THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Monday, December 04, 2023
Zero trust, by definition, requires multiple technologies and process elements and demands scale of data analysis and speed of execution to stop modern attacks.
FREMONT, CA: The majority of organisations are unaware of the number of endpoints that are actively using their networks as their tech stacks were created to excel at the idea of trust but verify rather than zero trust. They are becoming less aware of the number of human and machine-based endpoints they actually possess.
Attack surface protection evangelist at CyCognito, enterprises frequently produce thousands of unidentified endpoints yearly. Additionally, according to a Cybersecurity Insiders research, only 58 per cent of firms claim to be able to identify every vulnerable asset within their organisation within 24 hours of a critical exploit, and 60 per cent of enterprises are unaware of less than 75 per cent of the devices on their network. 75 per cent or more endpoint attacks won't be stopped. Currently, the average organisation manages over 135,000 endpoint devices, of which 48 per cent, or 64,800 endpoints, are invisible on their networks.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
According to a recent Ponemon Institute survey sponsored by Adaptiva, businesses spend an average of USD 4.2 million annually on endpoint security. The number of endpoints on a given enterprise's network that are known and secured is decreasing even as endpoint spending rises.
Zero Trust is the Future of Endpoint Security
Zero trust, by definition, calls on various technologies and process factors, as well as a large scale of data analysis and quick execution to thwart contemporary threats. Most CISOs seek a platform approach as they strive to consolidate security suppliers. In a standards-based, integrated paradigm, a platform strategy provides seamless execution to zero-trust deployment and leverages an enterprise's existing investments.
The future of endpoint security is zero trust since it addresses the following five issues:
Ransomware is Endpoint Security’s Most Persistent Threat
The prevalence of ransomware has grown by 466 per cent in the last three years. The vulnerabilities that most frequently result in ransomware attacks are identified in Ivanti's Ransomware Index Report Q2-Q3 2022, along with the speed at which undiscovered ransomware criminals move to seize control of an entire business. There are now 170 different ransomware families. The analysis is based on 154,790 vulnerabilities from the National Vulnerability Database (NVD).
Furthermore, the CISA's Known Exploited Vulnerabilities Catalog received 47 brand-new CVEs in the past three months. Cybercriminals use these new ransomware families to initiate ransomware attacks against unknown endpoints that are frequently not safeguarded.
Platforms for endpoint protection (EPPs) are becoming more data-driven. Absolute Software, whose Ransomware Response builds on the company's expertise in endpoint visibility, management, and resilience, is one of the leading providers of EPPs with ransomware detection and response. CrowdStrike Falcon, Ivanti, Microsoft Defender 365, Sophos, Trend Micro, ESET, and other manufacturers are additional suppliers.
Getting Microsegmentation Right is Challenging but Essential
Microsegmentation separates and isolates specific network components to minimise lateral movement and the overall number of attack surfaces. It is a key component of zero trust and is essential to the zero-trust architecture developed by the NIST. Making an effective ZTNA architecture also requires successful micro-segmentation. Assigning the least privileged access to every machine and human identity on a network typically becomes an iterative process, making it difficult to determine which identities belong in a given segment.
Eliminating Agent Sprawl, Misconfigurations and Breaches by Automating Device Configurations
In 82 per cent of data breaches, errors in database and administrator configuration unintentionally expose entire networks to attackers. On a typical endpoint nowadays, 11.7 security agents are installed on average. The frequency of collisions and decay increases with the number of security controls per endpoint, making them more prone to attack.
They free up IT staff time while lowering the risk of endpoint misconfigurations; self-healing endpoint management platforms that can rebuild and reconfigure themselves following an intrusion attempt are in demand. Self-healing endpoints are created to autonomously power off, update device configurations, manage patches, and then redeploy themselves without human intervention.
Self-healing endpoint management technologies that can automate device setups and deployment are claimed to be available from over 150 cybersecurity firms. 42 of them are currently tracked by G2Crowd. Leaders include Absolute Software, with persistence technology incorporated in its firmware that enables endpoints to self-heal while giving every PC-based endpoint an unbreakable digital tether.
Others include Ivanti Neurons, which uses AI-based bots for self-healing, patching, and endpoint protection, CrowdStrike Falcon Endpoint Protection Platform, Cybereason Defense Platform, and Malwarebytes for Business. Additionally, by combining threat information from emails, endpoints, identities, and applications, Microsoft Defender 365 employs its own strategy for self-healing endpoints.
Automating Patch Management Across Endpoints Reduces the Risk of a Breach
Over a third of security professionals spend on patch management and related cross-departmental collaboration. Additionally, 53 per cent of security experts claim that most of their work is spent keeping up with critical vulnerabilities.
Ivanti's introduction of an AI-based patch intelligence solution stands out among the various developments made in this field by EPP vendors for its distinctive strategy for scaling patch management. A collection of AI-based bots are used in the Neurons Patch for Microsoft Endpoint Configuration Monitor (MEM) to find, locate, and update all endpoint patches that require updating. Broadcom, CrowdStrike, SentinelOne, McAfee, Sophos, Trend Micro, VMware Carbon Black, Cybereason, and other firms are also suppliers of AI-based endpoint security.
More in News