Skip to content

Securing Your Organization Against the Harm of Identity-Based Attacks

Today, the specter of identity-based attacks looms larger than ever over the corporate world. These cyber-attacks, which exploit personal or organizational identifiers to gain unauthorized access to systems, have become a favored tool in the cybercriminal arsenal. Their rising prevalence underscores a critical vulnerability in the digital defenses of large organizations.

This discourse aims to dissect the anatomy of identity-based attacks, elucidate the tactics employed by adversaries, assess the potential harm to vast enterprises, and advocate for the strategic deployment of network access control (NAC) mechanisms as an essential countermeasure.

Understanding the Surge in Identity-Based Attacks

The escalation of identity-based attacks represents a sophisticated evolution in the cyber threat landscape, propelled by an intricate web of technological and behavioral factors. Sadly, 90% of organizations experienced at least one identity-related breach in the past year. This surge is primarily driven by the increasing digitalization of identities and the widespread adoption of cloud services, combined with the ubiquitous nature of remote work. These elements collectively expand the attack surface, offering cybercriminals a larger playground to exploit.

The complexity of these attacks is further magnified by the seamless integration of social engineering techniques with advanced technological exploits, making the detection and prevention of such intrusions increasingly challenging. Cybercriminals are leveraging the abundance of personal information available online to craft highly targeted attacks, exploiting the smallest vulnerability in human behavior or system security. In fact, more than 80% of confirmed breaches are related to stolen, weak, or reused passwords.

The shift towards more sophisticated and stealthy methodologies underscores a deliberate move away from brute force attacks to those that can silently bypass traditional security defenses, exploiting trust and the inherent weaknesses within organizational systems. This shift not only signifies a higher level of threat actor sophistication but also highlights the urgent need for organizations to adapt and evolve their cybersecurity strategies in response to this growing threat vector.

How Cybercriminals Execute Identity-Based Attacks

Cybercriminals, in their pursuit to breach corporate defenses, have fine-tuned the art of identity-based attacks through an array of sophisticated methods. Spear phishing represents one such tactic, wherein attackers, armed with detailed personal information, craft convincing communications to lure individuals into revealing their credentials. Additionally, attackers exploit the technique of password spraying, targeting numerous accounts with a few commonly used passwords, capitalizing on the prevalent issue of password reuse across multiple platforms. 74% of all breaches include the human element, with people being involved either via privilege misuse, use of stolen credentials, social engineering, or error

These adversaries are also adept at employing social engineering to manipulate users into granting access or performing actions that compromise security. Once the initial breach is achieved, these malefactors employ lateral movement strategies, exploiting legitimate but compromised credentials to navigate through the network undetected. This stealthy traversal is aimed at escalating privileges and gaining access to high-value targets, all while masquerading as legitimate users. These methods, rooted in deception and exploitation of trust, underscore the criticality of vigilant, adaptive security measures to counteract the ever-evolving tactics of cyber adversaries.

The Devastating Impact on Large Organizations

For substantial enterprises, the fallout from identity-based attacks extends far beyond immediate fiscal deficits; it strikes at the very heart of their long-term viability and brand integrity. Such intrusions inflict profound reputational harm, undermining public confidence and loyalty, which are not easily restored. The illicit acquisition of proprietary information, customer data, and sensitive strategic insights by adversaries can severely disrupt competitive positioning and operational continuity. This breach of confidential information often leads to non-compliance with stringent regulatory standards, attracting severe legal sanctions and further financial drain.

The aggregated impact of these repercussions can dramatically alter an organization’s market standing and its ability to secure future opportunities. In this challenging landscape, the paramount importance of robust cyber defenses becomes unequivocally clear, underscoring the necessity for organizations to anticipate, recognize, and neutralize these sophisticated threats with unwavering diligence and advanced protective strategies.

The Crucial Role of Network Access Control in Mitigating Risks

Network Access Control (NAC) stands as a paramount defensive strategy in safeguarding large organizations from the nefarious reach of identity-based attacks. This advanced guard operates by meticulously validating the credentials of both users and devices seeking entry into the network, ensuring that only those with legitimate authorization can penetrate its digital perimeter.

NAC’s efficacy is further enhanced through its dynamic policy enforcement capabilities, which tailor access rights based on a comprehensive assessment of user roles, device integrity, and the nature of the requested resources. Moreover, its sophisticated monitoring mechanisms are adept at swiftly identifying and isolating suspicious activities, thereby serving as an early warning system against potential breaches.

Through the diligent application of NAC, organizations erect a formidable barrier that not only curtails the operational playground of cyber adversaries but also fortifies the trust and confidence vested in them by their stakeholders. Implementing NAC is not merely a tactical defense measure but a strategic move towards creating a resilient and secure digital ecosystem, capable of withstanding the complex challenges posed by identity-based threats.

Best Practices for Leveraging NAC to Combat Identity-Based Attacks

To optimize NAC as a bulwark against identity-based attacks, a strategic approach rooted in vigilance and precision is imperative. Crafting a meticulous inventory that catalogues every user and device interfacing with the network underpins the creation of an impenetrable defense mechanism. This foundational step ensures no entity remains hidden or unmonitored within the digital expanse of an organization. Establishing policies that are not only robust but also nuanced, reflecting the unique position and access requirements of each user and device, is crucial. This granularity enables a more tailored security posture, minimizing unnecessary access that could potentially be exploited by cyber adversaries.

Engaging in relentless monitoring and conducting systematic audits are essential to unearth and swiftly mitigate any irregularities or signs of compromise. This proactive surveillance acts as the organization’s digital immune response, poised to neutralize threats at their inception. Further strengthening the NAC framework through seamless integration with complementary security technologies, such as Multi-Factor Authentication (MFA) and Security Information and Event Management (SIEM) systems, elevates the security matrix to new heights.

Additionally, fostering a culture of cybersecurity awareness among employees, emphasizing the criticality of vigilant digital hygiene practices, serves as the linchpin in safeguarding the organization’s digital domain against the scourge of identity-based attacks. This collective effort fortifies the digital bulwark, ensuring the integrity and resilience of the organization’s network against the evolving threat landscape.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

Unpacking Desktop as a Service (DaaS): A powerful tool for modern workforces

DaaS is a cloud-based model where a third-party provider hosts and delivers virtual desktops to users. Unlike traditional VDI, which requires organizations to manage their own on-premises infrastructure, DaaS offers a more straightforward, pay-as-you-go solution.

Leading providers like Parallels offer convenient access to virtual desktops, eliminating the need for upfront investments in hardware and software.

How does DaaS work?

DaaS leverages private or public cloud services, enabling multiple users to access virtual desktops over the Internet. The cloud provider takes care of everything, from infrastructure management to security, ensuring seamless and reliable access to virtual desktops. With an internet connection, users can access their desktops from any device, anywhere, using an endpoint application or web browser.

The benefits of DaaS

DaaS offers numerous benefits for organizations, including:

  1. Increased productivity: Employees can work from anywhere, anytime, if they have an internet connection and a suitable device.
  2. Lower costs: DaaS eliminates the need for upfront hardware and infrastructure investments, offering a more predictable cost structure.
  3. Enhanced security: Cloud providers manage security and compliance, ensuring excellent protection against cyber threats.
  4. Improved scalability: DaaS allows organizations to quickly scale their desktop infrastructure up or down as needed, adapting to changing business requirements.
  5. Reduced IT burden: DaaS frees IT staff from managing desktop infrastructure, allowing them to focus on strategic initiatives.

DaaS vs VDI

While DaaS offers several advantages, it is essential to compare it with traditional VDI to understand its suitability for your organization:

  • Cost: DaaS has a lower upfront cost with a pay-as-you-go model, while VDI requires CapEx upfront to set up the IT infrastructure.
  • Management needs: With DaaS, third-party management takes care of everything. With VDI, the organization is responsible for storage, computing, and network requirements.
  • Capabilities: DaaS has some limitations compared to VDI, which offers advanced capabilities like USB redirection and multiple monitors.
  • Regulatory requirements: DaaS may not align with certain industry regulations or compliance requirements, whereas VDI may meet more industry-specific security needs.
  • Control: DaaS requires less in-house IT management due to third-party management of the solution, while VDI requires more time and effort since IT has greater control over the virtualized desktops and infrastructure.
  • Usability: DaaS suits smaller organizations with proportionally lower needs, while VDI is suitable for larger organizations with higher security needs.

In summary, the choice between DaaS and VDI depends on your organization’s specific needs and resources. DaaS is ideal for organizations that:

  • Need a flexible and scalable desktop solution.
  • Have limited IT resources.
  • Want to reduce costs.
  • Prioritize security.

VDI, on the other hand, is better suited for organizations that:

  • Require a high level of control over their desktop environments.
  • Have the resources to manage their own infrastructure.
  • Need to comply with industry-specific regulations and compliance standards.

Which companies benefit most from DaaS?

Many companies are increasingly transitioning to the DaaS model due to its benefits. Some of the organizations that can benefit from a shift to DaaS offerings include:

  • Small and medium-sized businesses (SMBs) that want to reduce IT costs and improve flexibility. Such businesses can use DaaS to minimize the need for buying servers, software and other services.
  • Enterprises that need to quickly deploy virtual applications and desktops to support new business initiatives or otherwise scale up or down readily. Depending on the business demands, these companies can leverage DaaS to provision or de-provision virtual desktops for their employees quickly.
  • Organizations that want to centralize IT management capabilities and minimize IT costs. Utilizing DaaS allows IT administrators to easily deploy, configure, and maintain corporate resources from a single pane of glass.

How do you pick the right DaaS provider?

Before choosing an appropriate DaaS provider, you must first determine if DaaS or Desktop as a Service is the right approach for your organizational needs.

For example, you could have a scenario where employees are used to accessing resources through local PCs in an on-premises IT infrastructure. In this type of environment, it makes business sense to determine if a transition to cloud-based VDI can save costs and free up more resources.

Start by weighing the merits and demerits of VDI versus DaaS. For instance, do you have the necessary virtualization expertise, time, and other tools to manage on-premises IT infrastructure in-house, or would transitioning to DaaS make more business sense?

The future of work with DaaS

DaaS represents a significant advancement in desktop solutions, enabling organizations to embrace a more agile and efficient work environment. Its inherent benefits, like increased productivity, cost savings, and enhanced security, make DaaS a compelling choice for businesses of all sizes.

As DaaS offerings continue to evolve, these solutions are poised to become an essential tool for the modern workforce. As businesses seek to embrace modern work practices, understanding the benefits and challenges of DaaS is crucial.

By making informed decisions about their desktop infrastructure, organizations can unlock new levels of efficiency, cost-effectiveness, and security to thrive in the competitive landscape.

Discover Parallels DaaS

DaaS management

Parallels DaaS stands as a testament to the power of desktop as a service, offering organizations a comprehensive and secure solution tailored to their unique needs.

Our platform empowers businesses to enhance employee productivity, optimize costs, and achieve greater flexibility in a rapidly changing world.

Check out Parallels DaaS today.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Spy Skills for Your Business: Threat Intelligence Explained

Ever wanted to be a spy? With such a great deal of espionage operations happening online, gathering threat intelligence might feel like being a modern-day James Bond.

Think about cyber threat intelligence as having a spy network working to protect your business online. It’s all about gathering information on potential cyber threats — understanding how bad actors operate, what areas of business they might target, and what tools they use. Companies cannot effectively defend themselves from cyberattacks without well-researched, reliable data. With threat intelligence, businesses can stay one step ahead of cybercriminals, know what to look out for, and have a clear understanding of how to protect their assets.

A brief history of threat intelligence and its role in cybersecurity

Without cyber threat intelligence, a company is “blind and deaf.” It would not be an exaggeration to say that it is an essential part of cybersecurity. However, its shape and role in cybersecurity have changed over the years as a result of the internet’s evolution and the growth of worldwide interconnectivity. New cyber threats arise daily, making security experts develop innovative defensive strategies and tactics.

Initially, companies focused solely on basic security measures such as IP and URL blacklists and antivirus solutions. However, with the spread of malware, worms, and viruses in the early 2000s, they found themselves in need of more sophisticated threat detection and response capabilities. As cyber criminals got smarter and more organized, it became evident that security experts needed to collaborate and share information. Consequently, the President of the United States established the Information Sharing and Analysis Center (ISAC), a non-profit organization dedicated to facilitating the sharing of threat intelligence within specific industries.

In the 2010s, the rise of data automation and the emergence of Threat Intelligence Platforms (TIPs) resulted in organizations having the right tools to manage and analyze large volumes of data. These platforms are technological solutions that can manage data collected from multiple sources and presented in various formats.

Later on, TIPs were integrated into Security Operations Centers (SOCs), providing security analysts with a unified interface for accessing and utilizing cyber threat intelligence seamlessly in a company’s day-to-day operations. Threat Intelligence Platforms also became an integral part of Incident Response (IR) processes, delivering actionable scenarios for managing and mitigating the impact of a security incident on an organization. This integration made the response to cybercrime faster and more efficient.

Nowadays, the role of machine learning and AI in cyber threat intelligence grows stronger every day, helping to analyze and predict cyber threats. We can also see a shift in the cybersecurity objectives — from threat detection to cyber resilience, focusing on the business’s ability to recover quickly from cyberattacks. Fortunately, throughout the years of the digital revolution, the cybersecurity community has recognized the importance of collaboration, data sharing, and the integration of threat intelligence into the overall cybersecurity strategy.

Threat Intelligence Lifecycle

Gathering threat intelligence is a complicated process that involves collecting, processing, and analyzing large volumes of data. The outcome of this process should focus on vulnerabilities specific to your organization. It should be detailed and contextual and, last but not least, be actionable.

Let’s examine the six phases of the threat intelligence lifecycle:

1. Direction

The direction phase is a crucial part of the process: you cannot perform a secret service operation without specifying its objectives. Therefore, you should follow in the footsteps of the character played by Jodie Foster in the 4th season of “True Detective” and ask questions such as:

  • Who are the attackers?

  • What motivates them?

  • Which data assets and business processes need to be protected?

  • Protection of which aspects of the organization is our priority?

  • What happens if we fail to protect them?

  • What types of threat intelligence do we need to protect the company’s assets and respond to emerging dangers?

2. Collection

After setting goals and objectives, we can move to the next phase: data collection. The security team gathers raw data from various sources, including open-source intelligence (OSINT), commercial feeds, internal logs, and information shared within the cybersecurity community. At this stage, it’s important to validate our sources of information and the accuracy of collected data. This will allow us to avoid missing severe cyber threats or being misled by false positives.

3. Processing

Remember that nowadays, threat analysis relies on processing huge volumes of data, which is automated and requires data to be standardized and formatted. When our collected data are compatible, we can identify relationships and connections between different pieces of information to better understand the cyber threat landscape.

4. Analysis

Threat intelligence analysis is a human process that turns processed information into actionable intelligence, enabling data-driven decision-making. The analysis should prioritize risks, resulting in the creation of a threat management roadmap. It should also provide a context for collected threat intelligence by understanding the motives, capabilities, and tactics of cybercriminals. What’s important here is to present threat analysis in a way that decision-makers will easily understand.

5. Dissemination

Dissemination is a crucial part of threat intelligence management. Analyzed data must be transformed into actionable intelligence reports, alerts, or indicators of compromise (IOCs) that the security team can use to strengthen the company’s defense system. Then, those should be shared with relevant teams and decision-makers within the organization and, in some cases, with trusted external partners.

6. Feedback

Threat intelligence management and effectiveness must be evaluated. Did the intelligence have the impact you expected? Did it improve the company’s safety? What went wrong in the entire process? Answering those questions helps your business move forward and improve its threat intelligence program.

Four types of threat intelligence

We need to understand the types of threat intelligence to fully grasp its impact on overall business cybersecurity. Usually, cyber threat intelligence is divided into four categories, ranging from high-level information to specific technical details about cyber threats.

Strategic

Strategic threat intelligence is non-technical information focused on understanding the broader context of cyber threats. It may come in the form of reports describing hackers’ motives and capabilities, geopolitical influences, or industry-specific risks. Usually, this type of threat intelligence is presented to high-level stakeholders, e.g. the board of directors.

Tactical

This type of threat intelligence includes information that can be used by security experts to make data-driven decisions and actively defend the organization. Tactic intelligence is more detailed than strategic. For example, it may describe cybercriminals’ tools, attack avoidance tactics, or weak points in the company’s security infrastructure.

Operational

It provides real-time information on specific threats, ongoing crime operations, and emerging attack patterns. This type of intelligence enables the company to respond to specific cyberattacks immediately; it can also help mitigate the damage made by hackers.

Technical

Technical threat intelligence may come in the form of evidence that an attack is happening or specific indicators of compromise (IOCs). Ideally, it’s provided in real-time before the hackers can cause any significant damage. Examples of tactical cyber threat intelligence include phishing emails detected by AI tools or real-time data breach notifications sent by an advanced enterprise password manager.

How NordPass can help protect organizations

A country needs all kinds of security measures to protect its citizens: the border guard, the police, an army, and special agents. It can be safe only if all parties work together. The same rule applies to keeping your business safe. It requires all types of threat intelligence — every single one of them is an important part of the cybersecurity landscape. They are interconnected, and only together can they provide comprehensive defense against cybercrime. Even the best strategic plans won’t stand a chance if the company fails to recognize data breaches in real-time.

Luckily, there are tools available that can make gathering technical threat intelligence easier and more efficient. The NordPass built-in Data Breach Scanner automatically scans leaked databases and compares them with information stored in your and your employees’ password manager vaults. It generates password breach reports with detailed information about data leaks that have affected your company. Most importantly, it notifies you or your security team in real time about every new breach so you can act and protect your company immediately. Give it a try, and don’t let cyber threats slip through your company’s defense anymore!

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

What’s New? Quarterly Release 24.2 Mimas

This article covers what’s new our latest Quarterly release series from December 2023 to February 2024. Read the release notes here

Comet 24.2.0 Mimas

We’re very pleased to announce our latest Quarterly release series – Comet 24.2 Mimas. This is the the latest entry in our quarterly rollup series, that branches off from our main rolling Voyager development into a fixed target for you to qualify and build your service offering upon.

Mimas is named after a moon of Saturn, which in turn takes its name from an ancient Greek mythological giant. Mimas is relatively small compared to Earth’s moon, with a diameter of about 396 kilometers (246 miles). Its composition is primarily made up of water ice with a small amount of rocky material. Its most distinguishing feature is a giant impact crater which stretches a third of the way across the face of the moon, making it look like the Death Star from “Star Wars.”

For users coming from the previous 23.11 Saturn quarterly release series, Mimas adds 3 features and 15 enhancements, including Dark Mode for the Comet Server web interface and a Debian installer for the Comet Backup desktop app as mentioned below.

The full set of changes can be found in the release notes.

Webinar announcement

If you’d prefer to watch rather than read, we’re hosting a webinar to discuss this new quarterly release and all the new changes. Please register before we go live on Tuesday 12 March (4pm ET / 1pm PT) to catch up on all the latest Comet news with Comet’s CTO, Mason – and as usual, there will be time for a live question-and-answer session at the end of the presentation.

As well as that, we have many more videos available on our YouTube channel, including guides on getting started with Comet, individual features, demonstrations with our technology partners, and webinars for previous quarterly software releases.

Dark Mode for the Comet Server

To continue our visual improvements to the Comet Server web interface we have added Dark Mode support. This completely overhauls the look and feel of the Comet Server and automatically applies based on the theme you have chosen for your system. Next time you have a chance check it out by logging into your Comet Server and clicking the new toggle button in the top right corner.

Light Mode:

Dark Mode:

Debian Installer for the Comet Backup desktop app

To make it easier to install Comet on your Debian Linux installs, we are pleased to announce our new Debian Installer. Our new installer will walk you through all of the required steps to install Comet. Comet is installed as a systemd service meaning it will now automatically start when your device boots.

Once installed you can still upgrade Comet remotely using the Comet Server web interface meaning you now have multiple options for managing, installing and upgrading Comet on your Linux devices.

Improved S3-compatible Object Lock Performance

Object Lock is a great way to add additional security to your data stored in an S3-compatible Storage Vault. This month we’ve been hard at work finding ways to optimize Comet’s performance when backing up to an S3-compatible Storage Vaults. We have found a way to significantly decrease the time taken to extend the object lock duration on objects stored in the vault. As a result, backup jobs to an S3-compatible Storage Vault now complete up to 16 times faster than before.

Custom Headers added for Custom Remote Buckets

Comet has a great list of S3-compatible storage providers that we have storage templates for. To add better support for other S3-compatible storage providers you can now add Customer Headers to a Custom Remote Bucket in the Comet Server web interface. This greatly expands your options for which provider you would like to use as you can now add additional data such as long lived authentication tokens as part of the request Comet makes when connecting to the storage provider.

Faster Logins between the Comet Account Portal and Comet Hosted

Once Comet Hosted is running our new 24.2.0 Mimas release, we will enable the overhauled login button for Comet Hosted servers from the Comet Account Portal.

The new login button shares credentials between the Comet Account Portal and Comet Hosted meaning you no longer need to remember two sets of passwords. Because of this we have been able to solve all of the failing cases and can provide you with a reliable login experience for your Comet Hosted servers.

Once you’ve logged in with the new system for the first time, when you log out of your Comet Hosted Server you will see a new Login with Comet Account Portal appear on the login page. This allows you to jump straight back into your Comet Hosted server faster than ever before. This button will only appear on web browser sessions that remember you’ve clicked the login button from the Comet Account Portal first to ensure we don’t show Comet branding to unexpected users of your Comet Hosted Servers.

VM Pricing Adjustments

At Comet, we are committed to continuously improving our products and services to meet your evolving data protection needs. In order to do this, occasionally we find it necessary to make adjustments to our product offerings. We are updating our pricing structure in order to further standardize our virtual machine protected item types – VMware and Hyper-V.

Effective February 28th 2024, we are introducing a new unlimited guest license option for VMware, priced at $39. If you have 8 or more VMware guests backing up, you will automatically get the unlimited pricing; no action needed on your part. This change supports your business growth as you scale and add VM deployments.

Also as of February 28th 2024, we are dropping the $2 base charge for Hyper-V. You will only pay the booster charge for all virtual environment backups (both VMware and Hyper-V) going forward.

To bring our virtual machine licensing into alignment, starting February 28th 2024, Hyper-V licensing will be charged at $3 per guest or $24 for unlimited guests per host.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

How to use dark web monitoring: a talk with Mary D’Angelo

Today is just like any other day at the office. You are going through emails and laying out plans for your company’s upcoming big project when suddenly, your screen freezes. None of the troubleshooting steps work. Quickly, your IT team becomes anxious; the company’s network has stopped working. The reason is a security breach tied to stolen credentials from RIPE, an organization that assigns IP addresses across numerous countries.

This situation is similar to what Orange Spain experienced, suffering an outage due to a hacker who improperly accessed their RIPE account. Researchers at Resecurity have noticed a troubling trend: the dark web now houses millions of stolen network operator credentials, which cybercriminals are poised to misuse.

The dark web serves as a hidden space where these stolen credentials remain unseen. It is also where attackers coordinate their plans and recruit accomplices for future breaches. 

For businesses, keeping an eye on the dark web is vital. It helps uncover new threats and trends as they arise. 

Equally important are cybersecurity practices. They shield businesses from an increasing array of cyber threats. 

By combining dark web monitoring with solid cybersecurity, businesses can establish a protective strategy to remain secure.

That’s why we talked with Mary D’Angelo, a leading Cyber Threat Intelligence and Dark Web Advisor. We discussed how the dark web works and explored why businesses might need dark web monitoring.

The interview’s highlights

  • The deep web makes up 80% of the internet, while the dark web and clear web each make up 10%.

  • The US Navy originally created the Tor network for good reasons, but now less than 1% is for whistleblowers and journalists.

  • Dark web monitoring lets businesses see planned attacks, indicating the immediate need for protection.

  • Ransomware groups are growing, and threat actors are switching to platforms like Telegram.

  • Companies should combine dark web monitoring and cybersecurity practices for early threat detection.

Key insight #1: the clear web makes up only 10% of the internet

NordLayer: To start, what is the dark web?

Mary D’Angelo: When I discuss the dark web, I refer broadly to its distinction from the deep web and the clear web. The dark web is a segment of the internet accessible only through specialized software, typically Tor, which I’ll mostly reference. It’s because Tor is the most commonly used. The deep web and clear web are other internet segments. The clear web includes anything findable via Google and other search engines. The deep web, while still accessible through search engines, comprises sites that are very hard to enter. Statistics indicate that the deep web constitutes 80% of the internet, with the dark web and the clear web each accounting for only 10%.

Dark web takes up to 10% of the internet

NordLayer: The dark web ensures anonymity and is technically limitless. How does the Onion Router contribute to this anonymity?

Mary D’Angelo: The Onion Router, a type of software made to connect to the dark web, encrypts messages in multiple layers, similar to an onion. These messages, when sent, pass through various relays or nodes, mixing up communications. Upon receiving a message, each relay cannot trace its origin, making it extremely difficult to track the messages and users’ activities.

Key insight #2: the original purpose of the dark web, initiated by the U.S. Navy, now makes up just 1% of its current content

NordLayer: Could you explain the legal and illegal aspects of the dark web?

Mary D’Angelo: It’s a common misconception that the dark web is entirely illegal. Initially, the Tor network was developed by the US Navy research team to enable secure communications. 

The primary purpose of the dark web was to assist journalists and whistleblowers in remaining anonymous and using encrypted messaging on a privatized platform. Over time, it has evolved to host a significant amount of illegal activity. 

It’s estimated that 40% of the dark web is comprised of child sexual exploitation material, with less than 1% now dedicated to whistleblower and journalism activities. The majority involves illegal marketplaces, threat actor forums, ransomware groups, and similar entities.

NordLayer: But the dark web also has positive uses for privacy and free speech. Can you discuss them?

Mary D’Angelo: The dark web is valuable for media organizations and individuals in censored countries, providing a secure communication channel. Organizations like ProPublica use the dark web for secure communications, offering a platform for whistleblowers and those reporting from repressive regimes.

NordLayer: Considering its origins, does the dark web offer more security than platforms like Amazon?

Mary D’Angelo: The comparison depends on what you mean by security. The dark web provides anonymity, encrypted messaging, and privacy, even for websites. Users on the dark web enjoy encrypted and anonymized communication unseen by others. Conversely, Amazon tracks all user information, making the dark web, in some respects, more secure. However, this anonymity also contributes to the prevalence of illegal activities.

NordLayer: Is regulation of the dark web a significant challenge?

Mary D’Angelo: Yes, law enforcement faces considerable difficulties in tracking down illegal activities due to the dark web’s structure. Although recent efforts have improved, the process is complex and time-consuming.

NordLayer: Can dark web marketplaces be shut down successfully?

Mary D’Angelo: Marketplaces like Silk Road and Alpha Bay have been taken down by law enforcement, involving extensive international investigations. Often, the downfall of these sites is due to the carelessness of threat actors. However, new marketplaces frequently emerge, creating a continuous cat-and-mouse game between law enforcement and dark web users.

NordLayer: How does law enforcement investigate the dark web?

Mary D’Angelo: Investigations involve collaboration with various agencies and platforms like ours that can index and search the dark web efficiently. Law enforcement builds cases on threat actors, tracking their movements and communications, often capitalizing on their mistakes to dismantle operations.

Key insight #3: dark web monitoring helps to detect the threat on its planning stage

NordLayer: How did your interest in the dark web begin?

Mary D’Angelo: My journey into the dark web began with my background in cybersecurity and network detection. Joining Searchlight Cyber, I deepened my understanding of threat intelligence and the significance of dark web monitoring to identify potential security threats to organizations.

Dark web is a hub for threat actors to plan attacks

NordLayer: Why is it important for businesses to monitor the dark web?

Mary D’Angelo: The dark web is a hub for threat actors to plan attacks. Dark web monitoring allows businesses to detect potential threats early in the planning stage, giving them more time to prevent attacks.

“You can also try NordLayer’s ThreatBlock to prevent threats. It automatically blocks access to harmful websites, making it easier to avoid entering a malicious site. You won’t see harmful ads and pop-ups, and you will be prevented from accessing websites linked to illegal activities or those marked as unsafe in trusted databases. This tool makes life easier.”

Martyna Gaidelė, Product Marketing Manager at NordLayer

Click to tweet

NordLayer: So how can organizations monitor the dark web effectively?

Mary D’Angelo: Companies like Searchlight Cyber provide services to monitor the dark web safely and efficiently, helping businesses to protect themselves without risking exposure to malicious content.

7 stages of cyber-attacks

NordLayer: Can you share a success story related to dark web monitoring?

Mary D’Angelo: Our human intelligence team does a lot of the undercover work. Accessing some dark web sites is tough; it requires specific permissions. Our team managed to enter these sites and found someone selling domain access control credentials for a large US airline. They didn’t name the airline to avoid detection but shared details like the revenue size, location, and access type. High pricing often indicates legitimacy. Upon discovering this, I contacted the airline’s security team to alert them, despite them not being our client. We then discussed the intelligence, which was new to them, and together, we devised a plan to enhance their security.

NordLayer: That’s impressive. What security measures do you generally recommend to introduce? 

Mary D’Angelo: We generally suggest enforcing multi-factor authentication (MFA) across all platforms. The approach depends on the attack type, but ensuring MFA is in place is crucial so that only authorized individuals have access.

“Multi-factor authentication (MFA) is an essential part of NordLayer. However, we advocate for a broader range of multi-layered authentication solutions and encourage our customers to implement more comprehensive Zero Trust Network Access (ZTNA) strategies.

Multi-layered network access control minimizes the risks of data breaches and aids in achieving compliance certificates, contributing to business credibility as well.

My favorite NordLayer features for network access control are the Cloud Firewall and Device Posture Security. They are easy to use and powerful solutions, ensuring advanced network access control.”

Martyna Gaidelė, Product Marketing Manager

Click to tweet

Key insight #4: Ransomware groups are hiring, which means even more attacks in 2024

NordLayer: Have you observed any trends in the dark web, such as an increase in ransomware groups?

Mary D’Angelo: Last year, we saw ransomware groups increase their recruitment. This means that they only plan to increase their attacks. They now have larger budgets because they were so successful last year in terms of the ransom payments. And so now they have more purchasing power, they can buy better exploits and better credentials. Bad actors also have their AI tool, called fraud GPT, which can just more easily and quickly make very sophisticated attacks.

Related articles

 

In Depth

NordLayer insights: the making of a Black Friday cyber scam

14 Nov 20238 min read

NordLayer insights: the making of a Black Friday cyber scam

 

Partner Program

Capitalizing on threats & opportunities – now is the time to venture into cybersecurity

17 Aug 20236 min read

Taking advantage of threats and opportunities web cover 1400x800

 

NordLayer: How can businesses and law enforcement adapt to the evolving threat landscape on the dark web?

Mary D’Angelo: Understanding the tactics, techniques, and procedures (TTPs) of threat actors allows organizations to build more effective defenses. Monitoring threat actor movements helps in developing predictive security measures.

NordLayer: There is also a kind of “Robin Hood” mentality among some ransomware groups. Can you elaborate on this?

Mary D’Angelo: Interestingly, some ransomware groups adhere to a moral code, avoiding attacks on hospitals and focusing on other targets. This nuanced behavior among threat actors highlights the complex ethical landscape of the dark web.

Ransomware groups have been increasing their recruitment and budgets

NordLayer: Despite some groups avoiding healthcare targets, the sector remains highly vulnerable. Why is that?

Mary D’Angelo: The healthcare sector often faces the highest ransom demands, with many hospitals lacking the security infrastructure to defend against sophisticated attacks. The sale of access credentials to healthcare institutions is alarmingly common.

NordLayer: There’s also a trend where threat actors are shifting from dark web forums to encrypted messaging platforms like Telegram. Why do you think threat actors are choosing these platforms?

Mary D’Angelo: The shift to encrypted platforms like Telegram reflects threat actors’ increasing paranoia and desire to evade detection. As law enforcement and security firms improve their monitoring capabilities, actors seek new ways to communicate securely.

Healthcare sector and ransomware

NordLayer: How do you conduct research on the deep web and platforms like Telegram?

Mary D’Angelo: Our team utilizes a combination of human intelligence and proprietary automated technologies to gather intelligence from various platforms. This allows us to monitor threat actor activities across the deep web and dark web comprehensively.

NordLayer: What future research directions do you see for dark web intelligence?

Mary D’Angelo: Collaborating with security practitioners and academic researchers can lead to innovative strategies for mitigating risks and combating cyber threats. Future research will likely focus on predictive analysis and the development of more sophisticated defense mechanisms.

Encrypted platforms need increase

Key insight #5: for businesses to stay safe, they need all employees to be aware of possible attacks

NordLayer: What general advice would you give businesses to enhance their security?

Mary D’Angelo: Businesses should prioritize early detection of threats by monitoring for reconnaissance activities. Leveraging threat intelligence to understand the landscape and adopting a proactive security posture can significantly reduce the risk of attacks.

NordLayer: How important is cybersecurity awareness?

Mary D’Angelo: Cultivating a culture of security throughout an organization is crucial. Integrating cyber threat intelligence across all levels can inform strategic decisions and prioritize security measures, ultimately making it more difficult for threat actors to succeed.

Proactive security costs less

NordLayer: In conclusion, investing in cybersecurity is more cost-effective than facing the consequences of a ransomware attack.

Mary D’Angelo: Absolutely. The cost of proactive security measures is significantly lower than the potential losses from a successful cyber attack.

How NordLayer can help

NordLayer offers a comprehensive security approach, protecting your team with Threat Prevention from harmful sites, securing online activities with VPN, and ensuring appropriate access with Cloud Firewall. Beyond these tools, we advocate for adopting Zero Trust Network Access (ZTNA), Security Service Edge (SSE), and other cybersecurity frameworks to strengthen your defense. Our sales team is always here if you need any help along the way. 

Beyond NordLayer’s offerings, it’s essential to create a culture of cybersecurity, maintain up-to-date software, and use secure communication tools. Additionally, assessing your vendors through a Third-Party Risk Management Plan and restricting their access can significantly mitigate risks.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.