Tag Archives: cloud security

Five Things We Learned at VMWorld Europe

by Matt Poulton

It’s been a fantastic few days in sunny Barcelona where the Trend Micro team made the most of VMWorld Europe. It always offers a great opportunity to talk to customers, partners and prospects and this year was no different. On the event’s last day today, we reflect on some insight into what’s working, and where organisations feel there are still challenges to address.

A big thanks goes to all those hardy souls who manned the Trend Micro stand from morning till early evening, delivering over 130 demoes in eight languages on just the first day, as well as our spokespeople who spent countless hours talking to the press and presenting the Trend Micro vision to keynote attendees. Continue reading

VMworld Europe: Time to Simplify Cloud Complexity Through Unified Security

by Simon Young

Cloud is at the heart of any organisation’s digital transformation efforts today, with new DevOps practices driving innovation. But although these efforts promise faster time-to-market and greater agility, the truth is that with greater adoption comes potentially greater complexity and the danger of cloud siloes. According to the latest IDC stats out this week, 90% of organisations will look to migrate to hybrid and multi-cloud environments over the next six years. In this fracturing world, it’s important to ensure you have unified security which works across all major platforms.

That’s part of the message Trend Micro will be bringing to VMworld Europe next week. Continue reading

Securing Cloud Workloads: Making DevSecOps a Reality at VMworld Europe

by Bharat Mistry

You might have noticed new official ONS figures claiming a 30% drop in cybercrime in the UK over the past year. But don’t be misled by the headline stats: the truth is that threats, especially against organisations, are on the rise. Trend Micro blocked over 20.4 billion of them in the first half of the year alone. The risks are especially pronounced during the app development lifecycle when the focus can sometimes fall too heavily on time-to-market, at the expense of security. That’s why cloud workload security is one of the top two IT budget priorities for 2019, according to a new study.

As organisations increasingly look to DevOps to drive innovation and growth, the need to seamlessly integrate security controls pre-deployment and at runtime becomes more urgent. Join us at VMworld Europe next month to find out how Trend Micro is helping global organisations manage these challenges. Continue reading

Mitigating the Threat of the World’s Top Hacking Tools

By Bharat Mistry

When it comes to cybersecurity, information is power. So we were pleased recently to see GCHQ’s  National Cyber Security Centre (NCSC) release a new document highlighting the five most common publicly available hacking tools. Although far from exhaustive, it will provide some much-needed guidance for security teams on what to look out for and how to maximise detection and protection.

Those operating VMware environments and looking to follow this best practice advice would do well to consider our flagship Deep Security offering. As we’ll be discussing at VMworld Europe next month, the combination of tight integration and full-featured security is a winner for protecting software-defined datacentres and hybrid cloud environments.

The top hacking tools
Perhaps the most telling thing about the NCSC report is that it had to be produced at all. It’s very much a sign of the times: a reminder of how the cybercrime underground has democratised hacking tools for widespread use. According to the report, produced in concert with cybersecurity specialists from all Five Eyes nations, initial compromise is usually achieved via exploitation of software vulnerabilities or poorly configured systems. After that, hackers may use:

Remote Access Trojans (RATs): like JBiFrost which could be used to install backdoors and key loggers, take screen shots, and exfiltrate data.

Web shells: like China Copper — malicious scripts which offer remote administrative capabilities.

Credential stealers: like Mimikatz which steal user log-ins so an actor can move internally through a target network.

Lateral movement frameworks: like PowerShell Empire which allow attackers to move around once inside a network.

C2 obfuscation tools: like HTran which help to disguise the bad guys’ location when compromising a victim.

There’s a long list of recommendations from NCSC for firms looking to better detect and protect themselves from such threats. But among the key pieces of advice are:

Keep systems patched and up-to-date
Use “modern systems and software”
Employ network monitoring and firewalls
Implement network segmentation
Deploy host-based intrusion detection
Whitelist applications
Use AV from a reputable provider

Partnering on security

These recommendations play very much to Trend Micro’s strengths as a security pioneer and a decade-long partner of VMware’s with our flagship datacentre product Deep Security. We offer:

Anti-malware, firewall, log inspection, web reputation, integrity monitoring, and IDS/IPS and Application Control
Comprehensive security controls automatically deployed as each new VM is spun up
Virtual patching to keep apps/servers shielded from emerging threats until a patch becomes available
Support for NSX for hypervisor-based security, enabling micro-segmentation

All of this comes with an architecture designed to optimise performance in virtual environments, and offer enhanced visibility across physical, virtual and hybrid cloud IT from a single console. Trend Micro on VMware realises the NCSC’s vision of “modern” systems and software designed with security in mind.

We’ll be taking this message to VMworld next month, with two speaking slots slated:

Enabling Hybrid Cloud Security for NSX and VMWare Cloud on AWS [SAI1032BES]
Bryan Webster, Principal Architect, Trend Micro
Jeremiah Cornelius, Security Envisioning Architect – Partner Products – VMware Global Technology Alliance, VMware
Wednesday, Nov 07, 3:30 p.m. – 4:30 p.m.

Mind the Gap: Building a closer relationship between Security and DevOps [DEV1031BES]
Bryan Webster, Principal Architect, Trend Micro
Doug Cahill, Group Director and Senior Analyst , Enterprise Strategy Group
Wednesday, Nov 07, 12:30 p.m. – 1:30 p.m.

We look forward to seeing you at the show.

What: VMworld Europe
Where: Barcelona
When: 5-8 November