Skip to content

Unpacking the Okta Data Breach

Unpacking the Okta Data Breach: How It Happened

In recent years, the increasing frequency of data breaches has raised concerns among businesses and consumers alike. The Okta data breach serves as a stark reminder of these vulnerabilities, especially considering that in 2024, the average total cost of a data breach in the United States reached a staggering $9.36 million. This incident not only highlights the financial implications of such security failures but also underscores the importance of timely detection. With an average of 194 days taken globally to identify a data breach in 2024, which is a slight improvement from 2023, , organizations must prioritize their security measures to mitigate risks and protect sensitive information.

Who is Okta?

Founded in 2009, Okta is an identity and access management company. It was a forerunner of single sign-on, and many companies adopted the Okta portal to reduce the number of passwords users have to deal with. Okta also provides API access management, MFA, and other IAM solutions.  

Discovery of the Breach

The Okta data breach started when an employee’s Gmail account was compromised.  They had logged into their personal Gmail on their work laptop and also saved their work credentials in Chrome.  The compromise led to malware being installed on the laptop, which was used to gain access to Okta’s support system.  The hackers targeted the unsanitized HAR files submitted by Okta’s customers during the normal troubleshooting process.  The hackers then went to these companies and tried to breach their systems, largely without success. 

It was 1Password, an Okta customer, that first alerted Okta of suspicious activity that they suspected had originated with Okta in late September of 2023.  Okta suspected that 1Password had been the victim of a phishing attack and dismissed the claim.  

A few days later, on October 2nd, BeyondTrust uploaded a HAR file to Okta support while working on an issue.  A HAR file is a log of a web browser’s interaction with a website and is useful for diagnosing performance and other issues. Within 30 minutes, they saw an attacker attempt to breach the BeyondTrust Okta environment using a valid session cookie.  Thankfully, they had authentication policies in place that only allowed trusted users on trusted devices to access their Okta environment.

On October 17th, using the information provided by BeyondTrust, Okta pinpointed a service account with unusual activity that had previously gone unnoticed.  The service account and all associated sessions were terminated.  

On October 19th, Okta notified 1Password, Cloudflare, BeyondTrust, and a couple of others that they had been impacted by a data breach. At this time, Okta believed these were the only customers impacted.  

Finally, in December 2023, the full scope of the breach was revealed. The hackers gained access to the files of 134 different customers and also downloaded a report listing the names and e-mail addresses of all customers who had used Okta support. These were used to launch phishing and other targeted attacks against the companies who had the bad luck to have needed Okta’s support.  

What next?

After notifying the impacted customers and the appropriate regulators, Okta set to work. As an identity provider, transparency and thoroughness were the only hope of regaining customer trust. 

  1. Independent Forensic Investigation: Okta engaged Stroz Friedberg, a leading cybersecurity forensics firm, to conduct an independent investigation, which confirmed the company’s initial findings and identified no further malicious activity.
  2. Security Enhancements: In response to the breach, Okta implemented several security improvements, including:
    • Zero Standing Privileges for Administrators: Ensuring administrative roles are assigned only when necessary and for limited durations.
    • Multi-Factor Authentication (MFA) for Critical Actions: Requiring additional authentication steps for high-impact administrative tasks.
    • Enhanced Session Security: Implementing measures to detect and block requests from anonymizers and applying IP binding to Okta products and the Admin Console.
    • Restricting API Access: Enforcing allowlisted network zones for APIs to prevent unauthorized access. 

Oka deserves credit for being forthright with how the breach happened and what steps they took to prevent it from happening again.  While Monday morning quarterbacking always takes place after a major breach, there are plenty of large organizations that had – undoubtedly still have – similar (or worse!) Holes in their security posture.  

A Better Way Forward

Some of the remedial actions taken highlight a critical problem that security measures often face – security comes at the expense of the user experience.  It makes sense to session-limit administrators, and enabling MFA ensures that a compromised password will not result in widespread access, but one can imagine the poor Okta admins constantly having to reauthenticate and fumbling for their phones to accept a push notification or find a one-time passcode a million times over the course of a single work day.  Besides the massive inconvenience this poses, it isn’t really addressing the real threat – after all, compromised credentials are the cause of over 80% of all data breaches.

Passwordless authentication is a rarity in that it is not only more secure but a significantly better user experience.  Rather than racing to get a push notification or waiting for a text message, the authentication process happens with no user intervention required.  Not only is this a win for users and security, but IT staff have far fewer password issues to deal with as well.  

An ounce of prevention is worth a pound of cure, as the saying goes, and while Okta set the standard for a clear, transparent post-breach response, the data breach itself serves as a reminder of the vulnerabilities inherent in traditional security methods.  Looking towards the future with passwordless authentication will stop the next breach before it happens (and let you put your phone down once in a while!)

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

What Drives Data Breach Costs?

What drives data breach costs?

The worldwide cost of a data breach in 2024 averages around $4.88 million, which is a 10% increase over 2023.  If you are unlucky enough to be a victim of ransomware, the cost is 10% higher, at$ 5.37 million. And if you’re in the United States, the average cost almost doubles to $9.36 million.  What exactly are you spending all this money on?  Let’s dive deeper into the costs of a data breach.

Where does it all go?

According to IBM, there are four key categories to spend money in post-breach:  

Detection and Escalation

Detection is about finding the breach (and determining the extent of it) as fast and ideally as early as possible.  When a data breach is detected, the first priority is to figure out what has been compromised, how far the hackers got in, and how to plug the hole.  Costs associated with this might include a new messaging system – communicating via your existing e-mail or instant messenger might tip the hackers off as to your plans, which will prevent you from being able to contain the damage.  You might need more robust network monitoring, firewalls, SIEM (security information and event management) systems, and more. 

Time is of the essence during the detection phase – the longer it takes, the more expensive it will be to unwind.  It takes around 194 days to find a data breach, with an additional 64 days to contain it – that’s a lot of time for a bad actor to have access to your systems.  The longer detection takes, the more expensive the breach is.  

Escalation begins the process of notifying internal stakeholders.  IT and any Security personnel are often the first to know.  It’s crucial to loop in customer-facing organizations like support and sales early in the process, as they are the first points of contact your customers will often make when reaching out to you.  You will want to have a statement crafted that can be sent out, which will likely involve marketing. 

Notification

Moving on from internally, next will be letting the world know – this will include regulators, customers, and the general public. Hiring a  PR firm to help craft a statement is a smart move, and you’ll surely want to retain legal counsel to make sure you don’t make your situation any worse.  Doing this in a timely manner is crucial so that you don’t run afoul of any regulations.  There are several laws in different countries that have time-bound requirements; for instance, GDPR requires notification within 72 hours of discovering a data breach.  In this stage your customers will have questions – probably a lot of questions – and it will be all hands on deck, not just for sales and support, but product and marketing as well.  Maintaining accurate, clear, and consistent communication with customers, the press, and regulators is of paramount importance.

Post-Breach Response

This is a crucial, make-it-or-break-it time for companies; after the initial announcement, there is likely a great deal of attention laser-focused on you, your business, your customers, and any other person or organization in your orbit. A good post-breach response will help restore lost confidence, and hopefully minimize the impact of lost business.  

An excellent example of a post-breach response comes from Okta.  When they were breached in 2023, although only less than 150 customers were impacted, their communication was transparent, forthright, and thoroughly detailed what they found and their next steps.  

Lost Business Cost

Inevitably, when you suffer a breach, you will lose some business.  Some customers will leave, some prospects will go dark, and some current customers will reduce the amount they spend.  While that’s inevitable, you will also suffer the loss of future plans – your roadmap, feature development, and all other work will grind to a halt as the data breach becomes a black hole that sucks all activity in, and everyone focuses on the other three areas we’ve covered.  Your UX team will become QA testers; your marketers will become support reps; and your customers will be clamoring for answers you may not have yet.  It will take a long time, with a lot of intense effort, to return to some semblance of normal.

Each of these efforts alone can run up costs in the millions of dollars; combined altogether it’s easy to see why breaches like Target run into the hundreds of millions of dollars.  Given that these costs are projected to continue to skyrocket, and you probably have many other things to spend $10 million dollars on, it’s worth it to invest in training and security tools to keep your organization safe.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

An In-Depth Look at Bumblebee Malware and Other Famous Cyber Attacks

Network administrators and engineers face an ongoing battle against a myriad of threats. Among these, Bumblebee malware has emerged as a notable adversary. This blog post delves into the specifics of Bumblebee malware, along with an exploration of other famous cyber attacks that have left indelible marks on the digital world. From malware that locks you out of your system to the scariest computer viruses, understanding these threats is vital for safeguarding your network infrastructure. 

What is Bumblebee Malware?

Bumblebee malware is a sophisticated cyber threat characterized by its stealth and complexity. This malware is particularly notorious for its association with EXOTIC LILY, a threat actor group known for its aggressive and widespread email campaigns. At the height of their activity, EXOTIC LILY was dispatching over 5,000 emails daily to approximately 650 organizations worldwide. Such prolific email distribution highlights the group’s persistence and the potential reach of Bumblebee malware.

Bumblebee is primarily used as a delivery mechanism for more dangerous payloads. Once it infiltrates a system, it can download and execute additional malicious software, making it a potent threat. This capability to act as a precursor to more severe attacks is what makes Bumblebee particularly dangerous. It can serve as a gateway for other types of malware, such as ransomware or data-stealing Trojans, further compromising an already vulnerable system.

The multi-stage nature of Bumblebee malware means that its initial footprint on a network might appear benign or easily overlooked. This ability to evade early detection is part of what makes it so challenging to combat. Network administrators might not realize their systems have been compromised until the secondary, more damaging payloads have already been deployed.

What sets Bumblebee apart from other types of malware is its use of advanced evasion techniques. For instance, it can use process injection to run its code within legitimate system processes, thereby avoiding detection by traditional security tools. Additionally, Bumblebee often employs encrypted communication channels to exfiltrate data and communicate with its command-and-control servers, making it harder for security teams to monitor and block its activities.

The malware’s adaptability also poses a significant challenge. Bumblebee can be customized by threat actors to fit their specific needs, whether that involves targeting particular industries, geographic regions, or even individual organizations. This level of customization makes it a versatile tool in the arsenal of cybercriminals, capable of evolving to bypass new security measures and exploit emerging vulnerabilities.

Overall, Bumblebee malware represents a significant and multifaceted threat. Its ability to act as a delivery system for more dangerous payloads, combined with advanced evasion techniques and adaptability, makes it a formidable adversary in the cybersecurity landscape.

What is the Most Famous Malware Attack?

One of the most notorious malware attacks in recent history is the WannaCry ransomware attack that struck in May 2017. Exploiting a vulnerability in the Windows operating system, WannaCry rapidly spread to over 200,000 computers in more than 150 countries. This cyber attack did not discriminate, affecting both individual users and large organizations alike.

The damage caused by WannaCry was particularly severe in sectors like healthcare, where the ransomware forced hospitals and clinics to cancel appointments, delay treatments, and divert emergency services. The British National Health Service (NHS) was one of the hardest hit, with many of its systems rendered inoperable. This attack underscored the potentially life-threatening consequences of ransomware on critical infrastructure.

WannaCry’s success can be attributed to its use of a sophisticated exploit known as EternalBlue, which was developed by the U.S. National Security Agency (NSA) and later leaked by the hacker group Shadow Brokers. EternalBlue targeted a vulnerability in the Server Message Block (SMB) protocol in Windows, allowing WannaCry to propagate quickly across networks without user intervention. This made it exceptionally difficult to contain once it had infiltrated a system.

The financial impact of WannaCry was also staggering. While the ransom demands were typically set at $300 worth of Bitcoin, the overall economic damage, including the cost of downtime, loss of data, and recovery efforts, ran into billions of dollars. The attack demonstrated the high stakes involved in cybersecurity and the far-reaching effects of even a single vulnerability being exploited.

In response to the WannaCry attack, Microsoft released emergency patches for older, unsupported versions of Windows, highlighting the importance of regular software updates and patch management. Many organizations that were hit hardest by WannaCry had failed to apply existing patches that could have protected them against the exploit used by the ransomware.

The WannaCry incident served as a wake-up call for the global community, emphasizing the need for robust cybersecurity measures and proactive threat management. It also raised awareness about the importance of collaborative efforts between private companies, government agencies, and international bodies to combat the growing threat of cyber attacks. The lessons learned from WannaCry continue to shape cybersecurity strategies and policies to this day, making it a pivotal moment in the ongoing battle against malware.

What is the Malware that Locks You Out?

Ransomware is a prevalent and highly disruptive type of malware designed to lock users out of their systems by encrypting their files. One of the most notorious examples of ransomware is CryptoLocker. First detected in 2013, CryptoLocker spread primarily through email attachments disguised as legitimate files. Once the user opened the infected attachment, the malware would quickly encrypt the user’s files and demand a ransom, typically in Bitcoin, for the decryption key.

CryptoLocker stood out because of its use of strong encryption methods, which made it nearly impossible for victims to retrieve their files without paying the ransom. The malware targeted a wide array of file types, ensuring that critical documents, photos, and other important files were rendered inaccessible. This ransomware attack highlighted the crucial importance of maintaining regular data backups. Without an up-to-date backup, victims faced the grim choice of either paying the ransom or losing their files forever.

The impact of CryptoLocker was felt globally, affecting both individual users and businesses. The malware’s rapid spread was facilitated by its use of sophisticated social engineering tactics, such as crafting convincing emails that appeared to come from trusted sources. This led to a high infection rate, as users were tricked into opening the malicious attachments.

The success of CryptoLocker spurred the development of many copycat ransomware variants, each with their own unique features and enhancements. These subsequent strains often employed similar encryption techniques and ransom demands, but with varying levels of sophistication and additional evasion tactics to avoid detection by security tools.

To combat the threat of ransomware like CryptoLocker, organizations have had to adopt a multi-layered approach to cybersecurity. This includes implementing advanced email filtering solutions to block phishing emails, educating users about the dangers of unsolicited email attachments, and employing robust endpoint protection solutions to detect and prevent ransomware infections. Additionally, regular data backups and a comprehensive incident response plan are critical components of a strong defense against ransomware attacks.

While law enforcement agencies and cybersecurity firms have made strides in disrupting ransomware operations and recovering stolen funds, the threat remains ever-present. New variants continue to emerge, and threat actors are constantly evolving their tactics to bypass existing security measures. As a result, vigilance and continuous improvement of cybersecurity practices are essential in the ongoing battle against ransomware.

What is the Scariest Computer Virus?

When it comes to computer viruses that have instilled the most fear, the ILOVEYOU virus often tops the list. First discovered in May 2000, this virus spread like wildfire through email systems, masquerading as a love letter with the subject line “ILOVEYOU.” Its seemingly innocent appearance made it highly effective, as countless recipients were duped into opening the email and its malicious attachment. Once the attachment was opened, the ILOVEYOU virus unleashed its destructive capabilities.

It would overwrite various types of files, including important documents and multimedia files, rendering them useless. Additionally, it propagated itself by sending copies to all contacts in the infected user’s email address book. This rapid replication led to widespread infection in a remarkably short period, affecting millions of computers worldwide. The economic impact of the ILOVEYOU virus was monumental. It caused an estimated $10 billion in damages, as businesses and individuals alike scrambled to contain the infection and recover lost data. Organizations were forced to shut down their email systems temporarily to prevent further spread, leading to significant operational disruptions. The virus highlighted the vulnerabilities inherent in digital communication systems and underscored the importance of robust email security measures.

What made the ILOVEYOU virus particularly frightening was its combination of social engineering and technical prowess. By exploiting human emotions and curiosity, it managed to bypass traditional security measures that were more focused on detecting purely technical threats. This dual approach set a precedent for future malware, which increasingly incorporated social engineering tactics to enhance their effectiveness. The legacy of the ILOVEYOU virus persists in the lessons it taught the cybersecurity community. It emphasized the critical need for user education in recognizing and avoiding phishing attempts. Additionally, it spurred advancements in email filtering technologies and the development of more comprehensive cybersecurity protocols. In the annals of cyber threats, the ILOVEYOU virus stands out not only for the sheer scale of its impact but also for the wake-up call it delivered to a world becoming increasingly reliant on digital communication.

How can You Protect Your Organization Against Bumblebee Malware?

To protect against Bumblebee malware attacks, organizations need a multi-layered security approach that focuses on prevention, detection, and response. First, robust email security measures are essential, as Bumblebee often spreads through phishing campaigns. Implementing advanced email filtering can help detect and block malicious attachments or links before they reach users’ inboxes. Additionally, employee training programs can raise awareness about phishing techniques and teach staff to recognize suspicious emails, further reducing the risk of accidental malware activation.

For endpoint protection, organizations should deploy solutions capable of identifying and isolating unusual behaviors, such as unauthorized process injections or encrypted communications that Bumblebee often uses to evade detection. Regularly updating software and applying security patches is also critical to prevent Bumblebee from exploiting known vulnerabilities. Finally, establishing an incident response plan that includes malware isolation and rapid mitigation steps can help limit the damage should a breach occur. Together, these proactive defenses create a formidable barrier against Bumblebee and other sophisticated threats.

Conclusion

from Bumblebee malware to infamous attacks like WannaCry and CryptoLocker, understanding these digital dangers is essential for network administrators and engineers. Each malware type covered here underscores unique vulnerabilities in digital infrastructure, while also revealing the critical need for robust security strategies. The enduring impact of these attacks reminds us of the importance of proactive defense measures, regular software updates, and user education to safeguard our systems. As cyber threats become more sophisticated, a vigilant and well-prepared approach is key to minimizing risk and ensuring resilience in the digital realm.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Portnox and Jamf Integration Delivers Agentless, Risk-Based Authentication for Networks, Applications & Infrastructure

Portnox unveils integration with leading mobile device management (MDM) solution to strengthen passwordless, risk-based authentication and access control offering.

 

Austin, TX – Nov. 12, 2024—Portnox, a leading provider of cloud-native, zero trust access control solutions, today announced its new Jamf integration, enabling admins to define robust risk policies for MacOS and iOS devices with or without an agent. With this integration, Portnox Cloud customers can now manage secure access for these devices by seamlessly integrating with one of the leading mobile device management (MDM) solutions, ultimately improving operational efficiency and reducing total cost of ownership across their access control suite.

With this latest advancement, Portnox supports all major device types and operating systems, giving admins a unified approach to securing network access. By eliminating the need for multiple agents, IT teams can save time, improve efficiency, and ensure a seamless user experience.

“With growing concerns about potential risks with installing third-party agents, organizations are increasingly seeking agentless security solutions,” said Denny LeCompte, CEO of Portnox. “Our Jamf integration marks a major milestone in enabling secure, passwordless, and risk-based access control for all devices, while removing the limitations traditionally associated with agentless approaches.”

Portnox Cloud is the industry’s leading cloud-native platform that combines passwordless authentication, zero trust access control, endpoint risk mitigation, and compliance enforcement for networks, applications, and infrastructure. The platform empowers organizations to strengthen their security posture, streamline risk management, and achieve compliance—all without compromising user experience or productivity. 

This integration underscores Portnox’s commitment to helping organizations on their Unified Access Control (UAC) journey, offering a holistic, future-proof solution that enhances security while simplifying IT operations.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Portnox Wins Top Infosec Innovator Award for Cutting Edge Network Access Control

Portnox Honored by Cyber Defense Magazine During Cyber Defense Con in Orlando

 

Austin, TX – Oct. 31, 2024—Portnox, a leading provider of cloud-native, zero trust access control solutions, today announced that it was named winner in the Cutting Edge Network Access Control category from Cyber Defense Magazine’s annual InfoSec Innovator Awards. Winners were announced today during CyberDefenseCon 2024 in Orlando, Florida.

According to a recent survey conducted with Wakefield Research of 200 U.S. CISOs at companies with a minimum annual revenue of $500m at the end of Q3 2024, 100% agree that Network Access Control (NAC) is a critical component of any Zero Trust framework. In addition, more than 4 in 5 CISOs are increasing their investment in NAC over the next year.

“We are honored to be recognized by Cyber Defense Magazine as a top innovator in the Network Access Control space,” said Denny LeCompte, CEO of Portnox. “This award is a testament to our team’s commitment to providing cutting-edge, cloud-native zero trust access control solutions that empower organizations to stay ahead of evolving cyber threats. As the demand for robust, scalable security grows, we remain focused on delivering solutions that help businesses of all sizes secure their networks, applications, and infrastructure with confidence and ease.”

“We scoured the globe looking for cybersecurity innovators that could make a huge difference and potentially help turn the tide against the exponential growth in cyber-crime. Portnox is worthy of being named a winner in these coveted awards and consideration for deployment in your environment,” said Yan Ross, Editor of Cyber Defense Magazine.

The full list of the Top InfoSec Innovators for 2024 is found here: https://cyberdefenseawards.com/top-infosec-innovators-for-2024/

Related:

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.