Skip to content

Best Practices for Proper Cloud Configuration

Through the digital transformation, now driven by the Covid-19 pandemic, we see a massive migration to decentralized, cloud-based models. And those who already use these models will further accelerate the migration to the cloud. According to Gartner, by 2021, more than half of global companies that already use Cloud will adopt a strategy in a 100%-Cloud environment.

Proper protection of this type of environment becomes a growing concern for Security teams and a business must. Thus, the risks associated with the lack of proper protection of the Cloud environment must be considered not only by the Security team but also by senior management, in order to ensure the organizations’ digital sovereignty over data, in addition to business continuity.

Learn more: Remote Work and Increased Usage of Cloud

Lacework researchers, for example, found more than 22,000 container orchestration dashboards and API management systems open on the internet. Among the applications Lacework has found during the research, we have Kubernetes, Mesos Marathon, Swagger API, Red Hat Openshift, and Portainer from Docker Swarm and Swarmpit. Also, according to the research, 95% of these dashboards and management systems were stored on Amazon Web Services (AWS). Although the vast majority of these interfaces have privileged credentials for access control, the researchers consider it an issue that these interfaces are exposed on the internet. This is because anyone with access to dashboards is able to perform tasks such as starting or stopping workloads, adding or removing applications, or even configuring security controls.

Against this background, it would be very easy for security teams to hand over responsibility for the cybersecurity aspect to CSPs (Cloud Service Providers). It is worth mentioning, however, that in distributed environments, organizations should not rely only on their cloud providers to ensure this protection. If the interfaces are not properly configured, the attack surface increases considerably, which brings a greater risk of cyberattacks to organizations’ infrastructure.

Also, new regulatory requirements, such as GDPR and LGPD, require adequate data protection, which can lead to heavy sanctions if not met. For organizations that treat personal data of European citizens, this figure can reach up to 50 million euros, or 50 million reais if the organization treats personal data of Brazilians and is subject to the LGPD, considering that the Brazilian legislation is already in force.

Some of the best practices that can be implemented by the Security teams to reinforce the organizations’ behavior when it comes to the security of Cloud environments and avoid data leaks include:

Having an understanding of their cloud environments

While ease and convenience bring together some of the biggest advantages of using services in a cloud environment, the implementation of workloads is not as trivial as it seems. The security team must commit itself to know all the configurations and permissions of its Cloud-based services, and thus leverage the maximum of the security features integrated with the contracted services. Even though it is an activity that requires extensive effort, it is necessary to ensure the security of the distributed environments.

Checking and configuring credentials and permissions

Organizations that are implementing Cloud approaches may find that using the default security settings is enough to prevent their workloads from being compromised. However, these settings are very basic or even non-existent. Given this, the recommendation is that those responsible for security in the Cloud environment constantly check credentials and permissions and ensure that access to workloads is limited to those who really need access, ensuring the implementation of the Principle of Least Privilege. This can be achieved through a Privileged Access Management solution or PAM. Besides, the use of features such as Multifactor Authentication (MFA) ensures an additional layer of security to the environment immediately.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

TÜV Rheinland attends 14th Shanghai International Electric Vehicle Supply Equipment Fair

From August 26 to August 28, the 14th Shanghai International Electric Vehicle Supply Equipment Fair (EVSE) was held at the Shanghai New International Expo Center. TÜV Rheinland, an internationally independent third-party testing, inspection and certification organization, attended with a comprehensive display of its professional and one-stop service capability covering the upstream and downstream segments of the industry chain.

With the rapid implementation of the “New Infrastructure” strategy, the local subsidy for purchasing new energy vehicles is being gradually transferred to such segments as the construction and operation of charging infrastructure and the use and operation of new energy vehicles. In addition, electrification of buses and taxis, electrification of logistics transportation, and the increasing demand for charging services in the timeshare rental market will further promote the flourishing of the charging pile market.

The only company to win Golden Pile Award 2020 Excellent Brand of Testing and Certification Service for Charging Facility

On the morning of August 26, the Golden Pile Award 2020 Top 10 Charging Facility Brands Awarding Ceremony was held. The Golden Pile Award is an annual event recognizing development achievements in China’s charging technology. It aims to encourage outstanding enterprises to enhance technology innovation and improve product quality and service level, so as to promote the construction and development of China’s charging infrastructure. With leading technology and quality service in the testing and certification of charging equipment, TÜV Rheinland was awarded the 2020 Excellent Brand of Testing and Certification Service for Charging Facility, and is the only testing and certification organization to have won the award.

As a global leading technology service provider, TÜV Rheinland has rich experience of nearly 10 years in the field of charging and swapping systems. It can provide product testing and certification for charging piles, charging stations, pantographs, swapping stations, charging cables, charging connectors, and related parts. It can also provide audits and technology assessments for charging and swapping systems and provide automobile companies and charging operation service providers with comprehensive localization services, including charging pile installer training, operator qualification audits, and field installation audits.

During the EVSE, TÜV Rheinland issued corresponding product certificates to more than ten charging equipment enterprises, and signed cooperation agreements with numerous companies, comprehensively demonstrating its technology advantage and service capability covering the entire industry chain.

Safety assessment regulations project for HPC equipment liquid cooling systems launched

For a long time, range and charging time have been two key factors restricting the development of new energy vehicles. With range now increasing, battery capacity needs to be increased accordingly, and charging time will also become longer. In order to make new energy vehicles more practical and convenient, high power charging (HPC) is an effective way to reduce charging time, but this also puts the charging system at risk of overheating. Therefore, a liquid cooling system has been adopted for HPC products, with a special circulation channel set in the cable and charging connector and liquid coolant added in. A power pump pushes the liquid circulation and achieves heat dissipation, and simultaneously cools the charging connector and the direct current pin in the vehicle inlet. Built-in temperature sensors measure system temperature in real time. By evaluating the temperature-rise data, a control unit can effect timely adjustment of the operating parameters of the liquid cooling system, thereby solving the heat dissipation problem and ensuring the safe and stable operation of the charging system.

At the EVSE, TÜV Rheinland and 20 upstream and downstream companies focused on HPC technology gathered to launch a safety assessment regulations project for HPC equipment liquid cooling systems, giving full play to their respective advantages and joining hands to promote the establishment of system safety assessment regulations. The 20 companies are as follows: ABB Chargedot, Aptiv, Amphenol (Zhuhai), OMG, Haoli Technology, Jiangyin Zhongding, Kangni New Energy, Kunshan Hwatek, Phoenix (Nanjing), Shanghai Huber+Suhner, Wanbang (Star Charge), Wuxi Xinhongye, EN-plus, EAST, Infypower, Far East Cable, Uchen New Energy, UUGreenPower, Zhengqi Machinery, and JONHON.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About TUV
The TÜV Rheinland is a leading provider of technical services worldwide. Since our foundation in 1872, we have been providing safe and sustainable solutions for the challenges arising from the interaction between man, the environment and technology.As an independent, neutral and professional organization, we are committed to working towards a future that can fulfil the needs of both mankind and the environment in the long term.

About The Microfibre Consortium (TMC)
Founded in November 2018, The Microfibre Consortium now has 40 members from across the outdoor sector, sports, high street, luxury fashion and home textiles, with a combined turnover of over €250 billion. TMC also has a rapidly growing network of research institutions and affiliates from around the world, supporting the consortium’s mission for increased global topic alignment collaboration and research to understand and reduce microfibre pollution.

ESET Endpoint Protection, Detection and Response solutions commended in KuppingerCole Market Compass

BRATISLAVA – August 19, 2020 – ESET, a global leader in cybersecurity, has been highly commended in the KuppingerCole Market Compass 2020 report. The report analyzed ESET’s Endpoint Protection, Detection and Response solutions, including ESET Endpoint Security and ESET Enterprise Inspector, praising ESET for its universal coverage.

KuppingerCole Analysts is an international and independent analyst organization that supports companies, corporate users, integrators and software manufacturers in meeting both tactical and strategic challenges. The Market Compass provides an overview of a market segment and the vendors in the Endpoint Protection, Detection & Response (EPDR) market. It covers the trends that are influencing this market segment and the essential capabilities required of solutions in this space and provides ratings on how well the solutions meet expectations. 

ESET achieved high scores across all categories, achieving the third highest number of strong positives out of a total 17 vendors, with top scores in six out of nine criteria and the rest being evaluated as positive. KuppingerCole assesses vendor solutions on nine key criteria – Security, Interoperability, Usability, Deployment, Malware Protection, Threat Hunting, Automated Responses, Secondary EPP and Common Functions – with strong positive as the highest possible rating.  

In addition to broad support for a variety of operating systems, KuppingerCole cites ESET’s rare technical capability of being able to scan the Unified Extensible Firmware Interface (UEFI) as a core strength. ESET is further commended for its complete suite of detection and protection techniques, and excellent implementation of multiple, advanced ML algorithms for discovering malicious activity patterns. As one of the very few vendors on the market, ESET leverages Windows AMSI, and provides a Script Scanner, Advanced Memory Scanner and Ransomware Shield. The report also highlights ESET’s contribution to mapping the MITRE ATT&CK framework in order to facilitate analysis of malicious actors. KuppingerCole also commend ESET Enterprise Inspector’s support of interactive live querying and memory analysis with automated response options like network isolation of suspect nodes, process termination, moving/deleting files and running scripts.  

ESET Enterprise Inspector, ESET’s own proprietary solution for targeted attacks and advanced persistent threats, was previously evaluated in the KuppingerCole Executive View Report 2020. The report highlights ESET’s practice of publishing threat intelligence discoveries for the benefit of the community, and the additional detailed security analysis and threat research gained from ESET’s powerful cloud-based reputation system, the global LiveGrid®. ESET Enterprise Inspector can also generate attribution theories with high confidence levels, with customers having flexibility in creating rules for detection thresholds and alerting, filtering out certain conditions that may occur so as to reduce false positives, or customers themselves can design rules for assignment of attributes and even edit event attributes during investigations.  

Ignacio Sbampato, Chief Business Officer at ESET, commented, “At ESET, we are dedicated to providing cutting-edge security solutions for businesses, and we are proud to be continually recognized by expert analysts for our advanced software solutions. The digital threat landscape is constantly evolving and adapting, and it is vital that organizations and their systems are adequately protected. Reports such as the KuppingerCole Market Compass are vital in holding us accountable to the high standards we set for our solutions, and our dedication to keeping enterprises and their data safe and secure around the world.”

To find out more about ESET’s Endpoint Detection and Response solution, click here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

訊連科技U會議推出6.2版更新 新增等候室、廣播文字訊息至分組討論室功能 會議管理和互動更全面

【2020年08月26日,台北訊】數位多媒體應用及AI人工智慧領導廠商訊連科技(5203.TW)宣布推出「U會議」之6.2版更新,提供全新「等候室」及分組討論時的廣播功能,可讓會議主持人更方便管控進入視訊會議之人員清單,與分組討論的進行。

訊連科技U會議推出6.2版更新 新增等候室、廣播文字訊息至分組討論室功能 會議管理和互動更全面

U會議於近期來陸續推出各式針對企業及教育單位設計之全新功能,大幅提升會議進行順暢度及互動性。U會議6.2版新增的「等候室」功能,所有與會者加入會議後,先於等候室等待,待會議主持人核准後,方可進入會議,讓主持人更有效率的掌握會議進行流程。

此外,針對教育機構「分組討論」的需求,U會議除了在日前增加分組討論功能外,更於本版新增了廣播功能,於分組討論進行中,會議主持人可廣播文字訊息至所有分組討論室,如宣布分組討論結束時間、或提醒討論重點等。

「訊連科技持續更新『U會議』和『U簡報』,提升會議掌控和互動體驗,為學校和企業用戶之視訊會議和線上教學,提供更安全且全面的管理和互動功能。」訊連科技黃肇雄執行長表示:「『U簡報』將於九月推出全新『直播與談』功能,可讓各式企業、機關及教育單位,於疫情期間,舉辦多方與談者參與的線上研討會。」

用戶可於近日起至U官方網站下載最新「U會議」6.2版,或透過程式內建的升級功能取得6.2版更新,體驗最新功能。

U會議6.2版新增功能

  • 新增「等候室」功能,與會者需等候會議主持人核准後,方可進入會議。
  • 會議主持人可於分組討論進行時,廣播文字訊息到所有分組討論室。
  • 會議主持人可於分組討論進行時,為分組討論室重新命名。
  • 進行桌面分享時,Android/iOS使用者可快速切換至文字聊天室或觀看成員名單。

U會議產品資訊

訊連科技「U會議」,即日起可於U官方網站下載,並內建繁體中文、簡體中文、英文、法文、德文、義大利文、西班牙文、日文及韓文等九國語系。

您可根據與會人數及直播時間需求,選擇不同的 U 會議訂閱方案

關於訊連科技U整合通訊服務

訊連科技「U 簡報」、「U 會議」及「U 通訊」整合了遠距直播、視訊會議及即時通訊等功能,為企業及教育機構打造即時、跨國界、跨平台、行動優先、高影音品質之新世代視訊溝通服務。更多資訊,請洽:https://u.cyberlink.com/

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於CyberLink
訊連科技創立於1996年,擁有頂尖視訊與音訊技術的影音軟體公司,專精於數位影音軟體及多媒體串流應用解決方案產品研發,並以「抓準技術板塊,擴大全球行銷布局」的策略,深根台灣、佈局全球,展現亮麗的成績。訊連科技以先進的技術提供完美的高解析影音播放效果、以尖端的科技提供完整的高解析度擷取、編輯、製片及燒錄功能且完整支援各種高解析度影片及音訊格式。產品包括:「威力導演」、「PowerDVD」、「威力製片」、「威力酷燒」等。

TÜV Rheinland Becomes an Approved Laboratory for Fibre Release by The Microfibre Consortium

In June 2020, TÜV Rheinland Textile Testing Laboratories in Shenzhen and Shanghai were approved by The Microfibre Consortium (TMC) to conduct tests for quantifying fibre release from fabrics during domestic laundering. The TMC is an organisation leading in global reduction of microfibres released into our waterways and natural ecosystems. The laboratories can now conduct this testing service for the TMC members. This is a great step forward in the fight to reduce fibre fragmentation throughout the garment supply chain.

Recent studies have revealed that the fibres in our clothes could be poisoning our waterways and food chain on a massive scale. Microfibres – tiny threads shed from fabric – have been found in abundance on shorelines where waste water is released. WRAP, a non profit organisation founded in 2000 promoting methods for sustainable use of resources released “Report of Textile derived microfibre release” in December 2019. The evidence showed that 170,000 tonnes of textile-derived microfibres may be lost during textile processing and production. Another 1,300 tonnes was shed during domestic machine washing and tumble drying, and over 350,000 tonnes resulted as residual waste. While the volume of fibre released during laundry contributes to a relatively low level of fibre loss, the likelihood of this fibre source entering marine ecosystems is significantly higher than other sources.

The Microfibre Consortium (TMC) facilitates the development of practical solutions for the reduction of fibre fragmentation and pollution for the textile industry and supports their members with textile manufacturing needs all the way through the complete product lifecycle. Members range from clothing brands, retailers and manufacturers to research institutions and policy makers, all working toward globally aligned environmentally sustainable solutions. As an approved laboratory, TÜV Rheinland, provides microfibre shedding testing to support in the fashion, sport, outdoor and home textile categories in their reduction of microfibre shedding.


Hung Simon

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About TUV
The TÜV Rheinland is a leading provider of technical services worldwide. Since our foundation in 1872, we have been providing safe and sustainable solutions for the challenges arising from the interaction between man, the environment and technology.As an independent, neutral and professional organization, we are committed to working towards a future that can fulfil the needs of both mankind and the environment in the long term.

About The Microfibre Consortium (TMC)
Founded in November 2018, The Microfibre Consortium now has 40 members from across the outdoor sector, sports, high street, luxury fashion and home textiles, with a combined turnover of over €250 billion. TMC also has a rapidly growing network of research institutions and affiliates from around the world, supporting the consortium’s mission for increased global topic alignment collaboration and research to understand and reduce microfibre pollution.