Firewall News

Top Menu

  • Home
  • Our Blog
  • Contact Us

Main Menu

  • Software Updates
  • Alerts & Bugs
  • Out of the Box
  • Home
  • Our Blog
  • Contact Us

Firewall News

Firewall News

  • Software Updates
    • WatchGuard logo

      TDR 6.0.0 is now integrated into WatchGuard Cloud

      04/01/2021
      0
    • Sophos Logo

      XG Firewall 17.5 MR14 Released

      30/07/2020
      0
    • Sophos Logo

      Sophos Firewall Manager SFM 17.1 MR4 Released

      27/07/2020
      0
    • Sophos Logo

      Sophos Enterprise console - Endpoint Security and Control v10.8.9 for Windows has ...

      16/07/2020
      0
    • Sophos Logo

      Sophos iView v3 MR-2 Released

      07/07/2020
      0
    • Sophos Logo

      SD-RED Firmware 3.0.002 Pattern Update

      06/07/2020
      0
    • Sophos Logo

      XG Firewall 17.5 MR13 Released

      06/07/2020
      0
    • Sophos Logo

      End-of-Life (EoL) announcement for old firmware v17 and v17.1 for XG Firewall

      03/07/2020
      0
    • WatchGuard logo

      Fireware 12.5.4 Now Available

      01/07/2020
      0
  • Alerts & Bugs
    • Sophos Logo

      Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

      29/03/2022
      0
    • Sophos Logo

      Sophos: Important Product Lifecycle Updates

      03/03/2022
      0
    • WatchGuard logo

      WatchGuard Support Alert

      23/02/2022
      0
    • Sophos Logo

      Sophos: Important Product Lifecycle Reminder

      03/02/2022
      0
    • Sophos Logo

      Sophos: Product Lifecycle Information: Extended Support for Windows 7 and Windows Server ...

      31/01/2022
      0
    • Sophos Logo

      End-of-Life (EoL) announcement for Sophos SSL VPN Client

      29/11/2021
      0
    • WatchGuard logo

      WatchGuard: macOS Monterey 12.0.1 Does Not Support the AuthPoint Logon App

      09/11/2021
      0
    • Sophos Logo

      Sophos UTM Manager (SUM) End of Distribution

      04/11/2021
      0
    • WatchGuard logo

      WatchGuard: End of Sale Notice: AP420

      01/11/2021
      0
  • Out of the Box
    • WatchGuard’s Firebox T80 Earns 5-Star Rating in SC Labs Review

      17/11/2020
      0
    • WatchGuard Wins Big in CRN 2020 Tech Innovator Awards

      16/11/2020
      0
    • Coronavirus scams: what to look for and how to stop them

      02/04/2020
      0
    • Dell SonicWALL TZ 300

      Out the Box - Dell SonicWALL TZ 300

      05/07/2016
      0
    • Dell SonicWALL TZ SOHO

      Out the Box - Dell SonicWALL TZ SOHO

      05/07/2016
      0
    • WatchGuard Firebox T50

      WatchGuard Firebox T50

      31/03/2016
      0
    • WatchGuard Firebox M200

      WatchGuard Firebox M200

      31/03/2016
      0
NewsSonicWALL
Home›News›7 Key Security Risks to Address when Adopting SaaS Applications

7 Key Security Risks to Address when Adopting SaaS Applications

By admin
16/09/2019
1637
0
Share:

Infrastructure? Who needs it. The modern organization is ditching traditional on-premise software and related infrastructure in favor of software-as-a-service (SaaS) offerings.  SaaS provides attractive and often essential options for reducing CapEx, operational overhead and decreased deployment time — all of which translate into increased business agility.

But the increased agility isn’t without risks. Eager to keep projects moving, many internal business units will procure new SaaS applications without the guidance or approval of appropriate IT or security teams. Multi-SaaS organizations are often left to manage, protect and report on each SaaS service separately, further increasing risk with inconsistent security policies.

If your business is deploying more and more SaaS applications, be on the lookout for these seven primary security risks to understand where proper SaaS security should be applied.

  1. Phishing is still a threat. Email remains the most common threat vector with over 90% of the successful cyberattacks starting with a phishing email. Cybercriminals use phishing email to trick victims into delivering payloads using malicious attachments or URLs, harvest credentials via fake login pages, or commit fraud through impersonation.But modern phishing attacks also are increasing in sophistication and are often highly targeted.In addition, phishing has evolved to cloud-based attacks as organizations continue to accelerate the adoption of SaaS email (e.g., Office 365 or G Suite) and other productivity apps. Cloud applications present the next frontier for phishing since users need to authenticate to access their accounts, and the authentication is driven through industry-standard protocols, such as OAuth.For example, cybercriminals targeted O365 with highly sophisticated phishing attacks — including baseStriker, ZeroFont and PhishPoint — to bypass Microsoft security controls. Many secure email gateways, such as Mimecast, also could not stop these phishing emails.In another case, Google’s Gmail suffered a mass phishing attack in 2017 with an authentic-looking email that asked for permission and opened access to their email accounts and documents. The attack exploited Google’s OAuth protocol.
  2. Account takeovers open the door. Account takeover (ATO) attacks involve threat actors compromising an employee’s corporate credentials by either launching a credential phishing campaign against an organization or buying credentials on the Dark Web due to third-party data leaks. A threat actor then leverages the stolen credentials to gain additional access or escalate privileges. It is possible that a compromised account may remain undiscovered for a long time — or never be found at all.
  3. Data theft still profitable no matter where it’s stored. The risk of data breach is a top concern for organizations moving to the cloud. Sanctioning SaaS applications implies moving and storing data outside the corporate data center, where the organization’s IT department does not have control or visibility, but is still responsible for data security.The data stored in SaaS applications could be customer data, financial information, personally identifiable information (PII) and intellectual property (IP). Cybercriminals typically initiate a targeted attack or exploit poor security practices and application vulnerabilities to exfiltrate data.
  4. Loss of control may result in unauthorized access. Another risk of moving to the cloud is that the IT department no longer has complete control over which user has access to what data and the level of access. Employees may accidentally delete data resulting in data loss or expose sensitive data to unauthorized users resulting in data leakage.
  5. The unknown of new malware and zero-days threats. SaaS applications, especially file storage and file-sharing services (e.g., Dropbox, Box, OneDrive, etc.), have become a strategic threat vector to propagate ransomware and zero-day malware.According to Bitglass, 44% of scanned organizations had some form of malware in at least one of their cloud applications. Attacks taking place within SaaS environments are difficult to identify and stop as these attacks can be carried out without users’ awareness.One advantage of using SaaS applications is that the files and data automatically sync across devices. This can also be a channel for malware to propagate. The attacker would only have to upload a malicious PDF or Office file to the file-sharing or storage SaaS apps; the syncing features would do the rest.
  6. Compliance and audit. Government mandates, such as GDPR, and regulations for industries such as healthcare (HIPAA), retail (PCI DSS) and finance (SOX) require auditing and reporting tools to demonstrate cloud compliance, in addition to data protection requirements. Organizations must make sure sensitive data is secured, deploy capabilities to log user activities and enable audit trails across all sanctioned applications.
  7. The threats within. When it comes to security, employees are often the weakest link. Insider threats don’t always include malicious intent. User negligence can result in the accidental insider attack, which remains a top risk for organizations of all sizes. This risk isn’t isolated to weak passwords, shared credentials or lost\stolen laptops. It extends to data stored in the cloud, where it can be shared with external sources and often accessed from any device or location.The darker side of insider threats includes malicious intent. Insiders, such as staff and administrators for both organizations and CSPs, who abuse their authorized access to an organization’s or CSP’s networks, systems and data can cause intentional damage or exfiltrate information.

How to secure SaaS applications

Rapid adoption of SaaS email and applications, coupled with continuous technological advances, has resulted in multiple options for securing both SaaS email and data.

Geared toward the large enterprise, security vendors introduced Cloud Access Security Brokers (CASB) as a solution providing visibility, access control and data protection across cloud computing services using a gateway, proxy or APIs.

While traditional CASBs provide robust capabilities for the large enterprise, this isn’t always practical for every organization. In additional to being costly — with often complex deployments — few CASBs provide email security for SaaS-based email like Office 365 Mail and Gmail, leaving organizations to implement and manage separate security controls.

Expanded adoption of SaaS email and applications across organizations has created a need for an affordable, easy-to-use SaaS security solution. Thankfully, there are some approaches that can help close or eliminate new risks caused by SaaS applications.

For example, SonicWall Cloud App Security (CAS) combines advanced email protection and data protection for SaaS email and applications. This approach delivers advanced threat protection against targeted phishing attacks, business email compromise, zero-day threats, data loss and account takeovers.

Cloud App Security also seamlessly integrates with sanctioned SaaS applications using native APIs. This approach provides email security and CASB functionalities that are critical to protecting the SaaS landscape and ensure consistent policies across the cloud applications being used.

When used with Capture Security Center Analytics, and integrated with SonicWall next-generation firewalls, Cloud App Security delivers Shadow IT visibility and control through automated cloud discovery.

Previous Article

Sign up for instant product alerts with ...

Next Article

Information-Stealing Malware with Connections to Ryuk Targets ...

0
Shares
  • 0
  • +
  • 0
  • 0
  • 0
  • 0

Related articles More from author

  • Sophos Logo
    News

    Sophos Central Adds Support for SIEMs (Splunk, ArcSight, etc)

    04/11/2016
    By admin
  • FortinetNews

    Accelerating Your Cloud Security Strategy Without Compromising Protection

    04/09/2019
    By admin
  • BarracudaNews

    Barracuda named a Challenger in 2019 Gartner Magic Quadrant for Web Application Firewalls

    20/09/2019
    By admin
  • Meraki MS225-48
    MerakiNews

    ADD SECURITY, REMOVE COMPLEXITY

    21/11/2019
    By admin
  • Fortinet logo
    News

    Fortinet – FortiManager 5.6: Centralized Control for Today’s Networks

    15/08/2017
    By admin
  • News

    6 Essential Hardware Firewall Solutions For A Small Business 2019

    02/09/2019
    By admin

  • Sophos Logo
    Alerts & BugsSophos

    Advisory: Sophos Central Maintenance scheduled for Saturday November 9th, 2019

  • Alerts & BugsSonicWALL

    SonicWALL – ANDROID SCAMS RELATED TO THE NEW VIRAL TREND – FACEAPP

  • NewsTrendMicro

    Trend Micro Debuts World’s Broadest Security Services Platform for Organizations Building Applications in the Cloud

Timeline

  • 29/03/2022

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

  • 03/03/2022

    Sophos: Important Product Lifecycle Updates

  • 01/03/2022

    Shoring up your cybersecurity posture in light of ongoing crisis

  • 23/02/2022

    WatchGuard Support Alert

  • 03/02/2022

    Sophos: Important Product Lifecycle Reminder

Sponsored Links

Latest Comments

  • Paul Sillars
    on
    21/06/2016
    I received this in an email this morning, it was the first I heard about it ...

    Dell Software Group sold to help fund looming EMC deal

  • Paul Sillars
    on
    20/06/2016
    This is going to be an interesting one to watch. Especially after today's announcement that ...

    Ingram Micro gets distribution access to Dell’s security range in Australia

Find us on Facebook

Firewall.News Logo

This site serves more as a reference point for some of the major security vendor's updates and product/press releases

It will never be a definitive list, but it helps our customers keep up to date and also allows us to express our comment and observations as well.

About us

  • PO Box 451, North Lakes, Queensland, 4509, Australia
  • [email protected]
  • Recent

  • Popular

  • Comments

  • Sophos Logo

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

    By admin
    29/03/2022
  • Sophos Logo

    Sophos: Important Product Lifecycle Updates

    By admin
    03/03/2022
  • Shoring up your cybersecurity posture in light of ongoing crisis

    By admin
    01/03/2022
  • WatchGuard logo

    WatchGuard Support Alert

    By admin
    23/02/2022
  • Dell SonicWALL Supermassive

    Ingram Micro gets distribution access to Dell’s security range in Australia

    By admin
    14/06/2016
  • Francisco Partners and Elliott Management to Acquire the Dell Software Group

    Dell Software Group sold to help fund looming EMC deal

    By admin
    21/06/2016
  • WatchGuard Firebox M500 – The Cure for HTTPS Performance Headaches

    By admin
    05/03/2015
  • Sophos Logo

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

    By admin
    29/03/2022
  • Paul Sillars
    on
    21/06/2016

    Dell Software Group sold to help fund looming EMC deal

    I received this in ...
  • Paul Sillars
    on
    20/06/2016

    Ingram Micro gets distribution access to Dell’s security range in Australia

    This is going to ...

Follow Me

  • Contact
  • About Us
  • Home