spotlight with Rich (Latayan360@Outlook.com) - espresso to Security Business Leadership - splash of key note speaker @CISOmd
Friday, September 8, 2017
Equifax laswsuit filed (here we go)
Bloomberg.com Article source
A proposed class-action lawsuit was filed against Equifax Inc. late Thursday evening, shortly after the company reported that an unprecedented hack had compromised the private information of about 143 million people.
In the complaint filed in Portland, Ore., federal court, users alleged Equifax was negligent in failing to protect consumer data, choosing to save money instead of spending on technical safeguards that could have stopped the attack. Data revealed included Social Security numbers, addresses, driver’s license data, and birth dates. Some credit card information was also put at risk.
Equifax first discovered the vulnerability in late July, though it chose not to announce it publicly until more than a month later. The company was widely criticized for its customer service approach in the aftermath of the hack, as users struggled to understand whether their information had been affected. Others expressed frustration that three senior executives sold about $1.7 million in stock in the days following the discovery of the hack. A spokeswoman for Equifax said the men “had no knowledge that an intrusion had occurred at the time.”
The plaintiffs in the lawsuit are Mary McHill and Brook Reinhard. Both reside in Oregon and had their personal information stored by Equifax.
“In an attempt to increase profits, Equifax negligently failed to maintain adequate technological safeguards to protect Ms. McHill and Mr. Reinhard’s information from unauthorized access by hackers,” the complaint stated. “Equifax knew and should have known that failure to maintain adequate technological safeguards would eventually result in a massive data breach. Equifax could have and should have substantially increased the amount of money it spent to protect against cyber-attacks but chose not to.”
The case was filed by the firm Olsen Daines PC along with Geragos & Geragos, a celebrity law firm known for blockbuster class actions. Ben Meiselas, an attorney for Geragos, said the class will seek as much as $70 billion in damages nationally.
Equifax didn’t respond to request for comment on the matter.
Thursday, September 7, 2017
Equifax data breach affecting 143 Millions US consumers
Summary of breach from article:
- Equifax said data on 143 million U.S. customers was obtained in a breach [SSN, DoB, DL, Card Numbers)
- The breach was discovered July 29.
- Personal data including birth dates, credit card numbers and more were obtained in the breach.
- Three Equifax executives sold shares in the company days after the breach was discovered [over 2+M]
- And Stocks dropped 13% to $124
https://www.google.com/amp/s/
Monday, August 28, 2017
IT Finance
And, most of IT Spending will go to hardware/software over cloud technology:
· Predicted rise in 2018 spending
· Global small/medium business software spending will exceed that of hardware by 2018
· Hardware spend priority is with laptops/desktops (39%+32%), followed by Networking/Wi-Fi (30%) and then Security 23% (main driver being ransomware)
2017 U.S. State and Federal Government Cybersecurity Report - key findings:
Government rate among lowest for security scores,
Struggles include enpoint security: Endpoint Security, IP Reputation and Patching Cadence
US Secret Service appeared at top 10 best overall scores in the government
Report attached http://info.securityscorecard.com/2017-us-government-cybersecurity-report?hsCtaTracking=d3b85e60-b865-4ea3-8461-3be21d392a52%7Ceef498fc-6efd-42e9-a1ca-5daf70e535ecStruggles include enpoint security: Endpoint Security, IP Reputation and Patching Cadence
US Secret Service appeared at top 10 best overall scores in the government
Monday, July 24, 2017
Data Breach continue to rise
Article source: Poneman Institute's 2017 Cost of Data Breach Study
Global study at a glanc:
Other considerations: These number likely reflect breaches that were required to be reported, while identifying the breach is critical its remedy can be complex and long-term, the financial effects can also last including Target's settlement years after breach and latest FedEx affect after Petya randomware
Global study at a glanc:
- 419 companies in 13 country or regional samples
- $3.62 million is the average total cost of data breach
- 10% one-year decrease in average total cost
- $141 is the average cost per lost or stolen records
- 11.4% one-year decrease in the per capita cost
- 27.7% is the likelihood of a recurring material data breach over the next two years
- 2.1% increase in the likelihood of a recurring material data breach
- US with highest frequency of breach followed by UK then India and so on;
- while largest breaches were India, Middle East and US and conversely smallest being Australia, South Africa and Italy;
- per capita cost by industry results in Health at 380 in 2017 and 40year average of 369, followed by Financial at 245 and 222 then Services at 223 and 178;
- root cause of breach were malicious / criminal attack to system glitch and then human error for top 3;
- Decrease in cost of breach directly related to (in order) Incident Response Team, Extensive use of Encryption, Employee training, BCM involvement, Participating in Threat Sharing...and conversely the ones the Increase cost first, Third-party involvement, Extensive Cloud Migration, Compliance Failures
Other considerations: These number likely reflect breaches that were required to be reported, while identifying the breach is critical its remedy can be complex and long-term, the financial effects can also last including Target's settlement years after breach and latest FedEx affect after Petya randomware
Friday, May 12, 2017
Massive Ransomware hits worldwide proportions
CNN reporting over 99 countries hit thus far (81,000 in 12 hours according to Malwarebytes) with "WannaCry" ransomware leveraging Microsoft vulnerability and leaked prior in NSA spy tools...from Spain to Russia, UK, US
Reports:
https://isc.sans.edu/forums/diary/Massive+wave+of+ransomware+ongoing/22412/
http://money.cnn.com/2017/05/12/technology/ransomware-attack-nsa-microsoft/
https://krebsonsecurity.com/2017/05/u-k-hospitals-hit-in-widespread-ransomware-attack/
http://www.bbc.com/news/technology-39901382
Update:
https://www.symantec.com/connect/blogs/what-you-need-know-about-wannacry-ransomware
Some things to do:
• Patch UPDATE for Microsoft MS17-010
• Patch: CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148
• Apply hash filters
• Apply GPO for file extension WNCRY
• Apply email filter for “Please_Read_Me.txt” and extension “.wncry”
• Isolate communication to ports 137 / 138 UDP and ports 139 / 445 TCP in the networks of the organizations [might be challenging]
• Deploy specific TOR rules
• Filters on ET Trojan Possible WannaCry DNS Lookup
• Email quarantine password protected attachments
• Disabled/blocked inbound email for .zip/.js or inbound raw executables in email
• Identified and block variants: Wannacryptor, WannaCry 2.0, WCry2, or similar names
• Contact ISP and/or MSSP for additional blockage / alerting
What to have:
• Mentions of Cylance and Crowdstrike as well as Symantec cloud.email and Fortinet addressed/safeguarded environments from threats
Reports:
https://isc.sans.edu/forums/diary/Massive+wave+of+ransomware+ongoing/22412/
http://money.cnn.com/2017/05/12/technology/ransomware-attack-nsa-microsoft/
https://krebsonsecurity.com/2017/05/u-k-hospitals-hit-in-widespread-ransomware-attack/
http://www.bbc.com/news/technology-39901382
Update:
https://www.symantec.com/connect/blogs/what-you-need-know-about-wannacry-ransomware
Some things to do:
• Patch UPDATE for Microsoft MS17-010
• Patch: CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, CVE-2017-0147, CVE-2017-0148
• Apply hash filters
• Apply GPO for file extension WNCRY
• Apply email filter for “Please_Read_Me.txt” and extension “.wncry”
• Isolate communication to ports 137 / 138 UDP and ports 139 / 445 TCP in the networks of the organizations [might be challenging]
• Deploy specific TOR rules
• Filters on ET Trojan Possible WannaCry DNS Lookup
• Email quarantine password protected attachments
• Disabled/blocked inbound email for .zip/.js or inbound raw executables in email
• Identified and block variants: Wannacryptor, WannaCry 2.0, WCry2, or similar names
• Contact ISP and/or MSSP for additional blockage / alerting
What to have:
• Mentions of Cylance and Crowdstrike as well as Symantec cloud.email and Fortinet addressed/safeguarded environments from threats
Tuesday, April 4, 2017
DOJ Releases Important New Compliance Program Guidance
A copy-paste of the letter below:
AHLPA Weekly, By Michael W. Peregrine, McDermott Will & Emery
Health lawyers will want to brief their clients' audit & compliance committees on the substance and
implications of new compliance program guidance issued by the Fraud Section of the Department of
Justice (DOJ). The "Evaluation of Corporate Compliance Programs" (Guidance) is not specific to the
health care industry. Yet, the Guidance provides an exceptionally practical set of benchmarks
against which the audit & compliance committee, in consultation with the general counsel and the
chief compliance officer, can evaluate the effectiveness of the health system's compliance program.
The Guidance was quietly released, without any press announcement, by a February 8 posting on
the Fraud Section's "Compliance Initiative" page on the DOJ website. The absence of any formal
announcement is unusual given the extent to which the DOJ in general, and the Fraud Section in
particular, have tried to be publicly transparent in their discussion of the application of factors that
contribute to a decision whether to charge a corporation. One can only speculate as to the reasons
for this, but in no way should the "stealth release" undermine its materiality.
The Guidance is presented in the form of a series of substantive compliance-focused questions that the Fraud Division frequently considers when evaluating a corporate compliance program, e.g.:
1. Analysis and Remediation of Underlying Misconduct
2. [Role and Involvement of] Senior and Middle Management
3. Autonomy and Resources
4. Policies and Procedures
5. Risk Assessment
6. Training and Communication
7. Confidential Reporting and Investigation
8. Incentives and Disciplinary Measures
9. Continuous Improvement, Periodic Testing and Review
10. Third Party Management
11. Mergers and Acquisitions
These questions are drawn from multiple sources, some of which are somewhat familiar to health
lawyers (e.g., the Federal Sentencing Guidelines and the United States Attorneys Manual), and
some of which are less familiar (the joint DOJ/SEC Foreign Corrupt Practices Act guide and
compliance guidance from the Organization for Economic Cooperation and Development).
Questions particularly relevant to health care organizations include those that focus on the conduct
of senior and middle management; the internal stature of the compliance function; the autonomy of
the compliance function; program funding and resources; corporate response to expressed
compliance concerns; the process for responding to investigative findings; consistency of disciplinary
measures; and periodic updating of procedures and practices.
Important questions focus on the board's exercise of its compliance oversight duties—including
whether relevant expertise is available on the board and how compliance related is information
provided to the board.
The Guidance does not specifically address the appropriateness of a compliance officer-to-general counsel reporting relationship. (This, contrary to the interpretation of some compliance industry leaders). Nor does it comment on whether the roles of compliance officer and general counsel can be held by the same person.
Rather, it emphasizes the presence of a "direct to board" reporting option (as mandated by the
Federal Sentencing Guidelines) and other futility bypass mechanisms indicative of compliance
officer independence. This may serve to continue the debate on the most appropriate staffing,
reporting, and communication relationships between the general counsel and the compliance officer.
One theme that appears to run through the questions is a focus on how the corporation deals with
misconduct after it has been identified. This focus goes beyond the traditional emphasis on proper
incentives and appropriate discipline to an awareness of the root cause of the misconduct and
changes the company made to reduce the potential that similar problems will reappear.
The release of the Guidance is consistent with the Fraud Section's 2015 appointment of an internal
"compliance counsel." The specific role of that position is to help determine whether a corporation subject to DOJ investigation has maintained a good faith compliance program. DOJ's Principles of Federal Prosecution of Business Organizations (a/k/a the "Filip Factors") make it clear that the existence and effectiveness of a corporation's preexisting compliance program is a factor that the DOJ will take into consideration when making a prosecution decision. The new Guidance is reflective of the Fraud Section's interest in applying a deeper analysis of compliance program quality and effectiveness.
The Fraud Section's "common questions" are highly practical in nature and are well-suited for direct
audit & compliance committee consumption. There's no "inside baseball" involved. As such, the
Guidance needs little advance introduction before it is placed on the committee's agenda. And, once
on the agenda, the committee's logical role is to use the Guidance as a baseline from which to
comprehensively evaluate the effectiveness of the health system's existing program.
The release of this Guidance is a significant development in terms of assuring the most effective
possible corporate compliance plan. It is directly relevant to the fiduciary obligations of the board's
audit & compliance committee and should be brought to the committee's immediate attention by the
health system general counsel, in consultation with the compliance officer.
Source:
https://www.mwe.com/~/media/files/press-room/2017/02/weekly022417.pdf
AHLPA Weekly, By Michael W. Peregrine, McDermott Will & Emery
Health lawyers will want to brief their clients' audit & compliance committees on the substance and
implications of new compliance program guidance issued by the Fraud Section of the Department of
Justice (DOJ). The "Evaluation of Corporate Compliance Programs" (Guidance) is not specific to the
health care industry. Yet, the Guidance provides an exceptionally practical set of benchmarks
against which the audit & compliance committee, in consultation with the general counsel and the
chief compliance officer, can evaluate the effectiveness of the health system's compliance program.
The Guidance was quietly released, without any press announcement, by a February 8 posting on
the Fraud Section's "Compliance Initiative" page on the DOJ website. The absence of any formal
announcement is unusual given the extent to which the DOJ in general, and the Fraud Section in
particular, have tried to be publicly transparent in their discussion of the application of factors that
contribute to a decision whether to charge a corporation. One can only speculate as to the reasons
for this, but in no way should the "stealth release" undermine its materiality.
The Guidance is presented in the form of a series of substantive compliance-focused questions that the Fraud Division frequently considers when evaluating a corporate compliance program, e.g.:
1. Analysis and Remediation of Underlying Misconduct
2. [Role and Involvement of] Senior and Middle Management
3. Autonomy and Resources
4. Policies and Procedures
5. Risk Assessment
6. Training and Communication
7. Confidential Reporting and Investigation
8. Incentives and Disciplinary Measures
9. Continuous Improvement, Periodic Testing and Review
10. Third Party Management
11. Mergers and Acquisitions
These questions are drawn from multiple sources, some of which are somewhat familiar to health
lawyers (e.g., the Federal Sentencing Guidelines and the United States Attorneys Manual), and
some of which are less familiar (the joint DOJ/SEC Foreign Corrupt Practices Act guide and
compliance guidance from the Organization for Economic Cooperation and Development).
Questions particularly relevant to health care organizations include those that focus on the conduct
of senior and middle management; the internal stature of the compliance function; the autonomy of
the compliance function; program funding and resources; corporate response to expressed
compliance concerns; the process for responding to investigative findings; consistency of disciplinary
measures; and periodic updating of procedures and practices.
Important questions focus on the board's exercise of its compliance oversight duties—including
whether relevant expertise is available on the board and how compliance related is information
provided to the board.
The Guidance does not specifically address the appropriateness of a compliance officer-to-general counsel reporting relationship. (This, contrary to the interpretation of some compliance industry leaders). Nor does it comment on whether the roles of compliance officer and general counsel can be held by the same person.
Rather, it emphasizes the presence of a "direct to board" reporting option (as mandated by the
Federal Sentencing Guidelines) and other futility bypass mechanisms indicative of compliance
officer independence. This may serve to continue the debate on the most appropriate staffing,
reporting, and communication relationships between the general counsel and the compliance officer.
One theme that appears to run through the questions is a focus on how the corporation deals with
misconduct after it has been identified. This focus goes beyond the traditional emphasis on proper
incentives and appropriate discipline to an awareness of the root cause of the misconduct and
changes the company made to reduce the potential that similar problems will reappear.
The release of the Guidance is consistent with the Fraud Section's 2015 appointment of an internal
"compliance counsel." The specific role of that position is to help determine whether a corporation subject to DOJ investigation has maintained a good faith compliance program. DOJ's Principles of Federal Prosecution of Business Organizations (a/k/a the "Filip Factors") make it clear that the existence and effectiveness of a corporation's preexisting compliance program is a factor that the DOJ will take into consideration when making a prosecution decision. The new Guidance is reflective of the Fraud Section's interest in applying a deeper analysis of compliance program quality and effectiveness.
The Fraud Section's "common questions" are highly practical in nature and are well-suited for direct
audit & compliance committee consumption. There's no "inside baseball" involved. As such, the
Guidance needs little advance introduction before it is placed on the committee's agenda. And, once
on the agenda, the committee's logical role is to use the Guidance as a baseline from which to
comprehensively evaluate the effectiveness of the health system's existing program.
The release of this Guidance is a significant development in terms of assuring the most effective
possible corporate compliance plan. It is directly relevant to the fiduciary obligations of the board's
audit & compliance committee and should be brought to the committee's immediate attention by the
health system general counsel, in consultation with the compliance officer.
Source:
https://www.mwe.com/~/media/files/press-room/2017/02/weekly022417.pdf
Wednesday, March 29, 2017
SANS Announces 2016 Best of Award Winners
Winners and honorable mentions of the SANS Best of 2016 award (and previous 2 year comparison) below - for various cybersecurity areas:
Vulnerability Assessment
Winner again: Tenable Nessus (2 years in a row)
Honorable Mention: Rapid7, Qualys
Next Generation Firewall
Winner: Palo Alto Networks PA Series (2015 was Fortinet)
Honorable mention: Check Point Software, Fortinet
Advanced Threat Detection
Winner again: FireEye Network NX (3 years in a row)
Honorable mention: Snort, Cisco
End Point Protection
Winner: Cylance PROTECT (2015 was Symantec Endpoint Protection)
Honorable mention: Symantec, Trend Micro
Application Security
Winner again: Qualys Web Application Scanning (WAS) (3 years in a row)
Honorable mention: Rapid 7, Checkmarx (tie), Veracode (tie)
SIEM
Winner: LogRhythm Security Intelligence Platform (2015 was IBM Security QRadar)
Honorable mention: Splunk, IBM
Threat Intelligence
Winner: CrowdStrike Falcon Intelligence (2015 was FireEye Threat Intelligence)
Honorable mention: FireEye Threat Intelligence, Cisco AMP Threat Grid
Endpoint Detection/Response
Winner: Carbon Black Platform
Honorable mention: Palo Alto Networks Traps, CounterTack Sentinel
Wednesday, March 15, 2017
Quick and short about Botnets
When Zombies invade...
EFFECTS / Results can be devastating including:
PREVENTION can be knowing your environment, network and application baselining for traffic and network behavior analysis; usual software/patching updates being current; cyber awareness and training;
IDENTIFICATION typically includes
ERADICATION via botnet removal software including freeware BotHunter, Kaspersky, BotRevolt and others including rootkit detection/clean up packages. IP address block, reputation blocking and HoneyPots can be a source for helping in the scenario. That said, a plethora of vendor packages some under the term of Next-Gen Endpoint Protection address the detection / isolation / eradication of botnets...
Known Botnet list: Agobot, SDbot, mIRC-based; DSNX, q8, kaiten, Perl-based; Grum, Zeus, Conficker, Torpig, Sality, Cutwail, Tinba, Uptre, Ramnit, Windigo, Beehonem, Cutwail, Glupteba, ZeroAccess,
Also, useful sites for reference resource SANS
EFFECTS / Results can be devastating including:
- DDoS – bombardment of requests/packets/traffic rendering systems/network inoperable
- email spam that can be annoying but quickly lead to malicious / exploitation software and remote control of systems
- keylogger (identity theft)
- spyware and the likes that can lead to data exfiltration
- adware that can alter webpages or click fraud for traffic redirect
- DNS for misguided requests leading back to phishing and malware
- IRC chat networks, and of course worms that pilferate the networks/systems
PREVENTION can be knowing your environment, network and application baselining for traffic and network behavior analysis; usual software/patching updates being current; cyber awareness and training;
IDENTIFICATION typically includes
- anomalies in traffic patterns
- IRC traffic (port 6667)
- port 25 for spamming and outbound SMTP traffic
- port 1080 for proxy servers
- DNS requests
- C&C Command and Control triggers which next-gen firewalls and AV should have
- increased popups
- spike in CPU or network usage
ERADICATION via botnet removal software including freeware BotHunter, Kaspersky, BotRevolt and others including rootkit detection/clean up packages. IP address block, reputation blocking and HoneyPots can be a source for helping in the scenario. That said, a plethora of vendor packages some under the term of Next-Gen Endpoint Protection address the detection / isolation / eradication of botnets...
Known Botnet list: Agobot, SDbot, mIRC-based; DSNX, q8, kaiten, Perl-based; Grum, Zeus, Conficker, Torpig, Sality, Cutwail, Tinba, Uptre, Ramnit, Windigo, Beehonem, Cutwail, Glupteba, ZeroAccess,
Also, useful sites for reference resource SANS
Thursday, February 23, 2017
Cyber Security & Risk Mgmt Summit by Technology Executives Club
First timer and was a good day's conference (like the Lake Forrest Grad. location) - well represented by companies and leaders in the area...and good hand full of vendors too
Key cyber topics mentioned:
Key cyber topics mentioned:
- Top priorities: End users being phished and the aftermath, yes - Ransomware, Don't know what we don't know (visibility); and 3rd party (vendors requiring remote connection into company and there ability to maintain appropriate security on there own end)
- Vendor identified common thread/threats include: APT, Nation-state and of course phishing clicks
- ISACA top 3 threats: Social Engineering 52%, Insider threat 40% and Advance Persistent Threat 39%Action items: Look for anomalous not just malicious,
- Talent gap another theme in the industry - since automation can only go so far
- Incidents will happen, just don't let the same happen twice - investigate / learn from experience
- Risk management needs to be integrated and Privacy is required but not necessary the same agenda as Security
- Remember security is behavior and economics
Wednesday, February 22, 2017
RSAC in a flash – quotes, opinions, trends from some of the preso
No resounding theme this year (compared to last) outside of the words: Ransomware, DDoS, Machine Learning, and over use of “pivot”
- Security by obscurity is not security but a fallacy
- PLC lack programming interfaces for solid password authentication and overall security
- https://www.youtube.com/watch?v=KTKRjvTgTQI&feature=youtu.be
- https://www.youtube.com/watch?v=t4u3nJDXwes&feature=youtu.be
- Incident Response
- Availability – does not mean a fire extinguisher everywhere
- Budget – there will be unexpected cost
- Collaborate – with all groups and roles, with frequency
- Plan – for chaos
- Pay ransom sometimes (70% do and 20% over $40K), when you don't have backup or can't recover timely
- Security awareness strategy answers who, what and how – make it simple and don’t assume
- Uptick in HealthCare attacks
- Must lead without authority
- Machine Learning is the wave but is enhanced with GPO to speed up reaction
- 7 factors of organizational management
- Gain command of the facts
- Get the business to own risk
- Embrace the change agent role
- Run InfoSec like a business
- Build a technical and business capable team
- Communicate the value
- Organize for success
- CISO Impact Quotient equals 5-7 year journey before trust and value is seen/woven into the organization
- Building confidence is your first objective; and having a plan; as well as tying it back to the most critical business function
- Driver for Maturity is from Compliance to Solution to Vulnerability to Threat modeling/detection focused
- Change your habits and change your life
- 3 critical skills for better decisions and greater influence
- Self-awareness – clarity in thinking and feeling
- Deep work – attention management vs. time management
- Mindfulness and mentalizing
- Mandatory data breach notification is no longer just an option, to include within 72 hours to Data Protection Agency
- Burden of proof lies in the ability to prove (substance) unauthorized access/processing did NOT occur
- EU personal data definition is any information related to an identified or identifiable natural person so varies from US’s SSN and Driver’s License Number
- EU fines are 4% global turnover or €20,000,000
- Practicing fire drills is necessary – hands on exercise to test incident handling
- Variant of important trifecta is Speed, Security and Variability (aka cost)
- MARCI chart plots risks along impact and vulnerability with speed of risk (aka velocity)
- Diversity makes you smart; current role diversity is 31% Boomers, 38% Gex X and 46% Millennials
- Cyber skills shortage continue to rise
- 93% of organziations take just minutes to compromise (Synack)
- Few Good Links
- Nomoreransom.org for help
- https://github.com/jzadeh/Aktaion GPO and endpoints
- github.com/wickett/lambhack serverless security
- https://rsa2017.iansresearch.com survey
- www.iamthecavalry.org medical devices
Tuesday, February 14, 2017
C-level Tenure
Study/Pic from the Wall Street Journal - IT Execs are younger and generally at role 1 year less than other Execs
Wednesday, February 8, 2017
Cloud storage dilemma in a Corporate setting - Top10
How much do you really know about the providers’ encryption key management, or the shared virtualized environment?
Would a 3-tiered model for cloud storage be applicable e.g. Sanctioned, Tolerated and Unsanctioned. Taking into account the following consideration - Top 10:
Would a 3-tiered model for cloud storage be applicable e.g. Sanctioned, Tolerated and Unsanctioned. Taking into account the following consideration - Top 10:
- Policy driven - Acceptable Use, Data Classification and Retention
- Strong password
- Multi-factor authentication
- MDM: Access via managed devices only and limit linked applications or unsupported software connection
- Granular file security including share provisioning
- Encryption at-rest, in transit
- Timely patching – full cycle, all devices
- Data Loss Prevention enabled
- Country location based storage
- Rich feature enabled e.g. user notification for login of new devices
Subscribe to:
Posts (Atom)