A US government agency provides a powerful framework for understanding today’s cybersecurity challenges. Here’s where Vectra AI fits in.
If you ask security analysts to describe the biggest pain points in their role, you will no doubt get a diverse set of answers. One thing that they will almost certainly have in common is the challenge of dealing with alert fatigue.
Cybersecurity authorities from the United States, New Zealand, and the United Kingdom have released a joint Cybersecurity Information Sheet (CIS) that recommends proper configuration and monitoring of PowerShell to address the recurrence of the scripting language's use in cyberattacks.
Many security propositions claim artificial intelligence provides a value boost. The real story is more complicated.
by language
A comprehensive backup strategy is a cornerstone of any DR plan. But how would you distinguish between legitimate backup activity and malicious data exfiltration?
We at Vectra think that SOC teams need to focus on 3 challenges to stay ahead of cyberattacks. ✔️ Coverage ✔️ Clarity ✔️ Control
A US government agency provides a powerful framework for understanding today’s cybersecurity challenges. Here’s where Vectra AI fits in.
If you ask security analysts to describe the biggest pain points in their role, you will no doubt get a diverse set of answers. One thing that they will almost certainly have in common is the challenge of dealing with alert fatigue.
Cybersecurity authorities from the United States, New Zealand, and the United Kingdom have released a joint Cybersecurity Information Sheet (CIS) that recommends proper configuration and monitoring of PowerShell to address the recurrence of the scripting language's use in cyberattacks.
Wenn es um IT-Sicherheit geht, wird häufig behauptet, künstliche Intelligenz bringe einen Wertzuwachs mit sich. In Wahrheit ist die Geschichte etwas komplizierter.
Many security propositions claim artificial intelligence provides a value boost. The real story is more complicated.
How to move cybersecurity forward? At the core of this discussion, we always find the same core values. We at Vectra live up to the 9 C’s.
Hybrid working models are a hacker's dream! Every remote IP is a potential risk. Learn how to protect your organization in the modern world. | Read now!
Most marketing messages are a cocktail of sober reality and hyperbole. Of course, the proportions may vary from season to season, from one company to the next, but hype continues to be a perpetual factor in the cybersecurity world. At Vectra, however, we are firm believers in sober reality.
Our Vectra Masked CISO series tackles some of the biggest issues in security and how to overcome them.
The MITRE ATT&ACK framework helps to keep your business secure. Learn how Vectra leverages MITRE ATT&CK and supports MITRE D3FEND.
Vectra’s latest report on cybersecurity shows: Traditional approaches won’t work anymore. Key findings are listed here.
In order to help security teams validate the effectiveness of their Azure AD security controls and stop future attacks, the Vectra platform continuously monitors user activity and reveals instances of users bypassing multi-factor authentication (MFA) and other preventative controls.
L’intensificarsi di attacchi informatici negli ultimi anni ha influenzato in modo significativo l’attenzione rivolta dalle aziende sulla vigilanza. C’è ancora tempo, però, per fare della protezione la vera priorità.
Regardless of discipline, cybersecurity professionals deal with mounting pressure each day to make the right decisions and strategically play the right hand to keep their organisations a step or two ahead of cybercriminals. It can be stressful. And with good reason as the attack surface is wider and more diverse than ever driven by heavy cloud usage, while those who work to exploit it continue to develop new tactics and tools to help expose security weaknesses.
Con la pandemia e la diffusione del lavoro da remoto, gli attacchi informatici sono aumentati nel 2021, confermando una tendenza strutturale. Per difendersi, individuare i movimenti laterali è diventata una questione prioritaria per le aziende.
The Vectra Masked CISO series gives security leaders a forum for discussing the biggest issues in security and advising their peers on how to overcome them.
We have never seen a full-on cyber conflict rage across the world’s digital systems, but if the situation in Ukraine leads to such a thing, CIOs and CISOs will find themselves on the front lines. With escalation patterns uncertain and no “rules of the road” governing cyberwar, any organization risks becoming a casualty. Already, CIOs and CISOs are seeing their roles evolve and enlarge. Vectra AI CRO Willem Hendrickx discusses their transformational hour
What If there was a Supply Chain Compromise of an IDP? The recent security incident at Okta represents yet another perspective on supply chain compromises. While this attack appears to not have been fully realized, resulting in an apparently limited number of businesses affected, it poses an interesting set of questions to think about in terms of what a supply chain attack against an IDP would look like when fully realized. The result of any IDP compromise, or that of any similar pervasive use technology could be an attack group with access to millions of users and thousands of businesses. This blog provides perspective on the current situation and mitigation and defense strategies to manage such an event.
The cloud is complex. AWS alone has over 200 services (and quickly growing). Securely configuring even a small set of these services to operate at the scale of modern organizations today creates a variety of challenges.
El movimiento lateral ofrece a los atacantes puntos de control adicionales en una red comprometida
Gli attacchi informatici in Italia stanno crescendo a un ritmo elevato, sia in termini di complessità sia in termini di incidenza. Ciò è dovuto in parte alla crescente digitalizzazione, ma la maggiore esposizione alle minacce è frutto anche dei profondi cambiamenti portati dalla pandemia.
It’s only human to focus on external threats to your well-being. This often applies to organizations and their approaches to security as well; which is why so much energy is typically put into perimeter security. Yet, this approach is antithetical to the zero-trust methodology: Organizations must also pay attention to internal-to-internal and internal-to-external traffic just as much as traffic coming in.
I want Vectra to be known also for its values, for its vision, for its people and attitude, and for its passion for making the world a safer and fairer place. In short, for our culture.
“Artificial intelligence is no match for human stupidity,” observed a wry Albert Einstein. Today, we have evolved to where AI can deliver critical and indispensable advantages in the race toward cybersecurity. Nevertheless, even brilliant security managers do not always see how or why this is the case.
Nell’era della trasformazione digitale, i servizi automatizzati si sono assicurati un posto di primo piano nell’agenda della maggior parte delle organizzazioni. Eppure, fino a poco tempo fa la sicurezza informatica è rimasta secondaria.
Updated perspective on cyberthreats as a result of ongoing Ukrainian/Russian conflict, including specific custom recall queries, and aggregation of common Russian state actor TTPs.
As the new reality of the continual dangers of cyberwar gradually sets in, organizations globally are working to harden their defenses. Most cyber-attacks are blocked by preventative safeguards. Highly motivated attackers, however, tend to find ways to get through those defenses.
Cloud-basierte Lösungen sind für viele Unternehmen lebenswichtig und ein elementarer Teil der Infrastruktur geworden. Die wachsende Bedeutung der Cloud stellt IT-Administratoren vor eine Reihe von Fragen. Denn dadurch, dass IT-Systeme immer komplexer werden und die Sicherheit vielerorts in die Hände der Cloud-Provider gegeben wird, entstehen neue Herausforderungen für Unternehmen.
Advanced Microsoft Cloud Attacks often attack through three key areas which we enumerate in this blog: Service Principals, Multi-Factor Authentication (MFA) Downgrade, and Mobile-Device MFA Authenticators.
La digitalización de las estructuras industriales, comerciales y sociales aumenta las apuestas de nuestro futuro, tanto en lo que respecta a las oportunidades, la equidad y los logros, así como a la disrupción y el caos a escalas antes inalcanzables.
Wie laufen RansomOps Angriffe ab und wie kann man sie rechtzeitig stoppen? Mit dieser Frage beschäftigt sich Vectra AI in dem online Interview rund um das Thema der kriminellen Cyberangriffe. Das Gespräch fand zwischen Fabian Gentinetta, Country Manager für die Alpenregion (Schweiz, Liechtenstein, Österreich) von Vectra AI, und Urs Borter, IT System-Manager bei MPS Micro Precision Systems AG statt.
While this wiper malware is new, it reuses much of the playbook employed by Russian state actors and ransomware gangs - fighting back requires us to sharpen the tools we already have.
Die Aussicht auf einen anhaltenden globalen Cyberwar bedeutet, dass die Rollen von CIOs und CISOs sich weiterentwickeln und diplomatische und geostrategische Fähigkeiten einschließen werden. Aber sie sind nicht allein.
In che modo, le lezioni apprese dal 2021 ridisegneranno il panorama della sicurezza? Nel 2022 saranno quattro le aree della cybersecurity che evolveranno.
Vectra customers should be aware that current global events related to Russian recognition of separatist regions of the Ukraine carry with them the risk of increased cyber activity conducted by Russian state level actors. This includes evidence that the FSB, the main Intelligence Organization in Russia, is responsible for the DDoS against Ukrainian systems in February 2022. [1] Credible concern exists that target selection may expand past regional targets to include, for example, politically or economically useful targets in NATO countries.
I ransomware sono estremamente remunerativi per i cybercriminali e difficilmente spariranno dal panorama delle minacce informatiche nel breve periodo. Il rilevamento veloce e accurato – che al momento è possibile solo con approcci di detection and response basati sull’AI – è l’alleato migliore su cui gli stakeholder aziendali possono contare in questa battaglia.
Industrieunternehmen sind ein beliebtes Ziel für Cyberkriminelle. Erpresser gehen immer raffinierter bei Angriffen auf Netzwerke, Hacks und Sicherheitsverletzungen vor. Ransomware-Attacken haben sich 2021 rasant weiterentwickelt. Sie verursachen hohe Kosten und gefährden die Wettbewerbsfähigkeit von Unternehmen, besonders wenn diese neue digitale Technologien vorantreiben wollen.
The role of the CISO has never been clearly defined, and every CISO works differently.They are under a lot of pressure, and this leads to regular rotation of roles. The Masked CISO explains how this could be stopped if CISOs were given more autonomy and responsibility.
New Vectra CRO wants to achieve aggressive growth and continued global expansion for Vectra's leading network detection and response platform.
Las empresas han acelerado la adopción y transformación de la nube, principalmente debido a la pandemia del covid-19 que ha incrementado el teletrabajo y transformado la red. Dicha transformación ha creado nuevos retos y entornos que hay que proteger. La necesidad de desarrollar un nuevo paradigma de ciberseguridad que proteja el acceso a la red es uno de los desafíos a los que se están enfrentando las empresas.
Auch 2021 beschäftigen Cyberattacken IT-Spezialisten und Unternehmen gleichermaßen. Die ständige Bedrohung durch die Angriffe stellt die Cybersecurity-Experten vor eine ganze Reihe von Herausforderungen. Zunehmend komplexere Attacken erfordern eine immer professionellere Technologie und ausgefeilte Prozesse, um die Angriffe effektiv abzuwehren.
In this blog series, Kevin Kennedy, SVP of Products at Vectra goes beyond the buzzwords and explains what artificial intelligence and machine learning truly mean in relation to cybersecurity. He explains how organizations using AI can gain an advantage over today’s attackers that will stop them in their tracks.
In this blog series, Kevin Kennedy, SVP of Products at Vectra goes beyond the buzzwords and explains what artificial intelligence and machine learning truly mean in relation to cybersecurity. He explains how organizations using AI can gain an advantage over today’s attackers that will stop them in their tracks.
Estos últimos semanas, la vulnerabilidad Log4J está siendo de actualidad.
Existe el temor real de que muchas organizaciones sean víctimas de ciberataques en los próximos días, semanas e incluso meses. Sin embargo, existen soluciones técnicas para evitar este escenario catastrófico.
Software attacks with an extortionist background are unfortunately becoming the norm for many companies. But what if automated anti ransomware tools could unmask malware at an early stage and combat them effectively - even before they can cause harm?
Die aktuellen Entwicklungen der IT-Security hat Vectra AI immer fest im Blick. Andreas Riepen, Head of Central & Eastern Europe (CEE) bei Vectra AI, hebt fünf zentrale Trends hervor.
As we saw with the Log4J vulnerability, cybercriminals only need a single opening to infiltrate your environment. And while another vulnerability can’t be prevented, there’s still a lot that can be done to make sure you’re ready for the next one.
A threat-led approach is key to an organisation’s security strategy. CISOs should measure security based on their ability to discover if they’ve been breached, mean time to breach when testing security, or the mean time to detect unknown threats.
With ransomware attacks continuing to dominate media headlines, it’s clear that a security approach centered on prevention no longer suffices. A shift towards an ‘assume compromise’ security approach prepares your business to deal with the intensity and frequency of today’s ransomware attacks. To that end, advanced detection and response capabilities play a crucial role. In this blog, you will also learn why a large British multinational insurance company chose Vectra, Wipro’s Venture Partner, to meet its security needs.
Every year the world of cybersecurity encounters new challenges and obstacles for organisations to overcome, but 2021 managed to be an exceptionally dangerous year. So how will the lessons learnt from 2021 shape the cybersecurity landscape? Here are four areas of cybersecurity that will evolve in 2022.
When it comes to cyber security, the old adage of ‘doing the simple things well’ is more relevant today than ever before. Three simple principles have been around for decades but they hold true now more than ever because we live in an increasingly cloud-orientated environment where we need to be vigilant at all times.
Threat actors can use the Log4J vulnerability as a platform for launching attacks, but what does this mean for cloud environments? Find out exactly how attackers are exploiting this vulnerability and what this could mean for your organization.
Agile has its uses. It’s increasingly being adopted as a technology wide operating model—to drive transformation everywhere, from helpdesks to datacenters. But is it always appropriate?
Ransomware Angriffe bleiben eine ernstzunehmende Gefahr. Wie man sich mit Hilfe von KI vor Angriffen schützen kann, erläutert dieser Artikel!
A few days after the Log4Shell vulnerability was discovered, we now have more observations about how the exploit is being leveraged. Here’s what we know, today.
A new 0day was discovered in the log4j application on December 10, 2021. This vulnerability impacts a widely used logging solution spanning an incredibly large attack surface.
Asking the right questions to your vendor is critical to dissociate the trendy marketing wording from reality. Asking questions such as "What type of machine learning algorithms does your product use?" will help. Discover the top nine questions we think you should ask.
Exclusive cybersecurity research presented in a new report, details how hundreds of security leaders are addressing today’s complex cyberthreats in their organisations.
CISOs Must be Brave Enough to Throw Away Their Security Playbook or Suffer the Consequences!
Vectra has been recognized as a DeloitteTechnology Fast 500™ award winner — a ranking of the fastest-growing technology, media, telecommunications, life sciences, fintech, and energy tech companies in North America.
Introducing Sidekick MDR for VECTRA customers with 24*7 eyes-on-glass service leveraging cloud-scale analytics of the VECTRA Cognito platform to enable security teams to meaningfully detect and respond to ransomware, nation-state and insider attacks.
Learn why these two points are critical when choosing a threat detection and response vendor: 1) Darktrace is a sales & marketing engine, not a technology innovator 2) 91% of customers who consider both Darktrace and Vectra choose Vectra.
Hear what Tallink, the largest shipping company operating in the Baltic Sea, says are the most valuable capabilities in an NDR solution and what you need to know when selecting one for your environment.
“Do your part” is the theme of this year’s Cybersecurity Awareness Month. See what you can do right now so cyberattacks don’t become a problem in your Microsoft cloud environment.
Die Cyber-Sicherheitslösung Vectra Detect erkennt und blockiert Ransomware-Angriffe. Die agentenlose und KI-gestützte Cognito-Plattform bietet automatische Verhaltenserkennung und stoppt Ransomware, bevor diese Dateien verschlüsseln und Daten extrahieren kann.
Many organizations these days face incident response challenges. Get insight about the common challenges in this area, and what your organization can do to resolve them.
AI can save your SOC valuable time by automating workloads, while accurately tracking down cyberattacker activities found in ransomware and supply chain attacks.
Ransomware. It is the new digital bogeyman. In the UAE, an industry survey from June 2021showed the extent to which the country (and by implication, the wider region)has been subjected to ransomware. Some 37% of respondents said they had beenvictims in the previous two years. A staggering 84% elected to pay the ransom, only for most of them — 90% of those who paid — to suffer from second attacksthat often came from the same bad actors.
Vectra Detect cybersecurity solution is purpose-built to detect and stop ransomware attacks. The agentless and AI-driven Cognito Platform sees and stops ransomware before it can encrypt files and exfiltrate data by automatically detecting attacker behavior.
Stopping ransomware requires a new way of thinking. See why you can’t only rely on legacy tools to keep your organization safe, but rather how you can leverage AI to detect when this invasive threat enters your cloud.
Organizations continue to deploy rapidly in the cloud, while security is often an afterthought. Read about the five areas that could be exposing your AWS deployments to security threats.
Hear cloud security experts from Splunk and Vectra explain how digital transformation has drastically changed security and why organizations need to adapt.
T-Mobile investigates a hacker who claims to breach data of 100 million customers. See what possible outcomes this could result in for the telecoms company.
As organizations continue to build on AWS with no sign of slowing down, it’s important to know where the security blind spots are and how to address them.
The State of Security Report: PaaS and IaaS takes a close look at how organizations are addressing security in AWS and the challenges they face.
Microsoft partners with Vectra to deliver Zero Trust security framework to provide analytics and mitigate threats emerging from distributed and hybrid-remote workforces.
Attackers intent on stealing personally identifiable information (PII) and protected health information (PHI) can easily exploit gaps in IT security policies and procedures to disrupt critical healthcare-delivery processes.
After obsessing for years over pushing the limits with AI to detect cyberattacker behavior, Vectra is proud to hold the most patents referenced in MITRE D3FEND.
There should be fresh scrutiny of SaaS subscription relationships, and the security policies of managed service providers; you’re only as secure as your provider.
Vectra is key contributor to new CEPS Report on the Technology, Governance and Policy Challenges of AI and Cybersecurity and supports Vectra’s mission to make the world a safer and fairer place.
A new remote code execution vulnerability in Windows Print Spooler, now known as CVE-2021-1675, or PrintNightmare can be exploited by attackers to take control of affected systems. Find out how to detect and stop this exploit with Vectra.
Vectra is honored to be named Cloud Security/SaaS Disruptor Company of the Year with a Gold Globee® Award in the Annual 2021 Awards.
The rapid shift to cloud-everything left users and apps vulnerable to security threats across all environments. Andras Cser from Forrester joined Joe Malenfant and Gokul Rajagopalan from Vectra to discuss cloud trends among organizations.
As SOC 1.0 remains the norm for many organizations, this way of doing things does have its challenges. See why more organizations are updating their approach in an effort to spot attacks faster while benefiting from a cost savings.
DarkSide ransomware as a service (RaaS) group provided hackers with a convenient way to extort money from organizations after access was gained. Here are five things you need to know about this prominent cybercriminal group.
Vectra introduces Detect for AWS, solving threat detection and response for Platform as a Service (PaaS) and Infrastructure as a Service (IaaS) environments.
What makes threat detection so challenging? We answer that question and provide the expert insight around our latest Spotlight Report—Vision and Visibility: Top 10 Threat Detections for Microsoft Azure AD and Office 365.
As cloud adoption continues to accelerate, the evolution of the next generation of modern attacks will traverse through and towards an enterprise’s cloud control plane. Learn why this risk should not be underestimated.
Supply chain attacks represent an appealing opportunity for attackers. See why this type of attack is gaining in popularity and what defenders need to know to keep their organization safe.
In our latest Spotlight Report, see how the Top 10 Threat Detections seen across Microsoft Azure AD and Office 365 allow security teams to detect infrequent behavior that is abnormal or unsafe across their environments.
We’re excited to announce a new integration with Zscaler! Find out how this integration with Cognito Detect provides end-to-end access visibility and protection for remote workers and business-critical applications.
Just a week after the Colonial Pipeline was shut down due to ransomware—attackers are at it again. It’s now being reported that Ireland’s health service shut down its IT systems and a company in Germany had to fork out a $4.4 million ransom on the same day.
Cyberattacks are hitting the headlines around the world and there seems to be no end to the noise the attacks are making. We dive into what an organisation should do to stay breached.
The Vectra Cognito Azure AD Privilege Anomaly Detection is a radical step forward when detecting account takeover events targeting Azure AD to gain access to mission-critical SaaS applications. With it, teams are alerted, and attacks can be stopped before they cause harm.
Every year, this global retail giant in the beauty industry failed to pass red team exercises—until they deployed Vectra. Get the full story on how they use the Cognito platform to pass Red Team testing and ensure the overall security of its data.
Network and endpoint defense technologies will have to either rapidly update signatures or use other investigative ways to detect command and control (C2). Uncover how threat actors evade security tools to execute C2 techniques to learn about what you should look for.
We’re excited to announce extended EDR native integration support in the Cognito platform! Find out how you can benefit from these simple, seamless integrations for comprehensive coverage across the enterprise, IoT devices, hybrid cloud, and cloud environments.
For us as Vectra, equality and inclusivity are key components of our culture. This International Women's Day, we want to celebrate the women in cybersecurity and highlight the opportunities available in the industry.