https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Internet security

Customers Got Zero-Day Panic? Keep Calm, Keep Patching

  • Written by Channel
  • March 10, 2016
Don't get bogged down worrying about elite attackers. Excel at the basics.

Chester WisniewskiBy Chester Wisniewski

2015 was a record year for data breaches, both in terms of the number of leaked and stolen records and the amount of money the attacks cost victims. The breaches generated news headlines, with pundits repeating dire warnings over just how difficult it is to defend against sophisticated attackers who leverage zero-day threats. No wonder you probably got a few calls from customers asking, “Are we secure?”

While I don’t want to downplay the potential damage a zero-day attack can cause, I do want to remind all security industry professionals – including solutions providers, CSOs and security administrators – that zero days are a very small percentage of all attacks. I tracked incidents using zero-day exploits from October 2014 to October 2015 and discovered that more than half were used only in a targeted attack against one organization. Of the remaining four, only one was used in a widespread manner.

That means you need to keep up with the basics: updating systems with the latest patches, encrypting data and regular user education.

The most recent Verizon Data Breach Investigations Report (DBIR) confirms this. The initial DBIR in 2008 reported that the overwhelming majority of attacks exploited known vulnerabilities and that, in most of those cases, the patch had been available for months prior to the breach.

Fast forward to today, and things haven’t changed. The 2015 DBIR reveals that 99.9 percent of exploited vulnerabilities had been compromised more than a year after the associated patch was released.

To quote from the report, “Apparently, hackers really do still party like it’s 1999.”

Encryption a Must

Having made the case that you’re unlikely to be hit by a zero-day, I still recommend you help customers prepare for any attack that patching cannot stop. Applying patches quickly enough and across all devices is nearly impossible, so we must prepare for compromise.

That means encryption. Although most traffic to external sites utilizes HTTPS now, too many organizations still leave sensitive information at risk on their own networks. We surveyed 1,700 IT decision makers around the world and asked them what types of data their organizations encrypt, and why they don’t always encrypt everywhere. We found that nearly one-third (30 percent) fail to always encrypt their own corporate financial information, and 41 percent inconsistently encrypt files containing valuable intellectual property, despite the increasing risks of economic espionage.

Another red flag: Many organizations don’t recognize that the different types of encryption – full-disk and file – are not and should not be mutually exclusive. Full-disk encryption protects lost or stolen devices, but can’t protect the data once the user logs in or shares the content.

File-level encryption is often necessary and complementary so that data is always protected: at rest, in transit and when stored off-device. Yet only 36 percent of respondents said they use both full-disk and file encryption.

As more businesses migrate applications from the data center to the cloud, the risk of loss or theft increases. While 80 percent of the companies we polled are using cloud storage, only 39 percent encrypt all files they store in the cloud.

Recommendations

Sophisticated and targeted zero-day attacks like the one against Sony Pictures are devastating. Before you worry about prepping customers for a zero-day attack, make sure you’re protecting their information and systems against the vast majority of threats:

  • Be stringent about making sure customers stay up-to-date on all patches.
  • Ensure data is encrypted at rest and in motion across, and out of, the network.
  • Schedule regular education sessions for all users on best practices, such as verifying messages are genuine before opening attachments or clicking links.

Chester Wisniewski is a Senior Security Advisor at Sophos Canada. He provides advice and insight into the latest threats for security and IT professionals with the goal of providing clear guidance on complex topics. You can follow Chester on Twitter as @chetwisniewski, on App.net as Chester, Chester Wisniewski on Google Plus or send him an email at [email protected].

Tags: Agents Security

Most Recent


  • Update
    Cisco Updates Networking, Security and Operations Portfolio
    The vendor also announced ThousandEyes OpenTelemetry and a preview of its Full-Stack Observability Platform at Cisco Live Amsterdam.
  • Update
    Acronis Updates CyberFit Partner Program Amid Rapid Service Provider Growth
    The updates include several programs and promotions for all types of partners.
  • Cloud Roundup
    Cloud Computing News: Broadcom-VMware, Google-Anthropic, Red Hat, More
    A new week is kicking off with a slew of cloud updates.
  • Word new on fire
    Skyhigh Security Partners Get New Global Partner Program
    This is Skyhigh Security's first partner program since the company's launch last March.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • USB drive
    A Coup and a Theft: Why MSPs Can’t Let Clients Get Lax About USB Security
  • Ransomware skull and crossbones
    JBS Did What it 'Needed to Do' with $11 Million Ransom Payment
  • hybrid clouds
    Nutanix, HPE Team on Hybrid, Multicloud via GreenLake
  • lone Arctic wolf
    Arctic Wolf Enhances Partner Program with 2 New Tiers

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Abundant IoT, Advisors Tackle the eIoT Opportunity

February 6, 2023

Top 20 Stories in January: Avaya, Microsoft, IBM, AWS, Datto, More Layoffs

February 6, 2023

Cloud Computing News: Broadcom-VMware, Google-Anthropic, Red Hat, More

February 6, 2023

Industry Perspectives

View all

The Software Patching Problem – Solved

February 3, 2023

How to Break Through the Growth Ceiling

February 1, 2023

5 Things to Look for in a UC Partner

January 31, 2023

Webinars

View all

Next-Generation MSP Platform: The Building Blocks for Your Business

February 15, 2023

The SMB Opportunity: How to Sell and Service the SMB Market, Capture Customers and Expand Your Business

February 23, 2023

How To Boost Your Business With White-Label UCaaS

February 28, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 117: Cato Networks, Video Killed the Podcast Stars

Retired Astronaut Capt. Scott Kelly Previews His CP Expo Keynote

December 21, 2022

Fusion Connect Eyes Future with Intrado UC, Managed Network Customers

September 23, 2022

RingCentral Focused on Hybrid Work, Microsoft Teams, Other Integrations

September 23, 2022

Twitter

ChannelFutures

Are you going to #CPExpo? We have new vendors signing on to join us daily, don't miss out! Register today >>… twitter.com/i/web/status/1…

February 7, 2023
ChannelFutures

An expanded curated catalog of #SaaS offerings is now available to @Cisco partners via @awsmarketplace.… twitter.com/i/web/status/1…

February 7, 2023
ChannelFutures

.@AbundantIoT is putting more focus on the enterprise, CEO Vince Bradley tells Channel Futures.… twitter.com/i/web/status/1…

February 7, 2023
ChannelFutures

January's #topstories in channel include @Avaya @GTTComm @Broadcom @awscloud @citrix @Salesforce @Datto… twitter.com/i/web/status/1…

February 6, 2023
ChannelFutures

.@Acronis announces #CyberFit partner program updates. dlvr.it/Sj2FZQ https://t.co/z7lRdIRo9R

February 6, 2023
ChannelFutures

More #Avaya trouble: Lawsuit against company by bondholders claims "massive fraud." dlvr.it/Sj2DZT https://t.co/4Q1E7JAXXf

February 6, 2023
ChannelFutures

.@DellTech adds new #APEX delivery options for #delltechnologies partners. dlvr.it/Sj29c6 https://t.co/3qEEYpnOBX

February 6, 2023
ChannelFutures

There are some familiar names in @coxbusiness and @Rapid_Scales recent partner awards. dlvr.it/Sj1zm6 https://t.co/0BuGwBrnvM

February 6, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X