Skip to content

How much money is your data worth?

If you had to put a price on your data—say, your ID number, or one of your social media passwords—what would you say it’s worth? Would it shock you to learn that, if it ever got leaked, it could be sold on the dark web for just a few bucks? Well, buckle up then… because it only gets worse.

It’s a black market, not an auction

We all think our data is super valuable—after all, it’s ours. Companies like Google and Facebook think so too, using it to personalize experiences, fine-tune algorithms, and make their ads more relevant. You’d probably assume that means your data is worth a lot of money, especially with everyone saying that “data is the new oil.” But the reality is that some of it might not hold much value to hackers on the dark web. How so?

The dark web is packed with tons of data being traded all the time. So if yours got leaked, it could just be another piece in the pile. That doesn’t mean it wouldn’t get picked up and used against you—it just means someone might not have to pay much for it. Harsh, we know, but true. With no rules or oversight in illegal markets, even the most sensitive info could sell for a shockingly low price.

What data is sold on the dark web?

The types of data you’ll find on dark web markets range from the obvious—like stolen passwords, business credentials, bank statements, credit card details, emails, bills, and ID cards—to the less expected, like user account activity, browsing history, utility bills, license plate numbers, and store receipts.

To put it differently, if there’s information about a person or a business that exists somewhere online, it can end up for sale on the dark web. It’s that simple.

The price tag on different types of stolen data

Cybercriminals price data depending on the type and what they can achieve with it. Therefore, in general, they place less value on passwords for personal social media accounts than on things like IDs or health insurance cards.

Not too long ago, experts at NordLocker analyzed a dark web marketplace to get an idea of the average prices for various stolen items. The table below shows their findings. Keep in mind, however, that there are at least 30 major dark web markets, and their listings are always being updated with new items and prices.

Type of dataAverage price
Bank statement$12.30
Utility bill$13.00
VPN account$12.90
Store receipt or invoice$10.00
License plate$100.00
Health insurance card$9.90
Check$98.00

To give you a few more examples: according to Privacy Affairs’ Dark Web Price Index, credit card details with an account balance of up to $5,000 sell for around $110 on the dark web. Crypto accounts range from $20 to about $2,500, while stolen logins to platforms like Spotify, HBO, Hulu, and Airbnb can go for as little as $1 to as much as $300.

Of course, most of this is personal data, but business and enterprise data is also being sold on the dark web. We’re talking digital items like API keys, RDP passwords, cloud infrastructure logins, and other things that could give hackers access to a company’s IT systems and sensitive information. And the prices? They can range from $500 to over $100,000, depending on the size of the targeted company and the potential impact.

Fact: cheap data can actually be worth more

What’s important to know—and also terrifying—is that the same piece of data can be worth much more than what it initially sells for on the dark web.

As explained by Daniel Kelley—a former black-hat hacker turned cybersecurity educator—in a recent AMA on Reddit, personal passwords for consumer accounts like Netflix usually go for just $5 to $25. However, if someone is reusing their Netflix credentials for something more valuable, like a work account or business platform, suddenly that $5–$25 password could be worth hundreds of thousands of dollars.

The point is, data that goes for next to nothing on the dark web can end up being a goldmine for cybercriminals. If those stolen credentials work across multiple business accounts or systems, it could cost attackers just a few dollars to cause millions in damage to targeted organizations.

How does your data end up on the dark web?

Cybercriminals have a few go-to methods for getting their hands on personal or company data and selling it on the dark web. One of the most common is using malware—like Trojans, spyware, keyloggers, and stealers—which are specifically designed to steal passwords, credit card details, crypto wallet keys, and other sensitive data.

Malware threats usually spread through phishing emails with malicious links or attachments, fake websites, or even disguised as software updates. Once installed, they can scan the system, sift through files and browsers, record keystrokes, take screenshots—and do it all quietly, without the user ever realizing it’s happening.

Another way data—especially business data—gets compromised is when databases or code repositories are left exposed online. Misconfigured cloud storage or weak access controls can leave the door wide open for attackers to swoop in and take whatever they find. Once they’ve obtained the data, the next step is to upload it to the dark web, put a price on it, and wait for the buyers.

What can you do to prevent data exposure?

While everything we’ve covered so far may be overwhelming and spine-chilling, rest assured that you are not without options. There are several habits you can quickly adopt to protect your data from being exposed and sold on the dark web. Here are a few important steps to consider:

Don’t interact with suspicious emails and websites

We’ve all come across fake websites and scam emails at some point—it’s how we respond to them that matters. If something looks fishy, off, or just doesn’t feel right, don’t engage. Don’t click on any links, don’t enter your info, don’t log in with your Google or Facebook account. Just steer clear and avoid any interaction.

Avoid oversharing information online

Putting a spin on a popular saying: “What happens online, stays online.” This means that if you share something in the digital world, it’s highly likely that a trace of it will always remain. So, be mindful of what you share online. You never know how much information attackers might use to try to trick you with their advanced social engineering techniques.

Enable multi-factor authentication (MFA)

Relying on just a password to protect your accounts isn’t enough these days, especially if your passwords aren’t exactly strong. That’s where multi-factor authentication steps in. It adds an extra layer of security by requiring additional proof of identity (like a code sent to your phone) to confirm that it’s really you trying to log in. This means that even if someone gets hold of your password, it’s much harder for them to actually break in and steal your data.

Set up data breach alerts

One of the most important steps in solving a problem is knowing it exists in the first place. If your data has been compromised, the sooner you find out, the better your chances of minimizing the damage. For example, if you learn that your login credentials have been posted on the dark web, you can try to change your passwords before anyone has a chance to use them. Or, if something like your scanned ID card shows up, you can alert the authorities and start the process of getting it replaced. That’s why it’s smart to use the dark web and data breach monitoring tools, like NordPass’ Data Breach Scanner. They automatically scan the web for any signs that your data has been compromised and alert you right away if they detect anything suspicious.

Use a password manager

You really can’t afford to rely on old, weak, or reused passwords to protect your online accounts. What you need is a robust password manager like NordPass to keep things safe. It lets you create strong passwords for all your accounts and store them—along with your passkeys, credit card info, and other sensitive data—in a secure, encrypted vault. Plus, with handy features like autofill and Secure Sharing, you’ll be less likely to accidentally type your credentials into a fake website or send them through unprotected channels. If you want to protect access to your accounts, this is the way to go.

And how can businesses protect themselves?

For businesses, especially enterprises, defending against cyberattacks and preventing data from leaking into the dark web is no small task. But there are a few steps every organization can take to help avoid exposing sensitive company information. Those are:

Educate your employees

Human error is still a major cause of data breaches. So, investing in security training for your team is essential. It helps your employees realize how one small mistake can put the whole company at risk, and shows them how to use defense tools and follow processes so they can work efficiently and make smart cybersecurity choices.

Establish strong access controls

To protect your company from leaks, you need to know what information is shared, who it’s shared with, and why. You also need strict access rules based on the zero-trust principle—no one gets easy access, and everyone has to be authorized to get in. You can use tools like NordPass to keep track of how access is granted, managed, and shared across your teams—and revoke it if things start to go too far. This will help you limit and effectively secure access points to your company’s data.

Always keep your data in a truly safe place

Just like today’s data privacy laws, like HIPAA and GDPR, require your company to handle and store customer data securely, your internal security policies should do the same for all company data. That means making sure your company’s digital resources are stored in a secure environment where only authorized people can access them.

This can be achieved through encrypted cloud servers, a segmented network with monitored access points, and tight control over who can access sensitive information. Not only does this keep your data protected—it also shows clients and partners that they can trust you to keep their data safe and sound.

Bottom line

Some stolen digital goods are available for purchase on the dark web at shockingly low prices, like $5–$25 for a stolen online account password. Depending on the potential impact, prices can increase, especially for items that could give attackers access to a company’s IT infrastructure and databases.

Still, the cost of stolen data on the dark web is minimal compared to the illegal profits attackers can make and the financial damage they can cause to individuals and organizations. That’s why, whether you’re a regular Internet user or a large-scale company, you need to invest in strong cybersecurity tools and be vigilant about your online activities to minimize your digital footprint and prevent data leaks.

 

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

What is the Principle of Least Privilege (PoLP)?

How does the principle of least privilege work?

Technically speaking, the principle of least privilege—often called the minimum privilege principle—is rooted in the Zero Trust security philosophy. Access is restricted not only to specific resources and data but also to application functions, so users see only the features they need.

  1. Identify essential job functions and map out the precise permissions required for each role.

  2. Allocate minimal privileges to users, granting access only to the data, systems, and application features critical for their tasks.

  3. Monitor and adjust privileges over time, especially as roles evolve or employees join and leave.

By integrating PoLP with Zero Trust Network Access (ZTNA) 2.0, organizations can dynamically verify every access request, reducing the risk of privilege misuse and lateral movement by threat actors.

Why is the principle of least privilege important?

Let’s look at a hypothetical situation. Say an HR employee has access to the human resources management system to update employee records. But if they also have access rights to access the IT infrastructure, which are not essential for their HR-related tasks, the risk of a full-blown data breach increases significantly in the event their account is compromised.

The hypothetical above showcases the principle of least privilege benefits, which include:

  • Reduce the potential attack surface: Limiting user access privileges means fewer opportunities for bad actors to exploit those privileges.

  • Minimize the impact of exploits: Even if a hacker can gain unauthorized access to the user’s account, the security principle of least privilege confines the possible damage.

  • Come closer to adhering to regulatory frameworks such as GDPR and HIPAA: Regulatory frameworks such as GDPR and HIPAA require strict access controls. By applying PoLP and ensuring users have access only to the information and systems essential for their tasks, an organization can get closer to being compliant with various regulations.

  • Improve security within the hybrid work environment: In a hybrid work environment, where employees access systems remotely, maintaining strict access controls becomes even more important. Implementing the principle of least privilege ensures that the security risks associated with remote access are reduced significantly.

Zero Trust vs Least Privilege

In modern digital security, Zero Trust and the principle of least privilege in cybersecurity are the two sides of the same coin. Zero Trust demands that every access attempt be continuously monitored and verified, while PoLP ensures that, once granted, access remains narrow and appropriate.

Zero Trust is a cybersecurity concept built on another simple idea: never trust, always verify. Unlike the traditional security frameworks, Zero Trust Security assumes that threats can come from within as well as outside the network.

At its core, Zero Trust embodies the principle of least privilege by enforcing strict access controls and permissions. Every access or connection request, regardless of origin, is treated as untrusted until verified otherwise. This stringent verification process is an extension of PoLP’s main idea — to provide users with only the necessary access levels.

In practice, Zero Trust treats every access request as if it’s the first request coming from an untrusted network. Each request is always re-authenticated regardless of previous requests or connections. In this sense, you can think of Zero Trust as a dynamic framework while PoLP can be considered static because it provides users with specific access rights that remain the same unless adjusted.

To make the distinction between Zero Trust and PoLP clearer, let’s imagine a high-end office building. In this case, Zero Trust would be the foundation of the building’s security system, which requires employees, regardless of their position, to use an access card to enter the office building and other facilities. The principle of least privilege, in this scenario, could be likened to the specific programming of access cards based on the employee’s role: for instance, providing the IT staff with access to server rooms, while not granting the same privileges to, say, the marketing team.

 

What is Privilege Creep?

Privilege creep is a term that refers to a user who gradually accumulates more access rights than are required to execute their function. Privilege creeps most often comes into being due to role changes that do not trigger an adjustment concerning access privileges. When thinking about organizational cybersecurity, privilege creeps pose a serious risk where unauthorized access to a single account could lead to an enterprise-wide data breach.

Here are best practices when it comes to the principle of least privilege, helping to prevent privilege creeps from materializing:

  • Implement role-based access controls: Clearly define roles and associated permissions to make sure access rights are granted based on the necessities of the job.

  • Conduct regular access reviews: Schedule periodic reviews of user privileges to identify and rectify any discrepancies or excessive access rights.

  • Enforce a Zero-Trust security approach: Adopt a zero-trust policy where no user is trusted by default. Verify every access request, regardless of the user’s position within the organization.

  • Make use of automated tools: Leverage automation for managing access rights. Tools like Privileged Access Management (PAM) systems can help in monitoring and controlling access rights efficiently.

  • Promote security awareness: Educate employees about the risks of privilege creep and the importance of adhering to cyber security protocols.

By proactively managing user permissions and educating employees, you can significantly mitigate the risk of privilege creep and enhance your organization’s overall security posture.

How to Implement the Least Privilege Principle in Your Organization

Adopting the principle of least privilege in your organization can be a lengthy process; however, the juice is well worth the squeeze. Once your organization operates under PoLP, the potential attack surface will shrink significantly. Here are a few best practices when it comes to the implementation of PoLP:

  • Define access requirements clearly: Before adopting the principle of least privileges in your organization, you need to have a clear understanding of the data access needs of various roles within the organization.

  • Implement Role-based access control (RBAC): Once you have a clear understanding of access requirements, setting up RBAC will be a lot easier. You’ll need to create roles based on job functions and assign permissions to these roles rather than for individual users.

  • Utilize Just-In-Time (JIT) privilege access: Enhance security by granting time-limited privileges on a need-to-use basis. Establishing JIT access privileges will restrict the window of opportunity for access to sensitive data, minimizing the risk of insider threats or external breaches that would exploit user access privileges.

  • Enforce Multi-factor authentication (MFA) and password policies: Strengthen the authentication processes by establishing MFA as an additional layer of security next to company-wide password policies. MFA ensures that even if the password of a critical account is compromised, the attackers will not have a chance to access it as they will not have another authentication factor required.

  • Implement system monitoring: Establish surveillance of system and user activities to quickly identify and respond to abnormal access patterns or potential security incidents.

How can NordPass help?

These days, when access points seem to multiply as fast as potential security threats, adopting the principle of least privilege within a business setting should be a no-brainer. PoLP implementation can reduce, quite significantly, the organization’s attack surface and generally improve overall cybersecurity. There’s also the added benefit of coming closer to compliance with various regulatory frameworks such as HIPAA or GDPR.

While the adoption of PoLP can be challenging, there are tools that can make this a lot easier and NordPass Enterprise is one of them. It’s an enterprise-grade password manager that’s built on the principle of the Zero-Knowledge architecture and is equipped with the XChaCha20 encryption algorithm.

But that’s just the tip of the iceberg. NordPass’s integration with Single Sign-On (SSO) is a key asset in adopting PoLP. By allowing users to use a single set of credentials to access multiple resources, SSO simplifies authentication and enhances security. NordPass Enterprise is compatible with major identity providers such as Microsoft Azure AD, MS ADFS, and Okta. This centralized management system is effective in preventing unauthorized access and minimizing potential security breaches by assigning user access based on specific roles.

NordPass also helps organizations in managing user access effectively. It allows administrators to assign, revoke, or modify user access to login credentials, personal information, payment card data, and other sensitive data according to specific needs. This flexibility, powered by the Activity log feature, is critical when adopting PoLP. For teams looking to streamline this process and enforce access control across departments, NordPass Teams offers practical, scalable solutions. It’s particularly useful for IT managers and decision makers aiming to balance ease of use with advanced security protocols. Thanks to this functionality, organizations can easily adjust access rights in response to changes in roles or employment status.

Learn more about how NordPass Enterprise can benefit your organization’s overall security strategy by visiting the official NordPass Enterprise website.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Why AI ransomware is a new type of threat

Ransomware isn’t what it used to be

The origins of ransomware go back to the late 1990s, when the blueprint for an attack first took shape—using malicious software to block a user’s access to a computer system or encrypt their data, then demanding payment to restore it.

Over the years, ransomware attacks have become increasingly sophisticated. In the mid-2000s, cybercriminals relied on fake ads and deceptive websites to trick users into downloading ransomware-infused antivirus software. Later on, ransomware evolved into worm-like threats capable of spreading rapidly across organizational networks.

Fast forward to today, and we’re dealing with AI-powered ransomware. So, it’s no longer just about scrambling files—it’s about smart, targeted attacks that are harder to detect and even harder to stop.

What is AI-powered ransomware, exactly?

In short, AI-powered ransomware is about using AI or machine learning (ML) algorithms to automate, speed up, and improve every stage of a ransomware attack.

It starts with how AI-driven malware sneaks onto users’ devices. Not only can it quickly identify weaknesses in IT systems by exploring thousands of options at once, but it can also use advanced deepfake tactics to trick people into revealing sensitive information, like their business credentials.

Once inside, this type of ransomware can move through systems undetected, intelligently prioritizing which files to encrypt based on their value. The result is a smarter, faster, and far more effective form of ransomware compared to traditional attacks.

3 reasons why AI ransomware is so dangerous

By now, it’s probably clear that AI-powered ransomware is no joke—it’s a serious threat to both organizations and individuals. But if you’re still on the fence—or just want to understand the issue a bit better—let’s take a closer look at how AI ransomware works and what makes it so effective.

Automated attacks with high efficiency

Before AI, ransomware attacks had to be controlled manually from start to finish. But with AI, these attacks can now run on their own, working autonomously to reach their goal. They even use bots to contact victims, avoiding human-to-human communication altogether, which adds to the tension by forcing targets to interact only with a machine.

With the ability to analyze far more data than any living creature, AI can handle thousands of tasks at once, finding its way into systems and causing chaos, all without any human involvement. And let’s not forget that AI never gets tired, so these attacks can keep going as long as they need to. Unlike a human, artificial intelligence won’t get frustrated or lose motivation if things aren’t working right away.

Enhanced targeting and personalization

AI-driven ransomware attacks use machine learning to sift through public sources like social media and corporate websites, identifying valuable targets and learning more about them in the process. With this information, AI can later craft highly personalized phishing emails or ads, often using social engineering techniques to manipulate key staff into divulging sensitive data.

What’s even more concerning is the rise of deepfake technology. Attackers can now create convincing audio and video material, making it seem like a trusted family member or colleague is reaching out. This makes it easier for victims to divulge confidential details because they believe they’re communicating with someone they know.

Real-time adaptation

A target not on the hook? Not buying into the ransomware attack? Are they being extra cautious, trying not to slip up and expose their systems? It doesn’t matter to the AI behind the attack, which keeps watching and learning. With every interaction, it gets smarter and quickly figures out what it needs to do to get the victim to drop their guard.

An AI ransomware attack isn’t your average cyber threat. This malicious software can adjust to any situation on the go—all it needs is data to learn from, and then it can shift its tactics when needed. Where a human hacker might give up and move on to another target, AI never calls it quits.

 

Key strategies for mitigating AI-powered ransomware

Let none of what we’ve discussed so far make you feel powerless against AI-powered ransomware. There are smart, practical steps your business can take to stay protected and lower the risk of getting hit by an AI-powered attack. Here are a few to consider:

Run security checks regularly

This might seem like an obvious one, but we can’t stress enough how essential it is to objectively assess your company’s cybersecurity level on a regular basis. Think about it—your team is probably using a wide range of platforms and services to keep things running, and each one could be a potential entry point for cybercriminals if not properly secured. That’s why having strong monitoring and intrusion detection systems in place is so important.

You might also consider leveraging AI—after all, cybercriminals shouldn’t be the only ones using it, right?—to analyze your IT environment for unusual activity. This could help you identify threats like ransomware early, before they have a chance to do any damage.

Develop an incident response plan

Let’s be real—even with the best tools and real-time monitoring in place, there’s still a chance your company could face a cyberattack. Maybe an employee slips up, or someone forgets to secure a new piece of software. Whatever the reason, what matters most in that moment is having a clear plan of action.

That’s where an incident response plan comes in. It’s essentially a set of rules that outlines exactly what your team should do if you’re hit with an AI-powered ransomware attack. According to the National Institute of Standards and Technology (NIST), a solid incident response plan should cover 4 key areas: preparation, detection, containment, and recovery. If you’ve got those bases covered, you’ll be in a much better position to minimize damage and prevent similar incidents from happening again.

Raise awareness by training your employees

Like we mentioned earlier, human error can still play a big role—even if you’ve got all the right cybersecurity tools in place. That’s why it’s so important to have open conversations with your team and run regular training sessions. These should cover how to spot AI-generated scam messages and other sneaky tactics that might be used in a ransomware attack.

Make those trainings relatable. Use real-life examples to show how these attacks can play out, then offer practical tips your team can actually use—so they feel confident, not paranoid, when using company systems. The goal isn’t to scare them, but to empower them to make smart, informed decisions that help keep everyone safe.

How NordPass can help

While not specifically an AI ransomware prevention tool, NordPass can significantly enhance your company’s cybersecurity and reduce the risk of threats like ransomware.

At its core, NordPass is a password manager that uses XChaCha20 encryption to keep your team’s logins, credit card details, and other sensitive information safe and easy to share internally. It also gives you greater control over who in your company has access to which resources and supports features like multi-factor authentication, so even if attackers somehow got hold of a password, they still can’t break in.

But NordPass isn’t just about password management. It offers additional features like Email Masking to hide your real email when signing up for services, and Data Breach Scanner that alerts you if your company’s data is found in a breach. It even allows you to ditch traditional passwords in favor of passkeys, a more secure, phishing-resistant login method. These tools help reduce your company’s digital footprint and limit the exposure that AI-driven threats could exploit in a ransomware attack.

For a quick assessment of your company’s data exposure, you can use NordPass’s free online tool to check if your data has been compromised. But for long-term protection, try the full NordPass version so your team can stay secure and make smart cybersecurity choices every day.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Network segmentation: what it is and how to implement it

What is network segmentation, exactly?

Network segmentation is the practice of dividing a computer network into smaller subnetworks (also called “segments,” hence the term “segmented network”), each of which can function as a separate unit.

By following this architectural approach, you can define how traffic will flow between different parts of the network. This can be achieved by establishing specific security controls and policies for each segment.

The purpose of all this is to improve network performance, simplify management, and contain potential threats within a specific part of the network, preventing them from spreading to other areas.

How does network segmentation work?

Dividing a network into smaller, manageable parts is no simple task, especially when the network itself is quite expansive—it takes careful planning, IT know-how, and the right resources. The idea is to have elements like the client database, email servers, company website, guest Wi-Fi, and internal applications as independent parts of the network.

Enterprise network segmentation starts with figuring out how to divide the network based on criteria like function, security needs, or business requirements. After that, you use a mix of hardware (routers, switches, and firewalls) and software (virtual LANs, cloud technologies) to break the network into segments and control how traffic flows between them.

Once you’ve got the segments set up, the next step is to monitor and manage each of them, which can be made easier with tools like security information and event management (SIEM) solutions.

Network segmentation and zero trust

Network segmentation is key to how companies manage access to their digital resources. Back in the day, companies used to follow the “assumed trust” principle—the idea that everyone in the company was a good guy, and therefore, could be trusted with access to all company data and services.

However, after thousands of human errors and security breaches caused by bad actors, companies have shifted to the zero-trust model. This approach assumes that no one should automatically have full access to the company’s network and virtual assets. Instead, they must be verified and granted access only to the resources they actually need.

To make this a reality, companies use a few different strategies, with network segmentation being one of them. How so? Zero-trust network segmentation refers to IT teams creating dedicated subnetworks for specific groups of users, ensuring they cannot move beyond their designated limits. This adds an extra layer of defense and aligns with the “never trust, always verify” motto of zero trust. Each subnetwork functions as a secure zone, with access protected by authorization protocols.

And if you combine all of this with identity and access management (IAM) solutions to securely manage user credentials, and network access control (NAC) tools that restrict access based on user or device authentication, you’ve got yourself a solid system for keeping the network running smoothly while minimizing risk.

The benefits of network segmentation

At this point, you’ve probably got a good idea of the advantages that come with dividing your company network into smaller segments. However, if you’re not sure you’ve caught all of them, here’s a rundown of the best examples of network segmentation benefits for you:

Enhanced cybersecurity

Network segmentation helps prevent cyberattacks from spreading across the entire company network. For example, if malware infiltrates a subnetwork, it cannot easily spread to other parts of the network, thereby reducing the potential damage and facilitating a quicker response. Similarly, if someone makes an error and accidentally puts systems at risk, the problem remains confined to the parts of the network they had access to. This makes it much easier to identify the issue and resolve it.

Improved compliance

Complying with policies and regulations like HIPAA and GDPR can feel like a lot of work, but network segmentation can make things easier. By breaking up the network into smaller, more secure sections, businesses can isolate sensitive data in specific virtual environments—only accessible to the right people. Plus, by controlling how data moves between these subnetworks, it becomes a lot easier to demonstrate that you’re meeting compliance requirements during audits.

Increased performance

By dividing the network into smaller segments, a company can avoid network congestion, which occurs when a network carries more data than it can handle. This can lead to slow internet speeds, buffering during streams, video call glitches, and difficulty accessing company resources when needed—ultimately affecting employee performance. Keeping network congestion low helps ensure smoother online operations and prevents downtime.

Facilitated incident response

When dealing with smaller segments of the network, it becomes much easier to spot where an incident is happening. From there, that specific area can be isolated to keep the issue from spreading. Since the rest of the network stays secure and there’s a smaller scope to investigate, IT security teams can focus on the affected area and get to the root of the problem much faster.

How to implement network segmentation in your organization

Before you start breaking your company network into smaller segments, it’s a good idea to get familiar with some network segmentation best practices. That way, you’ll head into the project with confidence and a solid game plan—setting yourself up for a smoother process and better results. Here are a few key things to keep in mind.

Don’t oversegment or undersegment your network

As you read this article, you might get the impression that the more you segment your network, the better. But that’s not quite true. If you go too far, your employees will end up dealing with too many access points, leading to user fatigue, slower workflows, and traffic bottlenecks.

On the other hand, if you don’t segment enough—say, only into 3 or 4 subnetworks—you won’t get the security benefits we talked about. This means your attack surface will still be pretty wide. So, the key here is finding the right balance. Effective network segmentation is about finding that sweet spot in how many parts your company network really needs.

Follow the zero–trust principle

Like we mentioned earlier, keeping your network segmentation secure means sticking to a strict zero-trust policy. In simple terms, no one gets an easy pass—regardless of their role or how long they’ve been with the company. Everyone needs to go through proper authentication before accessing any resources. It may sound tough, but it’s one of the best ways to protect your network segmentation operations and stay in control of who can access what.

Minimize third-party entry points

Chances are, your organization relies on at least a few third-party tools and services to keep things running smoothly. Since these platforms are part of your IT ecosystem, they can also become entry points for cybercriminals if compromised. That’s why it’s important to keep their access limited. Don’t give third-party solutions more reach than they really need. A good way to do this is by setting up dedicated access points that connect them only to specific segments of your network. That way, even if something goes wrong on their end, the issue will not spread easily into your company network.

Protect all endpoints

As an employer, you’re providing your team with devices, business accounts, and access to company data. With that comes the responsibility of making sure what you provide can’t be used against your company, and that each employee’s device and account are properly protected.

That includes giving employees access to the right subnetworks—but it doesn’t stop there. You also need to use antivirus software and monitoring tools to ensure only authorized devices get through—so that, much like in Homer’s Iliad, you’re not inviting in modern-day Trojan horses, which could bring chaos once inside.

Monitor all your subnetworks

Segmenting your network is just the beginning—the real work begins after that. You’ve got to manage and monitor all those subnetworks carefully, making sure you have a big-picture view of the whole network while also keeping an eye on how each part is doing individually. For that, it’s a good idea to use modern monitoring tools to spot any unusual user behavior or get alerted if there’s a data breach, so you can quickly figure out which part of the network needs to be shut off.

How NordPass can help

While it is not software dedicated strictly to network segmentation, NordPass is a tool that can help your organization control access to company resources and secure multiple endpoints to minimize the risk of a cyberattack.

NordPass is more than just an encrypted password manager that allows teams to securely store, manage, and share business credentials, credit card details, and sensitive information—it is also a cybersecurity solution for managing user access to company resources and monitoring data breaches to determine if they involve company data. If you run a large enterprise, you can use NordPass to see what was shared, with whom, and for what purpose, and revoke access with ease when necessary.

The best part is that you can try NordPass before making any commitments—just use the free 14-day trial to see how it can improve your company’s cybersecurity and performance. It would be a shame not to use this opportunity.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

What Is Internet of Things (IoT) Security?

What is IoT?

The Internet of Things (IoT) is what we call networks of physical objects that are packed with sensors, cameras, listening devices, and other technologies—like today’s smartphones, appliances, wearables, and cars. These devices are connected over the internet or a local network, so they can exchange data with each other. This allows them to work together as part of a smart system, enabling the automation of tasks and the creation of intelligent environments like smart homes or smart workplaces. Because of the way IoT devices operate, the Internet of Things and cybersecurity must go hand in hand to deliver smart experiences while ensuring safety and privacy for all users.

What is IoT security?

IoT security is all about protecting the interconnected smart devices and the networks they connect to. Since these devices can collect, store, and share data about users’ surroundings, this data must be handled with the utmost care and caution.

IoT devices aren’t just for personal use—more and more are making their way into workplaces. For example, businesses now install smart thermostats, blinds, and seating planners to optimize resources in their offices.

The benefit of these devices syncing and working together is that they regularly share and communicate data to improve functionality. However, since these devices are interconnected, gaining access to one could allow bad actors to exploit and breach your entire network. That’s why Internet of Things device security (as well as IoT network security) is essential to prevent vulnerabilities that could lead to cyberattacks.

Why is IoT security important?

The recent influx of IoT devices has provided another avenue for hackers to exploit in recent years. IoT devices can be particularly vulnerable to security breaches. At the end of 2021, a study concluded that up to 82% of healthcare organizations experienced an IoT cyberattack over 18 months. There are often security oversights regarding the IoT and its apps. For example, a German teenager hacked Tesla vehicles’ app component not that long ago. While he couldn’t access the driving functions like steering or brakes, he could still exploit other potentially dangerous features like unlocking doors, playing music at max volume, and flashing lights. The more IoT devices become common, the more widespread their security threats will become.

Which industries need IoT security?

Smart devices have made their way into almost every part of our lives. However, some industries rely more heavily on IoT technology than others and require additional security due to its strategic meaning for the nations’ and communities’ welfare.

  • Healthcare

Patient monitoring, advanced medical equipment, administering treatments and vaccines: Medical services increasingly rely on smart devices. Cynerio and Ponemon’s Study proves that healthcare is especially vulnerable to cyber attacks involving the Internet of Things devices as they constitute 88% of all hospital data breaches. More than half of hospitals in the US have experienced an attack on their smart devices between 2020 and 2022. The damage that cybercriminals can cause in healthcare is horrifying — the mortality rate increased in 24% of the attacked hospitals.

  • Energy and Utilities

Internet of Things devices are widely used in the energy and utilities sector for smart grid management, optimizing energy consumption, and remote monitoring of infrastructure. Monitoring devices such as smart meters, security cameras, and temperature/fire/chemical leak controls are prime targets for cybercriminals. Protecting energy infrastructure is essential to prevent disruptions to critical services, including electricity, heating, traffic control, or medical care.

  • Manufacturing

It’s hard to imagine a modern factory without Internet of Things solutions enabling process automation, supply chain management, and predictive maintenance. The endless possibilities that smart devices present to this sector can be overshadowed by the costs of cyberattacks, as hackers often target factories to demand ransom.

  • Logistics

IoT devices are entering the logistics industry through fleet, vessel, and traffic management systems. Self-driving vehicles are becoming commonplace in major cities. Also, the railway relies on Internet of Things devices for traffic planning and power supply management. Hacking an IoT-reliant logistics system could cause chaos on highways or railroads.

  • Supply Chain

In the supply chain industry, connected devices are used for tracking, monitoring, and managing goods throughout transportation. The security risk created by IoT tools used in day-to-day operations grows with the number of vendors a company cooperates with. Supply chain attacks often target third-party partners or suppliers to access the company’s assets.

IoT security challenges

While smart devices introduce plenty of opportunities and convenience to our lives, they also open up the possibility of cyberattacks. Industries such as healthcare and manufacturing increasingly rely on IoT devices, exposing unprepared organizations to cyberattacks. Here are some of the threats IoT devices are susceptible to:

  • Malware: Because cybersecurity isn’t the primary concern of many smart devices, hackers don’t require advanced malicious software to attack. Rudimentary malware can steal data and cause damage to networks and devices. Mirai is used to infect security cameras, scan the network for the IP address of IoT devices, and connect. This allows hackers to launch significant DDoS attacks.

  • Credential-based attacks: Using stolen login IDs and passwords is a popular method for hackers because many people’s logins are already floating around online thanks to massive data leaks such as Collection #1. Once a business’s smart device’s application layer is breached, hackers can access any device connected to the network.

  • Data theft and exposure: Adding IoT devices to your home or office will introduce more potential entry points for hackers to access data. This increases the risk of personal information being stolen and exposed on the internet. A good example of this is when hackers used Amazon’s Alexa to issue self-commands allowing the attackers to control smart lights, buy items on Amazon, and tamper with calendars.

  • Incorrect device management and configuration: Similar to the above, the more devices and accounts you add, the greater the chance of reusing passwords and usernames. Companies often ship IoT devices with default logins that should be changed during their setup. However, a survey of CIOs and IT managers showed that almost 50% of them allowed IoT devices onto their corporate network without changing the default passwords.

  • Complex ecosystem and smart device diversity: An office’s IoT ecosystem can quickly become a juggernaut of interconnected devices. These devices have many moving parts that operate at different levels. Overseeing and managing your wide array of IoT devices will help you prevent IoT attacks.

  • Not following security by design: Cybersecurity is generally not the main focus of many IoT devices, often taking a backseat to its functionality. Your office’s IoT security could be at risk because specific devices may have cybersecurity weaknesses that need to receive software updates. There’s also the possibility that any security features may be obsolete if the product is discontinued and no longer supported by its developer.

Examples of IoT security threats

Jeep Grand Cherokee

Back in 2015, security researchers Charlie Miller and Chris Valasek set out to see if they could remotely hack into and take control of a new Jeep model—the Jeep Grand Cherokee. They ran a series of cybersecurity tests, and sure enough, they found a major backdoor in the Jeep’s built-in infotainment system, which handles things like navigation and entertainment.

Using this vulnerability, they were able to connect to the car’s other systems and take control of the car’s key mechanics like braking, engine control, air conditioning, and transmission. Basically, they turned that Jeep into one of the most expensive remote-controlled toy cars in the world! After this demonstration, Chrysler (the owner of Jeep) had no choice but to recall more than 1 million Grand Cherokees to fix the software vulnerability.

Mirai botnet

Probably the most famous—or infamous, actually—IoT security breach ever, the Mirai botnet was first identified in 2016 and has remained a persistent cyber threat ever since. It works by infecting vulnerable IoT devices—like AVTECH CCTV cameras and Four-Faith industrial routers—and using them to launch large-scale distributed denial-of-service (DDoS) attacks.

In 2018, a Mirai variant was used in a 1.35 Tbps DDoS attack against GitHub, briefly knocking the platform offline. In 2020, the FBI issued a warning that Mirai-based attacks could go beyond websites and target critical infrastructure, like power grids and industrial systems.

But here’s the real problem: the Mirai botnet is still out there. Its original creators released the source code online, and since then, cybercriminals worldwide have been modifying and weaponizing it. Even today, in 2025, Mirai-based botnets are still behind record-breaking cyberattacks, targeting everything from internet service providers to government networks.

ThroughTek

In 2021, security researchers uncovered a serious flaw in ThroughTek’s IoT software, which is used in millions of smart cameras, baby monitors, and security systems around the world. It turned out that hackers could use this vulnerability to remotely access live video and audio streams from the cameras, and in some cases, even take full control of these devices, exposing sensitive footage from homes and businesses in the process.

The vulnerability was so severe that the Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning, rating it 9.1 out of 10 on the severity scale.

How to secure IoT devices

The good news is that maintaining an overall good cybersecurity policy for your company will help safeguard your IoT devices. Training your staff with cybersecurity best practices and appointing specific admin roles to deal with the security of IoT devices in your organization are all methods for securing your business from IoT threats.

  • Regularly updating and checking IoT devices for patches: By staying up to date with your IoT devices’ firmware, you’re better equipped to protect your workplace from ever-evolving cyber threats. While people regularly update their computers and phones, they may forget to update their IoT devices.

  • Monitoring device behavior: By knowing your device’s base behavior and aspects such as its performance or regular network activity, you can recognize irregular behavior and intervene if you notice any deviations to your device’s performance.

  • Using strong and unique passwords: Using a password manager for your organization helps secure your IoT data security. NordPass Business creates unique, complex passwords. Additionally, it regularly reminds you to update passwords if they’re old, reused, or weak.

  • Checking app permissions for IoT devices: If an IoT device comes with an app, it is better to review the permissions it’s requesting before allowing access to your device or network. You shouldn’t grant apps more permissions than are strictly necessary.

  • Applying network segmentation and network security: Your workplace should have a way to monitor network activity and any devices connected to it. Tracking this information will help you recognize irregular internet traffic and act as an additional layer of security. This means that if one device is affected by an attack, it won’t be passed on to your other devices.

  • Considering additional security solutions and tools: To secure the app component of IoT devices, consider only accessing the app via a VPN. Doing so will encrypt the data transferred and give your network an extra layer of security.

  • Using multi-factor authentication (MFA): The more layers of security (authentication factors) smart devices used in your workplace have, the safer your company assets are. Incorporating additional factors to authenticate the user, such as biometric data or the user’s geolocation, makes your IoT devices less vulnerable to cyber attacks.

  • Applying Cloud IoT Security: Many IoT applications leverage cloud computing for storing, processing, and analyzing data. Therefore, it’s essential to implement security strategies, procedures, and tools that encompass cloud security if your organization utilizes smart devices.

How NordPass Business boosts your IoT security

The surge of IoT devices in private and professional settings provides more potential routes for hackers to steal valuable data and information. These devices and networks are more intertwined than ever, meaning cybersecurity for IoT shouldn’t be ignored. For companies working with large amounts of data, NordPass Enterprise is the cybersecurity solution you’re looking for. With NordPass, you can securely store and share login credentials for all your accounts and generate strong, unique logins in no time. NordPass allows you and your colleagues to quickly access important office notes (alarm PINs, WiFi passwords, and recovery codes) in one place.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.