{"id":13610,"date":"2019-07-16T16:06:27","date_gmt":"2019-07-16T16:06:27","guid":{"rendered":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/?p=13610"},"modified":"2022-10-14T18:28:36","modified_gmt":"2022-10-14T22:28:36","slug":"why-enterprises-are-still-falling-victim-to-breaches","status":"publish","type":"post","link":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/security\/why-enterprises-are-still-falling-victim-to-breaches.html","title":{"rendered":"Why Enterprises are Still Falling Victim to Breaches"},"content":{"rendered":"\n<p>Guest post by By Deepen Desai<\/p>\n\n\n\n<p>Despite spending billions every year to establish a secure\nperimeter around the network, organizations continue to suffer the loss of\ndata, time, productivity, intellectual property, and a staggering sum of money\nto breaches. With all the sophisticated technology that enterprises put in\ntheir gateways to block threats, why do breaches persist? I believe the\nfollowing are among the top reasons why breaches occur: <\/p>\n\n\n\n<ol><li><strong>Blindness to SSL\/TLS traffic<\/strong><\/li><\/ol>\n\n\n\n<p>As much as 90 percent of internet\ntraffic is now encrypted and, while SSL provides privacy, it also provides\nattackers with an opportunity to infiltrate networks and exfiltrate data. Attackers\nknow that many organizations allow encrypted traffic from \u201ctrusted\u201d websites\nand CDNs to pass uninspected, which is because SSL inspection requires\nsignificant processing power. As a result, SSL is among the most abused channels\nfor hiding malware.<\/p>\n\n\n\n<ul><li><strong>The need for segmentation at the application level<\/strong><\/li><\/ul>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"361\" height=\"361\" src=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/07\/Deepen-Desai.jpg\" alt=\"\" class=\"wp-image-13613\" srcset=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/07\/Deepen-Desai.jpg 361w, https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/07\/Deepen-Desai-90x90.jpg 90w, https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/07\/Deepen-Desai-300x300.jpg 300w\" sizes=\"(max-width: 361px) 100vw, 361px\" \/><figcaption> <em>Deepen Desai, Vice President of Security Research at <a href=\"http:\/\/www.tmcnet.com\/query\/SearchResults.aspx?searchstring=zscaler&amp;type=anywords&amp;stem=True&amp;phonic=False&amp;fuzzy=0&amp;feeds=True&amp;area=0&amp;sort=date\">Zscaler<\/a> and director of <a href=\"http:\/\/www.tmcnet.com\/query\/SearchResults.aspx?searchstring=ThreatLabZ&amp;type=anywords&amp;stem=True&amp;phonic=False&amp;fuzzy=0&amp;feeds=True&amp;area=0&amp;sort=date\">ThreatLabZ.<\/a><\/em> <\/figcaption><\/figure><\/div>\n\n\n\n<p>With so many remote employees,\ncontractors, partners, and other third parties connecting over VPNs, often from\nuncontrolled environments, networks are vulnerable, especially without proper\nsegmentation. If one of those systems connecting over VPN or site-to-site VPN\nis compromised, its infection can infiltrate the network and proliferate. &nbsp;<\/p>\n\n\n\n<ul><li><strong>IoT security<\/strong><\/li><\/ul>\n\n\n\n<p>The rapid adoption of IoT has created new\nattack vectors. IoT devices are notorious for poor security and, because\ndevices appearing on networks are often employee-owned, it\u2019s likely that many have\nweak, preset passwords. In a recent study, my team discovered that more than\n90 percent of the IoT traffic from enterprise networks was using unencrypted\nchannels, making it susceptible to man-in-the-middle attacks. The best way to\nprevent IoT devices from exposing your network is to isolate them on their own\nnetwork (to prevent lateral movement) and restrict inbound and outbound\ntraffic.<\/p>\n\n\n\n<ul><li><strong>Patch\nmanagement<\/strong><\/li><\/ul>\n\n\n\n<p>Most enterprise networks are complex,\nso setting up an effective patch management process can be challenging. Large networks\noften include unsupported operating systems, which further complicates patching\nby adding manual steps\u2014often leaving systems vulnerable longer. In the case of\nWannaCry, such vulnerabilities had devastating consequences. Automated patching\nhelps by pushing patches and providing consistent coverage against certain\nexploits. To block attackers\u2019 attempts to probe for unpatched devices, you need\nan effective intrusion prevention system. <\/p>\n\n\n\n<ul><li><strong>Employee training<\/strong><\/li><\/ul>\n\n\n\n<p>Most users understand the risk of\nclicking suspicious links or opening attachments from unknown senders. But what\nabout those that appear to be from a trusted source, like Amazon or Apple?\nAttackers are skilled at developing phishing sites that look just like legitimate\nsites, and they can often make URLs deceptively similar using domain squatting.\nIt\u2019s imperative for employees to have ongoing training that includes awareness\nof recent attack methods. Armed with knowledge, they provide a key layer in\nenterprise defense.<\/p>\n\n\n\n<p>Malicious actors will continue to target\nenterprise networks with phishing schemes and other sophisticated attacks. It\u2019s\nincumbent upon enterprises to ensure a defense-in-depth security strategy by\nusing the most effective technologies available and employing best practices to\nprevent intrusion or minimize its effects. One of those best practices that\nevery business should be following today is to ensure multifactor\nauthentication (MFA) is enabled. MFA provides more than one method of\nauthentication from independent categories of credentials to verify the user\u2019s\nidentity for a login or other transaction. Most enterprise applications support\nMFA and users are familiar with the process.<\/p>\n\n\n\n<p><em>Deepen Desai is Vice President of Security Research at <a href=\"https:\/\/www.zscaler.com\/ \">Zscaler <\/a>and director of ThreatLabZ.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"694\" src=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/07\/zscaler-building-1000x694.jpg\" alt=\"\" class=\"wp-image-13618\"\/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Guest post by By Deepen Desai Despite spending billions every year to establish a secure perimeter around the network, organizations continue to suffer the loss of data, time, productivity, intellectual property, and a staggering sum of money to breaches. With all the sophisticated technology that enterprises put in their gateways to block threats, why do<\/p>\n","protected":false},"author":44,"featured_media":13612,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[156],"tags":[1796,1929,2227,2228],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/13610"}],"collection":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/comments?post=13610"}],"version-history":[{"count":3,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/13610\/revisions"}],"predecessor-version":[{"id":13619,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/13610\/revisions\/13619"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media\/13612"}],"wp:attachment":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media?parent=13610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/categories?post=13610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/tags?post=13610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}