Skip to content

Blazing New Trails In Keeping Your Network Safe

zero-trust-model-tile

Not to brag, but 2022 was a banner year for us here at Portnox!  Not content with just having an award-winning cloud-native zero trust platform, we had several major releases that continue to raise the bar for zero trust solutions everywhere.

Tackling TACACS+ – as a Service!:

How do you keep network device administration from turning into a nightmare of changing password policies, too many people having too much access, and risking constant device lockouts?   

TACACS+, of course! After all, it’s the industry standard for making device access manageable.  

Portnox released the first ever cloud-native TACACS+ service, which combines Authentication, Authorization, and Accounting (AAA) services with all the benefits of a fully cloud-native platform – e.g. we work with the equipment you have, and no nights wasted for upgrades and patches.   

Our TACACS+ service offers seamless integration with your existing identity provider, as well as key features like privilege levels and executed command logging to make network device administration simpler than ever.  

Shining a Light on the Shadows: IoT Fingerprinting

IoT (Internet of Things) devices are inescapable at this point – everything from your fish tank to your fridge can connect to the internet.  The use cases for these devices span many industries – from IoMT (Internet of Medical Things) which can monitor your health and adjust medication in real-time, to IIoT (Internet of Industrial Things) which can track inventory down to the smallest screw in seconds, to the more familiar consumer IoT which lets you control your window blinds, thermostat, lights, and more from your phone.   

But as useful as these devices are, they present an equal number of security concerns, chief among them being visibility. That’s to say – how do you know when they’re connected to your network?    

Enter IoT Fingerprinting from Portnox – the first ever cloud-native fingerprinting service that requires no on-prem installation or setup whatsoever!  No more having to watch your network slow to a crawl while running a port scanner, or painstakingly troubleshooting how to deploy a listener. You will see your IoT devices and all the information you need – make, model, OS, firmware – and still maintain the magic of a cloud-native solution with no upgrades, patches, or maintenance taking up your free time.  

What’s our secret?  DHCP Gleaning! This is a process by which the switch listens in on DHCP requests when a device joins the network and asks for an IP and extracts information from the request that helps identify the device. Many enterprise switches support this (although they may not call it Gleaning specifically; that’s actually a Cisco term.)  

DHCP Goes Even Further 

While DHCP Gleaning is an excellent method of gathering critical information about your IoT devices, the downside is that not all enterprise switches support it. And that’s another tricky thing about IoT devices – they don’t respond to traditional monitoring protocols, they often ship with all ports closed, and you can’t install extra software on them. So how do you discover and fingerprint them on your network if you can’t take advantage of DHCP gleaning? 

Enter another first – Portnox’s SaaS-based DHCP listener! This makes IoT Fingerprinting truly vendor agnostic, as any switch worth its salt will be able to configure a DHCP helper (sometimes called a DHCP relay agent or forwarder.) With a simple configuration, your device will listen for DHCP and BOOTP broadcasts and forward them to our DHCP listener. And when we say simple configuration, we mean it – here’s a sample from a Cisco IOS router:

ROUTER> ENABLE
ROUTER# CONFIGURE TERMINAL
ROUTER(CONFIG)# INTERFACE VLAN2
ROUTER(CONFIG-IF)# IP HELPER-ADDRESS 20.85.253.96  

Just 4 simple lines and you’re ready to go. Most devices support the configuration of more than one listener, too, so if you already have one set up for something else you can still take advantage of our cloud-based listener.   

Wearing Shades for the Future 

We’re pretty proud of these features, but we obviously have no intention of resting on our laurels.  We have a lot of exciting things planned for 2023 to continue our commitment to protecting your weekends from maintenance and upgrades with a cloud-native, vendor-agnostic, feature-rich, zero trust, network access control platform.  

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

NIST Releases New AI Risk Framework to Combat Emerging Threats from Malicious AI

ztda-tile

 

For most of history, our species has found creative ways to use technology for both bad and good. For example, we can harness nuclear energy to produce vast amounts of clean energy, helping to reduce our reliance on fossil fuels. But we can also use nuclear power to create devastating weapons of mass destruction.

The same is true for many other technologies. Is the internet a way to unite people and revolutionize how we access information? Or is it a tool for cyberbullying, identity theft, and spreading misinformation? Well, it’s both.  

Now it’s AI’s turn to fall to the dark side. AI has the potential to transform industries, revolutionize the way we work, and improve our daily lives. And that’s precisely why it’s generated so much buzz in recent years. However, it’s also caught the attention of cybercriminals intent on using it to create AI malware, AI ransomware, and for a range of other deleterious purposes.

But how exactly are cybercriminals leveraging advanced AI tools like ChatGPT? And what are reputable industry bodies like NIST doing to stop them? Let’s get into it.  

ChatGPT & The State of Malicious AI Today 

Open AI’s ChatGPT has garnered much attention recently, with the tool reaching over one million users in just five days of its launch. But while most people are using the impressive AI for fun or to improve their workflow, cybercriminals are using it for more nefarious purposes, including:  

Phishing and spamming: Bad actors could use ChatGPT to generate convincing phishing emails or messages to lure victims into clicking on malicious links, downloading malware, or providing personal information. It can even help create convincing-sounding emails impersonating high-ranking individuals, like a CEO.  

Malware development: Cybercriminals could use ChatGPT to create more sophisticated malware that can evade detection by traditional security measures. In January 2023, Checkpoint outlined how fledgling and seasoned cybercriminals were using the chatbot to create infostealers and encryption tools.  

Scamming: ChatGPT could create convincing scams, such as investment or romance scams, that could trick victims into sending money or providing sensitive information. 

Automated attacks: Cybercriminals could use ChatGPT to automate brute-force attacks or password cracking, making it easier and faster to breach security systems. 

It’s important to note that OpenAI takes measures to prevent its technology from being used for malicious activities by working with law enforcement and security organizations and implementing ethical guidelines. So, for example, if you explicitly ask, it won’t write malicious code. Still, cybercriminals are finding ways around this. For example, some developers experimenting with ChatGPT found that if you detail the steps of writing the malware instead of giving a direct prompt, the AI will construct the malware for you.  

Perhaps the most dangerous thing about ChatGPT from a cybersecurity perspective is that it allows anyone to be a hacker. Before AI, there were several barriers to entry for becoming a hacker. For example, you would need technical skills like knowledge of computer programming and networking and access to specialized tools and resources, usually obtained on the dark web. But AI is helping bridge these gaps even for people with minimal hacking experience.  

The Rise of AI Malware, AI Ransomware, & Sophisticated Attacks 

While security-conscious companies and security researchers are busy finding new and increasingly advanced ways of safeguarding systems, cybercriminals are busy finding ways to bypass these advancements. It’s a constant game of cat and mouse. And the result? Increasingly sophisticated cyberattacks.  

Cybersecurity researchers have already found evidence of well-known cybercriminal gangs hiring pen testers to help break into company networks. The notorious ransomware gang Conti (who racked up a terrifying $182 million in ransomware payments in 2021) is one such group thought to be reinvesting its earnings into hiring experienced tech professionals.  

A natural next step for cybercriminals will be to hire ML and AL experts to create advanced malware campaigns. Cybercriminals may use AI to automate large portions of the ransomware creation process, allowing for accelerated and more frequent attacks. And then we have true AI malware and AI ransomware. This is where hackers create situationally aware malware that analyzes the target system’s defense mechanisms and quickly learns and mimics everyday system communications to evade detection. 

NIST’s New AI Risk Management Framework 

On January 26, 2023, The National Institute of Standards & Technology (NIST) issued Version 1.0 of its Artificial Intelligence Risk Management Framework to enable organizations to design and manage trustworthy and responsible AI. But what is this framework all about? 

The AI RMF divides into two parts. The first part frames the risks related to AI and outlines trustworthy AI system characteristics, while the second part describes four specific functions — govern, map, measure, and manage. These four functions are further divided into categories and subcategories and help organizations address AI system risks in practice. In addition, organizations can apply these functions in context-specific use cases and at any stage of the AI life cycle, making them versatile tools.  

Crucially, NIST’s AI Risk Management Framework focuses on changing how we think about AI. It outlines seven characteristics of trustworthy AI, including “Safe” and “Accountable & Transparent,” which are particularly relevant to AI’s use in cybercrime. The “Safe” section emphasizes the importance of designing AI systems that do not cause harm to humans, property, or the environment. Meanwhile, the “Accountable & Transparent” section requires that information and outputs from AI systems be available to all users. This helps prevent cybercriminals from manipulating the AI into providing responses that other users could not elicit. 

Final Thoughts 

The growing use of AI by cybercriminals has led to the emergence of new threats, such as AI ransomware and AI malware. These pose a significant risk to organizations and individuals alike. However, the new NIST AI Risk Management Framework provides a comprehensive approach to addressing these risks. By following its guidelines, organizations can mitigate the threats posed by malicious AI and ensure the development of trustworthy AI systems. As AI technology continues to evolve, organizations must take steps to protect themselves and stay up-to-date with the latest risk management strategies. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

AI-Powered Identity Authentication Is Here: What You Need To Know

It should come as no surprise that identity authentication is one of the most critical aspects of doing business in the digital age. Without verifying your users are who they say they are, you leave the doors open for fraud, data breaches, and harmful cyber attacks. But with the advent of AI, identity authentication is going through a transformation. To understand how, let’s dive into everything you need to know about AI authentication.

How Is AI Helping With Identity Verification?

Traditional authentication methods are becoming less effective today due to high levels of password reuse and the increasing number of stolen credentials available on dark web databases from previous data breaches. Luckily, AI can provide better, more secure authentication by going beyond traditional boundaries and incorporating data context, biometrics, and patterns in user behavior.

What Are the Different Types of AI Authentication?

Biometric authentication is especially popular with cyber-defense-minded companies today, and AI plays a huge role here. Some examples include keystroke dynamics (typing pattern), behavioral biometrics (analyzing user behavioral patterns to create cyber fingerprints), facial recognition, and voice recognition.

Behavioral biometrics, in particular, is quickly becoming the favored type of AI verification today. Why? Because behavioral biometrics can provide continuous authentication by tracking and verifying user behavior like typing rhythm, mouse movement, and device usage patterns. In addition, it also provides a more seamless and frictionless authentication experience, as it doesn’t require users to remember or enter passwords.

And critically, these identity authentication tools are only possible with artificial intelligence and machine learning. These technologies rely on highly precise authentication driven by large data sets and advanced algorithms. And as a result, they’re almost impossible for fraudsters to bypass.

How do AI Authentication Systems Mitigate AI Bias?

AI bias” refers to the tendency of artificial intelligence algorithms and systems to perpetuate and amplify existing biases and discrimination in the data they are trained on and in the decisions they make.

There are several ways in which AI authentication systems can mitigate bias:

  1. Diverse training data: Using a diverse and representative dataset for training the AI system can help reduce bias and improve accuracy for underrepresented groups.
  2. Fairness algorithms: These algorithms can help identify and address bias in AI systems by balancing accuracy across different demographic groups.
  3. Human oversight: Having human oversight and review in the development and deployment of AI systems can help ensure that potential biases are identified and addressed.
  4. Regular monitoring and evaluation: Regular monitoring of the AI system’s performance and outcomes can help identify any potential biases that may emerge over time and allow for appropriate corrective actions to be taken.
  5. Transparency and accountability: Making AI systems transparent and accountable can help increase trust in the technology and promote responsible use.

These measures can help mitigate AI bias in authentication systems and ensure that they are fair, unbiased, and effective in protecting the privacy and security of users.

Final Thoughts

The use of AI in cybersecurity is nothing new, but it is becoming increasingly powerful and more widespread. Today, more and more companies are looking to AI authentication to help safeguard their systems from nefarious actors.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

How Does Passwordless Authentication Fit With Zero Trust Security Models?

Will 2023 be the year we finally eliminate passwords? For the last decade, cybersecurity experts have both been pushing for and predicting that a passwordless future is just around the corner. However, while passwords have been declining in recent years in favor of more robust forms of authentication, an entirely passwordless future has yet to materialize.

But that all could be set to change with the increased adoption of zero trust security models. Zero trust does away with implicit trust and requires all users and devices, whether inside or outside the corporate network, to be continuously authenticated and authorized. And critically, zero trust is also starting to mean zero passwords. But why?

Let’s dive into why passwordless authentication is important and how it fits into zero trust security models.

What is Passwordless Authentication?

As the term suggests, passwordless authentication is a way of verifying a user’s identity with something other than a password. Common types of passwordless authentication include email-based or SMS-based one-time codes, multi-factor authentication, and biometrics.

Biometrics are increasingly favored over other types of passwordless authentication because they’re virtually impossible for hackers to imitate, and they reduce user friction. Some examples of biometric authentication include retinal scans, voiceprints, facial recognition, fingerprint scans, and biometric mouse movements.

As the term suggests, passwordless authentication is a way of verifying a user’s identity with something other than a password. Common types of passwordless authentication include email-based or SMS-based one-time codes, multi-factor authentication, and biometrics.

Biometrics are increasingly favored over other types of passwordless authentication because they’re virtually impossible for hackers to imitate, and they reduce user friction. Some examples of biometric authentication include retinal scans, voiceprints, facial recognition, fingerprint scans, and biometric mouse movements.

Why Use Passwordless Authentication?

Here’s what it comes down to; passwordless authentication is simply more secure than password-based authentication.

While businesses have relied on passwords for decades, they’re no longer considered a secure way to protect our accounts and corporate networks. For example, 44% of employees reuse passwords across personal and work-related accounts. Moreover, most passwords are extremely easy to guess – the top five passwords globally are “123456”, “Password,” “12345678”, “qwerty,” and “123456789”.

As a result, hackers have long favored password attacks to breach corporate networks or personal accounts. Many different password attack methods exist, but the most common are:

  • Brute-force attacks: This hacking method uses trial and error to crack passwords, typically using lists of common passwords or leaked passwords obtained from the dark web.
  • Surgical attacks: These are a type of targeted attack where the hacker researches the intended victim, scouring their public accounts to find key details like their birthday, favorite sports team, hobbies, names of their children, etc., that the user may use in passwords.
  • Phishing/Social engineering: Here, cybercriminals pose as a trusted entity like a well-known company or another employee and trick the target into sharing their login details via a fraudulent login screen. Other methods include sending emails with a malicious link that automatically installs key-logging malware on the victim’s computer.

But by opting for passwordless authentication, you can eliminate or vastly reduce the risk of falling victim to these types of attacks.

There are also other reasons to move away from passwords. For example, passwordless authentication is more convenient for workers because it leverages something the user has or something inherent to them, eliminating the need for them to remember anything. This also means employees can log into devices faster.

Rising Zero Trust Adoption

72% of organizations are in the process of adopting zero trust or have already implemented it. Moreover, an eye-watering 90% of organizations say that advancing zero trust is one of their top three IT and security priorities. But why exactly is zero trust becoming so widespread?

Adopting a zero trust approach can the cost of a data breach by approximately $1.76 million and offer boosted efficiencies that amount to savings of 40 manhours per week. Moreover, companies that leverage zero trust network segmentation (an element of ZTNA) are two times more likely to avoid critical outages due to security incidents.

Undoubtedly, the need for continuous authentication is rising as remote working, and distributed workforces become more common. Zero Trust Network Access (ZTNA) is a critical set of technologies and functionalities here, enabling remote users to access internal applications securely. ZTNA is fast becoming essential for businesses in the modern world.

Can You Have Password-Based Zero Trust?

Yes, and many organizations do. However, cybersecurity experts are now warning that password-based zero trust does not meet the defense demands of the increasingly severe cyber threatscape of today.

Why Passwordless Zero Trust Is the Way Forward

Here’s the bottom line. Passwords are not only weak forms of security, but they also make your zero trust program slower, more expensive, and less effective.

Passwords require more tools, which drives up costs. Additional tools demand more administrators, new user licenses, and often more training for users and the help desk. All of these factors result in a more expensive security program.

Additionally companies that use passwords in conjunction with MFA often still have security gaps. This is typically because legacy systems or otherwise awkward technologies don’t play well with some MFA tools, leaving specific corporate systems protected only by passwords. There can also be MFA gaps in workstation login, VPNs, RDPs, and VDIs or IoT devices where passwords are the default.

Lastly, there are resource constraints involved with managing robust password-based security. IT and security teams are often understaffed and overwhelmed, and the current cybersecurity skills gap exacerbates this problem. Moreover, rising economic uncertainty puts more pressure on businesses of all sizes to reduce their IT budgets and take cost-cutting measures.

In this increasingly severe climate, security teams are feeling the pains of passwords more than ever before. By taking passwords out of the equation, organizations can reduce the labor burden on already over-stretched security workers and give them more time to spend on proactive cybersecurity measures.

Final Thoughts

Credential stuffing may be one of the oldest attack methods, but it’s still going strong today. For example, credential stuffing attacks became so prevalent in the first quarter of 2022 that attack traffic surpassed legitimate login traffic in some countries. And equally concerning, the first half of 2022 saw more attacks against MFA than any previous year.

Simply put, cybercriminals are increasingly targeting our traditional defense measures, namely passwords and MFA. As a result, companies embarking on their zero trust journey need to move away from passwords and weaker forms of MFA in favor of more robust passwordless authentication.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

Understanding the Ins & Outs of Cyber Risk Quantification

Introduction

In today’s digital world, cyber risk is high and growing. The best way to control this risk is with a proactive cyber security strategy that quantifies and measures your company’s vulnerability to theft, fraud, or data breach.

The cyber threat landscape is diverse, and there is a wide range of potential threats in this sector, such as intellectual property theft, ransomware, data breaches, DDoS attacks, and insider threats. As cyber criminals improve on new methods for making threats, it is therefore important for cyber security professionals to be on top of where the latest threats are to hide from evolving threats. But for a company to achieve this, it must first understand the risks of cybersecurity, be vigilant in its security stance, and be aware of its accompanying risks.

Cyber risk quantification (CRQ) is the primary route to understanding the cyber threat landscape and mitigating risks within a cyber security environment. Cyber risk quantification is also part of Cyber Security Risk Management and is a crucial part of an organization’s overall security posture. It involves assessing risks relating to various cybersecurity topics, such as vulnerabilities, threats and impacts. Quantification addresses measurement, tracking and reporting on the risks relating to specific topics to prepare for cyberattacks effectively.

Risk quantification is determining how likely a threat or attack is to be successful against your organization and then assessing the severity of such an event. Cyber risk quantification is a part of this process, and it pertains specifically to threats that target information on computer networks or in physical systems, like computer networks or smartphones. These include both internal threats (such as employees) and those from external sources (hackers).

Risk quantification is an enterprise tool to help them understand their existing cyber risk environment. It also enables them to devise effective strategies for reducing those risks by implementing appropriate controls.

 

What is Cyber Risk Quantification?

This process of cyber risk quantification has been described as a three-step process: identifying the “pen-testing assets”, counting vulnerabilities, and measuring the potential threats. These steps represent a holistic approach, allowing a comprehensive view of one’s cyber risk posture and its vulnerabilities, threats, and risks.

At its core, cyber risk quantification is not a specific set of rules or methodologies but rather a method for conducting a rigorous, in-depth analysis of subjecting any IT infrastructure. The intent is to obtain objective evidence to develop strategies for reducing risks and ultimately strengthening an organization’s cyber resilience.

Benefits of Cyber Risk Quantification

Cyber risk quantification is important in ensuring that cyber threats are understood and can help cyber security teams analyse vulnerabilities and risks and create cyber risk mitigation strategies. The following are the benefits of cyber risk quantification.

Provides Insights into Vulnerabilities

An analysis of the information technology assets allows companies to understand their cyber risk posture and quantify their security vulnerabilities. The process makes companies feel more secure in knowing they are not as vulnerable as they originally assumed.

Helps Identify & Mitigate Threats

Cyber risk quantification is a process that helps identify the number of potential threats within an organization. It helps determine what the company needs to do to prevent a cyber attack.

Provides Information for Basing Decisions

The cyber risk quantification process allows the creation of an actionable and detailed plan for organizations to make informed decisions about protecting themselves from cyberattacks.

Helps Identify the Need for Resources

Companies can use the cyber risk quantification process results to determine what resources are required to reduce or eliminate current organizational threats and vulnerabilities.

Risk Management Decision

After a cyber risk quantification process, one can better understand their current security posture and related cyber risks to well-informed decisions about reducing this risk.

Automating the Process

Can automate cyber risk quantification to save time and labour. It means that technicians will not have to spend time performing cyber risk quantification on each piece of information technology equipment.

Cost-Effective

The overall cost of implementing cyber risk quantification will not be much more than processing a security vulnerability assessment.

 

Determining the Company’s Cyber Tolerance

Can use the information obtained for identifying and developing cybersecurity strategies for the foreseeable future. It means that the consequences of an attack during this planning period are less severe than those that would experience after a cyber attack once an organization has planned out their cyber security strategy.

Determining the Potential Cost of a Cyber Attack

Companies can use cyber risk quantification to estimate the cost of a successful attack and use this to determine how much money should be allocated towards mitigating the impact of an attack.

Planning Effective Training Programs

The results of a cyber risk quantification process can be used to create more effective training programs and plan for an organization’s IT infrastructure training needs.

 

How to Leverage on Cyber Risk Quantification

Cyber risk quantification can be leveraged on the following levels:

Organizational Levels

The senior management of an organization needs to determine the organizational level of cyber risk quantification. The level at which this model is used will depends on how large and how organized an organization is.

For example, an enterprise with thousands of employees or many systems will benefit from applying this model at a higher level (e.g., enterprise-wide) than a smaller company that runs just one corporate system.

Site Level

Organizationally focused cyber risk quantification methods can be applied to each site. It is the level at which most companies are structured; they have one or a few locations and may have dozens of sites. The IT personnel at each site may also not have direct access to all the data needed for an effective cyber risk quantification model.

Process Level

Many organizations are involved in processing large amounts of data (e.g. processing credit card information or handling employee information). These organizations can apply the same data processing methodologies to cyber risk quantification and perform a different amount of manual data analysis.

Asset Level

Cyber risk quantification can be applied to a specific asset (e.g., a server, router, switch). It is an effective method for performing cyber risk quantification on small network environments or those with limited access to the underlying devices on a network.

Information System Level

This level is useful for the entire IT infrastructure. Most organizations would benefit from a more holistic enterprise approach to cyber risk quantification.

Individual Asset Level

Some organizations may have large network environments that do not need a holistic enterprise-level approach to quantifying cyber risk. Some systems are relatively small and easy to manage individually with minimal use of IT resources.

Application Component Level

An individual application component (e.g. a web server) is typically not a significant resource on its own, and it has unique vulnerabilities that need to be fixed. In most instances, cyber risk quantification of an application component will include looking at its counterpart components. It would be a rare occurrence for those performing cyber risk quantification on an individual asset level.

Challenges of Cyber Risk Quantification

Cyber risk quantification is a challenging task because of the numerous variables can have an impact on how risks are quantified. Some of the most common factors that have to be considered when performing cyber risk quantification include:

Data Visibility

The amount of data for analysis is often limited in the cyber risk quantification process. It means that the available data has to be collected from a relatively small number of sources and then analyzed using an automated method.

Can’t Calculate Risk

Cyber risk quantification could be a better science. Often, organizations will need a higher level of understanding concerning the vulnerabilities they are trying to quantify and the impact a successful cyber attack would have on their company.

Partial Remediation

Sometimes, a company can perform some level of remediation, but not all of its IT infrastructure components. It is often the case in smaller companies where policy and security costs can be very high.

Time Frame of Analysis

Cyber threat intelligence is always changing, and so is the level of risk for an organization, even for an asset within that organization. Cyber risk quantification models must be set up to keep pace with these changes.

Data Manipulation

The information is also analyzed against other data that has been manipulated and stored for analysis. While this does not mean that all data is manipulated, it does mean that some data may have been tampered with or changed to alter the analysis’s findings (e.g., personal information).

No Consistent Methodology

Cyber risk quantification is not an exact science; therefore, it cannot be performed consistently.

No Standardization

The model used for cyber risk quantification may depend on the organization and the structure of its IT infrastructure. It is challenging to translate results from one organization to another or even use it across various industries.

No Known Method

Studies have shown that industry and IT experts do not widely accept any known cyber threat quantification methodology.

 

Conclusion

Cyber risk quantification stands as an emerging field in cybersecurity, that will undoubtedly play an increasingly crucial role in the future of cybersecurity for assessing organizational risk before potential attacks occur.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。