enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

STADA Group [FWB: SAZ]

Endpoint Security

Aleksandar Radosavljevic, Global Chief Information Security Officer, STADA Group [FWB: SAZ]

In today’s IT environment, technology services are continually changing. And as they continue to evolve, so too must security solutions evolve and adapt to protect systems from different security threats like ransomware, data breaches, etc. For example, endpoint security solutions, which are in essence used to protect endpoint devices such as desktops, laptops, and mobile devices from being exploited by malicious actors and campaigns, on a network or in the cloud from cybersecurity threats, have evolved as well. Endpoint security solutions were traditionally used as an antivirus solution, but nowadays they are also used as a comprehensive protection from sophisticated malware and ever evolving zero-day threats.

Every device connected to an organizational network could serve as an entry point for cyber adversaries. The trend of employees bringing their own devices to work and running potentially malicious applications on those devices is introducing an additional security risk. The importance of endpoint security solutions is obvious, especially with the rise of ransomware attacks, hence ignorance of protecting endpoints is a recipe for disaster. The security risks for endpoints are additionally amplified by people working from home or even from the library or coffee shop thanks to the internet, which results that organizational network can be accessed from almost anywhere.

As digital perimeters shift over time to be on the boundaries of the organizational networks, and to potentially incorporate third-party networks, applications, cloud databases, mobile devices, so too the function of endpoint security solutions function is changing from prevention to more detection and response control (EDR). Moreover, endpoint security solutions have started incorporating more application control and sandboxing, tools that limit participation in the network rather than completely ringfencing them.

“Every Device Connected To An Organizational Network Could Serve As An Entry Point For Cyber Adversaries.”

To understand what to do next to improve endpoint resilience to attacks, security professionals responsible for endpoint security should consider: the risks they want to manage; the level of adversary they're prepared to defend against; the residual level of risks they are prepared to accept; and their current situation. However not all organizations face the same level of business risk, and not all organizations are starting from the same baseline of endpoint protection. Moreover, endpoint security goes beyond just components that are usually installed on endpoints and must include, at a minimum, application-level network security products, such as secure web gateways (SWGs) and secure email gateways (SEGs).

Nowadays, the most prevalent risks fall into the categories of ransomware, financial fraud, disclosure of personal data, disclosure of intellectual property, third-party attacks and business disruption. In parallel, security professionals should also consider the profile of attackers, which could fall in three different categories: automated attackers, opportunistic attackers, and advanced persistent threats (ATP). This will help in defining an endpoint security strategy, which should consider the following:

• Centralized Management
• Multi Layered Security – deployment of different security controls
• Data Security - data loss prevention, file integrity monitoring, data governance, network segregation
• User Awareness
• Mobile Threat Handling - device authentication, application containerization
• Intrusion Detection System - suspicious activity detection
• Incident Response

Having EDR in place provides many benefits to a business. It is a key factor in providing a secure way of working from home and allows greater flexibility in accessing data from almost anywhere. With data being the most valuable business asset, loss of data could put a business’ finances and reputation at risk. EDR protection is fast becoming a must-have for modern organizations.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.