Network monitoring also for small and medium-sized companies

Share post

The ransomware attack on Kaseya shows the need for network surveillance for small and medium-sized businesses as well. Too often, SMEs assume that they are not a target for hackers.

“In the largest ransomware attack ever observed, the attackers used a zero-day vulnerability in the unified management software VSA from Kaseya for a serious break into numerous systems. The targets included managed service providers and their small and medium-sized customer organizations. The attack was apparently aimed primarily at on-premise servers, which many SMEs expect security from: According to Huntress Labs, hackers exploited previously unknown arbitrary file upload and SQLi code injection vulnerabilities, then circumvented authentication procedures and obtained them Access to the server in order to activate your encryption software later.

Attacks don't just hit large companies

Network Detection and Response (NDR) - such as the NovaCommand solution - offers a 360-degree view of all IT resources (Image: ForeNova Technologies).

As with the Solarwinds attack, the attackers used Kaseya as a legitimate springboard to hit a wide variety of victims. Large companies with their own IT security teams and tools may in many cases still have the means to proactively look out for the resulting dangers slumbering in the company network and to contain the damage.

Many small and medium-sized companies, on the other hand, still often assume that they will not be a target for hackers. You therefore only protect yourself with endpoint security solutions and firewalls, which are largely ineffective against such sophisticated attack paths. You can see the Kaseya hack as a wake-up call that you need to look into the network to stay safe. It is also necessary for small businesses to keep an eye on both incoming and outgoing traffic (north-south traffic) and all internal traffic (east-west traffic). That sounds harder than it is. Suitable solutions automatically discover and monitor all network resources, discover deviating behavior patterns and thus uncover seemingly harmless behavior in order to identify and block zero-day attacks. "

More at ForeNova.com

 


About ForeNova

ForeNova is a US cybersecurity specialist who offers medium-sized companies inexpensive and comprehensive Network Detection and Response (NDR) to efficiently mitigate damage from cyber threats and minimize business risks. ForeNova operates the data center for European customers in Frankfurt am Main and designs all solutions in accordance with GDPR.


 

Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

DSPM product suite for Zero Trust Data Security

Data Security Posture Management – ​​DSPM for short – is crucial for companies to ensure cyber resilience against the multitude ➡ Read more

Data encryption: More security on cloud platforms

Online platforms are often the target of cyberattacks, such as Trello recently. 5 tips ensure more effective data encryption in the cloud ➡ Read more