Skip to content

How to Protect Remote Access with PAM

The Covid-19 pandemic has caused massive adoption of remote working models in organizations of all sizes. Besides, security leaders have also accelerated the migration of their infrastructure to cloud environments. According to a study conducted in partnership by Forrester and CloudFare, 52% of the organizations surveyed indicated that the pandemic has caused a shift to cloud-based working models.

In these models, both employees and third parties need to have access to critical systems through privileged credentials, so that they can perform their daily tasks. And with the increase in the number of third parties, there was also an increase in the number of data leaks attributed to them. According to a study by Trustwave, 63% of these security incidents were caused by third parties, which makes this type of access an important attack vector in organizations. The associated costs are also higher. According to the Cost of a Data Breach 2020 report, the average cost of a data leak reaches USD 3.86 million. And leaks caused by third parties were one of the factors associated with even greater losses.

Considering this infrastructure that is distributed outside the security perimeter, many people responsible for Information Security have made their cybersecurity policies less restrictive, allowing access through insecure devices and networks (including BYOD or Bring Your Own Device), even VPNs without the proper security controls in place. And we already know that it is impossible to track what is not managed.

All of these aspects introduced new business risks and concerns for cybersecurity teams. In a study published by PDM Insights, 73% of IT decision-makers who responded to the survey recognize these new challenges. The related risks include opening phishing emails (for 38% of respondents) and inappropriate administrative access (37%), which required CISOs to seek the implementation of Zero Trust-based approaches.

In Zero Trust models, there is no concept of trust within the perimeters of the organizations’ infrastructure, and all actions taken by users must be continuously verified. Forrester reports that the percentage of IT leaders who have accelerated their investments in Zero Trust-based technologies reaches 76%. In addition, the same percentage also identified Identity and Access Management (IAM) as the biggest challenge for their Security teams. An example of Zero Trust-based IAM technology is just-in-time access.

In just-in-time accesses, access to applications or systems is allowed only at predetermined periods and on-demand. Therefore, through just-in-time it is possible to grant the required privileges for the performance of certain administrative tasks through the provisioning and de-provisioning of access in time of use, thus reducing the attack surface and the associated cybersecurity risks. As organizations adapt to a new working model, which includes the consolidation of remote work and the increase of third parties in the infrastructure, the use of PAM tools is imperative for security leaders to ensure compliance with policies and security regulations, such as PCI-DSS, HIPAA, and SOx. Also, it is possible to meet the requirements of data protection laws, such as LGPD and GDPR, mitigating security risks and preventing data leaks that can cost millions in fines, in addition to the loss of revenue, customers, and corporate reputation.

To solve the problems involved in the remote work of employees and third parties, senhasegura has launched Domum, which offers users secure access based on Zero Trust to devices of the corporate infrastructure wherever they are, without the need for VPN, installation of agents, and additional licensing or configurations. Access is granted instantly, easily, and securely, without exposing device passwords and without the user needing access credentials to the PAM security platform.

It works as follows: whenever it is necessary for an employee or third party to perform remote access to any device managed by the PAM platform in the infrastructure, senhasegura Domum will perform the provisioning of access using a just-in-time approach, sending an approved access link to the user, allowing immediate access only to authorized devices.

senhasegura Domum allows configuring access workflows at multiple levels to allow access, in addition to the high granularity offered by the PAM security platform, already recognized by the market. In this way, it is possible to have maximum adherence to the organization’s access policies, allowing the reduction of implementation and customization costs. After the predetermined time of authorization, access is revoked and the link is no longer valid, preventing the employee or third party from proceeding with malicious privileged actions on devices in the infrastructure, which allows for a smaller attack surface and security risks associated with the exploitation of privileged credentials. Besides, by automating the process of granting and revoking privileged access on devices used by third parties, senhasegura ensures the reduction of operational expenses with access management.

Domum also offers all the features offered by the senhasegura PAM platform, such as real-time monitoring of the actions performed. Through LiveStream, an auditor can check the actions taken by a user, allowing the blocking or closing of the remote session in case of non-compliance or if a malicious action is detected. Other features of senhasegura also offered by Domum include session recording, analysis of threats user behavior. Thus, one can reduce the time to detect and respond to malicious actions before the malicious attacker is able to take them. As a result, there is maximum visibility of privileged actions performed in the environment and compliance with regulatory standards.

Ensuring the protection of remote access for a lot of users working remotely is more than an optional security requirement, it is a business must. Therefore, by using the senhasegura PAM platform and senhasegura Domum to manage privileged access, you can reduce the attack surface and the associated security risks, avoiding data leaks and ensuring business continuity.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

WHAT’S NEW Pandora FMS 753

What’s new in the latest Pandora FMS release, Pandora FMS 753

Let’s check out together the new features and improvements related to the newest Pandora FMS release: Pandora FMS 753.

NEW FEATURES AND IMPROVEMENTS

New integrations

New plugins have been added to the module library for integration with: Telegram, Google Chat, Discord, MSteams and Slack.

Release
New event widget configuration fields

The possibility of using recursion within group filtering has been added; in addition to columns for groups and tags and the possibility of loading a saved event filter within the widget.

Retrieve selenium variable as new module

The possibility of generating new modules from the getValue variable within a WUX module with selenium has been added.

New media token in Availability Graph

A new token has been added to the Availability Graph to obtain the average result of both the selected modules and their associated failovers.

Release

Improved report histogram

By means of this new item, it will be possible to see the status of the module within the configured parameters in a histogram table.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

Portnox CLEAR vs. On-Premise NAC: A Look at Total Cost of Ownership (TCO)

On-Premise NAC vs. SaaS NAC

 

Set-Up & Configuration

Unlike traditional on-premise NAC solutions that require hardware appliances, software, and other on-premise elements, you can create your dedicated instance of Portnox CLEAR cloud-delivered NAC-as-a-Service in minutes.

Portnox CLEAR has been built from the ground up to simplify policy configuration, allowing for deployment timelines that can be measured in hours. In contrast, traditional on-premise NAC deployments can be measured in weeks or months.

Set-Up Costs Eliminated with Portnox CLEAR: Need for on-site appliances, need for third-party expertise, man-hours dedicated to systems training

Savings Value: HIGH

 

Scalability & Performance

As a cloud service, Portnox CLEAR eliminates the need for the capacity planning of on-premise NAC software or appliances. It also eliminates the need to expand capacity or upgrade appliances to meet future growth needs as required by traditional on-premise NAC.

Portnox CLEAR can automatically control the virtual machine size and the scale up or down rules. Dedicated F5 load balancers are spun up as well as auto-scale, so you never have to be concerned with service performance or scalability – it will automatically expand as needed to meet demand.

Performance Costs Eliminated with Portnox CLEAR: Man-hours dedicated to capacity planning, need for on-site appliance upgrades, need for local load balancing

Savings Value: MODERATE

 

Lifecycle Maintenance

Another hidden cost of on-premise is maintenance. All you have to do is search the web – in most cases you’ll find that vendors have lengthy manuals that outline the painful steps and procedures necessary to keep the software or its associated appliances updated.

These upgrades often come with time limits that can force you to start over and re-do your work. Worse yet, one simple mistake during these upgrades can take your network down for many hours or days. And guess what? You often get to go through these upgrades multiple times per year.

With Portnox CLEAR, never worry about software or hardware end-of-life, or costly, complex upgrades requiring hours and days of work and a never-ending checklist of to-dos. As a cloud-delivered service, Portnox CLEAR is always running the most up-to-date version with the latest features and capabilities. At the end of the day, Portnox CLEAR customers enjoy continuous service availability with ZERO lifecycle maintenance costs.

Maintenance Costs Eliminated with Portnox CLEAR: Software upgrades, NAC downtime, need for third-party expertise

Savings Value: HIGH

Michael Marvin

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

Walking Meetings: perfect new idea or the dumbest thing ever?

What are Walking Meetings and how can they help us?

I hope you are not tired of “trend” terms, the neologisms that multiply everywhere and the upstart concepts that you can’t seem to memorize that well because they always sound like something else. I actually hope you are not, because here it comes another one, fresh from the oven. Take note, because as soon as you learn about it, as it usually happens, it will start mysteriously proliferating around your acquaintances. Today, in our alien-green Pandora FMS blog, we talk about what Walking Meetings are.

What are Walking Meetings?

Walking Meetings, *drum rolls*, are nothing more than work meetings while you walk. Yes, instead of sitting in an expensive and comfortable desk chair you take a stroll. Therefore, if you work remotely, we recommend you to have a pretty big living room, otherwise, it won’t work, we guarantee…

One of the excuses that surround the concept for its immediate implementation is that it helps us alleviate the sedentary lifestyle of today’s jobs. And it is true that we are all fed up with those pounds we seem to be gaining afterwork, a concept with which I hope you are familiar with, because it is one of the few that truly succeeds today and it is worth it. Although, as for me, I would continue to call it “things got out of hand and I ended up having a hard time the next day at the office.”

Walking Meetings or “Walking while you talk to your boss“, in addition to lowering the volume of your stomach, would help you relax, set you in a good mood and foster a positive environment. The bad thing is that if you are immersed in teleworking and you no longer have data on your business cell phone, your walk would be limited to the place where you still have Wi-Fi connection. That is why it is better to have a big living room.

As we already knew from the famous peripatetic school, walking while talking encourages creativity and reasoning. It is not surprising then that Aristotle strolled around the gardens bordering the temple of Apollo, along with his disciples, to teach them while they did some exercise to digest lunch better.

I know that maybe you are more of an oval noble wood table, blazer and tie, cards and Power Point, seriousness and silence person, while someone explains the new ideas that will no doubt relaunch the company. But things are evolving and what is trending now are Walking Meetings, something like walking the dog but with your work colleagues and while someone assigns, by Skype or in strict presence, the tasks of the week. Sorry, boomer, the elevator pitch is more popular than the static monologues of seniors of the company remembering better times, back in the old days. Dynamism and fluidity, relaxation and conversation, pedestrian exercise and rhythm, cardio and walking, project solutions and original answers. That is what prevails nowadays. And we welcome it with open arms. I have already bought my sneakers for that purpose!

But Walking Meetings already existed

As it is often the case with these types of newly coined concepts, Walking Meetings already existed. There we also have freeganism, for example. Which is basically, for those of you who may not know, “the collection of food that has previously been thrown away or discarded because its expiration date is near or past.” That was already in motion since garbage existed, however now it has a striking name, which some may consider unnecessary, and different nuances, ranging from hipsterism to anti-consumerism.

With Walking Meetings it is the same thing happening again, there were already conversations in the hallway on the way to the cafeteria or restroom, but they have finally become institutionalized and we now have a new excuse to wear shorts to work.

So what before could be a meal for those leading two different companies to reach an agreement of vital importance until way later after dinner, now they meet at the park to talk between gasps while keeping a light gallop. Of course, it is much better for strengthening the core, than the digestive gin tonics and a cigar after a good steak.

Possible benefits of Walking Meetings

  • Promoting creativity:

For some causal reason, walking is better. Synapses proliferate, our neurons sparkle, everything seems clearer, and creativity arises, from ear to ear, with a rainbow glow. Stanford University does not have to come to tell us about its experiments with sedentary and athletic people, we all know that movement shakes our heads and favors creation.

  • Exercise included:

Until we can eat popcorn without choking and pay attention to Netflix as we drive around with the porch, walking while working is the closest thing to doing something uplifting while exercising. You take a break from the screen for once, relax your burned corneas, and make other just as interesting muscles work.

  • Ideal for dealing with complicated topics:

Being locked up, immobile and face to face with someone is not the healthiest way to deliver sensitive news. It is much better to enjoy the air, space, exercise to distress and see the landscape views. If things get ugly you can always accelerate until you leave your teammates behind.

  • Good vibes:

Do you remember how good it felt when the teacher decided to teach the class outside because it was too good a day to be inside? Well, the same happiness and good vibes arouse Walking Meetings in the open air. Encouragement and positivism will flood us when we listen to something more than the photocopier in the background and we see something more than the gray facing of our cubicle.

I hope that with this information you can guess by yourself whether Walking Meeting instauration is worth it and you should give it a chance or whether you should just completely ignore them. Maybe you like them and they seem appropriate but with another name, something more simple and humble like “Meetings strolling” or the always cool “Marathon Meeting” or “Running Reunioning”.

But once you’ve gotten into these ins and outs, would you like to keep going? Go even further but into the world of technology? What about spending a couple of minutes to find out what computing system monitoring is and why it is also very important?

Monitoring systems are responsible for supervising technology (hardware, networks and communications, operating systems or applications, for example) in order to analyze its performance, and to detect and alert about possible errors. And this leads us to Pandora FMS, that wonderful tool thanks to which this blog is possible.

Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

訊連科技推出全新FaceMe® Security智慧安控解決方案支援多種主流VMS 協助安控應用快速導入刷臉門禁、出勤及口罩、體溫監測

【2021年03月31日,台北訊】 世界級AI臉部辨識技術開發商訊連科技(5203.TW)宣佈推出全新版本的 FaceMe® Security智慧安控解決方案。透過全球頂尖的人臉辨識技術,FaceMe® Security可協助系統整合商於多種安控場景中,快速導入VIP/黑名單辨識、刷臉出勤打卡等應用,並可支援口罩偵測、體溫偵測,及配戴口罩時的人臉辨識等防疫需求。全新版本新增了Milestone、Nx Witness、VIVOTEK VAST2等主流VMS支援,亦可於場域中採用NVIDIA Jetson進行人臉偵測及特徵擷取,可讓人臉辨識安控系統的部署更具彈性、輕量化,並節省成本。

訊連科技推出全新FaceMe® Security智慧安控解決方案支援多種主流VMS 協助安控應用快速導入刷臉門禁、出勤及口罩、體溫監測

FaceMe® Security為訊連科技開發的智慧安控加值軟體,可協助系統整合商快速將人臉辨識應用於零售業、製造業、倉儲管理、辦公室與飯店等各種應用場景中,導入如刷臉門禁、出勤記錄統計、VIP/黑名單辨識等及口罩偵測、體溫量測等應用。FaceMe® Security可相容於大多數現行IP安控系統,可連接到現有IP攝影機,或者運行於各種類型的電腦和工作站設備上,使系統整合商能快速將此解決方案導入現有架構及設備。透過支援Milestone, Network Optix Nx Witness與VIVOTEK VAST2 等主流VMS(影像管理系統),於特定人士(如VIP、黑名單、員工)進入特定區域時,可透過API即時發送示警訊息至保全人員端的VMS,也可搜尋指定人員出入資料進行回放。

FaceMe® Security可部署於各種規模的安控場景,於邊緣端運行的FaceMe® Security Workstation可運作於工作站、工業電腦及物聯網裝置上,進行即時的人臉偵測及特徵擷取,用作身分比對。以人流來說,於工廠或科技園區等每小時上萬人流的大型場域,可選擇於單一Windows工作站上安裝至多四張的NVIDIA Quadro RTX 5000加速卡,提供每小時近八萬人的人流臉部辨識。而以數千人的中小型場域,如辦公大樓、零售商場及倉儲,則可運行於NVIDIA Jetson(AGX Xavier或Xavier NX)或採用Intel® Core 處理器或Movidius™ VPU的工業電腦或NUC等設備,以較低的成本和能源消耗下,維持高精準度的人臉辨識監控服務。

「人臉辨識技術是近年來IP安控最熱門的應用之一。透過導入人臉辨識技術,不僅可以高度精準辨識個人身分,也能在配戴口罩等人臉部分遮蔽的狀況下,精準辨識身分,並且偵測人員是否正確配戴口罩。」訊連科技執行長黃肇雄表示:「訊連科技擁有提供領先全球的人臉辨識技術,FaceMe® Security更提供完整一站式的解決方案,可協助現有的IP安控系統無縫升級人臉辨識,為各種行業、各種規模的使用者,提供最安全的門禁管理和健康偵測服務。」

針對出勤打卡及體溫量測需求,FaceMe® Security提供了兩個附加套件,可於場域入口處安裝於一般個人電腦上,提供員工出勤打卡和健康偵測的介面。FaceMe® Security Check-In Add-On可提供即時的身分驗證並記錄員工出勤。FaceMe® Security Health Add-On則提供了健康量測服務,包含偵測人員是否正確配戴口罩、驗證身分並量測體溫。當系統偵測到體溫過高或者未配戴口罩的人員,可即時將紀錄之照片和位置通報給保全人員,方便採取進一步的防疫措施。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於CyberLink
訊連科技創立於1996年,擁有頂尖視訊與音訊技術的影音軟體公司,專精於數位影音軟體及多媒體串流應用解決方案產品研發,並以「抓準技術板塊,擴大全球行銷布局」的策略,深根台灣、佈局全球,展現亮麗的成績。訊連科技以先進的技術提供完美的高解析影音播放效果、以尖端的科技提供完整的高解析度擷取、編輯、製片及燒錄功能且完整支援各種高解析度影片及音訊格式。產品包括:「威力導演」、「PowerDVD」、「威力製片」、「威力酷燒」等。