<?xml version="1.0" encoding="utf-8"?><rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Ivanti Blog: Posts by </title><description /><language>en</language><atom:link rel="self" href="https://www.ivanti.com/blog/authors/joni-moore/rss" /><link>https://www.ivanti.com/blog/authors/joni-moore</link><item><guid isPermaLink="false">1acd00d9-c594-4fb9-857f-c14202bb3c1c</guid><link>https://www.ivanti.com/blog/long-weekend-and-you-locked-yourself-out-of-your-computer</link><atom:author><atom:name>Joni Moore</atom:name><atom:uri>https://www.ivanti.com/blog/authors/joni-moore</atom:uri></atom:author><category>Security</category><title>Long Weekend and you Locked Yourself Out of Your Computer</title><description>&lt;p&gt;The latest Verizon DBIR report is out and we all should realize, normal is not the new workplace.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Picture this:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;You’re logging into the work account after a long weekend of gratitude, remembrance and maybe even getting to hug someone safely.&lt;/p&gt;

&lt;p&gt;*Please reset password.*&lt;/p&gt;

&lt;p&gt;*Cannot use a previous password.*&lt;/p&gt;

&lt;p&gt;*Must be 8-20 characters with one special character and a sprinkling of Latin.*&lt;/p&gt;

&lt;p&gt;*Must be written in Haiku form.*&lt;/p&gt;

&lt;p&gt;*Your account has been locked. Please try again in 2023.*&lt;/p&gt;

&lt;p&gt;*Oops, someone else logged into your account. It’s probably fine, right?*&lt;/p&gt;

&lt;p&gt;Okay, we’re exaggerating a &lt;em&gt;little &lt;/em&gt;but variations of this scene are playing out all over the country this week. You’re frustrated and you haven’t even gotten &lt;em&gt;started &lt;/em&gt;on the work that piled up over the weekend.&lt;/p&gt;

&lt;p&gt;And cybersecurity woes are doing more damage than just making you want to throw your laptop out the nearest window.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The latest &lt;a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="noopener"&gt;Verizon DBIR report&lt;/a&gt; is out, and – as anyone in cybersecurity guessed – it’s not good news.&lt;/strong&gt; The report shows that once again, phishing, ransomware and credential theft are on the rise. It makes a clear case for doing a better job protecting users as well as the devices used to access networks.&lt;/p&gt;

&lt;p&gt;Here are some highlights (or should we say lowlights):&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Report analyzes 29,207 quality incidents, 5,258 of which were confirmed breaches.&lt;/li&gt;
	&lt;li&gt;Phishing attacks increased by 11%, while attacks using ransomware rose by 6%.&lt;/li&gt;
	&lt;li&gt;85% of breaches involved a human element.&lt;/li&gt;
	&lt;li&gt;61% of breaches involved credentials.&lt;/li&gt;
	&lt;li&gt;Ransomware appeared in 10% of breaches, double the previous year.&lt;/li&gt;
	&lt;li&gt;Compromised external cloud assets were more common than on-premises assets in incidents and breaches.&lt;/li&gt;
	&lt;li&gt;Breach simulations found the median financial impact of a breach is $21,659, with 95% of incidents falling between $826 and $653,587.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That’s…not ideal. The fact that credentials were so commonly used is terrifying, to say the very least.&lt;/p&gt;

&lt;p&gt;Here’s a closer look at the findings:&lt;/p&gt;

&lt;p&gt;&lt;img alt="summary of findings" src="https://static.ivanti.com/sites/marketing/media/images/blog/verizon-dbir-1.jpg"&gt;&lt;/p&gt;

&lt;p&gt;&lt;img alt="additional findings" src="https://static.ivanti.com/sites/marketing/media/images/blog/verizon-dbir-2.jpg"&gt;&lt;/p&gt;

&lt;p&gt;Why are things getting worse, not better? For one thing, companies are undergoing digital transformations and shifts to the cloud that make those companies more agile and better suited to the Everywhere Workplace – but also vulnerable, without the right security measures in play.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;“As the number of companies switching business-critical functions to the cloud increases, the potential threat to their operations may become more pronounced, as malicious actors look to exploit human vulnerabilities and leverage an increased dependency on digital infrastructures” —Tami Erwin, Executive Vice President and CEO, Verizon Business&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;h2&gt;Phishing and Ransomware once again top the list&lt;/h2&gt;

&lt;p&gt;The DBIR states that phishing, ransomware and web app attacks dominated data breaches in 2020. This is part of an overall trend that we’ve seen since the pandemic hit.&amp;nbsp;&lt;a href="https://www.zdnet.com/article/ten-disturbing-coronavirus-related-cybercrime-statistics-to-keep-you-awake-tonight/" target="_blank" rel="noopener"&gt;ZNet reports,&lt;/a&gt;&amp;nbsp;“Email scams related to Covid-19 surged 667% in March (2020) alone.”&lt;/p&gt;

&lt;p&gt;Insights from the report reveal that among 1,148 people who received real and simulated phishes, none of them clicked the simulated phish but 2.5% clicked the real phishing email, reinforcing the need for better phishing simulations and security education training.&lt;/p&gt;

&lt;p&gt;&lt;img alt="percent of people likely to click phishing simulation templates" src="https://static.ivanti.com/sites/marketing/media/images/blog/verizon-dbir-3.jpg"&gt;&lt;/p&gt;

&lt;h2&gt;It’s not just businesses…&lt;/h2&gt;

&lt;p&gt;The federal government had a tough year when it came to data breaches and ransomware attacks. According to the&amp;nbsp;&lt;a href="https://federalnewsnetwork.com/commentary/2021/04/accidents-account-security-attrition-3-lessons-to-be-cyber-secure/" target="_blank" rel="noopener"&gt;Federal News Network&lt;/a&gt;, in the first quarter of 2020, government agencies&amp;nbsp;&lt;a href="https://www.infosecurity-magazine.com/news/rise-leaked-government-records/" target="_blank" rel="noopener"&gt;saw a 278% year-over-year increase&lt;/a&gt;&amp;nbsp;in compromised information, totaling more than 17 million records while institutions were hit with an unprecedented number of ransomware attacks that cost the US government of up to $1.4 billion.&lt;/p&gt;

&lt;p&gt;Ransomware attacks are continuing and it is not a minute too soon that that the&amp;nbsp;&lt;a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/" target="_blank" rel="noopener"&gt;White House released&lt;/a&gt;&amp;nbsp;an Executive order that said it is time to adopt security best practices. Specifically: “Within 180 days of the date of this order, agencies shall adopt multi-factor authentication and encryption for data at rest and in transit, to the maximum extent consistent with Federal records laws and other applicable laws.”&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.ivanti.com/blog/ivanti-s-take-on-the-cybersecurity-executive-order" target="_blank"&gt;&lt;em&gt;Read more: Ivanti Federal CTO's Take on the Cybersecurity Executive Order&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;So what can we do?&lt;/h2&gt;

&lt;p&gt;According to the DBIR, a “significant percentage of victims targeted” were organizations “that neglected to implement multi-factor authentication, along with virtual private networks.” And “the zero trust model for access quickly became a fundamental security requirement rather than a future ideal.”&lt;/p&gt;

&lt;p&gt;Translation: the old security methods don’t work in this new landscape. And they’re getting &lt;em&gt;less &lt;/em&gt;secure by the day as threats get more sophisticated.&lt;/p&gt;

&lt;p&gt;The future is passwordless, and the companies that take the longest to embrace that shift are the ones who will be most vulnerable.&lt;/p&gt;

&lt;p&gt;Eliminating passwords through &lt;a href="https://www.ivanti.com/products/passwordless-authentication"&gt;zero sign-on&lt;/a&gt; goes a long way toward shoring up security in this new, much more decentralized Everywhere Workplace. Eliminating passwords is also one of the clearest, simplest ways to prevent laptop-through-window incidents.&lt;/p&gt;

&lt;p&gt;We’d all like to see a better DBIR report next year – perhaps one marked by a dramatic downtrend in breaches combined with a surge in companies embracing the new business landscape with simpler, more secure access. That’s what we’re working on every day at Ivanti.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;
</description><pubDate>Tue, 01 Jun 2021 22:46:20 Z</pubDate></item><item><guid isPermaLink="false">5f22e28d-dccb-4c34-b286-2c7e7830f798</guid><link>https://www.ivanti.com/blog/the-30th-anniversary-of-rsa-would-have-been-one-heck-of-a-party</link><atom:author><atom:name>Joni Moore</atom:name><atom:uri>https://www.ivanti.com/blog/authors/joni-moore</atom:uri></atom:author><category>Security</category><title>The 30th Anniversary of RSA Would Have Been One Heck of a Party</title><description>&lt;p&gt;There is no doubt that a virtual RSA is not the same as catching up with colleagues and partners over great food, and of course meeting up at the W Bar. The good news is we all have or are adjusting to working remotely and we didn’t have to travel to hear what the industry luminaries think, or what our peers are saying they can do to keep the world safe. (not sure if you have caught our tagline but, we make the Everywhere Workplace possible – for us it was very comfortable to participate securely). It was pretty clear that not every organization has embraced the Everywhere Workplace and that “securing chaos” is a common need we are all trying to address.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;No surprise the recent Colonial Pipeline ransomware attack that has been making headlines prompted virtually every vendor to discuss how and why we need to get ahead of ransomware attacks – spoiler alert – ransomware makes cybercriminals money, and they are not going to stop anytime soon.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;Ransomware also has put the White House on notice. Anne Neuberger, Deputy National Security Advisor for Cyber and Emerging Technology in the Biden administration, stated on day two of the conference that, a recent executive order &lt;a href="https://www.pcmag.com/news/biden-calls-for-government-wide-2fa-energy-star-type-labels-for-software" target="_blank" rel="noopener"&gt;signed by President Biden&lt;/a&gt; "creates a pilot program to create an ‘energy star’ type of label so the government, and the public at large, can quickly determine whether software was developed securely,” the White House &lt;a href="https://www.whitehouse.gov/briefing-room/statements-releases/2021/05/12/fact-sheet-president-signs-executive-order-charting-new-course-to-improve-the-nations-cybersecurity-and-protect-federal-government-networks/" target="_blank" rel="noopener"&gt;says&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;In her remarks, Neuberger also stressed that the Biden administration is taking cybersecurity seriously and working internationally to combat security threats around the world. Specifically, the administration is making &lt;a href="https://www.pcmag.com/picks/the-best-ransomware-protection?test_uuid=05n7gTzbSo0Sh5pVEDljnCi&amp;amp;test_variant=b" target="_blank" rel="noopener"&gt;ransomware&lt;/a&gt; a top priority.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;It’s about time!&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;The other topic that dominated the conference was trust.&amp;nbsp;The main message heard from the keynote speaker and sessions was that you can’t let your guard down and although zero trust has been talked about it is time to actually start implementing a zero trust strategy.&amp;nbsp;The conference was packed with multiple sessions about how we (security vendors) and the average employee needs to be more vigilant about our credentials and what we click on (who hasn’t clicked on a too good to be true product on Facebook or Instagram?).&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;As another RSA comes and goes a few things are clear:&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;We can stop talking about digital transformation – It has happened&lt;/li&gt;
	&lt;li&gt;Whether companies are moving to the cloud or not – They are&lt;/li&gt;
	&lt;li&gt;Consolidation on security architectures and security stacks at the organization level are increasingly important&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;Lastly, we need to realize the security talent shortage is still a big issue that cybercriminals are capitalizing on, and we need to take Cisco’s CEO, Chuck Robbins, resiliency message to heart.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;Robbins described the challenges of the sudden shift to remote work by having the remote workforce try to connect over multiple networks and with whatever device workers could find to be productive from the Everywhere Workplace. Not only did this put an immediate strain on the IT departments to scale up and accommodate all the new remote connections, but the security threat landscape immediately expanded and kept the company’s security team and CISO up at night!&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“For instance, employees, just by working 30 extra minutes on a mobile device, create 20 percent more vulnerability than you would have normally, he said. “Every individual is carrying an average of four devices, and most of us are carrying even more. And this just creates more opportunity for breaches.”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;The threat surface keeps growing and will continue to expand in the future. What is your company’s plan of resiliency to protect the increasing number of mobile endpoints in the remote workforce, and how can you counter more sophisticated cyber threat actors in the wild? What is your company's journey to implement the Zero Trust security strategy?&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;Ivanti knows that the Everywhere Workplace is here, and it is essential to secure user identities, secure the remote user, secure their work mobile device (and laptop/desktops), and secure their access to critical work resources wherever they reside. Come see how &lt;a href="https://www.ivanti.com/company/news"&gt;Ivanti can help enable your company’s Everywhere Workplace&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;Until next year, goodbye from RSA! I’m looking forward to seeing you in person next year!&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;</description><pubDate>Fri, 21 May 2021 16:54:40 Z</pubDate></item></channel></rss>