cybersecurity map

Timing Isn't Everything But It Helps

Many lessons were learned in enterprise IT and security teams in 2020, right down to the final weeks of the year with the Solarwinds attack. We closed out a miserable year with a devastating reminder about the danger of third party access and supply chain attacks. Another painful lesson for IT teams was that current application access technologies, such as virtual private networks (VPN) or virtual desktop infrastructure (VDI), are too difficult to manage and scale. Even the most resource rich companies were forced to ration VPN access for employees, third parties, and partners. This is the opposite of digital transformation, and everything modern business is about. On top of those operational challenges was the fact that these solutions are not secure, and certainly not part of a zero-trust framework.

Meanwhile, in the C-Suite, secure application access went from off the radar completely to a business continuity issue on par with natural disasters and DDoS attacks. Modern business starts with the availability of enterprise assets. 2020 was the year that the C-Suite learned that legacy access solutions were a threat to business operations, digital transformation, and even margins. They are now asking IT leaders, why is something so fundamental to our business so out of touch with what we need?

Time for Change
IT leadership is about managing change and risk while charging full speed ahead. The old way of doing things does not last forever. Ask any developer. It turns out that the way we offer enterprise access is going through another step change in the never-ending march of progress that defines enterprise IT.

IT leaders have long had VPN/VDI on the list of eventual upgrades. Next year they said, other priorities took precedent, like managing an increasingly complex hybrid environment. Not this year. 2020 exposed the weakness of current approaches to the point the C-Suite noticed, and now something must be done. What lessons did we learn in 2020 that can lead us forward with a better, more secure, and user friendly approach to application access?

Lessons Learned
1. Business Starts with Access. Immediately following the work-from-home orders it became clear that access is where business begins. Legacy solutions could not scale quickly, as they relied on a mix of hardware, licenses, and agents on endpoints, requiring significant time and human resources, neither of which most companies had at that moment. When enterprise assets are unavailable to those who need them, business continuity and efficiency are disrupted. By turning to the cloud, businesses can enable access at scale, quickly and securely for employees and third-parties.

2. User experience matters. Users have complained for years that legacy access technologies were difficult to use, often leading them to avoid them altogether by logging into SaaS apps from personal devices outside the VPN/VDI. IT solutions should not be pushing users to make insecure choices for the sake of convenience. Again, by leveraging a modern cloud platform for application access, users are met with a familiar web interface to access all business applications.

3. Zero Means Zero. Zero Trust is a fantastic framework for organizational security. Most businesses say they are on their zero-trust journey. Leaving legacy access solutions behind for modern cloud-based application access solutions is one way to make a quantum leap forward. Legacy solutions offer too much implicit trust in the user, bringing them onto the network, to the doorstep of vulnerable applications. Furthermore, businesses have limited visibility and control over the user once they have gained access. With a cloud-based access solution, the cloud serves as a broker between the user and application. Users no longer gain access to the network, or the applications themselves. Furthermore, in this cloud-based model, every move by the user is checked, verified, and authorized. This is truly zero trust in action. Enterprise application access is now a C-Suite priority, and again, the cloud provides a way forward for enterprise IT teams. The cloud cannot solve all of your IT challenges, but it is certainly the future of enterprise application access solutions.

About the Author

Tamir Hardof, CMO, Axis Security

Featured

  • 91 Percent of Security Leaders Believe AI Set to Outpace Security Teams

    Bugcrowd recently released its “Inside the Mind of a CISO” report, which surveyed hundreds of security leaders around the globe to uncover their perception on AI threats, their top priorities and evolving roles, and common myths directed towards the CISO. Among the findings, 1 in 3 respondents (33%) believed that at least half of companies are willing to sacrifice their customers’ long-term privacy or security to save money. Read Now

  • Milestone Announces Merger With Arcules

    Global video technology company Milestone Systems is pleased to announce that effective July 1, 2024, it will merge with the cloud-based video surveillance solutions provider, Arcules. Read Now

  • Organizations Struggle with Outdated Security Approaches, While Online Threats Increase

    Cloudflare Inc, recently published its State of Application Security 2024 Report. Findings from this year's report reveal that security teams are struggling to keep pace with the risks posed by organizations’ dependency on modern applications—the technology that underpins all of today’s most used sites. The report underscores that the volume of threats stemming from issues in the software supply chain, increasing number of distributed denial of service (DDoS) attacks and malicious bots, often exceed the resources of dedicated application security teams. Read Now

  • Cloud Resources Have Become Biggest Targets for Cyberattacks According to New Research

    Thales recently announced the release of the 2024 Thales Cloud Security Study, its annual assessment on the latest cloud security threats, trends and emerging risks based on a survey of nearly 3000 IT and security professionals across 18 countries in 37 industries. As the use of the cloud continues to be strategically vital to many organizations, cloud resources have become the biggest targets for cyber-attacks, with SaaS applications (31%), Cloud Storage (30%) and Cloud Management Infrastructure (26%) cited as the leading categories of attack. As a result, protecting cloud environments has risen as the top security priority ahead of all other security disciplines. Read Now

Featured Cybersecurity

Webinars

Whitepapers

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3