https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures


hybrid work

HP: Hybrid Work Enabling Firmware Attacks

  • Written by Edward Gately
  • June 29, 2022

HP this week released research from HP Wolf Security showing changing workforce dynamics are creating new challenges for IT teams around firmware security.

As business workforces become increasingly distributed, IT leaders say it’s harder than ever to defend against firmware attacks.

The shift to hybrid work models has transformed how organizations manage endpoint security, while also highlighting new challenges for IT teams around securing device firmware.

The HP Wolf Security global survey of 1,100 IT leaders reveals that:

  • The threat of firmware attacks is a growing concern for IT leaders now that hybrid workers are connecting from home networks more frequently. With hybrid or remote work now the norm for many employees, there is a greater risk of working on potentially unsecure home networks, meaning that the level of threat posed by firmware attacks has risen. More than eight in 10 IT leaders say firmware attacks against laptops and PCs now pose a significant threat, while 76% of IT decision makers said firmware attacks against printers pose a significant threat.
  • Managing firmware security is becoming harder and taking longer in the era of hybrid work, leaving organizations exposed. Some 80% of IT leaders are worried about their capacity to respond to endpoint firmware attacks.

Ian Pratt is global head of security for personal systems at HP. He said firmware provides a fertile opportunity for attackers looking to gain long-term persistence or perform destructive attacks.

“The security of firmware is frequently neglected by organizations, with much lower levels of patching observed,” he said. “In the last year, we’ve seen attackers performing reconnaissance of firmware configurations, likely as a prelude to exploiting them in future attacks. Previously, these types of attacks were only used by nation-state actors. The tools, tactics and procedures for targeting PC firmware could trickle down, opening the door for sophisticated cybercrime groups to weaponize threats and create a blueprint to monetize attacks.”

Once an attacker has gained control over the firmware configuration, they can exploit their position to gain persistence and hide from anti-malware solutions that live in the operating system (OS), Pratt said. This gives them an advantage, allowing them to stealthily maintain persistence on target devices so they can gain access to infrastructure across the enterprise and maximize their impact.

“We urge organizations to deliver protection where it is needed most: the endpoint,” he said. “Organizations should embrace a new architectural approach to security that helps to mitigate risk. This involves applying the principles of zero trust – least privilege access, isolation, mandatory access control and strong identity management. This approach requires resilient, self-healing hardware designed to hold its own against attacks and recover quickly when needed, while also containing and neutralizing cyber-threats.”

 

Tags:

Edward Gately

Edward Gately

As news editor, Edward Gately covers cybersecurity, new channel programs and program changes, M&A and other IT channel trends. Prior to Informa, he spent 26 years as a newspaper journalist in Texas, Louisiana and Arizona.

Related Content

  • Cloud computing
    Public Cloud Momentum Pacing Past Forecasts, With AWS, Azure in Lead
  • Tape Measure
    How the Cloud Has Changed Measurement for Partners
  • Making Waves
    7 Channel People Making Waves This Week at Datto, New Relic, Kyndryl, More
  • Fireworks
    Cybersecurity Experts: July 4th Weekend Ripe for Ransomware, Other Attacks

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

Lumen Channel Leaders Talk Program Evolution, C-Suite Sponsorship, TSD Consolidation

August 15, 2022

Kaseya’s Auto-Renewal Changes Bring Glimmer of Hope to Partners Amid Turmoil

August 15, 2022

Analysts React to Rackspace Earnings with Downgrades

August 15, 2022

Industry Perspectives

View all

How to Take Shared Responsibility for Securing Cloud

August 11, 2022

Seize the Application Modernization Opportunity

August 2, 2022

A Growth Mindset: Your Organization’s Strategic Differentiator

August 1, 2022

Webinars

View all

Outsmarting RaaS: Implementation Strategies To Help Your Clients Before, During, and After a Ransomware Attack

August 23, 2022

Why it is Important to Upgrade Aging Servers and How to use Live Optics to Upgrade Efficiently

August 25, 2022

Executives at Home are Not Alright: An Intro to Digital Executive Protection

September 8, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

ThreatLocker Preaches Zero Trust, Addresses Industry Competition

Microsoft Targeting Partners to Sell Teams, Windows 365 to SMBs, More

August 15, 2022

ScienceLogic Debuts New Partner Portal

August 9, 2022

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

June 27, 2022

Twitter

ChannelFutures

.@Tanium forms integration partnership with #Microsoft, joins Microsoft Intelligent Security Association. #MISA… twitter.com/i/web/status/1…

August 16, 2022
ChannelFutures

.@msp360 refreshed and expanded its advantage partner program after experiencing significant channel growth in H1 2… twitter.com/i/web/status/1…

August 16, 2022
ChannelFutures

The countdown begins! Channel Partners Leadership Summit, MSP Summit, and Women's Leadership Summit are coming up i… twitter.com/i/web/status/1…

August 16, 2022
ChannelFutures

Use #remarketing to boost #revenue with MSP sales, says @zomentum. dlvr.it/SWjjV4 https://t.co/VAnTzCwArC

August 16, 2022
ChannelFutures

.@LumenCPP partner leaders say private equity investment in the advisory channel is validating the space to Lumen l… twitter.com/i/web/status/1…

August 15, 2022
ChannelFutures

.@KaseyaCorp's auto-renewal changes bring glimmer of hope to partners amidst turmoil. Some of our #MSP501 and… twitter.com/i/web/status/1…

August 15, 2022
ChannelFutures

.@AuCyble research shows #criticalinfrastructure at risk from exposed VNC endpoints. dlvr.it/SWhGhJ https://t.co/oMhiYxCT9L

August 15, 2022
ChannelFutures

Investment analysts are responding to @Rackspace’s Q2 earnings with downgrades, new price objectives.… twitter.com/i/web/status/1…

August 15, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X