Skip to content

ESET WORLD 2024: CANALYS’ Alastair Edwards: Even in a cloud-based world, relationships still matter

We are in the middle of a major transformation of how companies go to market, but relationships remain key.

Given market uncertainties, changes in partnering, and the surge in subscription models, most companies are now considering partnership ecosystems as the key ingredient to survival and success, according to Alastair Edwards, chief analyst at Canalys, who spoke on the State of the Channel at the ESET WORLD 2024 conference

“Increasingly, vendors co-selling, co-marketing, co-developing, and co-delivering with partners are becoming more important to delivering joint value to the customer,” Mr. Edwards told ESET after the conference.

In the interview with ESET, Mr. Edwards described the current situation with emerging hyperscale cloud marketplaces, the challenges that cybersecurity partnerships face, and the role of AI in the evolving world of cybersecurity.

What role do partners play in the world of emerging hyperscaler cloud marketplaces where vendors can approach customers directly?

While the initial assumption was that hyperscaler marketplaces would cut out channel partners, in fact the opposite is true. Partners will have an increasingly important role in this sales motion, as customers procure a greater proportion of software and cybersecurity through the cloud marketplaces of AWS, Microsoft, and Google Cloud in particular. Customers are able to use their committed cloud spend with the hyperscalers to buy third-party products through the marketplaces, which can be very attractive when core IT budgets are under pressure. They can take advantage of consolidated monthly or annual billing for all their purchases, which simplifies the billing process.

But beyond the transactions, customers will rely more than ever on partners, particularly as they purchase more complex solutions through these marketplaces. A marketplace is ultimately just a catalog of products and solutions. But end-customers need advice on the right technologies to buy, support for those technologies, integration, and management, which only trusted partners can provide. At the same time, vendors selling through these marketplaces continue to need partners to provide customer support, technical expertise, and complex services.

What do these marketplaces mean for vendor-partner-customer relationships?

These models create new dynamics for vendors, partners, and customers. But relationships remain key. Hyperscalers and vendors have recognized the importance of enabling partners to continue supporting customers directly, for example, through offering customized listings to customers through the marketplaces. The hyperscalers are investing in co-selling with both partners and vendors to drive momentum. There is a risk to the channel of course — those channel partners that don’t embrace this model will find themselves being overtaken by those that do. Even those that embrace this will need to continue showing value — and that value will change in future. But Canalys expects the share of hyperscaler marketplace business via channel partners to increase significantly over the next few years.

When preparing the latest Canalys Global Cybersecurity Leadership Matrix, Canalys worked with Channel Partner feedback collected over 12 months. What are the key lessons to take from it?

ESET’s Partners are generally very positive about their relationship with ESET and the support they receive. They are particularly positive about ESET’s ongoing commitment to partners (and channel-led strategy), ease of doing business, the quality of account management and technical support, and ESET’s ability to plan centrally and execute locally. This is why ESET achieved Champion status in this year’s global Cybersecurity Leadership Matrix report.

Based on this feedback, channel partners seek to prioritize relationships with vendors that align with the transformation in their business models and vendors offering products that partners can wrap their own services and solutions around. What does it mean for security vendors? What should they prioritize to create and maintain long-term relationships with partners?

In some ways, the same things apply to building long-term partner relationships: minimizing sales conflict, investing in partner profitability through effective partner programs, building trusted relationships between vendors and partners, and equipping partners with the skills to sell and support the vendor’s technologies.

But in addition to this, vendors must build greater flexibility into their programs and engagement strategies to support an increasingly diverse partner base and partners operating multiple business models, whether those are resell, managed services, consulting, development, etc. Increasingly, vendors co-selling, co-marketing, co-developing, and co-delivering with partners are becoming more important to delivering joint value to the customer. And recognizing customers will work with multiple partners throughout their technology life cycles — and that most partners lack the resources to specialize in every area — vendors must support effective collaboration between partners.

How important is it for cybersecurity vendors to bring innovations such as AI-powered services?

Of course, this is incredibly important. AI is moving to the center of a new cyber arms race between bad actors — cybercriminals that are weaponizing AI to launch more effective attacks — and the cybersecurity industry that is using AI to enhance cyberdefenses, augment existing capabilities, and improve predictions and remediation times. Vendors must be at the forefront of this race or risk falling behind. Canalys expects AI to usher in a whole new suite of advanced cybersecurity technologies. Channel partners and customers will choose to work with vendors that are staying ahead of a rapidly evolving landscape. At the same time, there is a danger that AI becomes overused in terms of vendor product launches and marketing, which will damage credibility and add to customer confusion when most are unclear about the value of AI. Avoiding this risk is critical to long-term success.

On the other hand, there are still some people who see cybersecurity as one single product, such as antivirus, and are surprised when they get a question about how many endpoints they have and what their network looks like. How to earn the trust of such potential partners and show them that cybersecurity is a much more complex topic?   

Many customers still don’t place enough strategic importance on cybersecurity, and these customers are most likely to only think of one product, like antivirus. But they are also the most vulnerable. Cyber resilience needs to become a business hygiene factor, not a nice-to-have. Government regulations will play a bigger role in forcing that. The reality is that building effective cyber resilience as a customer means addressing a plethora of new threats and an expanded surface area that needs to be protected. For companies that understand this, the biggest challenge they face is managing an exponential increase in cybersecurity complexity. One way to do this is to work with a single managed services partner who takes on the management of this complexity on behalf of the customer. MSPs are seeing the fastest growth in the market as a result.

What are the benefits of having a long-term relationship with a leading cybersecurity vendor such as ESET?

Maintaining a long-term vendor relationship is important to ensuring consistency but also efficiency, in terms of the cost and complexity of managing that relationship … partners and customers don’t have to constantly retrain on different vendors’ products and processes, for example. But while there is a growing trend toward ‘platformization’ in the cybersecurity industry (concentrated around a few big cybersecurity vendors), the reality is that no vendor can do everything effectively in security. So, integration with other (specialist) vendors also becomes key to success.

According to Canalys, many partners rank visibility and community involvement highest of their criteria for vendor partnership — even higher than product or pricing. Why is that so?

We are in an ecosystem-led world, in which partners differentiate through specialist skills, customer focus, and business model. Vendors who empower partners within a broader ecosystem, who promote their partners’ skills, and drive collaboration between partners will provide more value to partners than those that just focus on product or pricing.

In the current world when almost everything is cloud-based or XaaS, is it still important for vendors to maintain local offices providing support to their partners?

Yes, local support will remain key. Even in a cloud-based world, relationships still matter. Cloud and AI can be used to augment those relationships and improve efficiency and productivity. But this is a highly competitive world, and those vendors who see the cloud as a way to step away from their partner relationships will suffer from a loss of relevance and share.

Currently companies and their IT admins are battling alert and portal fatigue. How important is it for cybersecurity vendors to help their partners with simplifying alert management and what are the current trends? 

Extremely important. Customers are struggling to stay on top of the scale of cyber threats and the speed with which they emerge. Finding and retaining the skilled staff to do this is a constant struggle. One of the biggest trends in the market is the role of MSPs in managing that on behalf of customers. Vendors who empower their MSPs with tools like simplified alert management or use AI to automate certain low-level support functions will benefit (through enhanced chatbots, etc.) and ultimately this should enable them to deliver a higher level of support for their customers.

Is the pricing/billing system an important consideration in a partnership? What are the current trends? Do customers favor flexible daily billing or flat rates with long-term commitment?

With the shift to subscriptions, the biggest demands from customers in terms of billing and pricing are simplicity and predictability, when the complexity of managing multiple vendor subscriptions is increasing, with different start and end points, contract lengths, and billing models. This can make it extremely difficult to manage budgets, spending, and planning. Customers as much as possible want partners to help them eliminate that complexity. At the same time, they want flexibility to consume and pay in the way that aligns with their business models. The most successful cybersecurity vendors will help to simplify these models for customers and provide this flexibility to meet the needs of different customers.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET WORLD 2024: Building a proactive defense strategy featuring Forrester’s Madelein van der Hout

Threat actors are developing new tools, phishing is getting more sophisticated, and AI is finally here. Organizations need to adapt and be proactive. 

When you think about cybersecurity, it shares many similarities with strategic board games such as Risk, where players try to conquer enemies’ territories. To win, good players define their strategic assets, anticipate opponents’ moves, and create safe areas with limited access that allow further expansion.

The same can be said about companies and institutions trying to survive and thrive in the world of fast-evolving cyber threats, according to guest speaker Madelein van der Hout, a senior analyst from Forrester, a leading global market research company.

“Winning is everything. If you end up being second, you are actually being the first of the losers,” said Mrs. van der Hout during her presentation, hinting at potentially menacing outcomes of a data breach in a real-world scenario.

Using the popular game Risk as a metaphor for the cyber threat landscape, Mrs. van der Hout presented her insights into building a prevention-first approach in cybersecurity at the ESET WORLD 24 conference. After her session, she also kindly answered a few of ESET’s questions.

Strategic assets

Considering the current level of automation, cloudification, and remote working, there are numerous assets that institutions and companies need to protect, such as employees’ devices, customers’ data, or even IT Admin credentials, to name just a few.

But there are also other risk factors that are not directly caused by cyber-attacks. We are talking about pressure on both CISOs and security admins who bear responsibility for their organization’s cybersecurity and face a huge number of challenges including the financial consequences of cyberattacks.

For example, 97 percent of boards are expecting CISOs to deliver business value and 31 percent of boards will fire CISOs in case of a breach, according to Forrester’s research. This kind of pressure often results in high levels of stress and burnout.

Challenges faced by CISOs in 2024:

  • Changing/evolving nature of threats
  • Geopolitics
  • Regulations
  • Hybrid workforce
  • Economic pressure & cost savings
  • Integrating cybersecurity with business strategy
  • Complexity of IT environment
  • Lack of visibility
  • Talent shortage
  • Lack of comprehensive vulnerability and exposure management

Dealing with these challenges, 66 percent of employees working in cybersecurity stated that they are experiencing significant stress levels. Mrs. van der Hout took it a step further, surprising the audience with survey results revealing that among these highly stressed employees, 51 percent take prescription medicine and 19 percent drink three or more alcoholic beverages per day to cope with these challenges.

“We cannot meditate ourselves from (out of) cybersecurity burnout,” said Mrs. van der Hout, adding that there are some measures that companies can take immediately such as automated alert management or providing mental health support to employees.

But considering the current talent shortage, which exceeds 4 million unoccupied job positions worldwide, more measures will need to be taken.

Don’t dwell on the past

Be it a board game or real-world cybersecurity, adopting a prevention-first strategy relies on anticipating the opponents’ moves. But what Forrester analysts often see are companies making decisions based on what has happened before – i.e., using a rearview mirror. They set their priorities, create incident plans, and adjust their budgets, but when a data breach occurs, all this planning goes out the window.

“[Just like] how I flip the board [over] when I am about to lose a game, that’s how they flip their priorities for the upcoming year. Their investment profiles change,” said Mrs. van der Hout.

For example, in 2023, CISOs recognized the importance of the human factor in cybersecurity and increased budgets accordingly, but in 2024 their focus has shifted back to technological solutions.

And the situation has become serious. Within the last 12 months, 78 percent of surveyed organizations reported one or more incidents potentially compromising sensitive data. The estimated cumulative loss of those data breaches is on the rise in both the US and Europe and is now exceeding $1 million per company, according to Forrester.

How others play their cards

When moving to improve one’s game, it is often useful to see how others play their cards. To face current cybersecurity challenges, organizations need to follow current trends and learn from others.

For example, AI and machine learning help cybercriminals create more sophisticated threats, but legitimate security organizations can also harness this technology to build more effective cybersecurity tools and processes. Moreover, identity protection is no longer strictly about protecting the identity of employees, but also of partners, customers, and even non-human identities, thus the term: “everything identity.”

Current trends in cybersecurity:

  • AI and machine learning
  • Quantum computing and blockchain technology
  • Expansion of OT&IoT
  • Zero trust
  • Everything identity
  • Increasing regulations and geopolitics

New legislation has also been adopted around the world, but Mrs. van der Hout pointed out that following legislation is not only about checking compliance boxes but also about helping companies to build stronger defenses. Therefore, security solution providers should retain trusted advisors, and governments should educate companies and citizens to achieve the desired level of resilience.

“Governments need to be clearer about what organizations need to do to comply with new regulations instead of having really vague articles,” Mrs. van der Hout said.

When learning from others, organizations should look at the strategic and tactical priorities of other players on the market.

Strategic priorities:

  1. Boost cloud security strategy
  2. Improve the ability to detect and respond to threats
  3. Enhance identity and access management for employees, partners, and customers

Tactical priorities:

  1. Improve application security and/or product security
  2. Improve access management and policies for employees and partners
  3. Improve security operations’ effectiveness

Building a proactive defense strategy

Taking all this information into account, let’s build some proactive defense strategies.

First, determine business-relevant elements of your strategy and consider that board members will expect it to deliver some value. Business and cyber security need to work together to shape a strong security posture to persuade both partners and customers, who are increasingly taking a proactive interest in their own security.

With a business strategy set, look at possible risks and keep in mind that this should be an ongoing process. While doing this, make sure that you have proper data from cyber intelligence and advanced security technologies.

“And that’s not only about data collection. It’s also about action and response,” Mrs. van der Hout said.

Next step is to create a strong security culture within an organization as current Forrester predictions say that 90 percent of all data breaches will still include a human element.

“Looking at one cybersecurity awareness video while multitasking isn’t changing anyone’s behavior. So, when addressing awareness, please, move beyond videos. Make sure that your employees understand the importance of awareness and make security part of your organization’s culture,” Mrs. van der Hout said.

The final aspect of a proactive defense strategy is continuous improvement and adaptation. Instead of adopting one solution, and then setting and forgetting, organizations should review their defenses, close gaps, make adjustments, and ask for help if needed.

You are not alone

It is always nice to talk about the latest cybersecurity solutions and proactive defense but there are smaller companies or non-profit organizations that don’t have a budget for CISOs and high-end technologies.

When asked about this, Mrs. van der Hout remained in her winning mood, pointing out that even small companies can analyze their threat surface and set priorities. And what is more, the “good guys” in IT environments can help each other.

“We are operating in ecosystems where larger enterprises and SMBs are working together. We need to partner with each other to make sure that we are secure. Security should travel beyond just contractual agreements,” she said.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Launches AI Advisor to Enhance Threat Detection and Response

BRATISLAVA, SlovakiaMay 29, 2024 —  ESET, a global leader in cybersecurity solutions, is proud to introduce ESET AI Advisor, an innovative generative AI-based cybersecurity assistant that transforms incident response and interactive risk analysis. First showcased at RSA Conference 2024, the new solution is now available as part of the ESET PROTECT MDR Ultimate subscription tier and ESET Threat Intelligence.

Unlike other vendor offerings and typical generative AI assistants that focus on soft features like administration or device management, ESET AI Advisor seamlessly integrates into the day-to-day operations of security analysts, conducting in-depth analysis. Building on over two decades of ESET’s expertise in AI-driven endpoint protection, the offering provides detailed incident data and offers SOC team-level advisory. This is a gamechanger for companies with limited IT resources who want to utilize the advantages of advanced Extended Detection and Response (XDR) solutions and threat intelligence feeds.

“As cybersecurity threats become increasingly sophisticated, ESET remains committed to providing cutting-edge solutions that address these challenges. The ESET AI Advisor module represents a significant leap forward in our mission to close the cybersecurity skills gap and empower organizations to safeguard their digital assets effectively,” said Juraj Malcho, Chief Technology Officer at ESET.

One of its primary benefits for this new solution is closing the cybersecurity skills gap. Security analysts of all skill levels can use ESET AI Advisor to conduct interactive risk identification, analysis, and response capabilities, which are provided in an easily understandable format. The user-friendly interface makes sophisticated threat data actionable even for less experienced IT and security professionals.
 
The ESET AI Advisor also excels in facilitating faster decision-making for critical incidents. Security analysts can simply consult the ESET AI Advisor to understand the specific threats their environment faces. Leveraging extensive XDR collected data, the ESET AI Advisor identifies and analyzes potential malware threats, providing intuitive insights into their behavior and impact. It assists in recognizing phishing attempts and advising users on how to avoid falling victim to fraudulent emails or websites. By monitoring network traffic, the ESET AI Advisor can flag unusual or suspicious behavior, helping security teams take appropriate action. Its ability to automate repetitive tasks is an additional advantage. By managing routine processes such as data collection, extraction, and basic threat detection, it allows security teams to focus on more strategic initiatives.

In ESET Threat Intelligence, the new module will help researchers analyze vast quantities of unique APT reports and understand latest development in world of cyber threats. With its conversational prompts and interactive dialogue, ESET AI Advisor empowers organizations to analyze and mitigate threats effortlessly and fortify their cybersecurity posture.
 
For more information on the use of AI in cybersecurity, download ESET’s whitepaper here: Cybersecurity in an AI Turbocharged Era.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Armor your Achilles’ heel. Reduce your business’ attack surface vectoring from employee mobile devices

The number of Android threats detected by ESET telemetry in the past four years has tripled. 

Trojanized chat apps, software development kits turning legitimate apps into spyware, or fake websites offering malicious mobile applications — these are just a handful of the growing number of threats targeting smartphone users in the past few months discovered and analyzed by ESET researchers.

While these threats may sound like the personal problems of private individuals using their own devices, various surveys show that smartphone equipped rank-and-file employees are in fact yet another attack surface for businesses, one that should be prioritized. 

And that’s not easy. Even with thorough cyber-awareness training, there is still a good chance that an employee will fall victim to a sophisticated attack and become the Achilles’ heel in an otherwise first-rate defense of their respective business.

Being aware of this, ESET has introduced a new Mobile Threat Defense module to its comprehensive business solution ESET PROTECT, with sweet pricing available for the Advanced tier and higher. Users of ESET PROTECT Advanced and higher can enjoy one free mobile device seat per one paid seat for other devices. 

Growing numbers

To understand the scope of the problem, let’s review some key data from ESET telemetry. From the beginning of 2020 until the end of 2023, detections of Android malware rose by 222%. ESET Threat Reports provide further insight as to why this number has more than tripled in just four years.

In 2021, ESET telemetry detected a 428% annual increase in Android banking malware. The following year, the overall increase was driven by adware. And 2023 saw a significant increase in Android spyware cases.

If you are asking what it means for your business, check out the results of the surveys discussed below. 

A 2022 survey of working adults and IT security professionals from across the world revealed that half of the respondents used their employer-issued devices to check personal emails and messages. A further 45% used their work devices for reading news stories, while 32% shopped online.

Ironically, emails, online shops, and even news portals were the precise attack vectors described in several pieces of ESET research in 2023.

When it comes to employees using their own devices, 48% of organizations deploying a Bring Your Own Device (BYOD) policy witnessed malware being introduced through an employee’s personal phone, according to a Samsung 2023 survey.

If you wonder what’s behind these compromises, another 2022 survey found that the most common mistake contributing to cyber incidents is employees’ poor password hygiene and misuse of personal email.

Real-life examples

Maybe those numbers are too general, so let’s see some real examples of how a malicious app installed on an employee’s smartphone can endanger the whole company.

Last year, ESET researchers published a blog about two campaigns targeting Android users that had been active since July 2020 and July 2022, respectively, and were distributed across several app stores and dedicated websites. 

The threat actors in question patched open-source Signal and Telegram apps for Android OS with malicious code that ESET researchers later identified as BadBazaar. These malicious apps went by the name Signal Plus Messenger and FlyGram, and their purpose was to exfiltrate user data, such as contacts, call logs, and the users’ list of Google accounts.

The Signal Plus Messenger app proved even more dangerous than FlyGram with its unique capability to spy on the victim’s communications in the legitimate Signal app, an app that is often praised for its reliability and that is trusted by high-value targets, such as journalists.

However, after installing Signal Plus Messenger, threat actors were able to connect the compromised device to the attacker’s (Signal equipped) device and read its messages. Such sensitive information could be used in further spear phishing attacks against business officials.

A similar case was covered in June 2023, when ESET researchers published research on Android GravityRAT spyware. This malware was distributed within the malicious but functional messaging apps BingeChat and Chatico — both based on the OMEMO Instant Messenger app. The spyware can exfiltrate call logs, contacts, SMS messages, the device location, basic device information, and files with specific extensions, such as jpg, PNG, txt, pdf, etc.

If your company has a BYOD policy, taking an interest in Android malware, the threat behind the 89% increase in ESET telemetry detections in the second half of 2023 is a must. This increase was primarily due to a mobile marketing software development kit (SDK) that ESET identifies as SpinOk Spyware.

This SDK was offered as a gaming platform and was incorporated into numerous legitimate Android applications, including many available on official app marketplaces. Once an app with the aforementioned SpinOK SDK is installed, it operates like spyware, connecting to a command-and-control server and extracting a range of data from the device, including potentially sensitive clipboard (short-term storage) contents.

Again, this attack can impact employees who might “Game” on their smartphones, gathering sensitive data that can later be used against their company.

Other attacks

So far, we have been describing spyware detected by ESET researchers during past year, but there are also other threats to business coming from mobile devices. 

  • Other malicious apps – Not all malicious apps are spyware going after messages and files in a mobile device. Some of them, for example, try to lure victims into giving their bank account credentials or encrypt files in the victim’s device and ask for a ransom.
  • Phishing – Some of the biggest data breaches in history started with one employee falling for a phishing message, giving credentials, and letting cybercriminals enter the company’s network. 
  • Physical theft – Physical theft or loss of a corporate mobile device could be a serious cyber incident, especially if the smartphone or tablet contains sensitive information and is locked by a weak password. And such things happen often. In London alone, 90,864 phones were stolen in 2022. 
  • Vulnerabilities – If you think that you are safe with using only standard cloud-based team communications platforms such as Microsoft Teams or Slack, think twice. Vulnerabilities and bugs that can lead to a data breach don’t spare even the biggest names on the market.
  • Worms – Because laptops and smartphones use different operating systems, it is rare to see one malware that spreads and executes in different environments. However, there have been cases such as the Hamweq.A worm, which used smartphones as carriers to spread malware into Windows PCs via the USB cable.

Valuable targets

Most employees probably don’t use their mobile devices for accounting, coding, or administrative duties, but previously mentioned real-life cases clearly show that they are valuable targets for cybercriminals nonetheless. This makes them a potential liability to a business’s cyberdefenses.

This is why having complex, multilayered protection of your mobile devices within a unified cybersecurity platform is so important. If you want to protect that Achilles’ heel and are interested in ESET solutions for companies and their mobile devices, click here

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Europeans face evolving cyberthreats. Defense strategies need to be robust and pragmatic

Guest speaker, Forrester Sr. analyst Tope Olufon explains how to stay resilient in Europe’s fluid threat landscape.

Cybersecurity is a complicated and constantly changing endeavor requiring robust security solutions and services such as cyber threat intelligence, automated incident response, and managed detection and response (MDR). But having all of these is not enough, according to Tope Olufon, senior analyst at Forrester, a leading global market research company.

At the ESET WORLD 2024 conference, Mr. Olufon also highlighted the importance of threat actor motives and the specific context in which cybersecurity solutions are deployed. He also kindly answered a few of ESET’s questions afterward.

Considering the fluid threat landscape together with cybersecurity context, it is not possible to say what the best product is or how, for example, a good threat intelligence report should look, according to Mr. Olufon.

“No matter, how you slice and dice a threat intelligence report, what matters the most in the end is what it means for you, how can you use this and how this is going to make you more secure tomorrow, next week, or next year,” Mr. Olufon said.

Today’s threat landscape

Currently, the two most commonly reported attack methods are software supply chain breaches and software vulnerabilities, as organizations hit by those attacks tend to have noisy and opaque system environments, according to Forrester. 

This means that companies still struggle to achieve good visibility of their IT assets and are flooded by numerous false positive detections.  “The visibility needed to define your organizational needs and to set a context for cybersecurity investments is missing,” Mr. Olufon said.

Here are biggest information/IT security challenges noticed by Forrester:

  • Receiving too many false positive detection alerts
  • Lack of comprehensive IT asset visibility
  • Complexity of IT environment
  • Inability to measure the effectiveness of a security program
  • Receiving too many detection alerts

Besides these internal challenges, organizations need to also adapt to current external trends: Geopolitics are a lot more significant, since previously “insulated” sectors such as health care are now prime targets for threat actors, and the global skills gap means that things will get worse.

“It is an asymmetric playing field,” Mr. Olufon said, stressing that it doesn’t mean that those more vulnerable organizations are hopeless. “While there are, of course, some constraints, those organizations can start from somewhere. Organizations can start with creating an asset inventory, identifying what they have. The only way to eat an elephant is one fork at a time and that’s how you approach cybersecurity regardless of industry.”

Another thing that organizations need to consider is threat actors’ motivation. There are threat groups that go only for their targets’ money, but others want to stir political instability, or disrupt critical infrastructure.

To understand the current threat landscape and be prepared for upcoming threats, organizations should utilize cyber threat intelligence. However, many of them struggle to incorporate the compiled information into their security programs.

“In those organizations, the threat intelligence is something you pay for and show to the board at quarterly meetings. ‘We noticed 1000 samples of this attack,’ that doesn’t really mean anything,” Mr. Olufon said.

Therefore, threat intelligence needs to be contextualized and the right stakeholders need to be identified.

Responding to incidents

Despite cybersecurity companies investing a lot into prevention, organizations need to anticipate that something bad is going to happen. Therefore, incident response (IR) capabilities are a key part of cyber defenses.

Successful incident response means that a threat is mitigated quickly, and a targeted company doesn’t lose money or customers. But this is easier said than done. Currently, organizations face several challenges when utilizing proper IR:

  • Risks grow exponentially, but resources do not. Talent and tooling need to constantly evolve.
  • Data sovereignty requirements make data collection and storage a complex issue because local data residence requirements could make organizations’ capabilities constrained. 
  • Evolving privacy requirements introduce new complexities to employee activity monitoring as privacy requirements in some countries make data collection difficult.
  • Threat intelligence feeds are poorly integrated. Threat-hunting efforts are also rudimentary. 

And all this sheds light on the importance of MDR. Its essential component is Endpoint Detection and Response (EDR) which brings to the table the ability to respond to an incident both while it is still occurring and immediately after. Other important MDR components are threat-hunting capabilities.

“Human-driven threat hunting capabilities to be precise. Because what we have seen in the market is a lot of vendors saying that they have AI-driven threat hunting. But that is not sufficient, as AI is still just an enabler” Mr. Olufon said.

Finally, MDR should utilize automation because threat actors are very good at automation too, and MDR should help achieve a balance of powers.

But again, context is important. An MDR provider should also be able to bring contextual recommendations to improve an organization’s security posture. For example, by helping them to not only identify vulnerabilities but also smaller mistakes that lead to cracks in defenses.

Securing the future

All of this is good for today, but organizations need to look to the future and anticipate what is going to happen over the next months and years.

We can already see concepts like edge intelligence, TuringBots, or extended reality and organizations certainly don’t want to fall behind threat actors when they start to utilize these new technologies.

Let’s take cloud computing as an example: “A lot of companies still don’t have a cloud security strategy, but we have had cloud since 2006 and IT teams have been leveraging the cloud since then. Security teams started to take it seriously in 2016, ten years later, while still trying to treat the cloud as an emerging tech. It doesn’t really work that way,” Mr. Olufon said.

Conclusion

To sum up, the adversaries’ motivation and their capabilities are evolving, they are very good in automation and finding vulnerabilities in their targets’ systems. On the other hand, organizations often struggle with deploying automated cybersecurity solutions and don’t have a good visibility into their systems.

Especially, in case of more vulnerable organizations such as healthcare or charity organizations, all these challenges make cyber environment rather asymmetric. That is why organizations need to be smart about how they plan their defense strategies, how they adjust their budget, and how to make the most out of cybersecurity solutions they deployed.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.