trends in the modern IT landscape. Yet even among seasoned IT practitioners, confusion remains about why and how applications running at the edge are critical for business success.

At this year’s SpiceWorld Virtual event, Scale Computing’s co-founder and chief product officer, Scott Loughmiller will be presenting a half-hour session entitled “Edge Computing: Autonomous Application Infrastructure Beyond the Data Center.” Scott will demystify what edge computing is all about, describe the challenges that make edge computing necessary, and explain how the edge is fueling innovation in the modern enterprise. See his short welcome video, below.

If your organization operates in distributed locations such as remote or branch offices, retail stores, manufacturing facilities, or even a fleet of ships, you probably already run applications at all these sites. And the digital demands of today will only make that more necessary. The use cases for edge computing are being driven by the explosion of data generated by IoT devices and sensors, the need to reduce application latency and deal with unreliable connectivity, and the ever-present data security and privacy concerns.

Why the Edge is Now

Gartner estimates 10% of enterprise generated data is currently being created and processed outside the data center or cloud, but forecasts this figure will mushroom to 75% by the year 2025.

As Scott points out, “not all applications can or should run in the cloud.”

To make his case for why edge computing is having its moment in the sun, Scott offers up an example of a quick service restaurant with thousands of locations. In this scenario, he says the CEO has charged the CTO with the Herculean task of introducing app-based payments to all of their stores within a year.

Each of these locations operate like an independent small business without dedicated staff onsite to manage IT systems. Furthermore, as Scott describes it, the internet connection at all the stores is “literally the least reliable part of their infrastructure so they can’t count on the cloud to run their app-based payments.”

To which Scott poses a provocative question: “What kind of technology leader do you want to be? The one that suffers under the demands of the CEO because you’re behind or the one who’s leading the technology decisions and creating real value for your company?”

Edge Use Cases IRL

It’s easy to think of edge computing as another over-hyped technology that’s years away from being fully realized. However, businesses across a wide range of industries have already embraced edge computing and are leveraging it to drive innovative products and services to market.

To reinforce this point, Scott offers up three diverse use cases of edge computing in the retail, transportation, and manufacturing industries:

  • Jerry’s Foods (Retail): Jerry’s Foods is a chain of 50 retail, grocery, liquor and hardware store. Everything in the store—point of sale system, inventory management, security cameras, building controls and even digital signage—runs on a small cluster of Scale Computing HC3 infrastructure. Each one of these stores runs like their own business yet can be managed remotely in a centralized fashion. Read the Jerry’s Foods case study.
  • Northern Marine (Transportation): Northern Marine operates a diverse fleet of tankers, ferries, and off-shore assets. Each of these vessels rely on a host of critical applications such as crew management, cargo management, accounting, security, and maintenance systems, and even their digital entertainment systems for the ship’s crew. Because internet connectivity is highly intermittent with no on-board IT personnel, Northern Marine has deployed Scale Computing HC3 clusters to run their operations smoothly while at sea. Read the Technology Innovation at Sea white paper.
  • Harrison Steel Castings (Manufacturing): Unlike the other use cases that are really just a modernized way of doing things, with Harrison Steel, a manufacturer of highly engineered precision castings, edge computing is enabling them to do things that were simply not possible before. The machines on the factory floor require continuous calibration to produce the quality parts Harrison Steel is known for. Before deploying Scale Computing, they had to physically collect machine data from across the floor to make adjustments on their machines. With Scale Computing clusters now deployed across the factory floor, the company avoided building a costly new network while improving the delivery of their precision parts. Watch the Industry 4.0 webinar with Harrison Steel.

As Scott says in closing, “Customers are innovating and building better products with edge computing. These new paradigms will create a breeding ground of innovation because it’s happening now. Just like we saw with the cloud, now we will see something similar with the edge, This is the future that’s at our fingertips.”

You can watch Scott’s entire presentation on Tuesday, September 28th at 12:15PM EST by registering for SpiceWorld here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing 
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

ESET earns a 2021 Tech Cares Award from TrustRadius

Bratislava — ESET, a global leader in cybersecurity, today announced that it has been recognized for giving back to its community with a 2021 Tech Cares Award from TrustRadius. The second annual Tech Cares award celebrates companies that have gone above and beyond to provide strong Corporate Social Responsibility (CSR). To be accepted for the Tech Cares Award, each nominated organization had to be a B2B technology company that demonstrated strong CSR in 2020 and 2021. Anyone was welcome to nominate an organization for the award, including people who work for or with the company. All nominations were thoroughly vetted by the TrustRadius research team on their CSR initiatives. Alongside other pioneers in the technology industry, ESET is leading the way in pursuing meaningful progress in social, environmental, and cultural spaces. By encouraging employees across various volunteering activities, ESET is playing an active role in society and demonstrating a commitment to the broader community. The ESET Foundation provides support through ESET’s own Employee Grant Program to offer employees aid and assistance for projects for which they volunteer. The Safer Kids Online program reflects ESET’s dedication to building a safer online environment for children to enjoy the internet’s full potential without risk. In addition, the ESET Science Award promotes the importance of significant scientific breakthroughs to society. Launched in 2019, the award aims to attract talented students into scientific careers and raise awareness of Slovak science on a global scale. ESET is a firm believer that high-quality science is essential for countries to develop and progress. ESET is also a member of the Digital Skills initiative, which supports digital education among teachers. Additionally, ESET regularly monitors its energy consumption and waste production in cooperation with the Institute of Circular Economy (INCIEN) to reduce the company’s overall impact on the environment. To find out more about ESET’s CSR activities, visit our Social Impact website. Zuzana Legáthová, analyst relations manager at ESET, commented: “At ESET, we are committed to managing our business operations in a socially responsible and environmentally sustainable way. Working with ethical and passionate people, we are dedicated to building a safer technology environment. Through our cutting-edge cybersecurity solutions and by supporting education and a commitment to research and development, we aim to bring about change not only in the digital world but across wider society.” To find out more about ESET, visit our website.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Because not only autumn has a place in October: Cybersecurity Awareness Month.

Is Cybersecurity Awareness Month the event of the year?

Welcome back to the incredible and majestic Pandora FMS blog. In today’s post, we are going to deal with an event belonging to the month of October, that depressing month in which we become aware of fall, it is colder and someone keeps cutting short our daylight hours. If April is the month of flowers and November the month of the male mustache for testicular cancer, October is the Cybersecurity Awareness Month.

What is Cybersecurity Awareness Month?

Cybersecurity Awareness Month, which is commemorated every October, was created between the United States government and national industry to ensure that everyone had the necessary resources to stay safe and secure online.

Since its inception, under the supervision of the US Department of Homeland Security and the National Cyber Security Alliance, Cybersecurity Awareness Month has grown stronger and more widespread, reaching out to millions of users and businesses, and all types of corporations and institutions. Today, in 2021, it continues to make an impact, and not only in its country of origin, it already does around the world because, who would not join the cause of feeling more protected in these times we live in?

Cybersecurity Awareness Month: Origins

As we’ve explained, the National Cyber Security Alliance and the US Department of Homeland Security launched Cybersecurity Awareness Month in October as a shared effort to help Americans stay safe online. And they did it a few of years ago, at least all those that distance us from October 2004.

When a baby starts to walk, the first steps are short and simple. So were the early Cybersecurity Awareness Month awareness efforts. Most of them focused on giving recommendations on how to update the antivirus, at least twice a year. But little by little they increased their ambitions, their reach and their participation. For example, launching complex campaigns in the industry, involving clients, NGOs and even university campuses.

The organizers made it clear in these years that responsibility for cybersecurity problems is fully shared. From large companies to small users with their battered laptops, all of us must protect our digital treasures and always keep them under supervision.

The European Cybersecurity Month (ECSM)

What is European Cybersecurity Month? The European Cybersecurity Month works, like the American Cybersecurity Awareness Month, as an annual campaign devoted to promoting cybersecurity among users, companies and institutions. The only difference is that the European Cybersecurity Month is promoted by the European Union.

Throughout the month of October, safety information is provided online and awareness is raised through good practices. Activities are carried out around the entire continent: conferences, workshops, seminars, presentations, etc. Everything in order to make us finally aware of digital hygiene.

We must thank the European Union Agency for Cybersecurity (ENISA) and the European Commission for the fruitful month of European Cybersecurity Month, which, of course, has the full support of the EU Member States.

Some events of Cybersecurity Awareness Month

Like the Homecoming Week for high schools, Cybersecurity Awareness Month is also divided into different segments. We are going to list those established by the National Cybersecurity Alliance this year, 2021.

First week

The first week will be themed on creating strong passwords, using multi-factor authentication, backing up data, and updating software.

Only that way will we be able to realize how dependent we are on technology and reconsider the amount of personal and commercial data that we treasure on platforms located on the Internet. There, at the hand of any cybercriminal.

Second week

The motto? “You must be careful with emails, text messages, and chats opened by strangers and incognitos.” You are just one click away from a suspicious email, link, or attachment, to bother the hell out of you. Indeed phishing and digital scams in general have been on the rise since we began with this pandemic. Since we have the damn COVID among us, phishing attacks represent more than 80% of reported security incidents.

Third week

The third week of Cybersecurity Awareness Month will be focused on supporting, inspiring and applauding students who have chosen, or want to choose, a university career focused on cybersecurity. Whether they are teenagers, adults or confused kids who want to change fields of study. Cybersecurity is cool, youngster! It is fully growing and has space and credits for everyone!

Fourth week

This week we will try to make security a priority for companies more than ever. Incorporate security in products, processes, tools… Promote cybersecurity in employees and teams. Get cybersecurity in the minds of department heads until they themselves celebrate the vanguards and news of this discipline on a daily basis.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

IoT Profiling, Visibility & Classification, Powered by Portnox CLEAR

IoT/OT Blind Spots Across Your Network

At present, hundreds of millions of IoT/OT devices are in use, and that number continues to rise as organizations increasingly adopt such devices to improve productivity, insight and real-time decision making. Unfortunately, IoT/OT devices are particularly at risk to external and internal cyberthreats due to a lack of device patching and overall visibility and contextual understanding across networks. This makes IoT profiling quite difficult.

The healthcare, hospitality and manufacturing sectors are especially vulnerable due to their heavy reliance on ultrasound machines, avionics, building automation, VoIP, medical devices, printers, computers, networking equipment and energy and power infrastructure. To close this IoT/OT device visibility gap, Portnox CLEAR is introducing its IoT/OT Visibility Add-On, which enables organizations to see, profile and classify all IoT/OT devices on the network without an agent.

IoT Profiling in CLEAR: How it Works

Portnox CLEAR utilizes several methods and leverages multiple data points to actively and passively identify, profile and classify IoT/OT devices across enterprise networks, delivering detailed device profile data that takes into account device families, types, models and vendors.

iot profiling in portnox clear

With the IoT/OT Visibility Add-On, Portnox CLEAR can continuously discovers all IP-connected devices without requiring agents, the instant they enter your network. the add-on provides in-depth visibility into those devices using a combination of active and passive discovery, profiling and classification techniques.

IoT Profiling Capabilities with CLEAR

  • Device Discover – Automatically discover IoT/OT devices without needing to install yet another third-party agent across managed devices.
  • Device Profiling – Classify IoT/OT devices based on type, like MRI machines, printers, sensors and beyond.
  • Device Type Enforcement – Continuously monitor IoT/OT devices and enforce network segmentation and access policy based on device type.

IoT Profiling Advantages with CLEAR

  • Cloud Delivery – Portnox CLEAR leverages a central cloud database that utilizes crowdsourcing and machine learning to deliver better device predictability.
  • Microsegmentation – Automatically segment groups and enforce unique policies to reduce the network attack surface, improve breach containment and strengthen regulatory compliance.
  • Access Control – Define and enforce access control policies based on IoT/OT device types.
  • Complete Asset Management – Be able to report on and visualize in real-time the device types, locations and level of access for every IoT/OT on the network.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。