https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Security Central: Oracle Patches Major Vulnerabilities, Singapore Tests Cybersecurity

  • Written by Allison Francis
  • July 24, 2017
It was a week of securing, testing and reporting on cybersecurity vulnerabilities. In terms of securing, things at Oracle this week got a bit patch-y (in a good way).

It was a week of securing, testing and reporting on cybersecurity vulnerabilities. In terms of securing, things at Oracle this week got a bit patch-y (in a good way). The tech behemoth on Tuesday announced that it has issued a critical patch for a whopping 308 vulnerabilities across 90 products, making it the company’s biggest update ever (as reported by Threatpost).

Oracle E-Business Suite was the biggest focus point for the update, accounting for more than 120 of the vulnerabilities addressed – 118 of which are remotely exploitable. One of the flaws in particular allows attackers to download sensitive business documents and configuration files without authentication.

It has been a bit of a crazy year for Oracle. So far in 2017, the company has apparently patched 878 vulnerabilities through three CPUs. Woof. Oracle isn’t the only one feeling the sting, though. The WannaCry and ExPetr bugs exposed vulnerabilities like never before, throwing into sharp relief just how much the industry is still extremely far behind in terms of patching.

“Since the April 2017 Oracle CPU, the world has been rocked by global malware attacks that exploit well-known flaws that have readily available fixes,” said John Matthew Holt, CTO of Warwatek. “Overburdened and under-resourced security teams simply cannot apply physical patches fast enough to stay ahead of the attackers.

Holt also mentioned that businesses continue to rely on legacy applications that can’t be patched or upgraded, creating yet another avenue of attack. It’s a constant race – hackers continually finding flaws to exploit and cyber professionals desperately trying to find/plug those holes before they do.

However broken record-y it may be, this is yet another opportunity to educate all end users. With the ever-changing and evolving threat landscape, it’s something that must be done regularly. Exhaustively. Software must be kept up-to-date and patched. Basic and recent scams and phishing techniques must be gone over. The buck doesn’t stop with the expert – effective security takes the entire village, providers and users alike.

For the testing portion of the week, we look to Asia. On Tuesday, more than 200 participants from all designated Critical Information Infrastructure (CII) sectors in Singapore took part in a cybersecurity exercise put on by the Cyber Security Agency of Singapore (CSA). CII refers to the group of sectors that are in charge of delivering essential services in Singapore, such as Government, infocomm, energy, aviation, maritime, land transport, healthcare, banking and finance, water, security and emergency, and media (according to Channel NewsAsia).

The exercise involved series of scenario planning sessions, workshops and table-top discussions. Participants were taken through simulated cybersecurity incidents, such as a malware infection or a large-scale distributed denial of services (DDoS) attack, and were tested on their incident management, response and remediation plans.

Chief Executive of CSA David Koh stated that the exercise provides a great deal of insight, and an huge opportunity to bolster/strengthen each sector’s incident response plans. “With greater interconnectivity, and proliferation of cyber threats, the ability of our critical sectors to respond promptly to attacks is vital,” he said. 

Deputy Prime Minister and Coordinating Minister for National Security Teo Chee Hean also weighed in, touting the importance of being over-prepared. “This is a good opportunity for us to level-up our capability and make sure that we’re as ready as possible,” he said. “In this field, things evolve very, very quickly. You may be ready today, but may suddenly come up against a zero-day attack which you’re not even aware of. We must have a response capability if an attack does happen.”

Our final story this week takes a look at a few key takeaways from Cisco’s Midyear Cybersecurity Report. The report takes a broader look at cyber threats, findings and potential trends such as ‘destruction of service’ (DeOS) attacks. 

The size and impact of attacks are evolving in ways never seen before, and they’re becoming much more intricate. Hackers are getting fancy these days, and the backups and safety nets meant to restore systems and data after an attack just aren’t up to snuff. Further, with the age of the Internet of Things, more and more companies are bringing their operations online, which ups the chance of having vulnerabilities. 

Dave Gronner, senior manager for Cisco’s Security Partner Go-To-Market Global Partner Organization, shared a few key insights and actionable steps for channel partners, taking into the account the current landscape and the report’s findings. 

Insights

  • With the limited pool of in-house security expertise available to end customers today, channel partners have an opportunity to serve as billable trusted advisors and help customers manage their security requirements.
  • With the expansion of cyber threats, there is a clear opportunity for channel partners to help customers assess their threat risks and develop a strategic plan to minimize risk.
  • Threat assessment services and consulting services aimed at building, documenting and implementing cybersecurity strategies will continue to be a growing and profitable opportunity for channel partners.
  • Channel partners providing these professional and consultative services help bridge customers’ knowledge and talent gaps by delivering actionable policy and technical next steps.
  • Partners will greatly increase their success in security by developing a true architectural understanding of cross-platform solutions and threat intelligence. Achieving the highest level of security for end customers requires providing a layered security approach to address the multi-faceted threat vectors. 

Actionable Steps

  • Midsized to large partners should build their security practices as a complement to their existing networking and Data Center practices to provide holistic integrated solutions, while addressing customers’ needs to simplify, integrate, and automate.
  • As this research shows, vertical market and company size affects customers’ approach to security. Partners should tap into new opportunities by building specialized practices for specific vertical markets. This strategic advisor role helps the partner establish strong customer loyalty while also creating competitive differentiation.
  • IoT has become an extremely important part of many vertical markets. As a result, partners who work in specific industries must take advantage of vendor offers and training to build their competencies in IoT security.

The views expressed in this column do not necessarily reflect the views of Penton Media or The VAR Guy editorial staff.

Tags: Agents Cloud Service Providers MSPs VARs/SIs Security

Most Recent


  • SMB
    New Comcast Business SD-WAN Solutions Put Focus on SMBs
    The solutions appeal to smaller businesses that don't necessarily need site-to-site connectivity.
  • Cybersecurity research
    ConnectWise MSP Report: Cybercriminals to Heavily Target MSPs in 2023
    MSPs will remain the target of supply chain and critical infrastructure attacks.
  • online survey
    Kaseya MSP Survey: Growing Importance of Automation, Cybersecurity Remains Top Challenge
    MSPs will need to be up to speed on their security offerings to meet SMB demand.
  • Cloud Roundup
    Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware
    This cloud computing wrap-up showcases some big news and happenings at more under-the-radar cloud firms.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Conflict Boxing Gloves
    Channel Conflict, Controversy: SolarWinds Hack, Racism, Layoffs, Zoom-RingCentral
  • Paying ransomware
    Sophos: Avaddon Ransomware Becoming More Prominent, Aggressive
  • Data management platform
    IBM Acquires Catalogic Software's Copy Data Management Business
  • security
    The Mounting Need for an Integrated Security Platform

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Enterprise Connect 2023 Expo Hall: RingCentral, VMware, Five9, Cisco, More

March 31, 2023

HP’s Head of Global Channel Strategy Talks Program Changes, Poly Opportunity

March 31, 2023

National Women’s History Month: Channel Women’s Advice for Newbies

March 31, 2023

Industry Perspectives

View all

Co-innovation Is Needed to Effect Energy Transformation

March 31, 2023

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

The shortage of talent in the tech industry gives women a great opportunity to build a career in tech says… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Check out our images from the expo floor at #EnterpriseConnect: @Microsoft @Zoom @GoTo @Cisco @googlecloud @ujetcx… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Learn about @comcastbusiness and some of the trends partners are seeing with #SMB customers. @craigschlagbaum… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

🤔 Interested in expanding on your brand or building a business from square one? @SkySwitchSays explains everythin… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Energy transformation and climate change calls for innovation now @VMware #channelpartners #energycrisis #technews… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Predictions are important when shaping your 2023 expectations & goals. #ChannelFutures is here to help out. We aske… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Mary Beth Walker on @HP adapting its partner program in response to partner feedback, and what latest launches mean… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

.@ConnectWise report shows cybercriminals will continue heavily targeting #MSPs in 2023. dlvr.it/Slnlrj https://t.co/eEY0pMLJaQ

March 31, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X