CISA cybersecurity advice: move to SaaS and cloud to reduce complexity and improve security
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has seen many businesses and organizations suffer the consequences of destructive cyber attacks in recent years. Being involved in breach assessments along various industry stakeholders, their cybersecurity advice is notable, yet often overlooked/ignored:
"One major improvement you can make is to eliminate all services that are hosted in your offices [...] These systems require a great deal of skill to secure. They also require time to patch, to monitor, and to respond to potential security events. Few small businesses have the time and expertise to keep them secure. [...] We urge all businesses with on-prem systems to migrate to secure cloud-based alternatives as soon as possible."
Read more in CISA's Cyber Guidance for small businesses here:
https://www.cisa.gov/cyber-guidance-small-businesses
Should the advice be extended to larger organizations as well?
#cloud #saassecurity #SaaS
The recent ProxyNotShell Exchange attack chains are still being leveraged to gain foothold into remote networks. Many internet facing Exchange OWA servers worldwide are still vulnerable. The timeline below shows how ample an opportunity the attackers had up until Microsoft finally patched the bugs (at least 2-3 months of open access into any Exchange environment on the planet). It is a testament on how hard and risky it is to run public internet facing services nowadays.
#proxynotshell #owassrf #vulnerabilities #exchange
SASE approach
One more buzzword or acronym if you will: Secure Access Service Edge (SASE). Analysts expect it to reach a 15B USD opportunity with a 30%+ annual growth by 2025.
This unusually high growth rate is in fact justified: with remote work by default and a less relevant network edge, IT operations want to better secure remote corporate access, as well as offer consistent browsing experience regardless of location.
By moving firewall, secure web gateway, remote and cloud access infrastructure to an outsourced service layer, SASE promises simplified operations and more consistent security.
#sase #iaas #sdwan