Insight Blog

Log4j Breach Blog

15 Dec: Investigating and Mitigating Log4j/Log4Shell Vulnerability

On Dec. 9, 2021, a remote code execution (RCE) vulnerability in the popular Java-based logging package Log4j was disclosed.  Submitting a specially crafted request to a vulnerable system allows an attacker to download and execute a malicious payload to perform additional functions such as data exfiltration, diverting funds, performing surveillance, or disrupting service.  What many experts fear now is that the bug could be used to encrypt data and due to the discovery of this exploit being so recent, there are still many servers, both on-premises and within cloud environments, that have yet to be patched.  Scanning activity for CVE-2021-44228 has actively begun on the internet with the intent of seeking out and exploiting unpatched systems.  Apache Log4j versions <= 2.15.0 rc1 are vulnerable. 

Rob Kim Secure Everything

08 Dec: 3 Essential Capabilities to Secure Everything

Innovation and top-line growth are consistently two of the top three key priorities for business executives. Security is always sandwiched right in between these goals, as the threat landscape and perimeter constantly evolves – and never for the better. The digital paradox holds that the same technologies that allow us to innovate and grow give sophisticated intruders the same tools to innovate their method of attack. Just like a chain is only as good as its weakest link, the same goes for our approach to security. It doesn’t matter where in your IT environment a breach occurs; in the end, everything gets affected.

Intel Optane 3 Blog Image

01 Dec: Base your server refresh strategy on 3rd Gen Intel® Xeon® Scalable CPUs and Intel® Optane™ PMem

It’s a common occurrence in many data centers: systems are running at peak capacity, workload demands are increasing, and it’s time to plan for the next server refresh cycle. But all too often, organizations take the path of least resistance and simply augment existing server resources with more of the same – a “go with what you know” approach.

Cyber Month Recap Blog Tile

29 Nov: Recap: Cybersecurity Awareness Month 2021

Presidio celebrates Cybersecurity Awareness 24x7x365, but we especially love Cybersecurity in October. Cybersecurity & Infrastructure Security Agency (CISA) just closed out its 18th year deeming October as the month to bring awareness to the importance of cybersecurity. 18 years ago, the internet was in its infancy. Now, it is a part of everyday life.

Rob Kim Transform to Digital Blog FI 2

09 Nov: Why Data is Critical to ‘Transform to Digital’

The worst kept secret in the business world is the rapid disruption of traditional workplace and workforce norms, accelerated of course by the ongoing pandemic. There is no shortage of blog posts and think pieces written that compel organizations to digitally transform their business and operations to keep pace. Yes, technology is emerging as a true business partner, as executives across sales, finance, marketing, and other departments lean on their IT counterparts to innovate. Most organizations are even embracing a software engineering mindset, as containers and low-code options are democratizing the development space.

Security Gartner Blog FI

03 Nov: Pivoting Cybersecurity: Going on the Offensive

It has been about 5 years since WannaCry and NotPetya hit companies worldwide in full force, launching a new era of cybercrime. Now, there’s a new report of a ransomware attack weekly. Although this may seem scary, we know more now than we ever have. With each attack, we can see and ultimately learn from which vulnerabilities were exploited. We cannot prevent the inevitable, but we can prepare and minimize the effects. There is a famous quote by author Zig Zigler “Success occurs when opportunity meets preparation.” While a ransomware attack is not an opportunity to look forward to, it is important to be prepared. 

Modernize 2 Blog FI

29 Oct: 5 Tips to Avoid Toil & Trouble on Your IT Automation Journey

Accuracy in business processes has always been important, but it used to require tedious, error-prone manual processes to achieve. Today, accuracy and automation go hand-in-hand. For an easily recognizable example, just look at how modern retail stores manage their inventory. If stock runs low on certain items, the store will automatically kick off a stock replenishment process requesting that it be replaced.

Meraki MT-MV FI

26 Oct: It’s Time to Reevaluate Your Siloed Security Strategy

By converging physical and cyber security, organizations gain deeper business insights and better protection against sophisticated threats. The practice of segmenting security teams into distinct physical security and cybersecurity groups has been the norm since the early days of IT. Within the last decade, however, the Fourth Industrial Revolution, advances in cloud technologies and the digital transformation trend have led to a greater awareness between the cyber world and real world.

Cybersecurity Month CIS Blog FI

22 Oct: Unpacking the CIS 20 (Now the 18)

CIS Controls v8 is here, and there are some significant changes organizations should pay attention to. We spend a lot of time in our blogs talking about—and recommending—cybersecurity frameworks. The reason for this is pretty straightforward: there are a lot of decisions that go into cybersecurity planning, and failing to use a framework makes the process exponentially more complicated.

Cybersecurity Month Zero Trust Blog FI

21 Oct: 5 Mistakes Companies Make in their Zero-Trust Journey

Zero-trust is the logical successor to the legacy perimeter security model, but there are many common pitfalls to consider. Whether companies know it or not, we’re all on a journey toward zero-trust security. This concept, which can be summarized as “never trust; always verify,” has been around for over a decade as a security focus on least privilege. However, the pandemic brought it to the forefront, as corporate offices emptied and millions of workers started working from home. So, in a relatively short period, tens of thousands of companies inadvertently accelerated their zero-trust journey, often without a well-thought-out plan.