Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cloud Threats Memo: Exploiting Legitimate Cloud Services for Command and Control

Welcome to the first edition in 2022 of our Cloud Threats Memo! One of the key findings of our Cloud and Threat Report – January 2022 is the leadership of Google Drive as the most exploited cloud app for the distribution of malware (and for the record, guess which service ranks at number two—spoiler alert: it is a cloud storage service from Microsoft). Unsurprisingly, this is not the only way in which threat actors can exploit these and other cloud services.

SSH Hardening Tips to Prevent Brute-Force Attacks

SSH servers are a common target for brute-force attacks. This is even more true if your infrastructure sits behind an SSH bastion because attackers have no choice but to compromise the bastion host either by exploitation or denial of service. In this article, we will list a few controls which will help you harden your SSH servers from brute- force attacks.

Complete Guide to Common Cloud Misconfigurations and How to Avoid Them

Companies are increasingly moving their IT operations to IaaS (infrastructure-as-a-service) solutions. Gartner estimates that by 2022, about 60% of business entities will be leveraging cloud-managed offerings, doubling the recorded use in 2018. Cloud offerings like Amazon Web Services (AWS) are generally secure. But since IaaS uses a shared security model, there's a great chance of data security issues, including cybersecurity and workload concerns.

Egress Defend

Stop targeted email attacks with Egress Defend. We combine zero-trust models with intelligent linguistic and contextual analysis to detect the sophisticated cyberattacks that bypass your traditional email security solutions. Our real-time alerts and feedback provide teachable moments that clearly explain risk to users. This provides active learning that augments your security awareness training programs and builds a first line of defense against threats.

Egress Prevent

Stop email data loss with Egress Prevent Prevent uses social graph and contextual machine learning technologies on desktop and mobile to accurately model user relationships. We then detect anomalous recipients in real time to avoid a damaging data breach. Importantly, we also supervise our machine learning algorithms with policies so Prevent can immediately detect more outbound risks, such as wrong attachments, conflicts of interest, data exfiltration, and weak TLS certificates.

Egress Protect

Make sending encrypted emails easy with Egress Protect. Our simple controls combined with gateway encryption, means you can send and revoke sensitive emails and large files securely. Maintaining your compliance and removing risk. Our flexible authentication techniques remove friction and even allow trusted recipients seamless access to sensitive emails without having to log into a separate secure portal.

Egress Secure Workspace

Easily share confidential data with Egress Secure Workspace. Our encrypted environment offers enterprise-grade permissions at the click of a button. This enables employees to control how teammates and external partners interact with files to keep sensitive content secure. Secure Workspace can be used to share files of any size or format, and users can set controls to limit when and where recipients can access information, and what they can do with it. Robust anti-virus checks, and accredited security frameworks provide additional protection.

How Should Organizations Tackle Their Data Privacy Requirements?

Data is among the most valuable assets that need to be safeguarded at all costs. But in the digitally-driven business world, cybercrimes are prevalent, making data protection and data privacy a main focal point. The increasing use of technology and the growing exposure to evolving cyber threats have dramatically changed the data security and privacy landscape. For these reasons, international regulatory bodies around the world have created stringent data privacy laws for businesses to meet.

Why Is It Important to Invest in OT Cybersecurity for 2022?

As we enter 2022, it’s important that organizations invest in cybersecurity for their operational technology (OT) systems. Why? One of the reasons is that Industry 4.0 can sometimes introduce more risk for OT. This is evident in several Industry 4.0 market trends. For example, there’s digital twin infrastructure. That’s where you make a digital copy of your production facility or your machine.

How To Protect and Store Sensitive Data in SaaS Platforms with Cloud DLP

Mega-breaches, or reported breach incidents that impact more than one million records, have increased dramatically. Our analysis shows that, on average, mega-breaches increased 36% year over year since 2016. In total, mega-breach incidents that we analyzed cost at minimum a combined $8.8 billion and exposed 51 billion records.