Showing posts with label Cortex XDR Management. Show all posts
Showing posts with label Cortex XDR Management. Show all posts

Wednesday, January 24, 2024

Palo Alto Networks Asia Pacific Cybersecurity Predictions 2024

MANILA, PHILIPPINES – Palo Alto Networks, the global cybersecurity leader, has recently released its 2024 cybersecurity predictions for Asia Pacific – 5 key insights from industry leaders to help organisations ensure a secure future.

2023 saw organisations witness unprecedented levels of cybercrime. Palo Alto Networks’ State of Cybersecurity Report found that the Philippines experienced the highest number of disruptive attacks in Southeast Asia, with 29% of local organisations experiencing a 50% or more increase in incidents. Furthermore, the firm also received the most number of calls to its incident response team ever in October 2023. Cybercriminals have used ransomware to target critical infrastructures and found novel techniques to exploit emerging technologies like generative AI to ill-effect. 

 

Predicting cybersecurity trends for 2024 will be especially important if organisations want to get ahead of modern cyberattackers. With stakes higher than ever, organisations need to take a holistic approach – accounting for macroeconomic factors, emerging technologies, and cloud risks among others. 


Ian Lim, Regional Chief Security Officer, Palo Alto Networks, said, “In 2023, we’ve seen mature organisations, who invest heavily in cybersecurity, still falling victim to debilitating cyberattacks. This is due to the tenacity and ingenuity of attackers who exploit cyber hygiene issues or find novel ways to compromise legacy defences. Another key reason for these breaches lies in the complexity of security capabilities in most modern organisations. They use an average of 31.58 disparate security tools to protect their highly interconnected and innovative environments. The lack of correlation and the level of noise generated by these tools creates immense visibility gaps and dampens their ability for detection and response.” 


He added, “Going into 2024, highly motivated cybercriminals, nation state attackers and hacktivists will continue to innovate, expand and exploit – not much we can do to slow that down. However, we could and should definitely address the complexity of our security capabilities with AI to make them more effective and cost efficient.” 


Here are the five cybersecurity trends to watch out for in 2024:


  1. Hacktivism: the modern crusade 

2023 saw numerous instances of broadcast events being disrupted by climate activists. This year, this protest could take the shape of a cyber-first-campaign. With significant events like the Olympics, the Euros, and regional elections coming up, hacktivists will look to further their cause to audiences in the millions. Previously, a high level of technical expertise was necessary, but the cybercrime-as-a-service model has lowered this threshold. Now, it only takes an extremely motivated activist with sufficient funds.


Tumultuous geopolitical climate will provide opportunities for hacktivists to gain notoriety for their group and sympathy for their cause. Most hacktivist activity is via Distributed-Denial-of-Service (DDoS) attacks. For example, during the G20 Summit in India, more than 30 groups of hacktivists from neighbouring countries attacked more than 600 websites of government and private entities through DDoS attacks, defacements, and data leaks. 


In 2024, organisations should evaluate their risk profile according to the evolving threat landscape and ensure coverage not only for financially motivated attacks but also for hacktivism and nation-state attacks. 


  1. AI’s role in cybersecurity will evolve, for good and bad 

Since ChatGPT’s launch in October 2022, there have been concerns worldwide regarding its potential to democratise cybercrime. Despite having guardrails to prevent malicious applications, a few creative prompts can get ChatGPT to generate near flawless phishing emails that sound “weirdly human” at immense scale. We’ve seen attackers use Gen AI in novel ways like deepfake and voice technology to scam banks out of millions. Companies adopting Gen AI must be wary about the vulnerabilities of model poisoning, data leakage, prompt injection attacks, etc. Attackers will continue to exploit innovation gaps with the increased use of Gen AI for legitimate use cases.


Hence, one of the AI Cybersecurity trends we expect to see in 2024 is the maturation on how we protect enterprise-level use of Gen AI. This involves making sure that security controls, vulnerability management and threat monitoring activities are embedded through the entire lifecycle of AI development projects. Gen AI will further embed itself into cybersecurity capabilities. Its ability to summarise, weed through noise, and give concise summaries of security events is far greater than a human analyst’s (especially at the scale a modern SOC operates). With LLMs getting better by the day, we are bound to see more sophisticated applications that move beyond just being a clever and occasionally-hallucinating chatbot. 


  1. Operational technology will remain the low-hanging fruit

Operational Technology is the heart of any industrial organisation. As the primary generator of revenue, OT systems must have a high level of cyber maturity. However many organisations still believe OT environments are protected by an air gap, whereas IT/OT convergence has resulted in OT being more connected than ever to IT and also, in many cases, to the cloud. This has expanded the attack surface and greatly increased the risk to OT networks, without the investment in cyber controls. 


A breach of OT systems can not only result in lost revenue, but also potentially, injuries or loss of life. A cyber secure OT environment is also a safe and reliable OT environment. A Zero Trust architecture will protect the most critical OT systems from threats, while allowing organisations to focus on their digital transformation. 2024 will see organisations invest in OT cyber security maturity to protect their most important business systems and manage the increased risk to an acceptable level.



  1. Consolidation to enable the next frontier in cybersecurity 

Unit 42’s Cloud Threat Report (Volume 7) found that on average, security teams take approximately 6 days to resolve a security alert, with 60% of organisations taking longer than 4 days. In a threat landscape where attackers only require a few hours to find and exploit vulnerabilities, 4-6 days is just way too long. Organisations with disparate security tools that are not well integrated have a harder time deploying automation and orchestration. This is a major setback to reducing the mean time to detect and the mean time to respond. 


In addition to the lacklustre threat response, organisations with siloed solutions are having a hard time securing their rapid digital transformation initiatives. Alongside macroeconomic headwinds and workforce challenges, enterprises are looking to consolidate their vendor spread and reduce complexities. Put simply, it is way easier to manage the cybersecurity stack if there is one point of contact when a crisis inevitably strikes. Over the long term, it reduces costs and yields better results. This is thanks to the increased visibility and seamless integration that comes with a unified security offering. More organisations are waking up to these benefits and thus 2024 will see customers focus on reducing complexities and turning to consolidated cybersecurity stacks. 


  1. Securing multi and hybrid cloud will be a focus 

Per the State of Cybersecurity survey, APAC organisations are moving large chunks of their infrastructure to the cloud, with 44% adjusting their cybersecurity strategy to adopt cloud security. Early adopters of cloud typically start with a single hyperscaler. Naturally, the single cloud model would adopt native security tools from their chosen Cloud Service Provider (CSP). Through the course of time they experience issues and outages that can only be addressed by adopting a multi or hybrid cloud strategy. This multicloud  journey would most likely necessitate a review on their existing cloud security paradigm as native CSP security tools do not seamlessly translate to different CSPs. 


In 2024, organisations that have to contend with multi or hybrid cloud projects would move to establishing a more unified approach to security when dealing with more than one cloud provider. Rationalising cloud security tools across the entire development lifecycle will also be a focus as this provides much higher visibility, correlation and security monitoring.

Tuesday, November 21, 2023

Palo Alto Networks Adds "Bring Your Own AI" Capability To Cortex XSIAM AI-driven Security Operations Platform

MANILA, PHILIPPINES It used to take an attacker 44 days on average to exfiltrate data from an organization once it was compromised — now it’s a matter of hours — and with companies taking an average of 5.5 days to initially contain an incident, legacy security operations solutions no longer work. Since its debut, Cortex XSIAM® has helped customers revolutionize their security operations center (SOC). One services company improved its median time to resolution from days to minutes — 270 times faster than before. Further improving the award-winning AI-driven security operations platform, Palo Alto Networks (NASDAQ: PANW) recently unveiled Cortex XSIAM 2.0, which includes a new bring-your-own machine learning (BYOML) framework. 

Palo Alto Networks collects more security data than any other cybersecurity company, with more than 5 petabytes of security data ingested daily, and with more than 1 exabyte stored in total. XSIAM offers robust, out-of-the-box AI models built for superior security analytics and protection against threats. In addition, many mature SOCs want the ability to customize and create their own ML models. The BYOML framework makes the vast security data stored in XSIAM available for the first time. This allows security teams to create and integrate their own ML models into XSIAM to enable unique use cases like fraud detection, security research and sophisticated data visualization. 


In addition to the BYOML framework, XSIAM 2.0 includes new features that enable organizations to address today’s security operations challenges through increased visibility and threat prioritization. The new XSIAM Command Center creates a seismic shift in how security teams monitor their security operations with a comprehensive view of data sources and alerts, enabling the effortless identification and prioritization of security incidents within a single unified platform. Additionally, with the new MITRE ATT&CK Coverage Dashboard, organizations can swiftly gauge their overall defense against a broad set of threat actor tactics and techniques, channeling their efforts toward strengthening their overall security posture. 


Gonen Fink, senior vice president, Cortex products, Palo Alto Networks, said: 

“Effective security operations are a major challenge for companies all worldwide. The speed at which attackers are moving, coupled with new regulatory requirements like the SEC Mandate requiring public companies to disclose material cybersecurity incidents within four days of discovery, make it impossible to handle cyberthreats with traditional manual approaches. Using artificial intelligence and automation, XSIAM 2.0 closes this gap by addressing operational complexity, stopping threats at scale, and speeding up incident remediation.”


Further building on its recent success and recognition, Palo Alto Networks Cortex XSIAM was identified as a Leader and Outperformer in GigaOm's 2023 Radar Report on Autonomous SOC.* 


Andrew Green, research analyst, GigaOm, said:

“As a solution built from the ground up with lessons learned from a suite of leading security products, XSIAM delivers a comprehensive autonomous SOC solution that scores high on a wide range of key criteria."


The outcomes achieved by XSIAM 2.0 cannot be met with multiple point products and siloed data. XSIAM converges SOC capabilities, including XDR, SOAR, SIEM and more, into a single platform to streamline security operations. It also continuously collects, stitches and normalizes raw data, all through a unified approach. Unified data, coupled with an AI-driven platform approach, is why customers have seen the following results:


  • Oil and gas company: 75% reduction in incidents requiring investigation. This is from ~1,000 a day to ~250 a day, eliminating false positives and duplicates.

  • Boyne Resorts: Added 20 more data sources into one platform, streamlining and improving investigations.

  • Imagination Technologies: 10x improvement in incident closure rate, going from <10% to 100%.


Paul Alexander, director of IT operations at Imagination Technologies Group, said:

"One of our biggest pain points is information overload. Business growth is great, but it means we have more business operations to manage, and meanwhile, the threat actors are getting more sophisticated. XSIAM is helping because it effectively lets us cut straight to the real and serious incidents that we need to focus on and we're not wasting time on data that doesn't need our attention."


Mike Dembek, network architect at Boyne Resorts, said:

“Log collection was a huge weak point for us. Our SIEM was expensive, and it was difficult to integrate sources. We were hunting down alerts that weren’t accurate; it was a hodgepodge of stuff that wasn’t correlated together. With XSIAM, we have more visibility and faster investigations. Seamless data onboarding and automation setup are game changers.”

Wednesday, October 11, 2023

Palo Alto Networks: 1 in 3 SMEs not confident in Hybrid Work Security

Palo Alto Networks

MANILA, PHILIPPINES—Global cybersecurity leader Palo Alto Networks revealed in its 2023 State of Cybersecurity in ASEAN Report that one out of three small and medium enterprises (SMEs) in the Philippines and Southeast Asia is not confident in tracking cybersecurity breaches amid a hybrid work environment. With 41% of their infrastructure and processes running in the cloud for onsite and work-from-home setup, SMEs are most concerned about password attacks (63%), malware attacks (56%), and account takeovers (53%).

Steven Scheurmann, Vice President for ASEAN at Palo Alto Networks, shared, "In observance of Cybersecurity Awareness Month this October, we are reinforcing our mission of empowering SMEs with a stronger cybersecurity posture, recognizing their pivotal role as the backbone of our economy. It's crucial to remember that SMEs, just like larger organizations, hold valuable data sought after by cyber attackers for financial gain.”

For two years in a row, adopting cloud security has been a top cybersecurity strategy for SMEs. However, hybrid work continues to pose challenges for SMEs in securing their cloud applications and services due to risks associated with unsecured home networks and personal devices. These risks include data breaches, which can threaten both SME employees and customers, potentially leading to identity theft and unauthorized financial transactions. These vulnerabilities make it challenging for almost one-third of SMEs to procure a broader range of cybersecurity solutions for hybrid work.

To stay ahead of threats, Scheurmann underscored non-negotiables that SMEs should look for when securing cloud infrastructure in hybrid environments.

Holistic visibility of network traffic. Imagine your company's network as a bustling airport, where employees work from different 'terminals' or physical locations, such as offices, homes, or remote sites. The challenge resembles airport security—knowing who's allowed to board 'network flights' and who's not. The airport needs to have visibility on every 'passenger' (devices and users) and verify their 'boarding passes' (access permissions). This holistic visibility ensures SMEs that only authorised users and devices get access to data and applications.

Zero Trust Network Access (ZTNA). ZTNA operates on the principle of 'never trust, always verify.' If an SME's network is a mall establishment, not all of its tenants can freely move around the building. ZTNA acts as the diligent security manager, ensuring that each 'tenant' (employee) must show their identification and state their purpose before gaining access to areas reserved for authorized personnel only.

AI and machine learning. Artificial intelligence (AI)-backed machine learning in network security is like having personalized content recommendations on your social media. Just as algorithms analyze your preferences for tailored suggestions, AI-driven firewalls with machine learning analyze network traffic, predict, and prevent cyber threats that are also increasingly sophisticated due to AI. They continually adapt, ensuring SMEs are equipped to protect themselves from emerging threats.

"Even small-sized and resource-constrained businesses can establish a formidable security posture, rendering it challenging for attackers to breach, provided a strong cybersecurity hygiene culture prevails within the company. Holistic visibility, a zero-trust approach, and AI integration will help ensure that SMEs can scale up their cloud security to protect against both current and future threats, no matter where they choose to work,” concluded Scheurmann.sddddddddddddddddddddddddddddddddddddddd

Thursday, August 24, 2023

Establishing Zero Trust Cybersecurity in Philippines’s Newly-Connected Communities

Palo Alto

MANILA, PHILIPPINES—Internet access has transformed from a convenience to a necessity in today’s digital age. With the rise of remote work, distant learning, e-commerce, and financial technology, internet connectivity is increasingly considered a fundamental right. Unfortunately, a report from the Department of Information, Communication, and Technology (DICT) indicated that 65% of Filipinos still do not have internet access. 

To bridge the digital divide, the Philippine government is advancing projects to narrow the gap in geographically-isolated and disadvantaged areas (GIDAs). This effort involves welcoming a range of internet satellite providers to enhance accessibility in rural regions. This includes the launch of Starlink in February and upcoming market entry announcements from other key players, such as SES, Silkwave, and Astranis, all within the next two years. 


Digital inclusion promises greater economic growth and opportunities in rural and underserved regions. Achieving this goal requires collaborative efforts from all stakeholders to ensure that newly connected communities are well-informed about the associated risks. Consumers need education to embrace a proactive mindset, preparing for and mitigating the impact of cyberattacks. Organizations must offer cybersecurity training to employees and establish strong infrastructure to protect these communities from evolving and complex threats. 


Cybersecurity Foundation in Newly-Connected Communities 


Oscar Visaya, Country Manager for the Philippines at Palo Alto Networks, shared, “GIDAs are gaining internet access through public and private initiatives. But the greater challenge lies in shifting consumer behavior towards cybersecurity. Many people in these communities were never exposed to online risks, so taking on cybersecurity practices might take time—possibly too late. Early education on best security practices, like Zero Trust, is crucial for individuals and organizations within these areas.”


Zero Trust is a strategic approach that secures an organization by eliminating implicit trust and continuously validating every stage of digital interaction. This principle encourages users to adopt multi-factor login authentication and grant permission solely to recognized devices and applications. Given the country's high incidence of phishing, Zero Trust can also be extended to consumer behaviors. This involves individuals exercising elevated caution when encountering links in emails and social media, evaluating the credibility of links and their sources before clicking.


Companies at the forefront of driving the digital infrastructure of communities are also increasingly confronted with ransomware attacks. According to Palo Alto Networks’ 2023 Unit 42 Ransomware and Extortion Report, ransomware attacks in the Philippines surged by nearly 60%. These attacks employ tactics such as encryption, data theft, distributed denial of service (DDoS), and harassment. While no organization is impenetrable to cyber threats, embracing Zero Trust helps identify a network attack or breach at an early stage. 


As companies handle vast datasets, contend with supply chain vulnerabilities, and manage on-premise and cloud integration complexities, risks arise on various fronts. Securing network architecture with robust firewalls and intrusion detection systems (IDS) is vital to fortifying digital infrastructure against multifaceted threats. In this backdrop, leveraging artificial intelligence (AI) and machine learning becomes pivotal for a comprehensive Zero Trust approach, enabling continuous monitoring and verification of high-volume users, data, and applications to effectively address the rapid evolution of sophisticated risks that surpass manual monitoring capabilities.


Palo Alto Networks also reported that state and local government units (LGUs) emerge as one of the most vulnerable sectors in the country due to the abundance of extensive sensitive data and invaluable information they store. The possible fallout from a data breach within a public agency reverberates far beyond the digital realm, which could jeopardize citizens' privacy, public services, and even national security. In line with this, government agencies like the Bangko Sentral ng Pilipinas (BSP) advised their supervised banks and other financial institutions to embrace a zero trust operational model for security. 


One of the most important cybersecurity measures that the state and LGUs can integrate is having granular visibility over operational network traffic and scrutinizing it at both the application and user levels. This process would validate proper usage while promptly flagging any anomalous activity. Additionally, identity and access management (IAM) could help segment networks to limit extraneous and internal attack vectors while meeting stringent performance requirements. 


“Digital infrastructure's economic potential hinges on effective preparedness against attacks that could cause financial losses, cost livelihoods, and endanger people’s safety at worst. By implementing robust cybersecurity measures from the outset, attack surfaces shrink and pave a path for sustainable growth that benefits everyone in the long term,” Visaya concluded.


###


About Palo Alto Networks


Palo Alto Networks is the world’s cybersecurity leader. We innovate to outpace cyberthreats, so organizations can embrace technology with confidence. We provide next-gen cybersecurity to thousands of customers globally, across all sectors. Our best-in-class cybersecurity platforms and services are backed by industry-leading threat intelligence and strengthened by state-of-the-art automation. Whether deploying our products to enable the Zero Trust Enterprise, responding to a security incident, or partnering to deliver better security outcomes through a world-class partner ecosystem, we’re committed to helping ensure each day is safer than the one before. It’s what makes us the cybersecurity partner of choice.


At Palo Alto Networks, we’re committed to bringing together the very best people in service of our mission, so we’re also proud to be the cybersecurity workplace of choice, recognized among Newsweek’s Most Loved Workplaces (2021 and 2022), Comparably Best Companies for Diversity (2021), and HRC Best Places for LGBTQ Equality (2022). For more information, visit www.paloaltonetworks.com.


Friday, August 4, 2023

Palo Alto Networks Introduces CI/CD Security, Becoming the First CNAPP to Extend Security into the Software Delivery Pipeline

PALO ALTO NETWORKS

MANILA, PHILIPPINES — The attack surface of cloud-native applications continues to grow as adversaries look to exploit misconfigurations and vulnerabilities throughout the application life cycle. In response, the industry has turned to Cloud Native Application Protection Platforms (CNAPPs) to unify multiple disparate security capabilities and protect applications from code-to-cloud. Palo Alto Networks (NASDAQ: PANW) today introduced the CI/CD Security module to provide integrated software delivery pipeline security as part of our  code-to-cloud capabilities in Prisma Cloud's CNAPP platform. By securing the CI/CD environment and protecting against open source vulnerabilities with software composition analysis, Prisma Cloud is the most complete security platform for seamlessly protecting the entire engineering ecosystem.

According to Gartner, securing the software delivery pipeline is as important as securing the software that is delivered. The CI/CD Security module enables DevOps and security teams to better collaborate and improve security outcomes throughout the application life cycle. By adding CI/CD Security into the Prisma Cloud platform that already includes — Secrets ScanningSoftware Composition AnalysisInfrastructure as Code Security — organizations are able to optimize security and risk prevention throughout the entire software delivery pipeline, achieving a holistic and comprehensive security oversight which cannot be achieved with individual, siloed solutions.


Read here for more on Prisma Cloud’s CI/CD Security module. 


Ankur Shah, senior vice president, Prisma Cloud, Palo Alto Networks, said: 

“A major challenge in securing CI/CD pipelines is visibility. The myriad of third-party tools and applications running in development environments makes it almost impossible for security teams to determine if they are correctly configured. The integration of Cider’s capabilities secures the CI/CD environment and gives Prisma Cloud customers the ability to analyze individual tools, visualize how they interact with applications and each other, and identify and remediate risks.”


Daniel Krivelevich, CTO of Application Security, Prisma Cloud, Palo Alto Networks and former co-founder of Cider Security, said: 

“The only way to prevent insecure code from reaching production is to scan every code artifact, dependency, and ensure the delivery pipeline is effectively protected. Integrating Cider’s technology with Prisma Cloud strengthens the platform’s ability to help secure organizations' entire engineering ecosystem, ensuring only what is intended is pushed to production.”


CI/CD Security is the eleventh module integrated into the robust Palo Alto Networks cloud security platform, making Prisma Cloud the most comprehensive CNAPP platform to seamlessly protect the entire application lifecycle — from code through deployment to runtime. The new module is derived from Cider Security's cutting-edge capabilities that helps organizations "shift security left" to prevent threats and vulnerabilities before applications are deployed into production environments. 


Nir Rothenberg, chief information security officer, Rapyd, said:

“Since implementing Prisma Cloud’s CI/CD Security module, we now have complete visibility into all the third party tools we leverage to build and deploy applications to the cloud. This ultimately gives us the confidence that we’re eliminating threats and vulnerabilities in code from reaching production environments.”


As organizations continue their cloud transformation efforts, Palo Alto Networks next-generation security platforms collectively and comprehensively enable enterprises to stay ahead of threatssecure their networksprotect their cloud-native applications, and better manage security operations. With Palo Alto Networks, organizations can confidently protect their people, devices, applications and data.


- - - -


Follow Palo Alto Networks on TwitterLinkedInFacebook and Instagram


About Palo Alto Networks

Palo Alto Networks is the world's cybersecurity leader. We innovate to outpace cyberthreats, so organizations can embrace technology with confidence. We provide next-gen cybersecurity to thousands of customers globally, across all sectors. Our best-in-class cybersecurity platforms and services are backed by industry-leading threat intelligence and strengthened by state-of-the-art automation. Whether deploying our products to enable the Zero Trust Enterprise, responding to a security incident, or partnering to deliver better security outcomes through a world-class partner ecosystem, we're committed to helping ensure each day is safer than the one before. It's what makes us the cybersecurity partner of choice.


At Palo Alto Networks, we're committed to bringing together the very best people in service of our mission, so we're also proud to be the cybersecurity workplace of choice, recognized among Newsweek's Most Loved Workplaces (2021 and 2022), Comparably Best Companies for Diversity (2021) and HRC Best Places for LGBTQ Equality (2022). For more information, visit www.paloaltonetworks.com.


Palo Alto Networks and the Palo Alto Networks logo are registered trademarks of Palo Alto Networks, Inc. in the United States and in jurisdictions throughout the world. All other trademarks, trade names, or service marks used or mentioned herein belong to their respective owners. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.