Skip to content

What Does the Future Hold? MSP Industry Predictions for 2025 and Beyond

The beginning of 2025 has been wild so far, and there’s no sign of it slowing down. We’re back with more predictions for what 2025 will look like for MSPs, with an eye towards 2026 and beyond.

Whether it’s integrating cutting-edge technologies, adapting to regulatory shake-ups, or capitalizing on emerging markets, MSPs and IT leaders must stay ahead of the curve. That’s why ChannelPro turned to some of the sharpest minds in the channel and asked them to deliver an unfiltered forecast for the rest of 2025.

If you’re looking to enhance your service offerings or master shifting market dynamics, these predictions and insights will help you stay ahead in an unpredictable year.

Tarun Desikan

Desikan is executive vice president, cloud secure edge for SonicWall.

“In the Mission Impossible movie franchise, Tom Cruise and team make use of advanced techniques – latex 3D face masks, voice modulators, adaptive contact lenses and more – to impersonate people, enter restricted areas and save the world from destruction. In 2025, new AI capabilities will make what was only possible in the realm of movies available to the mainstream. And, as with all such new technologies, the bad guys will be amongst the first to take advantage. Unfortunately, the bad guys won’t be using impersonation to save the world; instead, they will launch more sophisticated spoofing and phishing techniques to launch cyberattacks against unsuspecting civilian organizations.”

Jim Elder

Elder is VP of global pathways at Blancco.

“The proliferation of AI will continue to increase demand for greater processing speeds and more scalable data operations in 2025. Hyperscalers will forge ahead with their buildout and focus on facilitating AI applications and supporting AI initiatives at large and medium enterprises. Meanwhile, the cloud migration “gold rush” will continue to cool off and balance out, leading CIOs to shift budget into their own enterprise data center operations. This will further increase spend and demand for partner services that include helping enterprises optimize their cloud environments.”

Tim Erlin

 

Erlin is VP of product at Wallarm.

“In 2025, Managed IT will be all about reducing the burden for customers. As security incidents continue to gain more visibility with businesses and their boards, I predict that the dividing line between MSPs and MSSPs will blur. MSPs who are looking to expand their ability to help customers are likely to expand into security.

Also, a backup is only as good as the business’ ability to recover. So, the opportunity isn’t around “SaaS backups,” but around SaaS recovery.

MSPs looking to expand their “data loss” offerings in 2025 should focus more on business continuity. The real value to customers is gained by examining the threats that might disrupt their operations, including their SaaS tools, and providing a fast, reliable path to recovery.”

Terry Hedden

Hedden is the CEO of Marketopia.

“I believe the Managed IT Industry will continue the transformation it began in 2024. Security risks are becoming more complex. MSPs will elevate the services they offer far beyond user support to become both providers of very robust security.  I also see increased regulation and industry requirements that MSPs will be required to provide. The market opportunity for businesses in general is great in 2025. That means a very bright future for MSPs that are able to demonstrate value and increase income and profit as a result.”

J.J. Kardwell

Kardwellis the CEO of Vultr.

“In 2025, agentic AI will leap from imaginary to necessary, quickly redefining enterprise automation. Self-directed AI applications will allow organizations to make real-time, data-driven decisions, particularly in sectors already making use of sovereign and private clouds. Expect early enterprise-level adopters to crop up in places where CapEx isn’t an issue, deploying high-performance GPU and CPU clusters for mission-critical applications. Simultaneously, lighter agentic AI solutions will flourish through alternative cloud providers, enabling serverless inference at the edge, slashing costs and complexity.

By outsourcing infrastructure management, businesses will be able to focus on optimizing the AI application layer, unlocking unparalleled productivity and customer engagement. To support the massive scale of AI inference required, organizations will increasingly deploy specialized models paired with vector databases and RAG at edge locations. This edge-focused architecture will deliver the ultra-low latency needed for AI agents to effectively support the volume of AI interactions needed for agentic AI at scale.”

Denny LeCompteDenny LeCompte of Portnox

LeCompte is the CEO of Portnox Security.

“There will be an even greater financial opportunity for MSPs to offer SaaS data backups in 2025. As organizations increasingly migrate to cloud-native solutions, the need for comprehensive data protection has never been higher. MSPs can capitalize on this demand by providing reliable SaaS backup services, thereby expanding their service portfolio and generating new revenue streams. By addressing a critical need, MSPs can enhance their value proposition and strengthen customer relationships.”

Dror Liwer

Liwer is the co-founder of Coro.

“In 2025, AI can either be a powerful ally or an unseen double agent. On one hand, it will help MSPs and their clients boost productivity; on the other, it introduces significant risks. In the rush to improve efficiency, security often takes a back seat, and sharing sensitive data with AI tools can result in severe consequences.

In addition, expect more AI-driven attacks as hackers further experiment with the technology and become more clever in their social engineering. For example, phishing emails are getting alarmingly good at mimicking people’s tone and even referencing past conversations. The usual security training is not cutting it anymore and MSPs will need to lean on advanced tooling like email address cross checking and behavioral tracking to plug those gaps. For SMBs, having an MSP who can stay ahead of these attacks will be a game-changer.”

Gary Pica

Pica is the president of TruMethods, a Kaseya company.

“Managed service providers (MSPs) are taking a more strategic role with their small to medium-sized business (SMB) customers as they invest more in technology and security. Lowering costs, adding value, and becoming more efficient is the top priority of every MSP. Automation and AI will play a critical role in this phase of the MSPs’ journey.

SMB decision-makers are now more educated about what a comprehensive IT and security offering looks like. For this reason, a more complete, automated solution will be more important than ever, and MSPs will need to be ready to offer it to their customers.”

Manny Rivelo

Manny Rivelo is the CEO of ConnectWise.

“The cybersecurity landscape is evolving rapidly, driven by technological advancements and increasingly sophisticated threats. This is pushing Managed Service Providers (MSPs) and Technology Solution Providers (TSPs) to adapt quickly. To stay secure in today’s digital world, businesses must simplify their infrastructure and operations. Looking ahead to 2025, there will be an intensified focus on cybersecurity and data protection from both MSPs and their SMB clients, with a growing emphasis on integrating innovative solutions into existing technology ecosystems.

Technologies like hyperautomation and AI will be key in transforming how services are delivered and managed. These advancements will enable MSPs to automate routine tasks, enhance operational efficiency, and strengthen their cybersecurity posture. As businesses prepare for the future, their priorities will include product innovation, improving the partner experience, and helping partners succeed in an AI-driven market. By leveraging AI tools and hyperautomation platforms, MSPs and TSPs can simplify operations, improve user experience, and provide stronger support. These innovations will not only drive operational efficiency but also offer more integrated, robust solutions, ensuring that providers are well-equipped to navigate the challenges of a rapidly changing business environment.”

Manny Rivelo

Manny Rivelo is the CEO of ConnectWise.

“The cybersecurity landscape is evolving rapidly, driven by technological advancements and increasingly sophisticated threats. This is pushing Managed Service Providers (MSPs) and Technology Solution Providers (TSPs) to adapt quickly. To stay secure in today’s digital world, businesses must simplify their infrastructure and operations. Looking ahead to 2025, there will be an intensified focus on cybersecurity and data protection from both MSPs and their SMB clients, with a growing emphasis on integrating innovative solutions into existing technology ecosystems.

Technologies like hyperautomation and AI will be key in transforming how services are delivered and managed. These advancements will enable MSPs to automate routine tasks, enhance operational efficiency, and strengthen their cybersecurity posture. As businesses prepare for the future, their priorities will include product innovation, improving the partner experience, and helping partners succeed in an AI-driven market. By leveraging AI tools and hyperautomation platforms, MSPs and TSPs can simplify operations, improve user experience, and provide stronger support. These innovations will not only drive operational efficiency but also offer more integrated, robust solutions, ensuring that providers are well-equipped to navigate the challenges of a rapidly changing business environment.”

Anton Shipulin

Shipulin is industrial cybersecurity evangelist for Nozomi Networks.

“In the coming months, we are likely to see an increase in AI/ML-enabled cyberattacks targeting critical infrastructure and new attacks on AI/ML-based OT/IoT cyber-physical systems. Smart city projects, particularly entertainment and sports facilities are increasingly recognizing the importance of securing their cyber-physical systems. Often overlooked, systems like building management and other connected devices can both be final targets and serve as potential entry points for cyberattacks.”

 

Pravin Vazirani

Vazirani is assistant vice president of growth at Chetu.

“Data loss will continue to create havoc for businesses, often bringing its operations to a standstill. A Marriott data breach affected 300-500 million guests and cost the hotel chain more than $23 million in fines, not including the damage it did to Marriott’s reputation.

Managed Service Providers can create a steady revenue stream by offering SaaS backups. MSPs can develop proprietary SaaS backup systems or partner with various SaaS backup applications. Whichever path MSPs take, the backup systems must protect the applications their clients use, host the data in reliable data centers with proven uptime guarantees, and provide comprehensive recovery features.”

 

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How NAC Should Fit Into Your Larger Security Monitoring Strategy

If your organization takes security monitoring seriously, you’re likely drowning in dashboards, logs, and alerts from SIEMs, EDRs, SOAR platforms, and enough threat intelligence feeds to make your head spin. But amidst all the buzz about real-time monitoring, anomaly detection, and automated response, there’s often a glaring blind spot: Network Access Control (NAC).

Yes, NAC—arguably one of the least flashy but most foundational security tools—is often overlooked in security monitoring discussions. But if you’re not integrating NAC into your security monitoring strategy, you’re leaving gaps in your visibility, increasing your attack surface, and making it harder to respond to threats in real time.

So, let’s talk about where NAC fits into a well-rounded security monitoring strategy and why ignoring it is a mistake your SOC (Security Operations Center) can’t afford.

The Role of NAC in Security Monitoring

At its core, NAC enforces security policies by controlling which devices and users can connect to your network. But in doing so, it generates a wealth of valuable data that should feed into your broader security monitoring ecosystem.

Here’s what NAC brings to the table:

  • Real-time visibility into device connections: Every device that attempts to access your network—whether a corporate laptop, a rogue IoT device, or an attacker’s foothold—gets logged by NAC. This visibility is essential for identifying unauthorized or suspicious devices before they become a problem.
  • Policy enforcement and automated responses: NAC doesn’t just alert you to security issues; it acts on them. When a device fails compliance checks (e.g., missing security patches, outdated AV, unrecognized MAC address), NAC can quarantine or block it automatically, reducing the time attackers have to move laterally.
  • Contextual data for security investigations: When correlating data from a SIEM or SOAR platform, NAC logs can provide context on whether a user’s device was compliant, where it connected from, and whether access was granted or denied. This is crucial for incident response.

Now, let’s look at how NAC should integrate into your broader security monitoring strategy.

1. Feeding NAC Data into SIEMs for Comprehensive Monitoring

Most organizations rely on a Security Information and Event Management (SIEM) solution to centralize security logs, detect anomalies, and trigger alerts. Yet, many fail to include NAC data in this process.

Why it matters:

  • SIEMs thrive on correlation—NAC provides essential data on who’s connecting, from where, and whether they passed security checks.
  • If a user’s account triggers a login from an unusual location in the IAM logs, NAC can confirm whether their device was present on the corporate network or using a VPN.
  • NAC logs can identify when devices that were previously blocked attempt to reconnect, potentially signaling an insider threat or an attacker persistently probing for access.

How to integrate NAC with your SIEM:

  • Send NAC logs and alerts to your SIEM in real time.
  • Correlate NAC data with firewall logs, endpoint detection and response (EDR) tools, and authentication data.
  • Use NAC policies as an early indicator of device compliance issues before they escalate into security incidents.

2. Using NAC as a First Line of Defense in Zero Trust Architectures

Zero Trust isn’t just a buzzword—it’s a necessary shift in security strategy. NAC plays a crucial role by ensuring that only authorized, compliant devices gain access to the network in the first place.

How NAC fits into a Zero Trust strategy:

  • Continuous verification: NAC doesn’t just check compliance at login; it continuously enforces security policies. If a device falls out of compliance (e.g., a user disables their endpoint protection), NAC can revoke access immediately.
  • Least-privilege access: Combining NAC with microsegmentation ensures that even if an attacker compromises a device, lateral movement is restricted.
  • Dynamic risk-based access: Integrating NAC with identity providers (e.g., Entra ID, Okta) and security monitoring tools enables adaptive access controls based on risk signals.

By ensuring that every device accessing your network is continuously assessed, NAC strengthens the foundation of Zero Trust security monitoring.

3. Automating Incident Response with NAC and SOAR

Security teams are overwhelmed with alerts, making automation a must. NAC, when integrated with a Security Orchestration, Automation, and Response (SOAR) platform, can act as an automated containment mechanism for threats detected elsewhere.

Example use cases:

  • If an EDR detects malware on a device, SOAR can trigger a NAC policy to isolate that endpoint from the network.
  • If an unusual login attempt is flagged by an IAM system, SOAR can use NAC to block the user’s device until security reviews the case.
  • If a SIEM detects multiple failed login attempts from an unknown device, NAC can automatically deny access and flag the security team for investigation.

With SOAR integration, NAC isn’t just enforcing access controls—it’s actively participating in threat containment.

4. Strengthening Security for IoT and Unmanaged Devices

IoT security remains a nightmare for enterprises. These devices often lack traditional endpoint security controls, making NAC one of the few tools capable of providing visibility and enforcement for them.

What NAC can do for IoT security:

  • Fingerprint and classify devices to detect unauthorized or rogue IoT devices.
  • Segment IoT devices to prevent them from accessing sensitive corporate resources.
  • Trigger alerts and block anomalous behavior—for instance, if a smart thermostat suddenly starts trying to communicate with external servers in Russia.

By integrating NAC data into security monitoring platforms, you can detect and mitigate IoT threats in real time.

Final Thoughts: NAC as a Security Monitoring Force Multiplier

If you’re only using NAC as a compliance checkbox, you’re missing out. In the right hands—and integrated with SIEM, SOAR, Zero Trust, and IoT security frameworks—NAC becomes a force multiplier for security monitoring.

Instead of viewing NAC as a standalone gatekeeper, think of it as a real-time security enforcer that feeds critical data into your broader threat detection and response strategy.

A well-integrated NAC strategy doesn’t just keep attackers out—it actively helps your security team detect, investigate, and respond to threats faster and more effectively. And in today’s landscape, where speed is everything, that’s not something you can afford to ignore.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How CISOs Can Implement Effective Crisis Simulations: A Strategic Guide

It’s not a matter of if a crisis will happen but when. Whether it’s a ransomware attack, a massive data breach, or an insider threat gone rogue, the best defense is a well-practiced offense. That’s where crisis simulations come in.

CISOs who want to ensure their organizations are prepared for the inevitable must go beyond basic tabletop exercises and create realistic, high-pressure simulations that truly test their teams’ readiness. But how do you build an effective crisis simulation? What are the key roles that need to be involved? And how do you measure its success?

Let’s break it down.

Key Considerations for Crisis Simulations

Before jumping into running a crisis simulation, CISOs must consider several factors to ensure the exercise is meaningful and impactful.

1. Define Your Objectives

Not all crisis simulations are created equal. Some aim to test incident response speed, while others focus on communication breakdowns or decision-making under pressure. Clearly defining the goals of your simulation will guide its design and ensure participants extract valuable lessons from the exercise.

Some common objectives include:

  • Identifying gaps in incident response plans
  • Evaluating the effectiveness of security controls
  • Improving interdepartmental coordination
  • Strengthening executive decision-making under stress

2. Choose the Right Type of Crisis Scenario

CISOs should tailor the crisis scenario to their organization’s risk profile. A fintech company may prioritize a financial fraud attack, while a healthcare provider might focus on ransomware locking up patient records.

Popular types of crisis scenarios include:

  • Ransomware Attack – Simulating a situation where an attacker encrypts company data and demands a ransom.
  • Data Breach – Testing how the organization handles a leak of sensitive customer or employee data.
  • Insider Threat – Examining the impact of an employee with privileged access who intentionally or accidentally compromises security.
  • Cloud Service Disruption – Evaluating response when a critical third-party provider suffers an outage.
  • Social Engineering Attack – Assessing how well employees can detect and respond to phishing, smishing, or deepfake-enabled threats.

3. Simulate Real-World Pressures

One of the biggest pitfalls of crisis simulations is making them too easy. A real cyber crisis will be high-stakes, with confused teams, conflicting information, and time-sensitive decisions.

To create realistic pressure, consider:

  • Injecting misinformation to see how teams separate fact from fiction.
  • Simulating media or public relations pressure with mock journalist inquiries.
  • Testing executive decision-making with financial or regulatory consequences.
  • Limiting key resources (e.g., “your security lead is on vacation”).

4. Cross-Functional Involvement is Key

Cybersecurity is not just an IT problem—it’s a business problem. Crisis simulations should involve a cross-functional team that reflects real-world response dynamics.

Critical Roles Involved

For a comprehensive simulation, ensure the following key roles are represented:

1. Cybersecurity & IT Team

  • Security Operations Center (SOC) analysts
  • Incident response team
  • IT infrastructure and cloud security teams
  • Forensic investigators

2. Executive Leadership

  • CISO (Chief Information Security Officer)
  • CIO (Chief Information Officer)
  • CEO (if testing high-stakes decision-making)
  • Board members (for strategic-level simulations)

3. Legal & Compliance Team

  • General counsel or external legal advisors
  • Data protection officers
  • Compliance officers (GDPR, CCPA, PCI-DSS, etc.)

4. Public Relations & Communications

  • Media relations specialists
  • Internal communications team
  • Crisis PR consultants (if available)

5. Business Unit Representatives

  • Finance and operations teams
  • HR (for insider threat scenarios)
  • Customer support (if client data is impacted)

Different Approaches to Crisis Simulations

There are multiple ways to conduct crisis simulations, ranging from low-key discussions to full-blown cyber war games. Here are the most common approaches:

1. Tabletop Exercises (TTXs)

Tabletop exercises involve gathering key stakeholders in a conference room (or virtual call) to walk through a hypothetical crisis. Participants discuss how they would respond at each stage of the attack.

Pros:

  • Low cost and easy to set up
  • Ideal for leadership teams
  • Good for testing policies and communication plans

Cons:

  • Lacks real-world technical stress
  • Doesn’t test hands-on incident response skills

2. Live Incident Response Drills

This method involves a simulated attack on the company’s network to test the SOC, IT, and security teams’ ability to detect, contain, and mitigate threats in real-time.

Pros:

  • Provides a hands-on technical test
  • Identifies gaps in threat detection and response
  • Builds muscle memory for security teams

Cons:

  • Requires more time and resources
  • Can be disruptive if not planned properly

3. Red Team vs. Blue Team Exercises

A dedicated “red team” of ethical hackers attempts to compromise the organization’s defenses, while the “blue team” (internal security teams) defends against them.

Pros:

  • Mimics real-world adversarial behavior
  • Improves detection and response capabilities

Cons:

  • Requires skilled red teamers
  • Can create internal friction if teams take it personally

4. Full-Scale Cyber Wargames

In this high-intensity approach, multiple teams (security, legal, PR, executives) must respond to a simulated crisis over several hours or days, dealing with real-time injected challenges.

Pros:

  • Comprehensive stress test of incident response plan
  • Encourages interdepartmental collaboration

Cons:

  • Resource-intensive and complex to manage

Measuring the Effectiveness of Crisis Simulations

How do you know if your crisis simulation was a success? Here are some key metrics and evaluation techniques:

1. Response Time Metrics

  • Time to detect and escalate the incident
  • Time to contain the threat
  • Time to restore normal operations

2. Communication Effectiveness

  • How well teams coordinated their response
  • Accuracy and speed of internal and external messaging
  • Effectiveness of executive decision-making under pressure

3. Policy & Process Gaps

  • Did teams follow the incident response plan?
  • Were there any gaps in escalation procedures?
  • Were legal and compliance requirements met?

4. Post-Mortem & Lessons Learned

Conduct a structured post-mortem meeting to:

  • Identify what went well and what failed.
  • Document gaps in security controls.
  • Update incident response plans accordingly.

Final Thoughts

Crisis simulations are one of the most powerful tools in a CISO’s arsenal. When done correctly, they expose weaknesses before an actual attack does, ensuring that both technical teams and business leaders are ready to handle high-stakes incidents.

By taking a structured approach—defining clear objectives, involving the right stakeholders, using realistic stressors, and continuously improving based on lessons learned—CISOs can turn crisis simulations from a check-the-box exercise into a critical pillar of their organization’s cyber resilience strategy.

So, are you ready to put your organization’s crisis response to the test?

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Portnox Awarded 2025 TMCnet Zero Trust Security Excellence Award

Portnox Honored for Offering Exceptional Unified Access Control Solutions that Fortify Zero Trust Security Strategies

 

Austin, TX – Jan. 30, 2025—Portnox, a leading provider of cloud-native, zero trust access control solutions, announced today that TMC has named Portnox as a 2025 TMCnet Zero Trust Security Excellence winner.

The award recognizes the leaders and pioneers in the industry with the best and the brightest providers, offering the most innovative, effective solutions leveraging zero trust principles and strategies. Judged by the editors of TMCnet, each winner submitted a thorough application, nominating the selected solution.

“We are thrilled to be recognized by TMCnet for our commitment to advancing zero trust security solutions,” said Denny LeCompte, CEO of Portnox. “This award underscores our mission to make zero trust accessible and manageable for organizations of all sizes. With the Portnox Cloud, we’ve focused on delivering a solution that is not only effective and innovative but also simple to deploy and maintain, empowering IT teams to stay ahead of increasingly sophisticated access-related security threats without unnecessary complexity.”

The Portnox Cloud delivers the best value in cyber security today, enabling companies to enforce passwordless zero trust security through unified access control, risk mitigation, and compliance enforcement across their entire IT environment – no matter how distributed or complex it may be. But that’s not all – easy deployment and scalability paired with no maintenance make Portnox headache-free, freeing up your IT security team to tackle other priorities.

The Portnox Cloud supports several key tenants of zero trust:

  • Unified: Control access to your network, applications, and infrastructure – all under one roof.
  • Cloud-Native: The Portnox Cloud is fully cloud-native, making it easy to scale and manage with no on-prem components.
  • Vendor Agnostic: Apply access controls across any networking hardware or applications in use.
  • Maintenance-Free: Never lose sleep over upgrades, patches, or costly maintenance ever again.

“It gives me great pleasure to honor the recipients of the TMCnet Zero Trust Security Excellence Award,” said Rich Tehrani, CEO, TMC. “The award recognizes solutions providers championing the ‘Trust nothing, verify everything’ mantra of a Zero Trust approach to security at a time when businesses are facing more complex and frequent threats than ever. The TMCnet Team is thoroughly impressed and congratulates the recipients.”

The 2024 TMCnet Zero Trust Security Excellence Award winners were recognized on TMCnet news portal.

 

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Throwback to the Target Hack: How It Happened, and Lessons Learned….We Learned Lessons, Right?

The December 2013 Target hack remains one of the most infamous data breaches in cybersecurity history.  The hackers stole 40 million credit card numbers, got the PII (Personal Identifiable Information) of 70 million people, cost Target upwards of $200 million, and ruined Christmas for probably every single person working in Target’s IT department.  The breach not only tarnished Target’s reputation but also impacted several other sectors, highlighting the ripple effects of large-scale cyberattacks. Financial institutions faced increased costs for reissuing millions of compromised cards, while consumers dealt with heightened anxiety over identity theft and fraud. The breach also served as a wake-up call for retailers and businesses worldwide, prompting many to reevaluate their cybersecurity practices and adopt more robust systems to safeguard sensitive data. Ultimately, it underscored the critical importance of proactive cybersecurity measures in an increasingly interconnected world.

What the Hack Happened

The breach began when attackers targeted a third-party vendor that had legitimate access to Target’s network. The vendor, Fazio Mechanical Services, was a Pennsylvania-based HVAC (heating, ventilation, and air conditioning) company that provided maintenance services to Target.

Attackers sent a phishing email to Fazio employees, and one unfortunate soul fell for it. That’s a point that deserves some emphasis – it only takes one person, one click, in one unguarded moment, to give the bad actors a way in.  

The laptop was protected with the free version of Malwarebytes – an excellent tool that scans for and eliminates malware when initiated by the user.  The version you pay for – that actually gets appropriately licensed for corporate use – has a real-time scanner that probably would have caught the issue, because the malware installed, called Citadel, was pretty well-known.

Network Infiltration

Using the stolen credentials from Fazio Mechanical Services, the attackers got access to a Target-hosted web service dedicated to outside vendors.  They uploaded a file that allowed them to install a web shell to execute commands on the hosting server.  Some call this a vulnerability, but there are lots of legitimate reasons a web application would let you upload files – invoices, for example – and while it should ideally block executables, it’s easy enough to disguise them. 

 They used a Pass-the-Hash attack to get domain admin credentials, and then the network was their playground.  They went looking for database servers, and they found them – to the tune of 70 million records of PII (Personally Identifiable Information.)

But here’s a fun fact – know what those databases did not contain?  Credit card numbers!  Because Target’s data was PCI-DSS compliant, there was no financial info stored on their database servers.  

Deployment of Malware & Exfiltration of Data

Having been foiled in their scheme by Target’s PCI-DSS compliance, the hackers moved on to plan B (or what might have been plan A all along, we don’t really know) – infiltrate the PoS (Point-of-Sale) servers and capture credit card data in real-time.  They did this using malware called Kaptoxa, which would scrape the machine’s memory and store anything that looked like a credit card number in a file. Then, the malware would periodically transfer that file to another server, which would transfer it back to the hackers via FTP.  

If you’ve been following along so far, one thing that may have stuck out to you was how the attackers were able to wander through the network, accessing pretty much whatever they pleased.  This is why standard security procedures – like role-based access control and network segmentation, are so important.  

Note: There’s a very thorough deep-dive about the hack here, including all of the tools, protocols, and technology used if you want to geek out.

Target’s Security Posture Before the Breach

You might think that Target had pretty poor security before the breach, but that was surprisingly (and alarmingly) not true.  They had a security team of over 300 employees and had just invested in the well-known security tool FireEye.  This tool actually did send out alerts about the malware, which the security team forwarded on to the operations team….but no one did anything about them.  Not only that, FireEye has a setting that can automatically remove Malware….and they turned it off. The thought was they wanted a human to make decisions about what to remove vs. automated software.  

Lessons Learned

So what are the lessons we can take away from Target?  Let’s review:

Lesson 1: Security can be expensive – but not nearly as expensive as a breach.

Lesson 2: Assume every device outside your organization is compromised, because eventually one will be.

Lesson 3: Regulatory compliance might be difficult, but it is often worth it.

Lesson 3: Pay attention to the security basics.  Role-based access control, least-privileged access and network segmentation are not new concepts, but they are invaluable to minimize damage.  

Lesson 4: Your security tools are essential; invest in them and tailor them to work for you.  Automation is there to make your life easier.  

We’re going on 12 years since this hack happened, and it still serves as a powerful reminder of the critical importance of cybersecurity in today’s digital age.  The Target breach underscored how even a single weak link in a company’s supply chain can have catastrophic consequences, impacting not only the business but also millions of customers. It also paved the way for stricter industry regulations and greater emphasis on safeguarding sensitive data. As cyber threats continue to evolve, the lessons from this breach remain especially relevant.  

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.