Talk to us Risks to Watch

3 Incidents that Could Have Been Averted with ARCON | EPM

A holistic endpoint security management is an absolute must for data-centric security. It helps to maintain a firm grip on sensitive data. In our previous blog, we recommended some of the best practices in endpoint security. In this blog, we have highlighted what could happen if organizations show lackadaisical attitude towards endpoint security. Three infamous IT incidents have been identified where ARCON | EPM (Endpoint Privilege Management) could have prevented data misuse with the help of its robust security features.

Incident 1 – No Data Loss Prevention mechanism

In January 2021, four in-house lawyers of a renowned law firm in Pennsylvania siphoned off some of the organization’s secret files and deleted its emails illegally. The data included lots of legal records, correspondence, confidential firm records, and multiple client databases. Adding to the woes, after the malicious act, the attorneys of the firm double erased all the emails to ensure that there is no evidence of the act if there is any investigation in future. The culprits stealthily used an unauthorized USB device, and their malicious actions remained unnoticed. After this incident, the organization lost its competitive benefits in the market.

This untoward incident could have been prevented by ARCON | EPM with the help of its prevention of data exfiltration capabilities. “Data Loss Prevention (DLP)” feature of ARCON | EPM helps organizations to mitigate data security vulnerabilities by restricting any kind of removable devices including mobiles, USBs, or external hard drives from accessing any data asset from any system at any point of time. Even if someone tries to transfer data via Bluetooth, that also is prevented by EPM because mobile Bluetooth connections and Bluetooth transfers are restricted with ARCON’s DLP feature. Hence, there are no chances of data misuse.

Incident 2 – Absence of User Behaviour Analytics

At the end of 2021, around the month of November, a former employee of the South Georgia Medical Center, downloaded multiple sensitive files from the data assets of the medical center’s systems to his personal USB drive the day after quitting the organization. Along with personal data, it included patients’ test results, names, birth records etc. This is an ideal example of a compromised insider with malicious intent. There was no mechanism to monitor and analyze the behaviour and activities of users who frequently access critical data repositories for various purposes. As a result, the medical center had to provide services including free credit monitoring and identity restoration to all the patients who suffered this unprecedented data breach.

Had ARCON | EPM solution been deployed by the organization, the malicious insider would have been caught before any data theft incident. The “User Behaviour Analytics” feature of EPM solution detects anomalous behaviour profiles in the network on real-time and immediately generates risk-based scores for each user with the help of Machine Learning (ML) algorithms. Based on these scores, the Risk Manager analyzes and takes crucial decisions about whom to continue with the access permissions and whom to deny.

Incident 3 – Absence of File Integrity Monitoring

In the months of March and April 2021, the department of police in one of the cities from the state of Texas suffered massive data loss as one of its employees deleted 8.7 million critical files (approx. 23TB of data) by mistake. These files included crucial evidence of many criminal cases in video, photos, audio, case notes, and other items the police department collected. It resulted in slowing down the process of prosecutions impacting around 17,500 cases with the County District Attorney’s Office.

This is an ideal instance where a government department faced an IT disaster though there were no malicious or fraudulent activities. The employee was unable to manage and verify the existence of the files before deleting them and there were no backups. There was no mechanism to ensure the security, integrity, and confidentiality of data assets of the said Police Department. 

ARCON | EPM solution could have averted the disaster with the help of “File Integrity Monitoring (FIM)” feature. FIM keeps on checking and identifying any modifications or changes made to any file or directory. It continuously monitors critical system files, and configuration files/ folders to detect unauthorized changes done by end users, intentionally, accidentally or for some other purpose. Once ARCON’s FIM detects any sudden unauthorized changes, it sends instant alerts to the IT administrator who investigates and takes prompt action. FIM enables IT security teams in maintaining an organization’s compliance policy.

Conclusion

ARCON | Endpoint Privilege Management (EPM) solution addresses the endpoint security challenges with the help of a robust security layer around endpoints. It detects risky behaviour profiles, prevents data exfiltration, and identifies any sudden unauthorized changes made to any files/ folders.

10 Recommendations for Robust Endpoint Security

Endpoint Security: Overview 

Vulnerable endpoints can lead to serious IT incidents. Protecting endpoints with adequate security controls is of paramount importance to avert breaches and insider attacks. 

While organizations have several security measures in place to secure their servers and data centers, the endpoints unfortunately do not receive as much attention as they should be. Endpoints carry a significant security risk because they provide access to business applications many times critical in nature while sometimes endpoint privileges are also granted to conduct IT tasks on different Oses (privilege elevation and delegation management). A compromised insider or some sort of social engineering by malicious elements can exploit endpoints to gain critical information.

A recent study by the Ponemon Institute found that:

  • Almost 81% of organizations revealed that endpoint security is the ‘most sought after’ security in complex IT infrastructure today. The proliferation of hybrid work practices has made data access methodologies more open and riskier in all areas in the IT ecosystem.
  • To manage risk, 69% of respondents say their organizations either currently outsource endpoint protection to an MSP or any other third party.
  • Only 47% of organizations monitor their networks 24/7, and only 50% encrypt sensitive data that are stored on endpoints/ devices

ARCON’s 10 Recommendations for Protecting Endpoints 

Based on day-to-day practical enterprise use cases, ARCON lists 10 recommendations for robust endpoint security. 

  1. Mapping end users: What can be done if there is deployment requirement of Endpoint Security for a large number of endpoints? Just think of a situation when the organization is ready to secure their ever-increasing number of endpoints but worried about the time taken in the deployment process.  There is no idea about how to segregate end users based on their responsibilities.  ARCON | Endpoint Privilege Management (EPM) helps organizations to run the activities normally for the first thirty days without hampering the regular work process. No restriction is applied during this time. With the help of “Automated Profiling” feature ARCON | EPM gathers the data, identifies the profile, and determines the necessary access areas. After thirty days, based on the users’ usage patterns, ARCON | EPM segregates them into user groups based on the process they have used. This removes the tediousness of manual integration and profile creation and ensures seamless IT operations. 
  1. Implementing unified engine to control end users: Once profiling is done, is it possible to manage and control those profiles seamlessly? There are multiple levels of users in multiple functional departments. ARCON | EPM offers “Centralized Profiling” mechanism that helps to manage existing profiles and new profiles for various departments in an IT ecosystem. Centralized profiling enables granular level segregation of profiles in every department, and ARCON | EPM helps the IT admin to set a default profile as well for a user, group of users, endpoints and a group of endpoints based on OS type. This helps admins to keep a systematic track of user profiles.
  1. Contextualization of data: Every day a large volume of data is generated. Therefore, it is important to understand “where” “what” and “who” of data. How about securing and categorizing different endpoint data? It is extremely essential to classify and categorize data while allowing access to any specific set of users. ARCON | EPM offers “Data Intellect” feature that enables the classification and categorization of the critical data in the enterprise network. It not just helps to itemize data as per users but also prevents any malicious activity with the data assets. Data Intellect identifies risky or suspicious data files present on endpoints that should be prevented from access (or transfer anywhere) to maintain the integrity of the data assets.
  1. Enforcing credentials vaulting: Weak password management is the leading cause of breaches and insider attacks. ARCON | EPM offers “Credential Rotation” feature that helps administrators to vault and rotate credentials for endpoints regularly. The admin can even create a stringent policy by providing length, use of characters, non-repetitive passwords etc. based on which the rotation is done. Undoubtedly, this prevents chances of password misuse and keeps the organization secure from unauthorized access on the endpoints.
  1. Ensuring access based on “need-to-know” and “need-to-do” basis: What could happen if any user requests access to any application to perform any task and the request is granted? The scheduled task might be completed, but at the same time there could be risks of unauthorized activities. ARCON | EPM provides “just-in-time” privilege elevation through which any user can get one-time access to any application based on roles and user profiles. Not just that, the duration of the task can be prescheduled and privileged access rights are revoked immediately after the task is accomplished. This feature ensures implementation of the Least Privileges principle and follows Zero Trust architecture. 
  1. Complying with baseline policies: What are the security risks if there is any unapproved modification to any data file? It can simply impact the security, integrity and confidentiality of data assets in the organization. ARCON | EPM offers “File Integrity Monitoring (FIM)” that keeps on checking and identifying any modifications or changes made to any file or directory. It continuously monitors critical system files, and configuration files/ folders to detect unauthorized changes done by end users, intentionally, accidentally or for some other purpose.  Once ARCON’s FIM discovers such changes, alerts are delivered to the IT administrator who investigates and takes prompt action. FIM enables IT security teams in maintaining an organization’s compliance policy. 
  1. Eliminating data exfiltration: How does it impact data security if any user connects mobile devices or any removable storage with desktop/ laptop within enterprise IT periphery? It can compromise endpoint security with critical data loss – that too without the knowledge of the IT security team. ARCON | EPM’s “Data Loss Prevention (DLP)” feature helps organizations to mitigate data security vulnerabilities by restricting mobile devices or any removable devices from accessing any data asset from any system at any point of time. Even mobile Bluetooth connections and Bluetooth transfers are restricted with ARCON’s DLP feature. Hence, there are no chances of data being compromised. 
  1. Implementing strong authentication: What if an IT administrator wants some additional authentication for any specific endpoint? To ensure verification and re-verification of any user, ARCON | EPM offers “Two-factor Authentication” feature that works as an additional security step to authorize and authenticate user activities especially Windows login, any critical application access or any sensitive URL access. If the administrator wishes to have an additional security layer during endpoint access, this feature works as an additional validation step as and when required.
  1. Identifying anomalous profiles: The risk assessment teams of modern organizations prefer predictive security mechanisms to preventive security measures. The simple reason behind is “Better safe than Sorry”! What could happen if users’ behaviour is not monitored after they are given privileged rights? If any anomalous is done by the users, it could go unnoticed and that itself is a risk. Accordingly, ARCON | EPM provides “User Behaviour Analytics” feature that detects anomalous behaviour profiles on real-time and generates risk-based scores for each user with the help of advanced Machine Learning (ML) and Artificial Intelligence (AI) algorithms. These scores help the Risk Manager to take crucial decisions regarding permissions/ denials.
  1. Isolating malicious applications: What could happen if there is any malicious application running in the IT environment? It could simply lead to data loss, financial loss, service disruption, IT downtime, decreased productivity and what not! ARCON | EPM offers “Application Security” feature that secures the endpoints by detecting the malicious applications and blacklisting those applications and URLs before notifying it to the administrator. At the same time, application security helps in situations when any blacklisted application needs to be whitelisted temporarily and blacklist it again within a certain time. 

Conclusion

ARCON | Endpoint Privilege Management (EPM) builds comprehensive security layer around endpoints. It enables compliance with organizations’ security policies and enforces controlled access to business-critical applications.

3 Distinct Use Case Challenges Addressed by ARCON Cloud Access Governance

Overview

Rapid adoption of dynamic multi-cloud environments is making cloud infrastructure and entitlement management extremely complex. With every new addition of cloud technologies and services, organizations are witnessing a growing number of users, their privileges and corresponding services. This continuous process is resulting in the emergence of new and unique use case challenges. If these use case challenges are not solved with adequate access control policies, organizations can face devastating consequences. 

ARCON, being a strong advocate of cloud-first journey, has always been at the forefront of offering best-in-class Cloud Access Governance solutions that include comprehensive CIEM capabilities as well as classic PAM capabilities. In this blog, we will discuss three distinct use cases solved by ARCON Cloud Access Governance. 

Use Case 1: Modify Access Policies (Provision or Deprovision of Policies)

In a typical cloud environment, there are hundreds of identities that continuously interact with applications and cloud systems to perform different tasks. There are identity access policies assigned to these identities that ensure role-based and need-based access to systems and applications to perform various tasks. There could be situations where few of these assigned policies remain unused over time. Unutilized permissions, if misused, could potentially affect the application assets/ data assets/ systems. 

Alternatively, there could be requirements to add any new access policy against any identity either permanently or temporarily. When the user requests new access permissions to perform and specific task and there is an unexpected delay from the admin, there could be a hindrance in the regular workflow. If there is no mechanism to modify the identity access policies required in multi-cloud environment to ensure scalability, flexibility, and security, it could affect IT efficiency and productivity. 

ARCON Cloud Governance is useful to organizations as it removes the need for planned provisioning or deprovisioning of identities. It offers the flexibility to add/ remove access permissions based on requirements as per requirements, even ad hoc requirements. As a result, there –

  • Won’t be any risk of access permission misuse
  • Won’t be any risk of ‘default’ access permissions
  • Will have the benefit of on-demand provision/ deprovision of policies
  • Will have the flexibility of policy deployment
  • Will be uninterrupted workflow even in multi-cloud environments

Use Case 2: Risk Score based on the Level of Risks

It could be a huge risk if an organization has an access policy for a user and there is no risk assessment of the utilization of the permission given to that user. The organization could face long term consequences sans risk analysis mechanisms because if the access right is misused, the IT security team will remain unaware of it.

ARCON Cloud Governance solution evaluates the utilization of permissions granted to the users for different systems and applications seamlessly. The access information details are analyzed thoroughly by the solution and does the categorization whether the action is used or unused. It can even detect shadow-admin rights where the users may not have highly privileged access rights but have delegated privileges by being a part of a group of users. ARCON Cloud Governance peruses the access permission patterns, password reset requests or new policy enforcements of each user in the cloud platform and identities whether it is an absolute requirement or not. 

This way the solution can –

  • Help IT administrators to take major IT decisions on whom to continue allowing with crucial access and whom to revoke of access rights
  • Ensure every suspicious user is revoked of privileges on time before any potential damage
  • Any act of authorization and authentication (valid access, genuine password resets, new policy enforcements etc.) in cloud is restored throughout

Use Case 3: Data Visualization and Recommendations

With the help of data visualization, organizations can ensure comprehensive visibility of the available data in the organization in the form of common graphics, charts, infographics, etc. The visuals give data-driven insights that are easy to comprehend.

Now, in a multi-cloud environment, if there is no data visualization mechanism, then the organization will not be able to analyze the “which”, “where” and “what” of any data. Indirectly, the administrators could face challenges to check the usage of policies and service principles attached to the displayed data. This could be dangerous from the admin perspective. Be it an individual user, or any role-wise user group, or even a service account holder – the organization could face unprecedented threats without any visibility of the data of their activities, workflow, distribution pattern of policies and the associated services.

ARCON Cloud Governance helps organizations with a comprehensive visibility of the data that includes detailed analysis of the permissions associated with the designated user/ user group/ service principles/ service accounts. The dashboard shows a detailed graphical representation of the distribution of policies and the valid services associated with those incorporated policies. With this solution, it eliminates access threat possibilities by identifying the anomalies in real-time and thus security is restored even in multi-cloud platform. Here, the administrator can –

  • Keep a track of the access policies allowed to any user/ user groups/ roles of the users and service principles/ service accounts
  • View and verify the distribution of services and utilization of data against every action on the cloud platform, even in multiple layers
  • Inspect, analyze and implement which policy must be continued and which one to be revoked on time

Conclusion

ARCON continuously innovates and carries out R&D to identify emerging use case challenges and design solutions. The solution, Cloud Access Governance secures organizations’ cloud-first journey through its robust access control and risk management features.