Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, August 21, 2020

Acronis True Image 2021 Unites Award-Winning Backup With Advanced Antimalware, Creates Personal Cyber Protection Solution

Acronis, a global leader in cyber protection, has today announced the release of Acronis True Image 2021. The new release integrates advanced cybersecurity capabilities with unmatched personal backup to create the first complete personal cyber protection solution for home users, prosumers, and small businesses around the world.

Delivery comes as the COVID-19 pandemic exposes gaps in traditional solutions and strategies. Securing home machines has never been more important, yet a recent Acronis survey found nearly half (47%) of remote workers never received clear guidance on working from home.

Incorporating cybersecurity capabilities such as real-time antimalware protection, on-demand antivirus scans, web filtering, and videoconference protection into Acronis True Image ensures users have complete cyber protection. For individuals and small business users, unifying these vital capabilities in one solution makes their protection easier to manage and more affordable, while greatly improving the security.

“As more people work or attend classes from home, the FBI documents a 400% increase in cyberattacks because hackers know home systems are not usually as well-defended as an office,” said Serguei “SB” Beloussov, founder and CEO of Acronis. “Backup without cybersecurity is an incomplete option in that situation, as is cybersecurity without backup. Acronis True Image 2021 delivers the easy, efficient, and secure cyber protection needed today.”

Standalone backup and cybersecurity are obsolete

With the modern reliance on everyday devices like computers, smartphones, and tablets, the data they contain has an inherent value. Cybercriminals are constantly evolving their attacks to reach that data, which is why security research firms such as AV-Test report more than 350,000 new malware threats every day.

Since backup software and files are often the targets of these new attacks to prevent recovery, backup alone no longer provides suitable protection for users. Similarly, conventional cybersecurity solutions do not provide the data protection and recovery capabilities users need.

Relying on multiple products that were not designed to work together creates security gaps, is more complex to manage, and is more costly. With a single, integrated solution, Acronis True Image 2021 users can proactively stop any malware attack and then quickly restore affected files. The single, intuitive interface reduces the complexity of managing their security and backups.

Integration delivers superior cyber protection

For the last few years, Acronis True Image has been the only personal backup solution with a built-in antiransomware that stops attacks in real-time, while automatically restoring any affected files.

With the launch of Acronis True Image 2021, those capabilities are expanded with the addition of the company’s advanced antimalware technology, which is currently deployed in Acronis Cyber Protect Cloud. This next-gen, full-stack antimalware has been shown by independent security labs such as Virus Bulletin and AV-Test to return a 100% detection rate with zero false-positives.

As a result, home users gain advanced capabilities with Acronis True Image 2021, including:

* Real-time protection, driven by AI-enhanced behavioral heuristics, which stops all malware – including zero-day attacks by never-before-seen threats

* On-demand antivirus scans of the full system or quick scans of at-risk files, either of which can be scheduled in advance or run instantly

* Web filtering that automatically blocks Windows users from accessing malicious websites that harbor malware, disinformation, scams, and phishing attacks

* Videoconference protection prevent hackers and malware injection attacks from exploiting popular apps like Zoom, Cisco Webex, and Microsoft Teams

* Comprehensive detection, with both behavioral analysis and signature-based analysis engines

These advanced antimalware capabilities are included with Advanced and Premium licenses, and offered as a three-month trial with Standard and Essential licenses.

Acronis True Image 2021 gives individuals and small businesses access to the same protection technologies relied on by global companies and top teams in the world’s most high-pressure professional sports.

“Cyber protection is a top priority for Rahal Letterman Lanigan Racing,” explains Bobby Rahal, co-owner of Rahal Letterman Lanigan Racing. “When our races were on pause, Acronis continued to provide protection for our team working remotely. Now, with Acronis True Image, everyone can safeguard their personal data against the worst-case scenario.”

Pricing and availability

Four versions of Acronis True Image are available: Standard, Essential, Advanced and Premium. One-computer licenses starting at $59.99 for Standard and $49.99 for Essential. Special launch prices for Advanced and Premium licenses (starting at $69.99 and $99.99, respectively) are available until November 2020, at which time the full MSRP will be in effect (starting at $89.99 and $124.99, respectively).

SmarterBiz Raises INR 8 Crores Pre-Series from StartupXseed and Prominent Angels


 • A post-COVID new norm start-up working on Customer Experience delivery with the most secure technology stack

• Aims to grow at 8X doing about 72 Crores in ARR by Mar 2021 

• Remote WFH solution to enable companies to traverse towards OPEX model 

• Solving Customer Experience (CX) for enterprises 

SmarterBiz, India's first end-to-end CX platform enabled with the gig workforce has raised INR 8 crore as a part of their Pre-Series A round. 

The contributors for this funding round were StartupXseed Ventures (Deep Technology – B2B – Early-stage fund); Mr. Bhaskar Pramanik, Former Chairman of Microsoft India; Mr. MJ Aravind, Former co-founder Daksh, Former Partner Artiman; Mr. Ravi Viswanath; Mr. Ramesh Radhakrishnan; Mr. Ranjan Biswas; and Mr. MJ Aniketh. 

Founded in 2014 by Rajesh Bernard, Vijay Krishna, and Prateek Mehta, the company was funded initially by Utthsihta Yekum Fund.

SmarterBiz is an AI-powered customer experience platform that enables remote management of customer journeys and agent life cycles. SmarterBiz has helped several enterprises, including unicorns build scalable, flexible, and hyper-local customer experience, cost-effectively. 

The COVID-19 pandemic has challenged businesses to ensure business continuity and manage increased customer interactions through remote workforce and reduced costs. With the SmarterBiz CX platform, customers can now remotely enable and manage the complete life cycle of the CX process across both digital and human touchpoints. With a single integrated approach, SmarterBiz takes away the pain of running customer experience on multiple siloed systems and processes that do not talk to each other. SmarterBiz provides an end-to-end platform to CX teams to manage the entire lifecycle of their customer, technology backbone, process, and customer support agents on the cloud. 

SmarterBiz serves several enterprises, including five segment leaders in E-commerce, BFSI, Hospitality, and Telecom sectors. It manages more than 5000 agents as part of its gig workforce. 

Rajesh Bernard, CEO & Co-founder of SmarterBiz said, "SmarterBiz has built a CX platform for a gig-workforce ideally suited under these COVID 19 conditions. SmarterBiz is committed to offering an omnichannel experience that elevates the experience across all customer touchpoints. We provide a competitive advantage to our customers by offering a choice between automation and manual intervention at all these touchpoints. With the investment, we plan to grow by 8X ARR this year and create more gig opportunities in the market." 

"Companies like SmarterBiz can foresee the benefits technology can bring, to reinvent the businesses and add value to the system. It will surely be a game-changing category disruptor during and post-COVID 19. There will be an increasing need for companies to integrate customer journeys, tech, remote work, and Gig models into their business process. We believe that SmarterBiz will be one of the most sustainable global companies of the future, for the solution it brings in and the execution capabilities of the team," said Mr. BV Naidu, Managing Partner, StartupXseed Ventures.

"At last, a seasoned leadership team, a novel premise, immaculate conceptual skills, and meticulous execution. SmarterBiz is indeed a company to watch out for." Mr. M J Aravind, Ex co-founder Daksh. 

The key benefits of the solution for customer experiences are that it facilitates remote work opportunities across India, flexible working hours, earning potential in a WFH set up, and is a mobile light, simple, and efficient application. 

The unique CX platform—Uearn.ai— streamlines the customer journey across multiple touchpoints with an omnichannel CX tech platform, fluid workflow management, and gig workforce, replacing the CapEx model to an OpEx model. The competitive advantage of SmarterBiz is the scalability (4X) it offers at lower costs and faster time to serve as compared to traditional models. 

About SmarterBiz: SmarterBiz, founded in 2014, is India's first end to end CX platform enabled with gig-workforce. It allows companies to shift their CX centres to 100% OpEx model. SmarterBiz streamlines customer journeys across multiple touchpoints with its CX platform—Uearn.ai—lowering the cost to serve, time to serve, for CX centre. It delivers the customer experience through its platform and gig-workforce, bringing convergence of tech and people to run multi-layered operations for its clients. Its fluidity allows clients to scale 4X times faster than the traditional model supported by a talented workforce that can work from remote distributed locations. Uearn.ai facilitates remote work opportunities and has 5,000 trained gig workforces with customer experience profiles. Uearn is available as a remote gig workforce app in Google Play Store. 

SmarterBiz is transforming the CX delivery for some of the leading banks to tech unicorns. To know more, visit www.smarterbiz.ai

Wednesday, August 19, 2020

Trend Micro Brings DevOps Agility and Automation to Security Operations through Integration with AWS Solutions


Trend Micro Incorporated (TYO: 4704; TSE: 4704), the leader in cloud security, enhances agility and automation in cloud security through integrations with Amazon Web Services (AWS). As a result, Trend Micro delivers flexible and scalable all-in-one security that helps DevOps engineers securely build and innovate as they migrate to and build in the cloud. 

Trend Micro has demonstrated the strength of its collaboration with AWS since 2012 with a deep understanding of customer use cases and by integrating with leading AWS security services at launch. Most recently, Trend Micro Cloud One™ offerings have been natively integrated with AWS Control Tower and AWS Systems Manager Distributor. These additions are designed to bring immediate benefit to security, cloud, and DevOps teams leveraging AWS by automating enforcement of security capabilities earlier in the account and resource provisioning process. 

"Trend Micro is an Advanced Technology Partner in the AWS Partner Network (APN) with  a long-standing history of providing security solutions to help customers address their portion of the shared responsibility model," said Siva Padisetty, General Manager, AWS Systems Manager, Amazon Web Services, Inc. "Trend Micro's continuing investment in integrations with native AWS capabilities, such as AWS Control Tower and AWS Systems Manager Distributor, reduces onboarding and management friction while adopting an enhanced security posture." 

According to a recent report from IDC, "Trend Micro is the dominant leader in Software-Defined Compute (SDC) workload protection," making up 29.5% of the worldwide hybrid cloud workload security market share, proving the company's hybrid cloud security expertise, capabilities and trust by customers. As the leading cloud security experts, Trend Micro engineers develop security solutions designed to meet the needs of cloud engineers. 

"We understand that security teams don't always have complete control or visibility into how cloud instances are being spun up, configured and used across the company," said Sanjay Mehta, senior vice president of business development and alliances for Trend Micro. "Listening to and understanding customer needs and feedback drives our innovations and collaboration with AWS. Having our solutions plug in natively with AWS offerings like AWS Control Tower and AWS Systems Manager Distributor adds visibility and automates security for our customers." 

Through this collaboration, Trend Micro Cloud One offers the broadest platform support and API integration to protect your AWS infrastructure whether building with Amazon Elastic Compute Cloud (Amazon EC2) instances, AWS Lambda, AWS Fargate, containers, Amazon Simple Storage Service (Amazon S3), or Amazon Virtual Private Cloud (Amazon VPC) networking. 

Thursday, August 6, 2020

Infogain Achieves Google Cloud Partner Specialization in Application Development

Infogain, ​a leading provider of technology solutions, today announced that it has achieved the “Application Development Partner Specialization” in the Google Cloud Partner Specialization Program. The program provides Google Cloud customers with qualified partners that have demonstrated their expertise and success in advanced application development using Google Cloud technology. Infogain’s​proven success in building and managing applications using the best of Google Cloud in both web, and mobile environments led to this specialization. 

Infogain helps enterprises, ISVs, and innovative start-ups build modern software products and applications on Google Cloud. Infogain was one of the first to deploy and integrate Automation Anywhere RPA platform to Google Cloud Platform (​Press Release​).​Infogain’s experience spans modern application development and deployment architectures, Google Cloud IaaS, and PaaS platform development and DevSecOps driven application delivery. 

Nishith Mathur, Chief Technology and Strategy Officer, ​Infogain, said, “We are pleased that Infogain achieved the Google Cloud ​Application Development Partner Specialization​. The specialization from Google Cloud is a validation of our commitment to provide the most innovative and best solutions for our clients by leveraging Google Cloud environment​. This accreditation enables us to help our clients achieve agility and security, leading to better business outcomes, using advanced Google Cloud solutions.”

About Infogain

Infogain is a Silicon Valley headquartered company with digital platform and software engineering expertise in the travel, retail, insurance, healthcare, and high technology industries. We accelerate design-led transformation and delivery of digital customer engagement systems and platforms. Infogain engineers business outcomes for Fortune 500 companies and digital natives using technologies such as cloud, microservices, robotic process automation, IoT, and artificial intelligence.   A ChrysCapital portfolio company, Infogain has offices in California, Washington, Texas, London, Dubai, India, and Singapore, with delivery centers in Austin, Kraków, New Delhi, Bangalore, Pune, and Mumbai.

Monday, August 3, 2020

Trend Micro Cloud-Powered XDR Drives Monumental Business Value


Trend Micro Incorporated, the leader in cloud security, today shared the significant business value driven by cloud-powered XDR and Managed XDR offerings, which optimize threat detection and response across all critical vectors. In a recent survey commissioned by Trend Micro and conducted by ESG, organizations surveyed experience faster detection and less alert fatigue as a result of intelligently using data from all their security controls (including those covering endpoints, email, servers, cloud workloads and networks). 

According to the recent findings from ESG*, previewed here with a white paper to publish in August, 85% of organizations claim that threat detection and response is getting harder due to an exponentially more sophisticated threat landscape and a lack of highly skilled security experts over the last two years. 

Trend Micro's XDR solution is both a SaaS-based offering as well as a managed service with the "X" referring to the most extensive sets of data from more protection points, which is critical to find hidden threats. It was recently named by Forrester as a Leader in enterprise detection and response and achieved the highest initial detection in the MITRE ATT&CK® Framework. 

City of Tyler, Texas CIO and Trend Micro customer, Benny Yazdanpanahi said, "Our citizens and employees have a right to expect that their data and public services are secured from cyber-threats, but our small IT workforce can't do everything, so we turned to Managed XDR. Finding a strong, committed partner with knowledge and expertise we don't have was a game-changer for us. Our city motto is 'We are called to serve,' but the same could equally be said of Trend Micro. They care about their customers." 

Today's organizations are faced with sophisticated threats that may bypass even advanced protection. However, most current detection and response approaches are siloed, incomplete and overwhelm limited security teams with disconnected alerts that lack actionable information. Security practitioners currently report being able to find critical alerts but not necessarily having the clarity to resolve the issue due to lack of additional details.  

In fact, ESG found that only 30% of organizations are confident that their threat detection and response functions can perform at the speed needed to keep up with threats over the next 12-24 months. Additionally, on average, organizations and overtaxed IT teams ignore 32% of security alerts. 

Trend Micro XDR was the first solution to launch that offers correlated detection beyond the endpoint: collecting and analyzing data from email, endpoints, servers, cloud workloads, and networks to more effectively hunt, detect and contain threats. It amounts to greater context, greater understanding and faster, more accurate incident response. ESG found that organizations that employ automated data aggregation techniques, like those enabled by Trend Micro XDR, enjoy improved security outcomes. For example, they are generally able to restore in hours vs. days by a ratio of 83% vs. 66%. 

The solution is also available as a managed service (MDR), to further take the pressure off constrained in-house teams with 24/7 full-threat analysis, threat hunting, response plans and remediation recommendations. 

"There's no such thing as 100% prevention anymore, which puts the focus on effective threat detection and response. With XDR, we've broken the mould with correlated detection across traditional siloes to help stretched IT teams optimize their response to stealthy threats," said Steve Quane, executive vice president at Trend Micro. "I'm proud of the fantastic value our solution offers businesses and of once again delivering on our commitment to secure the connected world. It's a privilege to remain a trusted cybersecurity advisor for our global customers." 

*ESG Research Insights Report, Validating Trend Micro's Approach and Enhancing GTM Intelligence, 2020, to be published August 2020. 

Wednesday, July 29, 2020

Tech Mahindra and Hinduja Group’s CyQureX Sign a Global Strategic Partnership

Tech Mahindra, a leading provider of digital transformation, consulting, and business re-engineering services and solutions, announced a global strategic partnership with Hinduja Group’s CyQureX, a leading provider of advanced Cyber Security solutions world-wide, with a view to offer world class cyber security solutions in support of clients through successful digital transformation.  

The strategic partnership will enable the organizations to become leaders in the emerging ‘Zero Trust’ environment, leveraging CyQureX’s core SDP (Software Defined Perimeter) technology and solutions, alongside Tech Mahindra’s strategic focus on cybersecurity and other next generation technologies. The partnership will enable Global customers to have access to state-of-the-art cyber security protection for Data Assets across the entire life cycle i.e “Data in Motion”, “Data in Use” and “Data at Rest”.

With decades of consulting and digital transformation expertise, Tech Mahindra will provide consulting, planning, designing, integration, orchestration and automation of services. CyQureX, which represents a new and critical business vertical of the well diversified, multimillion dollar turnover transnational Hinduja Group, with research and development centers in India and USA and offices spread across USA, Europe/United Kingdom, Middle East and India, will prioritize capabilities in the ‘Cyber Security domain - the new middleware of the future’.

CP Gurnani, Managing Director and Chief Executive Officer, Tech Mahindra, said, “Organisations have accelerated their digital transformation journey to emerge stronger and smarter from the current crisis. As a global leading provider of digital services, Tech Mahindra is committed towards leveraging new-age technologies to unleash new business opportunities and experiences for our customers and partner ecosystem through strategic partnerships and world class solutions. We see cybersecurity not only as an essential service but as a key business differentiator for our clients. The partnership with Hinduja Group’s CyQureX aligns with our core business proposition, and will further strengthen our position as the cybersecurity partner of choice for our customers globally.

GP Hinduja, Co-Chairman, Hinduja group is of the view that “This partnership is a game changer in the cyber security domain. It brings the leading security services company Tech Mahindra, and our newest technology company, CyQureX, together to create a highly secure, agile and resilient digital world. I am extremely delighted to see this strategic partnership formed, as it is in line with one of the core principles of our founder, Partnership for Growth. With rapid transformation of business to digital, we believe cybersecurity will be the cornerstone to protect all digital assets, particularly for digital transformation of India and other geographies. We are committed to develop many more indigenous state-of-the-art cyber security products and technologies in the coming years, with a vision to be a major global player in the emerging cyber security solutions market”.

“I am very excited about the alliance with Tech Mahindra” observes M.K.Narayanan, Executive Chairman of CyQureX, a Former National Security Advisor and Special Advisor on Intelligence and Security to the Prime Minister of India.  “This is a critical alliance and I am hopeful that it will be the catalyst to leverage next generation technologies like Cyber Security, Artificial Intelligence, Blockchain and create Cyber Security platforms to protect businesses, critical infrastructure and government. It promises to take digitalisation to the next level, providing clients across the globe with fully integrated cyber security solutions.”

The strategic partnership between Tech Mahindra and Hinduja Group’s CyQureX  will not only provide affordable protection to critical data, and defend nations against ‘stealth offences’, but would provide Cyber Security solutions for agile deployment that are critically important for business continuity, competitiveness and flexibility. Together, given TechMNxt charter, which focuses on leveraging next-generation technologies, and Hinduja Group’s CyQureX as a leading provider of cyber security solutions, exciting new opportunities have become available in the arcane world of Cyber security. Simultaneously, Tech Mahindra and Hinduja Group’s CyQureX will work towards Product Development, Consulting Services and Delivery in the Cyber Security space.

About CyQureX

Established in 2017, CyQureX is a cyber security solutions provider headquartered in London, UK. A Hinduja Group company, CyQureX focuses on design, development and delivery of next generation cyber security portfolio and services. Providing Software defined perimeter based network security solutions to a diversified set of industries such as banking, engineering and financial institutions.

About Hinduja Group

The Hinduja Group is one of India’s premier diversified and transnational conglomerates. Employing nearly a 150,000 employees, with presence across 38 countries it has multi-billion dollar revenue. The Group was founded over a hundred years ago by Shri P.D. Hinduja whose credo was "My duty is to work so that I can give."

The Group owns businesses in Automotive, Information Technology, Media, Entertainment & Communications, Banking & Finance Services, Infrastructure Project Development, Cyber Security, Oil and Specialty Chemicals, Power, Real Estate, Trading and Healthcare. The group also supports charitable and philanthropic activities across the world through the Hinduja Foundation.

Zoomcar, ETO Motors Partner to Announce a Platform of Services to Boost Shared EV Mobility


Zoomcar, India’s largest personal mobility platform, signed an agreement this week with Hyderabad based ETO Motors, a full-fledged electric mobility solutions & services company, to provide a diverse array of platform services for ETO’s electric, shared 3-wheeler business. As part of this agreement, Zoomcar will provide access to its state-of-the-art, proprietary tech stack which emphasizes security and maintenance of vehicles, thereby building a consumer base for electric vehicles and improving the overall customer experience. In the partnership, ETO Motors will own and operate electric three-wheelers for shared first-mile and last-mile passenger commute as well as goods movement within the cities. 

Zoomcar’s tie-up with ETO Motors entails the development of an innovative platform to address the vast opportunities across India in the first mile, last mile, and Intracity passengers as well as goods movement space using electric vehicles. The strategic partnership will help create the necessary competency and technology for building the future of the mobility market in India. 

Commenting on the latest development, Greg Moran, CEO & Co-Founder Zoomcar said, ‘’The mobility industry is going through a transformational phase globally due to the pandemic. At Zoomcar, we strive to be at the forefront of creating innovative solutions that can help shape this transformative shift. From the beginning, we set out to build a software solution that helps reduce accidents and improves asset longevity.  Through this partnership with ETO Motors, we aim to leverage our AI based platform to enable large fleet operators to better manage their assets through greater vehicle safety and lower total operating cost. We are delighted to partner with ETO Motors on the next phase of their growth journey in India’s rapidly expanding EV market.” 

Commenting on the development which will boost ETO Motors efforts to drive the sustainable EV revolution, Mr. Biju Mathew, CEO, ETO Motors said, “The coming together of both companies marks a significant beginning in boosting the shared EV mobility space. Zoomcar’s contribution will be in the form of its technology, including apps for customers and drivers combined with the experience of managing large scale mobility solutions.ETO will own and operate state of the art electric vehicles to deliver seamless mobility to customers. The next phase of collaboration between our respective companies with respect to the development of the co-branded digital platform will undoubtedly mark a significant step forward for the industry.” 

Zoomcar’s previously announced driver score tech stack is an AI powered algorithm with machine learning capabilities that rates the driver’s performance on a scale of 0-100.  The driver score tracks the condition of the vehicle, the driving style of the customer, and the real-time critical events impacting the vehicle health. The scoring system possesses capabilities to give real-time feedback to drivers in the advent of rash driving to help them adjust their behavior accordingly. The platform is agnostic to the vehicle type and the telematics device installed.  Moreover, the platform works for both traditional internal combustion vehicles as well as electric vehicles. 

This signing of the MoU for the co-branded platform is part of ETO Motors plan to introduce a fleet of smart electric vehicles and strengthen its clean mobility solution offering. The platform will focus on the deployment of electric vehicles in the three-wheelers, four-wheelers, and two-wheelers segment for first-mile, last-mile, intracity passenger, and goods movement across India. The platform will help in the discovery of the vehicle and will ensure a safe commute for the passengers. The smart vehicles can be geo-fenced and disabled remotely in case of any emergency. ETO has already introduced its smart vehicles for first and last-mile connectivity service in Noida Metro and is poised to expand its presence in the coming times. 

About Zoomcar 

Zoomcar holds the distinction of being India’s first personal mobility platform, with the introduction of car-sharing services in 2013 and today is the market leader in the self-drive space with over 10,000 cars in its fleet. With a strong focus on the mobile experience, Zoomcar allows users to rent cars by the hour, day, week, or month. Headquartered in Bangalore, Zoomcar is over 250 people strong and operates in 45+ cities across India. In 2018, Zoomcar introduced India’s first peer2peer based marketplace for cars with the launch of its shared subscription mobility model and currently commands over 90% market share in this space. 

About ETO Motors PVT Ltd. 

ETO-is a full-fledged electric mobility solutions and services company into large-scale deployment of multi-brand shared electric diverse fleet for cleaner cities that provides clean, safe, noise free public transportation for first mile, last mile and intracity operations. ETO-addresses issues of Clean shared Public Mobility Traffic Congestion Reduce co2 emissions Direct transfers Efficient use of capacity Public Parking Space. Cheaper Journey Price – 2W,3W, 4W, Bus, Cargo. 

IBM Report: Compromised Employee Accounts Led to Most Expensive Data Breaches Over Past Year


IBM Security announced the results of a global study examining the financial impact of data breaches, revealing that these incidents cost companies $3.86 million per breach on average, and that compromised employee accounts were the most expensive root cause. Based on in-depth analysis of data breaches experienced by over 500 organizations worldwide, 80% of these incidents resulted in the exposure of customers’ personally identifiable information (PII). Out of all types of data exposed in these breaches, customer PII was also the costliest to businesses.  

As companies are increasingly accessing sensitive data via new remote work and cloud-based business operations, the report sheds light on the financial losses that organizations can suffer if this data is compromised. A separate IBM study found that over half of employees new to working from home due to the pandemic have not been provided with new guidelines on how to handle customer PII, despite the changing risk models associated with this shift.  
Sponsored by IBM Security and conducted by the Ponemon Institute, the 2020 Cost of a Data Breach Reportis based on in-depth interviews with more than 3,200 security professional in organizations that suffered a data breach over the past year.1Some of the top findings from this year’s report include: 

Smart Tech Slashes Breach Costs in Half: Companies who had fully deployed security automation technologies (which leverage AI, analytics and automated orchestration to identify and respond to security events) experienced less than half the data breach costs compared to those who didn’t have these tools deployed – $2.45 million vs. $6.03 million on average.  
Paying a Premium for Compromised Credentials: In incidents where attackers accessed corporate networks through the use of stolen or compromised credentials, businesses saw nearly $1 million higher data breach costs compared to the global average – reaching $4.77 million per data breach. Exploiting third-party vulnerabilities was the second costliest root cause of malicious breaches ($4.5 million) for this group.    
Mega Breach2Costs Soar by the Millions: Breaches wherein over 50 million records were compromised saw costs jump to $392 million from $388 million the previous year. Breaches where 40 to 50 million records were exposed cost companies $364 million on average, a cost increase of $19 million compared to the 2019 report.  
Nation State Attacks – The Most Damaging Breaches:  Data breaches believed to originate from nation state attacks were the costliest, compared to other threat actors examined in the report. State-sponsored attacks averaged $4.43 million in data breach costs, surpassing both financially motivated cybercriminals and hacktivists. 

“When it comes to businesses’ ability to mitigate the impact of a data breach, we’re beginning to see a clear advantage held by companies that have invested in automated technologies,” said Wendi Whitmore, Vice President, IBM X-Force Threat Intelligence. “At a time when businesses are expanding their digital footprint at an accelerated pace and security industry’s talent shortage persists, teams can be overwhelmed securing more devices, systems and data. Security automation can help resolve this burden, not only enabling a faster breach response but a significantly more cost-efficient one as well.” 

Employee Credentials and Misconfigured Clouds – Attackers’ Entry Point of Choice  
Stolen or compromised credentials and cloud misconfigurations were the most common causes of a malicious breach for companies in the report, representing nearly 40% of malicious incidents. With over 8.5 billion recordsexposed in 2019, and attackers using previously exposed emails and passwords in one out of five breaches studied, businesses should rethink their security strategy via the adoption of a zero-trust approach – reexamining how they authenticate users and the extent of access users are granted. 
Similarly, companies’ struggle with security complexity – a top breach cost factor – is likely contributing to cloud misconfigurations becoming a growing security challenge. The 2020 report revealed that attackers used cloud misconfigurations to breach networks nearly 20% of the time, increasing breach costs by more than half a million dollars to $4.41 million on average – making it the third most expensive initial infection vector examined in the report. 

State Sponsored Attacks Strike Heaviest

Despite representing just 13% of malicious breaches studied, state-sponsored threat actors were the most damaging type of adversary according to the 2020 report, suggesting that financially motivated attacks (53%) don’t translate into higher financial losses for businesses. The highly tactical nature, longevity and stealth maneuvers of state-backed attacks, as well as the high value data targeted, often result in a more extensive compromise of victim environments, increasing breach costs to an average $4.43 million. 

In fact, respondents in the Middle East, a region that historically experiences a higher proportion of state-sponsored attacks compared to other parts of the world3, saw an over 9% yearly rise in their average breach cost, incurring the second highest average breach cost ($6.52 million) amongst the 17 regions studied. Similarly, the energy sector, one of the most frequently targeted industries by nation states, experienced a 14% increase in breach costs year over year, averaging $6.39 million.  

Advanced Security Technologies Prove Smart for Business  
The report highlights the growing divide in breach costs between businesses implementing advanced security technologies and those lagging behind, revealing a cost-saving difference of $3.58 million for companies with fully deployed security automation versus those that have yet to deploy this type of technology. The cost gap has grown by $2 million, from a difference of $1.55 million in 2018. 

Companies in the study with fully deployed security automation also reported significantly shorter response time to breaches, another key factor shown to reduce breach costs in the analysis. The report found that AI, machine learning, analytics and other forms of security automation enabled companies to respond to breaches over 27% faster than companies that have yet to deploy security automation – the latter of which require on average 74 additional days to identify and contain a breach. 
Incident response (IR) preparedness also continues to heavily influence the financial aftermath of a breach. According to the report, companies with neither an IR team nor testing of IR plans experience $5.29 million in average breach costs, whereas companies that have both an IR team and use tabletop exercises or simulations to test IR plans experience $2 million less in breach costs – reaffirming that preparedness and readiness yield a significant ROI in cybersecurity. 
Some additional findings from this year’s report include: 
 
Remote Work Risk Will Have a Cost – With hybrid work models creating less controlled environments, the report found that 70% of companies studied that adopted telework amid the pandemic expect it will exacerbate data breach costs.  
CISOs Faulted for Breaches, Despite Limited Decision-Making Power: Forty-six percent of respondents said the CISO/CSO is ultimately held responsible for the breach, despite only 27% stating the CISO/CSO is the security policy and technology decision-maker. The report found that appointing a CISO was associated with $145,000 cost savings versus the average cost of a breach.  
Majority of Cyber Insured Businesses Use Claims for Third Party Fees: The report found that breaches at studied organizations with cyber insurance cost on average nearly $200,000 less than the global average of $3.86 million. In fact, of these organizations that used their cyber insurance, 51% applied it to cover third-party consulting fees and legal services, while 36% of organizations used it for victim restitution costs. Only 10% used claims to cover the cost of ransomware or extortion. 
Regional & Industry Insights: While the U.S. continued to experience the highest data breach costs in the world, at $8.64 million on average, the report found that Scandinavia experienced the biggest year over year increase in breach costs, observing a nearly 13% rise. Healthcare continued to incur the highest average breach costs at $7.13 million — an over 10% increase compared to the 2019 study.  
 
About the Study 
The annual Cost of a Data Breach Report is based on in-depth analysis of real-world data breaches taking place between August 2019 and April 2020, taking into account hundreds of cost factors including legal, regulatory and technical activities to loss of brand equity, customers, and employee productivity.  

Tuesday, July 28, 2020

Trend Micro Announces Cloud Solution to Strengthen Misconfiguration Protection for Microsoft Azure



Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global leader in cloud security, today announced its Trend Micro Cloud One™ – Conformity offering is now available to Azure customers, helping global organizations tackle misconfigurations, compliance challenges and cyber-risks in the cloud.

The company also achieved the CIS Microsoft Azure Foundation Security Benchmark. This certifies the Conformity product has built-in rules to check for more than 100 best practices in the CIS framework. 

“The security of the cloud is a cloud providers’ responsibility, but security in the cloud falls to the customer, which is where we fit,” said Wendy Moore, vice president of product marketing for Trend Micro. “Our Cloud One platform integrates closely with Microsoft Azure allowing DevOps to easily deploy against any hybrid cloud environment during their migration to the cloud.”

In-house skills are often overloaded with the challenge of managing hybrid cloud complexities. The proliferation of shadow IT projects in the enterprise also means IT functions are often the last to know if cloud accounts have been created by business units without adequate care and attention paid to compliance, security and governance controls.

Conformity tackles these challenges by providing powerful visibility and control of Azure environments. Its continuous cloud security and compliance posture management capabilities alert customers to the risk status and provide easy-to-action remediation recommendations. These can help prevent common mistakes such as unauthorized database access and public access to Blob storage accounts. 

By implementing the Conformity API into a CI/CD pipeline and existing workflows, DevOps teams can identify potential risk in their cloud infrastructure before they are deployed to live environments for automated, proactive prevention of vulnerabilities. 

Trend Micro Cloud One – Conformity identifies around 230 million cloud misconfigurations for its global Azure and AWS customers every single day. 

Trend Micro’s experience securing multi-cloud environments is a key differentiator to many organizations. “Trend Micro is one of just a few vendors that provides the same full security and monitoring capabilities across both Microsoft Azure and AWS,” said Mario Mendoza, Team Lead, Cyber Security Architecture and Engagement at Blackbaud. “Blackbaud adheres to a DevOps approach internally, so any shift in security vendors requires buy-in from the DevOps teams. The fact that Trend Micro is able to protect Blackbaud’s hybrid cloud environment without slowing down its DevOps teams was critical in our decision for Trend Micro.” 

Trend Micro helps Blackbaud maintain constant vigilance for security and monitoring across its cloud operations. Trend Micro is always on the cutting edge of new threats, and they include us in those efforts. As a market leader, that’s what we look for in partners,” said Mendoza. 

Wednesday, July 22, 2020

Advanced Persistent Threats Backed by Nation-States Focus their Intelligence Gathering on COVID-19 Research: NTT Ltd

NTT Ltd., a world-leading global technology services provider, today released its GTIC Monthly Threat Report for the month of July 2020. The Global Threat Intelligence Center (GTIC) protects, informs, and educates NTT Group clients through threat research, vulnerability research, intelligence fusion and analytics. Attacks from Advanced Persistent Threat (APT) actors continued to be on the rise, despite COVID-19; in fact, the virus has added fuel to the fire and has provided a cover for their operations. Organizations and industries that are considered as essential were increasingly targeted: power grids, oil and gas, postal and delivery services, first responders and law enforcement– assets which are even more valuable during a global crisis.

Key findings:

APTs, particularly those suspected to be backed by nation-states, are focusing on intelligence-gathering efforts on COVID-19 research
APT groups with links to Iran have attempted to breach the World Health Organization (WHO) via phishing campaigns, likely seeking information on testing, treatments, or vaccines
Extortion, espionage, financial gain, and disinformation were the key objectives behind APTs conducting various operations, especially now, during a global crisis
Companies researching the disease should expect to be targeted, whether for purposes of medical advantage to better treat or prevent COVID-19, for monetary gain or purely to inhibit the target from making progress
In addition, APT32 attackers linked to the government of Vietnam have been targeting China, reportedly over its perceived lack of accurate information dissemination during, and the overall handling of the initial outbreak
Normal APT operations have also continued during this same timeframe; and operations related to – or leveraging– COVID-19 have served as a smokescreen as countries continue to focus their efforts in response to the pandemic, from both healthcare and cybersecurity perspectives

Considerations:

As businesses continue to digitally transform and rapidly expand their footprint, they’ve been looking for a network that balances cost, user experience, agility and efficiency. The answer, and solution is a software-defined wide area network (SD-WAN), a virtualized network overlay and a lightweight replacement for traditional physical WAN infrastructure.

While WAN technologies have some native security features, unless reviewed holistically, it’s likely not enough to ensure your SD-WAN is inherently secure. It is a fundamental requirement to do a risk analysis and assessment that considers your organization’s risk profile at the outset of designing your SD-WAN and selecting appropriate security controls
As the threat landscape evolves, even the organizations that may not be considered an essential service cannot let their guard down. Enterprises must continue to adopt best practices and build awareness in both their network environment and their global state of things.

Leveraging intelligence capabilities and resources from around the world, NTT Ltd.’s threat research is focused on gaining understanding and providing insights into the various threat actors, exploit tools and malware.

Tuesday, July 21, 2020

Netmagic Launches SaaS Based Application Performance Monitoring Services Based on the AppDynamics Platform


Netmagic  (An NTT Company), and a leading managed hosting, security and multi-cloud hybrid IT solution provider in India, today announced its partnership with AppDynamics, a Cisco company, to provide Application Performance Monitoring (APM) as a service to enterprises in India to ensure deep visibility into their customers’ critical applications and end user experience.

This service enables businesses to deliver flawless digital experiences consistently by connecting end-user experience and application performance to business outcomes. APMaaS is intuitive to configure and deploy, automatically discovers business transaction, consumes little production overhead, monitors every line of code, and dynamically baselines performance to proactively identify and resolve application performance issues before they impact customers and the business.

Contemporary businesses rely heavily on digital technology to deliver a superior customer experience. Technology today includes a complex fabric of multi-cloud, IOT, distributed services, microservices, containers, APIs and much more that need to work in harmony to ensure that the application performance as experienced by the end user is of high quality.

Speaking about this, Nitin Mishra, Senior Executive Vice President, and Chief Product Officer, Netmagic (An NTT Company) said, “We are extremely pleased to partner with AppDynamics to offer Application Performance Monitoring Service (APMaaS) empowering businesses to navigate this turbulent pandemic period and emerge stronger and more scalable. With the business transaction-centric management of most complex and distributed applications, the APM service will bring value and enhance customer experience by providing clear visibility on the underlying components of the application. Apart from narrowing down to the source of the problem in the entire application flow, it will also provide deep user insights and analytics that will help the customer deliver significantly improved end user experience”

Adding further, Abhilash Purushothaman, Managing Director, India & SAARC, AppDynamics, said, “Our partnership and joint solution offering with Netmagic is a significant milestone for the AppDynamics India business. In India, adoption of online application-led services has sky-rocketed across all industry verticals in recent years. Now with the recent pandemic and increased reliance on remote working, our customers have shared that managing digital user experience in real time is no longer nice to have but a necessity. This strategic partnership will help us scale and deliver APM as a service across all business and industry segments.” 

The modules of this tool that will help in delivering the APM services include Application Performance Management – Core, Performance Management – Microservices Application Performance Management – SAP, Synthetic Transactions Monitoring, Browser Real User Monitoring, Mobile Real User Monitoring, Database Visibility, Infrastructure Visibility, and Business Analytics.

The benefits of the service that would add value to customers’ applications management are –

* Uptime and availability of the applications.
* Slowness in response in terms of time and database can be identified using this service.
* Application performance monitoring for end-users who use browsers and mobiles, tablets etc. to access the applications.

The modules will be wrapped under different packages and offered to customers. The APM solution is based on the package and can be scaled up depending on business requirements. This service can be delivered as a standalone offering or as an enhancement integrated with Netmagic’s Infra Manage Services.

About Netmagic (An NTT Company)

Netmagic, an NTT Company, is India’s leading Managed Hosting and Multi-Cloud Hybrid IT solution provider serving more than 2000 enterprises globally. Headquartered in Mumbai, Netmagic also delivers Remote Infrastructure Management (RIM) services to various enterprise customers globally across Americas, Europe and Asia-Pacific region. The Company was the first in India to launch services – Cloud Computing, Managed Security, Disaster Recovery-as-a-Service (DRaaS) and Software-Defined Storage. Netmagic has been recognized with 8 awards at the CIO Choice 2020, and 2 awards at the Datacenter Dynamics India 2019.

Friday, July 17, 2020

L&T Technology Reports Q1 FY21 Results Medical and Telecom & Hitech Segments Show Resilience, Announces Acquisition of Orchestra


L&T Technology Services Limited (BSE: 540115, NSE: LTTS), India’s leading pure-play engineering services company, announced its results for the first quarter ended June 30, 2020.

Key financial parameters for Q1FY21:

USD Revenue at $171 million
Revenue at ₹12,947 million; down 4% YoY
EBIT margin at 12.1%
Net profit at ₹1,173 million; down 42% YoY
 
LTTS has executed a definitive agreement to acquire 100% stake in Orchestra Technology, a specialist technology solutions provider for the Telecom industry. Orchestra is based in Texas, USA and will enable LTTS to strengthen its capabilities in network engineering and modernization.

“With many industries operating at limited capacity on account of the pandemic, Q1 was a challenging quarter as expected. Still, we had a good performance in two of our segments - Telecom & Hitech and Medical, and our large deal engine continues to churn wins. Free cash flow generation was strong during the quarter and the healthy cash position sets us up well for the future.  Looking ahead, we see a path for recovery backed by good order bookings and a healthy pipeline. We expect both revenue and operating margin to show sequential improvement over the remaining quarters of the current fiscal.

The acquisition of Orchestra will enhance our offerings in the areas of Network Engineering & Enterprise Mobility and provide us strategic access to Telecom service providers who are investing in next generation digital systems for 5G and IoT networks.

As customers redraw their business plans, we are working with them to improve operating efficiency, finetune sourcing and production plans, and prepare for faster go-to-market.  Our newer set of offerings like Frugal Manufacturing, Telehealth solution and i-BEMS Shield are seeing good traction in the market. The large deal discussions we are having with customers are a notch higher in terms of criticality and adoption of new age technologies, which we believe will pave the way for greater mind share and competitive differentiation”, said Dr. Keshab Panda, CEO & Managing Director, L&T Technology Services Limited.

During the quarter, LTTS won 9 multi-million dollar deals across all major industry segments which includes one deal with TCV of USD30mn plus and two deals with TCV of USD15mn plus. On a YoY basis, LTTS has increased its USD10mn+ clients by 5 and its USD1mn+ clients by 3.

Industry Recognitions:

* TechCircle honored LTTS with the Business Transformation Award in the “New Markets” category to our IT and HR functions jointly for leading digital transformation at LTTS with innovative solutions.

* Enterprise IT magazine conferred LTTS’ IT Team with the “COVID-19 Super Hero Award” for their tireless efforts to help LTTS’ workforce during lockdown.

Patents

At the end of the first quarter, the patents portfolio of L&T Technology Services stood at 525, out of which 385 are co-authored with its customers and the rest are filed by LTTS.

Human Resources

At the end of Q1FY21, LTTS’ employee strength stood at 16,641.

Seagate's ‘Rethink Data’ Report Reveals that 68% of Data Available to Businesses goes Unleveraged


The report also identifies the missing link of data management—DataOps—which can help organizations harness more of their data’s value and lead to better business outcomes.

Seagate Technology plc, a world leader in data storage and management solutions, today released Rethink Data: Put More of Your Data to Work—From Edge to Cloud. The report—based on a survey of 1500 global enterprise leaders, which was commissioned by Seagate and conducted by the research firm IDC—identifies today’s most pressing data management challenges, and solutions to them. It pinpoints the amount of data available to enterprises that goes unused: 68%.

“The report and the survey make clear that winning businesses must have strong mass data operations,” says Seagate CEO Dave Mosley. “The value that a company derives from data directly affects its success.”

The most significant findings include:

Data management is increasingly important as data proliferates. IDC projects that over the next two years enterprise data will grow at a 42.2% annual rate.
Only 32% of data available to enterprises is put to work. The remaining 68% is unleveraged. 
The top five barriers to putting data to work are: 1) making collected data usable, 2) managing the storage of collected data, 3) ensuring that needed data is collected, 4) ensuring the security of collected data, and 5) making the different silos of collected data available.
Managing data in the multicloud and hybrid cloud are top data management challenges expected by businesses over the next two years.
Two thirds of survey respondents report insufficient data security, making data security an essential element of any discussion of efficient data management.
 
The report identifies the missing link of data management: data operations, or DataOps. IDC defines DataOps as “the discipline connecting data creators with data consumers.” While the majority of respondents say that DataOps is “very” or “extremely” important, only 10% of organizations report having implemented DataOps fully. The survey demonstrated that, along with other data management solutions, DataOps leads to measurably better business outcomes. It boosts customer loyalty, revenue, profit, cost savings, plus results in other benefits.

"The findings of this study illustrating that more than two-thirds of available data lies fallow in organizations may seem like disturbing news," said Phil Goodwin, research director, IDC and principal analyst on the study. "But in truth, it shows how much opportunity and potential organizations already have at their fingertips. Organizations that can harness the value of their data wherever it resides—core, cloud or edge—can generate significant competitive advantage in the marketplace."

The survey queried 1500 respondents—500 in the Asia Pacific and Japan region, 475 in Europe, 375 respondents in North America, and 150 in China.

About Seagate Technology

Seagate Technology crafts the datasphere, helping to maximize humanity’s potential by innovating world-class, precision-engineered data management solutions with a focus on sustainable partnerships. Learn more about Seagate by visiting www.seagate.com or following us on Twitter, Facebook, LinkedIn, YouTube, and subscribing to our blog.

About IDC

International Data Corporation (IDC) is the premier global provider of market intelligence, advisory services, and events for the information technology, telecommunications, and consumer technology markets.

©2020 Seagate Technology LLC. All rights reserved. Seagate, Seagate Technology, and the Spiral logo are registered trademarks of Seagate Technology LLC in the United States and/or other countries. All other trademarks or registered trademarks are the property of their respective owners.

Thursday, July 16, 2020

Trend Micro Research Discovers Botnet Battle for Home Routers


Trend Micro Incorporated, a global leader in cybersecurity solutions, today released new research warning consumers of a major new wave of attacks attempting to compromise their home routers for use in IoT botnets. The report urges users to take action to stop their devices from enabling this criminal activity.

There has been a recent spike in attacks targeting and leveraging routers, particularly around Q4 2019. This research indicates increased abuse of these devices will continue as attackers are able to easily monetize these infections in secondary attacks.

"With a large majority of the population currently reliant on home networks for their work and studies, what's happening to your router has never been more important," said Jon Clay, director of global threat communications for Trend Micro. "Cybercriminals know that a vast majority of home routers are insecure with default credentials and have ramped up attacks on a massive scale. For the home user, that's hijacking their bandwidth and slowing down their network. For the businesses being targeted by secondary attacks, these botnets can totally take down a website, as we've seen in past high-profile attacks."

Trend Micro's research revealed an increase from October 2019 onwards in brute force log-in attempts against routers, in which attackers use automated software to try common password combinations. The number of attempts increased nearly tenfold, from around 23 million in September to nearly 249 million attempts in December 2019. As recently as March 2020, Trend Micro recorded almost 194 million brute force logins.

Another indicator that the scale of this threat has increased is devices attempting to open telnet sessions with other IoT devices. Because telnet is unencrypted, it's favored by attackers – or their botnets – as a way to probe for user credentials. At its peak, in mid-March 2020, nearly 16,000 devices attempted to open telnet sessions with other IoT devices in a single week.

This trend is concerning for several reasons. Cybercriminals are competing with each other to compromise as many routers as possible so they can be conscripted into botnets. These are then sold on underground sites either to launch Distributed Denial of Service (DDoS) attacks, or as a way to anonymize other attacks such as click fraud, data theft and account takeover.

Competition is so fierce that criminals are known to uninstall any malware they find on targeted routers, booting off their rivals so they can claim complete control over the device.

For the home user, a compromised router is likely to suffer performance issues. If attacks are subsequently launched from that device, their IP address may also be blacklisted – possibly implicating them in criminal activity and potentially cutting them off from key parts of the internet, and even corporate networks.

As explained in the report, there's a thriving black market in botnet malware and botnets-for-hire. Although any IoT device could be compromised and leveraged in a botnet, routers are of particular interest because they are easily accessible and directly connected to the internet.

Trend Micro makes the following recommendations for home users:

Make sure you use a strong password. Change it from time to time.
Make sure the router is running the latest firmware.
Check logs to find behavior that doesn't make sense for the network.
Only allow logins to the router from the local network.

Thursday, July 9, 2020

JFrog Launches First Security-Focused, Immutable Chart Repository for Helm, the Package Manager for Kubernetes


JFrog, the Universal DevOps technology leader known for enabling liquid software via continuous update flows, announced the launch of ChartCenter, the first free, security-focused central repository of Helm charts for the community. The ChartCenter repository ensures that developers can easily access consistent versions of any publicly available Helm charts, which are currently stored in various locations across the web and can be changed or removed at any time.

“Helm plays a critical role in the fast-growing Kubernetes ecosystem, and it’s important for developers to be able to access and share consistent and secure versions of Helm charts for their applications,” said JFrog CTO and co-founder Yoav Landman. “We are creating a true unified and open repository that allows developers to set up a single, trusted location to consume immutable charts from every chart creator, together with important security information and metadata attached to these charts.”

Helm is an application package manager running atop Kubernetes that simplifies the process of defining, storing, and managing applications through convenient Helm charts. With different Helm charts and versions traditionally stored on various sites across the internet, it has been hard for developers to trust, locate, and learn about them all. Developers also risk losing access to a specific chart if the host removes it. ChartCenter joins the JFrog “centers” family, already encompassing GoCenter, ConanCenter and JCenter as hubs for immutable artifacts. JFrog’s centers are provided as free services, which already support millions of developers globally.

“While security and immutability are very important, another critical concern is observability of transitive dependencies,” said JFrog VP of Community Engineering, Jagan Subramanian. “Installing Helm charts results in pulling in container images and other sub charts that may contain security and license issues, deprecated artifacts, or outdated library dependencies. Making this information readily available promotes higher quality in managing open source dependencies by making the community aware and enables consumers to take proactive measures to safeguard their production deployments”.

JFrog’s ChartCenter addresses this issue by offering a one-stop shop that includes all major Helm charts currently available across the web today, along with important security information and metadata around dependencies and application versions. Organizations can use ChartCenter to find immutable and highly available versions of Helm charts and can even add their own.

ChartCenter was built with the help of Rimas Mocevicius, the co-creator of Helm, to address the needs of the Kubernetes developer community. Along with serving as the first immutable repository for Helm charts, ChartCenter offers super search and other important features and functionality, including:

* Robust metadata about each chart version including downloads, license information, apiVersion, application version, and more!
* Superior search by name, description, and keyword
* Free security scanning that shows vulnerabilities in dependencies
* Ability for developers to add their own charts to the UI
* Dependency tree showing all dependencies of each chart and version
 * ChartCenter is available to the general public immediately.

Thursday, July 2, 2020

Trend Micro Finds 72% of Remote Workers Have Gained Cybersecurity Awareness During Lockdown


Trend Micro Incorporated, a global leader in cybersecurity solutions, today released survey results that show how remote workers address cybersecurity. Nearly three quarters (72%) of remote workers say they are more conscious of their organisation’s cybersecurity policies since lockdown began, but many are breaking the rules anyway due to limited understanding or resource constraints.

Trend Micro’s Head in the Clouds study is distilled from interviews with 13,200 remote workers across 27 countries on their attitudes towards corporate cybersecurity and IT policies. It reveals that there has never been a better time for companies to take advantage of heightened employee cybersecurity awareness. The survey reveals that the approach businesses take to training is critical to ensure secure practices are being followed.

In India, the results indicate a high level of security awareness, with 84% of respondents claiming they take instructions from their IT team seriously, and 83% agree that cybersecurity within their organisation is partly their responsibility. Additionally, 67% acknowledge that using non-work applications on a corporate device is a security risk.

However, just because most people understand the risks does not mean they stick to the rules.

For example:

44% of employees admit to using a non-work application on a corporate device, and 46% of them have actually uploaded corporate data to that application.
83% of respondents confess to using their work laptop for personal browsing, and only 45% of them fully restrict the sites they visit.
42% of respondents say they often or always access corporate data from a personal device – almost certainly breaking corporate security policy.
14% of respondents admit to watching / accessing porn on their work laptop, and 14% access the dark web.

Productivity still wins out over protection for many users. 52% of respondents agree that they do not give much thought to whether the apps they use are sanctioned by IT or not, as they just want the job done. Additionally, 44% think they can get away with using a non-work application, as the solutions provided by their company are ‘nonsense.’

Dr Linda K. Kaye, Cyberpsychology Academic at Edge Hill University explains: “There are a great number of individual differences across the workforce. This can include individual employee’s values, accountability within their organisation, as well as aspects of their personality, all of which are important factors which drive people’s behaviours. To develop more effective cybersecurity training and practices, more attention should be paid to these factors. This, in turn, can help organisations adopt more tailored or bespoke cybersecurity training with their employees, which may be more effective.”

Nilesh Jain, Vice President, Southeast Asia and India, Trend Micro, said, “It’s really heartening to see that so many people take the advice from their corporate IT team seriously, although you have to wonder about the 16% who don’t. At the same time those people also accept their own role in the human firewall of any organisation. The problem area seems to be translating that awareness into concrete behaviour. To reinforce this, organisations to take into account the diversity across the organisation and tailor training to identify and address these distinct behavioural groups. The time to do this is now, to take advantage of the new working environment and people’s newfound recognition of the importance of information security.”

The Head in the Clouds study looks into the psychology of people’s behaviour in terms of cybersecurity, including their attitudes towards risk. It presents several common information security “personas” with the aim of helping organisations tailor their cybersecurity strategy in the right way for the right employee.

Wednesday, July 1, 2020

Godrej Security Solutions Launches UV Case; Expands Health Security Portfolio in India

Godrej Security Solutions (GSS), the leading player in future technology of security solutions, announced its venture into the health security segment with the COVID Defence Security Range of products in May. To meet the growing demand for products in the health security space, Godrej has launched ‘UV Case’ and expanded its health security segment.  The  portfolio address the issue of sanitising daily objects, equipment and surfaces that come in contact with several people before entering a premise.

The newly launched UV Case from Godrej Security Solutions uses the UV-C light disinfection technology that helps to create a multiple barrier approach to reducing the transmission of the virus and germs based on current disinfection data and empirical evidence. Worldwide, UV-C Sterilization is the most established scientific method for dry killing more than 65 families of pathogens, viruses and bacteria, including SARS-CoV-1.

Commenting on the launch Mehernosh Pithawalla, Vice President, Godrej Security Solutions said, “Studies show that UV-C light has been used extensively for more than 40 years in disinfecting drinking water, wastewater, air, pharmaceutical products, and surfaces against a whole suite of human pathogens. Today, health security has become a priority for everyone. There is an increased need for a product post-COVID-19 that would sanitise anything that has been brought home from external environments. The Godrej UV Case meets this need; it disinfects and decontaminates almost everything used by an individual daily from mobiles, masks, newspaper, clothes, accessories, books, bags and many other innumerable articles. It will also be helpful for the healthcare sector for sanitisation of PPEs kits. As a market leader, it was incumbent on us to launch a product only after rigorous internal and external testing before it could reach consumers. With the UV Case, we move one step closer to achieving our mission of making the world a safer and healthier place.”

Mehernosh added, “Godrej Security Solution estimates the total addressable health security and safety market for FY-2021 in the country is around INR 200 Crore. We seek to capture at least 20% share of the addressable market. Homes, work-places of the future, as well as many industries, will have to ensure minimum human interference and combat spread of infectious diseases through surface contact. The product enables homeowners and commercial establishments to sanitise their daily-use items like watches, wallets, keys, mobiles, clothes, parcels, among others. Stationery, medical equipment, and salon products can be disinfected in the case to protect and sanitise them before use. Shop owners can disinfect their items for sale before and after customers have had a touch and feel of the same.”

The sanitisation process of the UV Case is a chemical-free case that helps to kill 99.9% viruses and sanitises everything from cash, jewellery, mobile phones to masks, and PPE Kits. The new product has found industry-wide applications in Hospitality, Healthcare, Leisure, Retail, and Homes. The UV Case comes in 3 sizes – 15L, 30L and 54L which gives consumer maximum usable volume ranging for home use to industrial use starting at INR 8,999. Currently available across stores from GSS and will be available on their e-commerce website (shop.godrejsecure.com).

Tuesday, June 30, 2020

IBM Study: Security Response Planning on the Rise, But Containing Attacks Remains an Issue

Security Study

*Global Survey Finds Use of More Than 50 Security Tools Leads to Less-Effective Security Response
* Majority of Organizations Don’t Have Specific Plans for Common and Emerging Attacks  

IBM Security has announced the results of a global report examining businesses’ effectiveness in preparing for and responding to cyberattacks. While organizations surveyed have slowly improved in their ability to plan for, detect and respond to cyberattacks over the past five years, their ability to contain an attack has declined by 13% during this same period. The global survey conducted by Ponemon Institute and sponsored by IBM Security found that respondents’ security response efforts were hindered by the use of too many security tools, as well as a lack of specific playbooks for common attack types.

While security response planning is slowly improving, the vast majority of organizations surveyed (74%) are still reporting that their plans are either ad-hoc, applied inconsistently, or that they have no plans at all. This lack of planning can impact the cost of security incidents, as companies that have incident response teams and extensively test their incident response plans spend an average of $1.2 million less on data breaches than those who have both of these cost-saving factors in place. IBM Security and Ponemon Institute: 2019 Cost of a Data Breach Report

The key findings of those surveyed from the fifth annual Cyber Resilient Organization Report include:
* Slowly Improving:  More surveyed organizations have adopted formal, enterprise-wide security response plans over the past 5 years of the study; growing from 18% of respondents in 2015, to 26% in this year’s report (a 44% improvement).
* Playbooks Needed: Even amongst those with a formal security response plan, only one third (representing 17% of total respondents) had also developed specific playbooks for common attack types — and plans for emerging attack methods like ransomware lagged even further behind.
* Complexity Hinders Response: The amount of security tools that an organization was using had a negative impact across multiple categories of the threat lifecycle amongst those surveyed. Organizations using 50+ security tools ranked themselves 8% lower in their ability to detect, and 7% lower in their ability to respond to an attack, than those respondents with less tools.
* Better Planning, Less Disruption: Companies with formal security response plans applied across the business were less likely to experience significant disruption as the result of a cyberattack. Over the past two years, only 39% of these companies experienced a disruptive security incident, compared to 62% of those with less formal or consistent plans.

"While more organizations are taking incident response planning seriously, preparing for cyberattacks isn’t a one and done activity," said Wendi Whitmore, Vice President of IBM X-Force Threat Intelligence. "Organizations must also focus on testing, practicing and reassessing their response plans regularly. Leveraging interoperable technologies and automation can also help overcome complexity challenges and speed the time it takes to contain an incident.”

Vikas Arora, VP, IBM Cloud & Cognitive Software & Services, IBM India and South Asia, said, "While Indian organizations have shown improvement in terms of their cyber resiliency by hiring skilled professionals and overall planning, there needs to be a lot more done to manage the dynamic cybersecurity landscape. Organizations need to look at testing their cybersecurity incident response plan regularly and leverage technologies like Automation, Cloud, AI, and interoperable solutions to help sail through any unforeseen situation."

Updating Playbooks for Emerging Threats
The survey found that even amongst organizations with a formal cybersecurity incident response plan (CSIRP), only 33% had playbooks in place for specific types of attacks. Since different breeds of attack require unique response techniques, having pre-defined playbooks provides organizations with consistent and repeatable action plans for the most common attacks they are likely to face.  

Amongst the minority of responding organizations who do have attack-specific playbooks, the most common playbooks are for DDoS attacks (64%) and malware (57%). While these methods have historically been top issues for the enterprise, additional attack methods such as ransomware are on the rise. While ransomware attacks have spiked nearly 70% in recent years, IBM Security, 2020 X-Force Threat Intelligence Index, (2020), p. 15 only 45% of those in the survey using playbooks had designated plans for ransomware attacks.

Additionally, more than half (52%) of those with security response plans said they have never reviewed or have no set time period for reviewing or testing those plans. With business operations changing rapidly due to an increasingly remote workforce, and new attack techniques constantly being introduced, this data suggests that surveyed businesses may be relying on outdated response plans which don’t reflect the current threat and business landscape.

More Tools Led to Worse Response Capabilities
The report also found that complexity is negatively impacting incident response capabilities. Those surveyed estimated their organization was using more than 45 different security tools on average, and that each incident they responded to required coordination across around 19 tools on average. However, the study also found that an over-abundance of tools may actually hinder organizations ability to handle attacks. In the survey, those using more than 50 tools ranked themselves 8% lower in their ability to detect an attack (5.83/10 vs. 6.66/10), and around 7% lower when it comes to responding to an attack (5.95/10 vs. 6.72/10).

These findings suggest that adopting more tools didn’t necessarily improve security response efforts — in fact, it may have done the opposite. The use of open, interoperable platforms as well as automation technologies can help reduce the complexity of responding across disconnected tools. Amongst high-performing organizations in the report, 63% said the use of interoperable tools helped them improve their response to cyberattacks.

Better Planning Pays Off
This year’s report suggests that surveyed organizations who invested in formal planning were more successful in responding to incidents. Amongst respondents with a CSIRP applied consistently across the business, only 39% experienced an incident that resulted in a significant disruption to the organization within the past two years compared to 62% of those who didn’t have a formal plan in place.

Looking at specific reasons that these organizations cited for their ability to respond to attacks, security workforce skills were found to be a top factor. 61% of those surveyed attributed hiring skilled employees as a top reason for becoming more resilient; amongst those who said their resiliency did not improve, 41% cited the lack of skilled employees as the top reason.

Technology was another differentiator that helped organizations in the report become more cyber resilient, especially when it comes to tools that helped them resolve complexity. Looking at organizations with higher levels of cyber resilience, the top two factors cited for improving their level of cyber resilience were visibility into applications and data (57% selecting) and automation tools (55% selecting). Overall, the data suggests that surveyed organizations that were more mature in their response preparedness relied more heavily on technology innovations to become more resilient.

About the Study: Conducted by the Ponemon Institute and sponsored by IBM Security, the 2020 Cyber Resilient Organization Report is the fifth installment covering organizations’ ability to properly prepare for and handle cyberattacks. The survey features insight from more than 3,400 security and IT professionals from around the world, including the United States, India, Germany, United Kingdom, Brazil, Japan, Australia, France, Canada, ASEAN, and the Middle East.

VMware Partners with Netmagic to Launch CloudHealth Service in India


Netmagic, an NTT Company, and India’s leading Managed Hosting and Multi-Cloud Hybrid IT solution provider, today announced its partnership with VMware to launch SimpliInsight Services powered by VMware CloudHealth service in India. VMware Cloud Provider Program (VCPP) s is a global ecosystem of providers offering cloud services based on VMware technology.

Netmagic is one of the largest VCPP partners in India to develop the orchestration layer on top of the VMware virtualization platform.

Netmagic has achieved VMware Cloud Verified status and becomes the first Cloud verified partner to launch SimpliInsight Services powered by VMware CloudHealth in the country.

The Cloud Verified badge signals to customers that Netmagic offers a service running on top of the complete VMware Cloud infrastructure. Through Cloud Verified partner services, customers attain access to the full set of VMware Cloud Infrastructure capabilities including integration and interoperability, cost optimization and flexibility.

With SimpliInsight Services powered by VMware CloudHealth, Netmagic will deliver a consistent and actionable view into cost and resource management, security, and performance for applications across multiple cloud environments. SimpliInsight Services powered by VMware CloudHealth will help Netmagic’s customer realize costs saving across multi-cloud deployments such as Azure, AWS, Google Cloud Platform (GCP), etc.

“We are extremely pleased to partner with VMware. Netmagic's SimpliInsight service powered by VMware CloudHealth will support businesses with in-depth visibility on cost, performance and security – allowing our customers to make informed strategic decisions for their deployments across hyperscalers like AWS, Azure and Google,” said Nitin Mishra, Senior Executive Vice President and Chief Product Officer, Netmagic.

Pradeep Nair, Managing Director, VMware India, “Cloud infrastructure services spend hit yet another record in Q1 2020, growing 34% (YoY) to $31 billion[1]. This growth in cloud services is driven in no small part by the global shift to remote working and increased push for digital transformation. Organizations in India are cognizant of the value delivered by cloud and we are witnessing a significant upswing in cloud adoption across sectors. At VMware we strive to help our customers manage their cloud infrastructure seamlessly and efficiently for maximum ROI. With CloudHealth, organizations in India can effectively manage multiple cloud environments through a single pane of glass.  Our partnership with Netmagic will enable a wide range of Indian customers to benefit from our unified cloud management solutions and help accelerate the Indian cloud adoption narrative further.”

David Bate, VP, Cloud, VMware Asia Pacific & Japan, VMware, “Enterprises in APJ are embracing a multi-cloud model and are looking for ways to assemble, deploy, shift and manage workloads across their hybrid cloud environment.  The partnership with Netmagic will bring together the capabilities for delivering cloud infrastructure, consumption and resource management to customers in India. We are excited to support their journey and are confident that SimpliInsight Services powered by VMware CloudHealth will utilize our platform to deliver a fully automated cloud management experience.”

VMware’s global network of more than 4,000 VMware Cloud Providers leverage VMware’s consistent cloud infrastructure to offer a wide array of services, provide geographic and industry specialization, and help customers meet complex regulatory requirements. Cloud Providers operating under the VMware Cloud Provider Program deliver individually tailored cloud solutions and services in more than 120 countries.

Total Pageviews