Skip to content

What are ransomware attacks, and why are they on the rise?

The number of cyberattacks increases every day. Most notably, ransomware attacks are continuously on the rise: not a day goes by or a new ransomware attack and data breach are mentioned in the press. But what is ransomware exactly, and which types are there? How do these ransomware attacks happen, and what can you do to prevent them? In this blog post, we’ll formulate an answer to all of these questions.

A ransomware payment request – that’s one message you don’t want to see.

What are ransomware attacks?

Ransomware is a type of malicious software (malware), that is used by cybercriminals to encrypt a (portion of a) device’s data, rendering it no longer accessible. To regain access, criminals will demand a big ransom payment before they will give the decryption key or deactivate the lock screen. But, of course, it’s better to mitigate your chances of getting attacked to begin with – rather than paying the ransom. To put more pressure on the victims regarding the ransom demand, the hackers can use specific ransomware software to not only encrypt files but also search for sensitive data and send this information back to the hacker. During this type of malware attack, ransomware groups often spend much time unnoticed in the operating system, while searching for the most valuable data to exploit. If organizations then do not want to pay the ransom, the malware attacker often threatens to publish the stolen data online, which has disastrous consequences.

Who are ransomware attack targets?

In general, anyone can become the target of ransomware attacks. However, looking at the most recent data breaches in 2022 alone, it’s clear that hackers will focus on organizations that work with a lot of personal files and sensitive data, big user groups, and possibly smaller IT teams (such as in education or healthcare). Furthermore, they also tend to target industrial players as disruptions in their IT processes pose prominent problems for the company’s supply chain.

Which types of ransomware attacks are there?

A wide range of ransomware variants are being used, but let’s take a look at the most common ones:

  • Crypto ransomware or ‘encryptors’: This type of malware is perhaps the most famous one. A cybercriminal will encrypt files and to keep the decryption key, for which you will have to pay ransom. Notable examples are CryptoLocker, GoldenEye, WannaCry, …
  • Locker ransomware: This ransomware variant will block your basic computer functions. You won’t have access to your device and you’ll only see one lock screen or popup with the message that your files and applications are inaccessible and that you need to pay a certain amount of money before gaining access again.
  • Scareware: A type of malware designed to scare or manipulate people into visiting website pages or downloading malware-infested software. This is done by using social engineering tactics and popup ads. The goal is to make users believe they need to buy or download software (which is actually malicious). Some examples of scareware are: PC Protector, SpySheriff, Antivirus360, …
  • Doxware: With this term, we refer specifically to ransomware that is used to get personal data. They compromise the privacy of the employees by getting access to photos and sensitive files, after which they will threaten to release the data. Often attackers will deliberately target specific victims for this type of attack.
  • Ransomware as a service (RaaS): This is a business model for cybercriminals. Anyone, even without knowing how to code, can buy tools on the black market and use them for carrying out ransomware attacks. The tools are hosted and maintained by hacker collectives. Well-know RaaS providers are REvil, DarkSide, Maze, …
Ransomware’s goal is to lock up your data, and get you to pay for the key.

How do ransomware attacks happen?

Ransomware operators try to gain access to the company’s network or system via different techniques. Very often, they will try to do this via individuals in the organization, but they can also attempt to infect systems directly. The following list highlights some of the most common ways ransomware attacks happen.

  • Phishing: Criminals send employees of your organization an email that contains a malicious link or malicious attachments. It could be that the link goes to a website hosting a hostile file or code, or that the attachment has a download functionality built in. If one of the people at the company clicks on or opens the content of the phishing emails, malicious software could be installed and the ransomware infects the systems.
  • Insufficiently protected network: If you’re acting proactively in securing your network, cybercriminals can attempt to exploit multiple vulnerabilities and attack vectors to get in and let their malicious software do its thing.
  • Open RDP: Using RDP without any security measurements is something cybercriminals like to see, as they can exploit its weaknesses. That way they get access to the company’s system. Researchers found 25 vulnerabilities (!) in some of the most popular RDP clients (FreeRDP, Microsoft’s built-in RDP client, …) used by businesses in 2020.
  • Insecure VPN connections: VPN tunnels directly from your employees’ devices to your network. Together with RDP, the UK National Cyber Security Centre identified VPN as one of the largest risk factors for a ransomware attack, because malicious software from the client device can enter your corporate network remotely.

Examples of major ransomware attacks in 2022

Every day, another major organization is the victim of a ransomware attack. Some recent victims were:

  • Government systems in Costa Rica (May 2022): Cyberattack targeting systems from tax collection to importation and exportation processes through the customs agency. Furthermore, they also got access to the social security agency’s human resources system and the Labor Ministry. The Conti cartel has been demanding a lot of money for the attack. In the meantime, they have been starting to publish stolen information as they were tired of waiting for the ransom.
  • Florida International University (April 2022): Data breach that impacted the sensitive information of students and faculty. BlackCat was behind the attack.
  • The Scottish Association for Mental Health (March 2022): The health organization was targeted by a ransomware gang that impacted the IT systems. More than 12GB of personal and sensitive data was leaked online. Behind the attack was RansomEXX ransomware gang.
  • KP Snacks (February 2022): The hackers of the Conti gang were able to steal many sensitive documents like samples of credit card statements, spreadsheets including employee personal data, and confidential agreements, … They published even more of these data online after not receiving the ransom in time.
  • Moncler (January 2022): At the beginning of the year, the luxury Italian fashion giant became the victim of a data breach following an attack by ransomware gang BlackCat. Afterward, the company explained that various data had been impacted. The data was not only related to customers, but also to current and previous employees, as well as to suppliers, and business partners.

These are only a handful of thousands of (publicly known) examples. Ransomware attacks are not limited to certain verticals or countries. Without the right security measures in place, everyone can become a ransomware victim.

The notorious hacker collective Conti Group is behind many of the past year’s ransomware attacks.

Why are ransomware attacks rising?

Shift to hybrid and remote working

Ransomware attacks are on the rise as ransomware groups are continuing to adapt their techniques in this changing digital world. With the acceleration of remote working and shift to hybrid working, malicious actors are not only focusing on organizations in general but are also targeting individuals to gain access to the operating systems, files, and applications of companies.

More and more people are working outside the office networks. A lot of companies have set up a remote working solution in a quick way as they were surprised by the worldwide pandemic. However, in multiple cases businesses chose insecure solutions to do this (e.g. via opening RDP endpoints or facilitating ‘naked’ VPNs). The result was that they created gaps in their cybersecurity defense, which makes them an easy target for malware.

Financial benefits for ransomware group

Another reason for the rise is that more criminal groups see the benefit of ransomware attacks as companies tend to (in most times) pay the ransom. It can be a quick money win for them. Stealing and threatening to leak the data has been working well for these ransomware gangs, so we see a clear shift from denial of data to data extraction. Let’s take a look at how you can prevent making them rich.

Best practices to prevent ransomware attacks and spreading

Nobody wants to pay the ransom or wants to have encrypted files and encrypted data, right? So how can organizations prevent such ransomware attacks? How can you defend yourself? We’ve listed some best practices of ransomware protection for you:

  • Inform and train your employees:
    • IT admins shouldn’t click on unknown links or open malicious mail attachments, and should always use strong passwords with MFA enabled.
    • Facilitate security awareness training for your employees. The above is more difficult to enforce on your employees, so it is fundamental that you make them aware and train them in cybersecurity hygiene.
    • Phishing emails and social engineering attacks are still very popular techniques with cybercriminals to target individuals to make them the gateway into the organization’s computer system. Make sure your employees are aware of these practices so that they can recognize and counter them when they face an attempt.
  • Data backup:
    • Backup files and applications regularly.
    • Make sure to secure your offline data backups as well, and check that they are not connected permanently to the computers and networks that they are backing up.
  • Network segmentation:
    • If you have an infected system, make sure that malware cannot spread to another computer system by segmenting production and general-purpose networks.
    • That way, if somebody is using an infected computer and infects one of the smaller networks, you can try to isolate the ransomware before it spreads further.
    • This also gives the IT team more time to remove ransomware without it spreading throughout the entire organisation.
  • Review port settings:
    • Open RDP ports are one of the most common ways ransomware attacks are initiated. Using ‘naked’ RDP port 3389 to give employees remote access is opening the door for hackers and saying: “Welcome, this way please!”
    • Another port that is often targeted is Server Message Blocked port 445.
  • Limit user access privileges:
    • To block ransomware from entering, define the permissions of users thoroughly.
    • Set limitations to which applications, desktops, and files they have access.
    • Add security layers in line with the Zero Trust model as you can not trust anyone, even if it’s an authorized employee. Make sure you have control over what each user or user group can access or do.

What to do if you’re a victim of a ransomware attack

What can you do if you are the victim of a ransomware attack? Let’s check out the most common ways to recover from a ransomware infection.

  • Do not make a ransom payment: Firstly, stay calm and don’t rush into paying the ransom. It will only encourage criminals to keep on doing this. (And how can you be sure that the ransomware attackers will give your data back after you paid?)
  • Identify the source of the ransomware: Try to find out what the point of entry of the ransomware was. Talk with your users to find out who experienced the first signs of the attack.
  • Isolate the infected machines: You don’t always know how fast the ransomware could be spreading, but disconnect all devices from the network as soon as possible. This may help reduce the impact of a company-wide ransomware infection.
  • Report the attack to the authorities: This is a crime, and you should report it to the police. They could also be able to help you as they have access to more powerful resources for this type of crime.
  • Restore your data: If you have been taking regular backups of your data, you can use those off-site or cloud backup files to restore your data. This is why you should have a backup data strategy so you can move forward quickly without losing too much time. However, be careful as some ransomware may have been for months in your systems and therefore in your backups as well. You should always run an anti-malware solution on your backups first to check.

How can Awingu help with ransomware prevention?

Awingu on devices

Awingu is a unified workspace that makes it possible for a company to enable secure remote access to file servers, applications, and desktops for its employees. Our customer use it as an extra protection layer to secure ‘naked’ RDP, as well as to provide a secure alternative to VPNs. Users can access the workspace via the browser and nothing needs to be installed on the device. So even if they are using an infected device, there is no direct connection to the company’s network, so you don’t have to fear a ransomware infection. Awingu comes with various built-in security capabilities that will help you secure the access:

  • Browser-based workspace
  • Built-in MFA
  • Anomaly detection and monitoring in the dashboard
  • SSL encryption
  • No local data on the end-user device
  • Granular usage control
  • Context-awareness


If you want to learn more about how Awingu can help you protect your organization against ransomware attacks, click here!

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Awingu as a secure homeworking solution at the Municipality of Evere

Evere is a Belgian municipality with 43.000 inhabitants, in the Brussels-Capital Region with 1.220.000 inhabitants. In the municipal administration, there are about 300 computer users, working in different departments each with their own needs and work requirements. At the end of 2019, the IT team was looking for a simple and secure solution to enable teleworking for their employees.

Long before working with Awingu, the municipal administration of Evere had implemented the Citrix solution for all its users both within the municipal administration, as well as to allow employees to work remotely on an occasional basis. Over time, limitations encountered with certain specific business applications resulted in a mixed fleet of classic computers and Citrix workstations.

Too much complexity

In 2019, before the health crisis, the situation was as follows: two different solutions for workstations, one of which (Citrix) was slowly being upgraded or replaced by another solution.

“Managing two different technologies but especially the complexity of the Citrix configuration means more complex management, a higher level of skill for the IT team and higher support costs when faced with more advanced technical issues.”

“Managing two different technologies but especially the complexity of the Citrix configuration means more complex management, a higher level of skill for the IT team and higher support costs when faced with more advanced technical issues.”

fournier
Philippe Fournier
Responsible for IT at the Municipality of Evere

Working from home

To continue to make remote working possible and in anticipation of the implementation of structural teleworking, the IT team had already initiated before the start of the pandemic to look for another solution to replace their current configuration.

When the need for teleworking exploded in 2020 due to COVID, the team was pleased to have identified and begun implementing an ideal solution like Awingu.

Advantages of Awingu

Working with Awingu brings only advantages, both for the IT department and for the end users of the municipal administration of Evere, explains Philippe :

“The licensing model is very transparent and easy, especially when compared to other solutions like Citrix or VMware, where you need a consultant just to explain the model to you. Awingu offers competing licenses, so the only choice you have to make is whether to buy or rent the licenses.”

fournier
Philippe Fournier
Responsible for IT at the Municipality of Evere

In addition, he is very pleased that he can purchase Awingu through the CIBG’s central purchasing office. In their catalog, you can find Awingu licenses. All Brussels administrations that have joined the central purchasing office can buy Awingu licenses in compliance with public procurement legislation but without the administrative burden. When Philippe heard about this possibility from a colleague in Sint-Agatha-Berchem, a long-time Awingu customer (as well as 80 other local authorities in Belgium), he immediately saw the great advantage.

In addition, the IT team explained to him that it was relatively easy to install, set up and configure Awingu. For end users, Philippe adds, it couldn’t be simpler:

“Just go to the web, enter a predefined custom url, provide your username and password and you’re in. Then you can easily work with any application (legacy, web, SaaS) or file needed, all in a secure environment. If necessary, you can even mandate that some or all of the integrated MFA solutions be used at no additional cost.”

fournier
Philippe Fournier
Responsible for IT at the Municipality of Evere

For now, they are only using Awingu to facilitate teleworking in a seamless and consistent manner. Other goals are to enable secure remote access for external contractors via Awingu as well.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

What is cyber insurance and what does the MFA insurance mandate mean?

In this blog we’ll give an overview about what a cyber insurance is and what you need to get it. Furthermore, we’ll talk about why multi factor authentication (MFA) has become a mandatory requirement to get one of those cyber insurance coverages.

What is cyber insurance?

What does cyber insurance mean?

A cybersecurity insurance or cyber liability insurance is a coverage against financial losses caused by cyber incidents (for example data breaches) and offers technical and recovery support.

To define the cost of your insurance, cyber liability insurers will look at multiple risk-factors, like for example, what industry you’re in, which way the organization covers data and of course, which security measures the organization already has in place.

There are various requirements that insurance companies define for organizations to be eligible for the insurance coverage. One of the most fundamental ones that most insurers ask for nowadays is Multi factor authentication (MFA).

train-employees-cybersecurity
Questions about training for employees will for sure be on the questionnaires you’ll need to fill in for an insurance quote.

All depends of course on the type of insurance you take.

It is important to understand that a cyber insurance coverage will not help you to identify cyber risks themselves, nor will they eliminate these. However, when your organization would be hurt by a cyber attack or data breach, having a cyber liability insurance will help you to, for example, recover compromised data, restore personal identities, or repair your damaged computer systems.

Some examples of events that could be covered by your insurance:

  • Data loss or breach (after hacking, employee theft, loss of memory stick, …)
  • Computer fraud
  • Business interruption due to a breach

Keep in mind that an insurance like this will protect you financially regarding your digital assets, but it won’t be able to cover every possible risk.

What does cyber insurance not cover?

Cyber liability insurance doesn’t cover claims of property damage or bodily injury. For this, you will need a general liability insurance, as a cyber one does not protect you against these claims.

Furthermore, your insurance (probably) also won’t cover:

  • Potential lost profits in the future.
  • Cost of restoring and improving your computer systems to a higher level of functionality than they were following a cyber event.
  • Loss of value caused by the theft of intellectual property from your company.
  • A lawsuit for any potential vulnerability in the systems of your organizations before a breach.

How much does cybersecurity insurance cost?

It’s not possible to give an exact answer on this question as it really depends of the protocols and systems you already have in place for cybersecurity. Cyber insurers will look at your current state to provide you with an exact cost of the cyber insurance policy. However, we see that the prices have been increasing on the cyber insurance market. So be sure to investigate what you can do to lower your premium.

How can you get a cybersecurity insurance?

What do you need to get such a cyber liability insurance? What is expected by cyber insurance providers to have in place already when looking for an insurance? To purchase one, you’ll have to provide information about your security controls to insurance underwriters.

What do you need to get a cyber insurance?

Insurance providers (like for example Hiscox, Chubb, AIG, The Hartford, …) will carry out a cyber insurance risk assessment to define your premium and coverage limits. You will have to fill out a questionnaire about your cybersecurity protocols, IT risk management, protocols, … The better you score on this one, the less expensive your coverage will be.

One of the minimum common requirements to get one nowadays is having Multi Factor Authentication (MFA) enabled for administrators and privileged users. This cyber insurance MFA mandate exists, because the additional layer is seen as a fundamental access security measure to protect not only on-site but also remote access. If you only use a password, cyber insurers will believe compromised accounts are inevitable for your organization’s future.

Of course, securing a password with MFA (for privileged and not privileged access) is no silver bullet that can protect against every attack, but it’s certainly a vital layer organizations will need. This MFA insurance requirement is thus something you’ll have to keep in mind when considering an insurance.

Furthermore, there are some more steps that (often) are standard requirements to get a cyber insurance:

  • All PCs must have antivirus software (up to date)
  • Company network must be protected by a firewall
  • Companies should back up business data, by using external media or a secure cloud service (this should be done regularly)
  • Users that want to have or gain access must follow a secure process
cyber-insurance-requirements
To get a cyber insurance coverage, you’ll need to fulfill some requirements.

What can you do extra to lower your cyber insurance?

There are multiple steps you can take to lower your premium. We’ve listed 5 of the most common industry practices that you should definitely take a look at:

  • Organize regular cyber training for employees
  • Make sure stored data is limited and restrict network access
  • Have 24/7 monitoring of suspicious activity
  • Provide solid recover procedures

What is Multi factor authentication (mfa) and why do you need it?

What does Multi factor authentication mean?

Authentication means the process of verifying the identity of a user. With Multifactor authentication this process exists of at least 2 different authentication factors. We speak specifically of two factor authentication when there are only 2 factors, and even that is already better than just one factor.

Knowledge factor

One factor to authenticate can be something you know like a password or a pin. Sometimes the knowledge factor can also be a security question that you’ll need the answer to gain access.

Possession factor

You can authenticate with something you have, like for example your phone. By using authenticator applications on your device, you can then receive a one-time code, that only works during a restricted time. Or you can receive a SMS code with a security key that you then fill in.

Inherence factor

This refers to something you ‘are’, more specifically biometric data. Sometimes fingerprints or face IDs are used to recognize the user’s identity.

Why do you need to implement MFA?

Multi factor authentication is seen as the extra layer to authentication that organizations need to avoid that compromised passwords can lead to a compromised network. If you adopt MFA as an extra security measure, you can protect your sensitive data, even if there are compromised credentials.

Often criminals of cyber threats try to gain broader access via individual users, and they have various strategies (phising, password spraying, credential stuffing, …) to get these passwords. If you use credentials with this extra security step like MFA, you’re making it more difficult for them.

To minimize the impact of cyber attacks on your IT infrastructure, insurers will inform you on this mfa insurance requirement for security when you’re reaching out to them.

How can you mitigate your organization’s remote access cybersecurity risks?

Awingu aggregates different applications, desktops and file servers and makes them available (with the possibility of single sign on) for your remote workforce in the browser via its ‘RDP-to-HTML5’ gateway. As Awingu runs completely in the browser, it’s possible to work on a Chromebook, iPad, mobile device, laptop, … any device really!

A variety of security features come bundled with our all-in-one solution:

  • Browser-based solution: All runs and stays in the browser. No direct connection with the end-user device, so no need to install extra antivirus software on the PC.
  • Secure authentication process: MFA is built-in, or you can integrate another commercial platform that you already have in place.
  • Context-awareness: It’s possible to define geo locations and/or IP addresses as safe zones per user (group) or feature.
  • No local data: There is no data stored locally on the device, ever.
  • Auditing: Access to various auditing capabilities like session recording, usage control, anomaly detection, …

Sources

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Gas transport company switches from Citrix resulting in an 80% reduction of their infrastructure footprint

SPEED OF IMPLEMENTATION
EASE OF USE
COST SAVINGS
“Awingu just worked and that’s what we needed. A simple, straightforward application that accelerated our ability to achieve our goals.”
davidderoock2
David De Roock
IT Director, Exmar NV

🔶 CHALLENGE: Provide employees and external contractors seamless access to business assets quickly and efficiently without continuously needing to maintain the environment. 

❓ TEST: Will Awingu be easier to maintain while offering a stable user experience? 

⭕ SOLUTION: Awingu enabled the bulk of Exmar NV’s workloads to shift from twenty-five to five remote desktop machines by assigning more resources to them than their Citrix solution could handle. 

✅ RESULT: Moving away from Citrix was critical to realizing significant cost savings and improved user experience for both IT teams and end users.

 

Exmar NV is an energy supply chain provider with 2500 employees offering tailor-made energy solutions to the gas industry. The mission is to serve their customers with innovations in the fields of offshore extraction, transformation, production, storage, and transportation by sea of liquefied natural gases, petrochemical gases, and liquid hydrocarbons. 

Prior to 2019, Exmar was utilizing the Citrix solution in tandem with VPN for their employees to access business files and applications. This was a sufficient solution for the most part, but it was complex and costly. Also, accessing large files was problematic. The load was heavy and extra traffic added an additional challenge, especially when traveling end users went to remote locations in Asia, Africa, or vessels out to sea. 

THE CHALLENGE: Provide employees and external contractors seamless access to corporate files quickly and efficiently without the need to constantly maintain the environment. 

Exmar was looking for: 

  • Simple workspace management 
  • Seamless implementation 
  • Uninterrupted access to business files and applications 
      

The arrival of COVID in 2019/2020 resulted in a shrinking IT team at Exmar. This made maintaining the elaborate Citrix environment increasingly difficult. After a 2.5 year struggle, David De Roock, IT Director with Exmar, went back to the drawing board for alternate solutions.

“Citrix was too complex with a lot of virtual servers, layering storage issues etc. I lost count how many times team members would mention in meetings that ‘Citrix isn’t working again’. This was disruptive to our day-to-day business and we couldn’t continue this way”, David De Roock (IT Director, Exmar NV) says.

THE TEST: Will Awingu be easier to maintain while offering a seamless user experience?

David was impressed that within 2 days of his conversation with Awingu, the pilot was off the ground. 

The following week, David’s team conducted extensive testing with both external and internal users. 

Positive user feedback included:  

  • The testing process was easy and straight forward.
  • Accessing resources through a web browser—without the need to install anything—was an immense benefit.
  • Speed was impressive; the startup time of applications was drastically reduced since no plugins were required. 
  • The support efforts needed from their desktop team were reduced since a modern HTML 5 browser is the only requirement.
  • A much better user experience – the server didn’t crash and browser updates didn’t interfere with plugins.
  • Users can use any device so laptop distribution was eliminated.

 

“The overall sentiment of those involved in the pilot was that Awingu was simple. The time previously used to maintain the Citrix environment shifted to focus on how we can improve our processes and environment to positively affect our customers’ bottom line”, David mentions.

This was enough for David to decide to make the move from Citrix to Awingu.

THE SOLUTION: Awingu enabled Exmar to shift the bulk of their load to five remote desktop machines, assigning them more resources than the Citrix solution could handle.

David was pleased to see that the number of virtual machines reduced drastically from twenty-five to five.  

Plus, the need for Exmar-provided laptops was eliminated for external agencies. Not only was this advantageous for their budget but it also enhanced security as there is always elevated risk when you have laptops traveling to every corner of the globe. 

The simplicity of Awingu is what made the biggest impact. The learning curve was minimal, and it only took two weeks to decide that a full roll out was the best choice for their business. 

The personal attention of Awingu’s Support team was another deciding factor. A couple of minor issues popped up over the weekend and the Awingu Support team was available and willing to help. By Monday, issues were solved, and it was business as usual without any interruption for the end user. 

David explained that “Awingu is very straightforward and easy to roll out. This was the driver to make the move from Citrix to Awingu. 

THE RESULT: Moving away from Citrix was critical for Exmar to realize significant cost savings and ease of use for both IT teams and end users.

Moving to Awingu was the solution Exmar needed to strengthen their budget and reassign resources where they were needed. 

In summary, the main benefits they experienced were: 

  1. Reduction of infrastructure footprint: What once required twenty-five virtual machines now only requires five. A reduction of 80%.
  2. Zero complexity: The learning curve was minimal thanks to the easy-to-use and secure unified workspace. Their pilot was rolled out in two days. Full deployment and testing with 100 users spanned an additional 2 weeks.
  3. Cost savings: Licensing costs were reduced by 66% annually.

 

“The overall picture? The Awingu experience is a lot better, simpler, and easier to maintain. We haven’t looked back and an expansion of the solution is in the works”, David concludes.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

How to secure remote access in education in 2022

Remote learning and remote teaching are indispensable concepts in higher education around the world. Since the shift to remote working and online learning, the sector is facing more and more cybersecurity challenges. Where before the biggest part of school operations stayed in the school’s environment, there is now an increased use of technology in a remote environment. That means that there are also more potentially vulnerable access points for attackers. But how can you let staff and students securely access a desktop or application without putting the school network at risk?

IT admins of universities and colleges are thus looking for secure remote access solutions in education, as security is one of the primary worries in an increasingly digital world. We’re talking about enormous user groups (dozens of teachers and often thousands of students) that use many different devices to access applications and files with a lot of personal and sensitive data.

Remote learning is a standard part of the curriculum, but it comes with its own cybersecurity challenges

In this blog, we will be looking at  the top 4 remote access solutions used in education. Those are Teamviewer, VPN, RDP and secure unified workspaces. Needless to say, all these solutions are valid options to enable remote access in education – but they’re not always equally secure. Nevertheless, it’s important to keep the specific problems you want to solve in mind. Define how you want to enable remote access, and what remote access solution fits your query. That way, it will be clear that some solutions offer more advantages, often in terms of security, than others.

Why have remote access for staff and students?

In their courses, students often have to use very class-specific applications and software, which are installed on computers in university PC rooms. In times where (partially) remote learning is the norm rather than the exception, it is usually not possible to offer this software personally to students, as it is very expensive for the university and/or cannot be installed on any hardware. A way to solve this, could then be to give students remote access to the school computers via their own device (Chromebook, tablet, …) . Depending on what type of access your provide for these forms or remote learning, they can easily access the software – even if it’s legacy software (that needs to be installed on the device) from outside the university or college.

Another often-heard use-case is that of network-restricted third-party services. Educational institutions often have memberships for services like JSTOR that they offer to their students and academic personnel. Often, access to those services is limited to the network of the university or college. If a researcher or student can get access to these services from anywhere, this would greatly benefit the institution’s (and their personal) academic prowess.

However, enabling remote access is not only a necessity for the students. There are also many administrative staff members working in universities and colleges who would like the option of working remotely. For example, they may need access to personnel files or work with accounting applications from home. For those people, universities and colleges should be looking for a secure and simple solution, because this administrative staff often works with personal data of staff and students. There must be absolutely no risk of data loss, so security is very important. Furthermore, the IT team should not be burdened with the fact that these employees want to work at home, so a school should look for a simple solution that requires few support (tickets). Of course, this is also the case for teachers who want to be able to access files and applications they need for lessons remotely.

Remote access solutions in education in 2022

There are many remote access solutions for education on the market. However, some of them are complex to use or to manage, and others pose a risk to the educational organization’s critical cybersecurity. Let’s take a look at the top 4 remote access solutions in education in 2022:

TeamViewer

TeamViewer is a remote control computer software, that allows you to maintain computers and other devices. In an educational context it is sometimes used by IT teams to give remote support to students or teachers when one of those parties is not present at school. With the software, users can share their screens, application window and even an entire remote desktop.

This solution is especially useful to share a remote desktop view between users to collaborate or support. However, it is a less ideal software for teachers and students to connect with lab computers in the school.

Disadvantages of TeamViewer

TeamViewer is used to remotely control a computer. It’s simple, but comes with a set of security issues.

  • It is free for home/personal use, but it cannot be used for free in the commercial settings. Prices are steep: $130/mo for 3 concurrent sessions – at that rate, giving entire classes remote access quickly becomes a costly affair.
  • TeamViewer offers built-in MFA, but there is as of yet no way to enforce its use. This is a long outstanding request by the TeamViewer community
  • Because integration of AD and MFA are not mandatory, you risk leaked credentials. Students will log in with a username and password, and they’re in. It is unwise to have thousands of credentials shared with users that can access your network, and that don’t necessarily adhere to the privacy protocols you have put up
  • In the past years, researchers (and hackers) have discovered multiple 0day exploits in the TeamViewer software, such as CVE-2018-16550 (brute-force vulnerability) and CVE-2020-13699 (allowing malicious websites to launch the host device’s TeamViewer application)
  • Depending on your license, you can miss out on mass deployment. If you’re configuring (and maintaining) accounts for the entire school, this can become a very time-consuming effort. Furthermore, users report that its AD integration is cumbersome and requires many steps (it requires an additional software download (the TeamViewer AD connector), API key generation, etc.)
  • TeamViewer doesn’t have the ability to use full screen with high-resolution screens
  • A student or teacher needs a fast and continuous internet connection if they want to use TeamViewer
  • Students and staff are not able to share large files in an easy way
  • Every system needs to have a TeamViewer and the same version installed on it to work which is not efficient when students work remotely on an unmanaged device

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.