Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

December 2021

Digital signatures must use MFA

Digital signatures are increasingly used in companies and public administrations. However, without adequate cybersecurity measures, this method can be a vector for cybercriminals and fraudsters: through social engineering they can dupe signer victims into believing a document is legitimate and, through their signature, obtain authorization to carry out other operations without their consent, among many other malicious activities. So, how can we avoid this?

Top 4 Malicious Domain Incidents of 2021

Cybercriminals are increasingly using malicious domains as an attack vector. Our Internet Security Report Q1 2021 already detected a 281% increase in the number of domains blocked by DNSWatch over the previous quarter, and there has been significant activity in the past year with such links exploiting the interest in COVID-19.

Ugly Sweaters, Season's Greetings, and Cybersecurity Advice - Marketing Support

The pressure of creating products customers want to use while growing a business can take away from important priorities. Luckily, WatchGuard can support you with your marketing, whether that be web marketing, advertising, trade shows, and so much more.

Other Ways Remote Work Has Changed Businesses

As the pandemic continues and employees are finding themselves “stuck at home” for the foreseeable future, companies are coming up with new ways to approach overall wellbeing for their employees. Things like breakroom snacks, on-site gyms, and commuting passes are less appealing and don’t make a lot of sense. So, companies are getting creative in the ways they support their employees during remote work. Here are some of our favorite examples.

AuthPoint Risk Framework - Geofence Risk Policy

The geofence risk feature is available in WatchGuard Cloud and provides advanced risk-based authentication capabilities to customers and partners. Two key benefits include enhanced real-time incident management and limited exposure by configuring rules that block attempts from unauthorized geographies.

Ugly Sweaters, Season's Greetings, and Cybersecurity Advice - Charge Up Coffee

Running a small business has a never-ending list of tasks that needed to be done yesterday. WatchGuard’s network of service providers helps business like Charge Up Coffee Shop keep their customers and employee secure so they can focus on their products.

2022 Predictions #5 - Companies Increase Cyber Insurance Despite Soaring Costs

Since the astronomical success of ransomware starting back in 2013, cybersecurity insurers have realized that payout costs to cover clients against these threats have increased dramatically. In fact, according to a report from S&P Global, cyber insurers’ loss ratio increased for the third consecutive year in 2020 by 25 points, or more than 72%. This resulted in premiums for stand-alone cyber insurance policies to increase 28.6% in 2020 to $1.62 billion USD. As a result, they have greatly increased the cybersecurity requirements for customers. Not only has the price of insurance increased, but insurers now actively scan and audit the security of clients before providing cybersecurity-related coverage.

2022 Predictions #6 - And We'll Call It Zero Trust

Most security professionals have had the principle of least privilege grilled into them from the very beginning of their careers. Giving users the minimum level of access needed to perform their job functions is for the most part an uncontested best practice. Unfortunately, best practices don’t directly translate into wide adoption, and least to their full extent. Over the past few years, or decades really, we’ve seen the ease in which attackers can move laterally and elevate their level of access while exploiting organizations that haven’t followed basic security principles.

2022 Predictions #1 - State-Sponsored Mobile Threats Trickle Down to the Cybercrime Underworld

Mobile malware certainly exists – especially on the Android platform – but hasn’t yet risen to the same scale of traditional desktop malware. In part, we believe this is due to mobile devices being designed with a secure mechanism (e.g., secure boot) from the start, making it much more difficult to create “zero-touch” threats that don’t require victim interaction. However, serious remote vulnerabilities have existed against these devices, though harder to find.

2022 Predictions #3 - Spear SMSishing Hammers Messenger Platforms

Text-based phishing, known as SMSishing, has increased steadily over the years. Like email social engineering, it started with untargeted lure messages being spammed to large groups of users, but lately has evolved into more targeted texts that masquerade as messages from someone you know, including perhaps your boss.

2022 Predictions #4 - Password-Less Authentication Fails Long Term Without MFA

It’s official. Windows has gone password-less! While we celebrate the move away from passwords alone for digital validation, we also believe the continued current focus of single-factor authentication for Windows logins simply repeats the mistakes from history. Windows 10 and 11 will now allow you to set up completely password-less authentication, using options like Hello (Microsoft’s biometrics), a Fido hardware token, or an email with a one-time password (OTP).

WatchGuard's 2022 Predictions

In our 2021 Security Predictions, the WatchGuard’s Threat Lab team anticipated that authentication would be the cornerstone of strong security. “With billions of usernames and passwords ripe for the picking on the dark web and the prevalence of automated authentication attacks, we believe that any service without MFA enabled will be compromised in 2021,” said WatchGuard CSO Corey Nachreiner.

Why MSPs Save the World

Organizations of all sizes are struggling to keep up with the increasingly complex and evolving cybersecurity landscape. Threat actors aren’t just hunting large corporations, they’re aggressively targeting small and midsize businesses, too. As networks become more porous and cyber threats rise, organizations that lack in-house security expertise will increasingly become targets of attack and their losses will grow.

WatchGuard's SVP of Marketing, Michelle Welch, named 2021 Security Channel Chief of the Year by Channel Partner Insight

For the third year in a row, WatchGuard has been honored at Channel Partner Insight’s 2021 Channel Innovation Awards. This year, Senior Vice President of Marketing Michelle Welch was named the “Security Channel Chief of Year.” This annual awards program celebrates the partners and vendors that have brought true value and innovation to the managed services market and made a real difference to their customers over the last 12 months.