{"id":34132,"date":"2019-01-09T12:03:40","date_gmt":"2019-01-09T04:03:40","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=34132"},"modified":"2019-01-09T12:05:48","modified_gmt":"2019-01-09T04:05:48","slug":"cybersecurity-resolutions-to-implement-for-2019","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/01\/09\/cybersecurity-resolutions-to-implement-for-2019\/","title":{"rendered":"Cybersecurity resolutions to implement for 2019"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>The recent findings of the <\/strong><a href=\"http:\/\/www.sophos.com\/\"><strong>Sophos<\/strong><\/a><strong> <\/strong><a href=\"http:\/\/www.sophos.com\/threatreport\"><strong>2019 Threat Report<\/strong><\/a><strong> highlighted how cybercriminals are stepping up their game and are outsmarting and overpowering traditional antivirus or endpoint security solutions. &nbsp;Unfortunately, many Filipino organizations today still think&nbsp; that these suffice as cybersecurity measures. However, these are only equipped to block known threats and can only play catch up with the speed and creativity of ransomware today. An independent global research study commissioned by Sophos actually found that over three quarters (77%) of ransomware victims were actually running up-to-date endpoint security when they were attacked.<\/strong><a href=\"#_ftn1\"><strong>[1]<\/strong><\/a><strong> <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In what ways are cybercriminals today more dangerous? The\nSophos 2019 Threat Report found the following three emerging cybercriminal\nbehaviors and attacks:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Cybercriminals are now taking time to get to know you.\n<\/strong>They\nare going beyond \u2018spray and pray\u2019 style attacks\nthat are automatically distributed through millions of emails, and turning to premeditated and targeted ransomware\nattacks.These are more damaging than if delivered from a bot, as\nhuman attackers can find and stake out victims, think laterally, trouble shoot\nto overcome roadblocks, and wipe out back-ups so the ransom must be paid.<\/li><li><strong>&nbsp;They are using\nyour own admin tools against you.<\/strong> They are using Advanced\nPersistent Threat (APT) techniques to advance through your system and complete\ntheir mission \u2013 whether it is to steal sensitive information off the server or\ndrop ransomware. In addition, lateral distribution on corporate networks allows\ncybercriminals to quickly infect multiple machines, increasing payouts to the\nhacker and heavy costs to victims. <\/li><li><strong>They are going beyond organizations\u2019 infrastructures\nand following victims home by unleashing mobile and IoT malware<\/strong>.With illegal Android apps on the increase,&nbsp;2018\nhas seen an increased focus in malware being pushed to phones, tablets and\nother Internet of Things devices. As homes and businesses adopt more\ninternet-connected devices, criminals have been devising new ways to hijack\nthose devices to use as nodes in huge botnet attacks. <\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">To help you stay ahead of these new threats, Sophos\nhas the following recommended cybersecurity New Year\u2019s resolutions for your\norganization:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Implement\nmulti-layered security. <\/strong>This will\nprotect your organization from multiple frontlines. As attackers today become\nincreasingly sophisticated, they use multiple techniques and points of entry to\nbypass defenses and evade detection. This drives the need for securing not just\nendpoints such as workstations, laptops, and mobile devices, but also\norganizations\u2019 networks and firewalls.&nbsp;&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While the time, cost and complexity&nbsp;of\nimplementing additional layers of technology can be overwhelming,&nbsp; <strong>synchronized security<\/strong> simplifies things\nand enables defenses to work together as a system to be more coordinated than\nthe attackers. In\ntoday\u2019s world of constant and changing cyber-threats, having endpoint and\nnetwork products communicating with each other and sharing intelligence is more\nimportant than ever. Aside from removing the headache of having\nto deal with multiple&nbsp;endpoint agents, multiple management consoles, and\nmultiple security vendors, this also makes more effective, while making the\nfinancial cost of security to the organization easier to manage. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Predictive protection<\/strong> is\nthe future of IT security.&nbsp;It allows organizations to protect against the\nnext unknown attack instead of waiting for it to arrive, changing the way IT\noperations in every organization can protect their users and assets. Security\nsolutions with predictive protection powered by deep learning neural-network\nalgorithms make smarter and more scalable detection than endpoint solutions that use traditional machine\nlearning or signature-based detection alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Stay on top of your patching, vulnerability scans,\nand penetration tests.. <\/strong>Security experts\nestimate that 90% of successful attacks against software vulnerabilities could\nbe prevented with an existing patch or configuration setting.<a href=\"#_ftn2\">[2]<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">4. <strong>Maintain good password discipline and use\nmulti-factor authentication<\/strong>. Passwords are at the frontline of\ncybersecurity and can provide a formidable barrier to targeted attacks. Explore\ncreating unique and complex passphrases on your own or getting assistance from\npassword managers. Fortify this barrier by making it a standard to enable\nmulti-factor authentiation.&nbsp; When\npossible, use app-based options like Sophos Authenticator.&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">5. <strong>Establish cybersecurity protocols with your\nteam.<\/strong>&nbsp; Restrict RDP (remote desktop\nprotocol) access to staff connecting over a VPN (virtual public network). For\nthose unfamiliar, RDP allows organizations to outsource their IT to remote\nsystem administrators. While it can be a helpful cost-effective measure for\norganizations, it also has its own dangers. SamSam, a particularly sophisticated\nand destructive ransomware known for its ability to put entire organizations\nunder siege, enters victims\u2019 networks using exploits in internet-facing servers\nor by brute-forcing&nbsp;RDP passwords. This is why RDP needs to be\nhighly-secured. In case a crook has been able to sneak in through an open RDP,\norganizations can have another measure of protection if they have back-up files\nthat are kept offline and offsite.<br><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref1\"><em>[1]<\/em><\/a><em> In late 2017, Sophos sponsored the \u201c<\/em><a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/Gated-Assets\/white-papers\/endpoint-survey-report.pdf\"><em>State of Endpoint Security Today<\/em><\/a><em>\u201d to gain a deeper understanding into the state of endpoint security in mid-sized organizations across the globe. This extensive research program explores key areas of development and concern: security breaches, technology usage, attitudes to threats, and future investment plans.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"#_ftnref2\">[2]<\/a> <a href=\"https:\/\/www.sophos.com\/en-us\/security-news-trends\/security-trends\/three-simple-steps-to-better-patch-security.aspx\">Sophos security\ntrends<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In what ways are cybercriminals today more dangerous? The Sophos 2019 Threat Report found the following three emerging cybercriminal behaviors and attacks.<\/p>\n","protected":false},"author":6,"featured_media":33149,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[1141,6498,6151,54,206,96],"class_list":["post-34132","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinions","tag-cybercriminals","tag-good-tech","tag-high-tech","tag-security","tag-sophos","tag-technology"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/34132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=34132"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/34132\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/33149"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=34132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=34132"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=34132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}