VPN

Banyan Security Research Uncovers Primary Considerations Influencing Zero Trust Network Access (ZTNA) Adoption

Banyan Security | June 28, 2022

Banyan Security
Banyan Security, a leading provider of Zero Trust Network Access (ZTNA) solutions, today revealed new research highlighting organizations’ preferences and hesitations for adopting modern remote access solutions. The independent survey was conducted by Sapio Research and engaged over 400 senior decision makers from mid- to large-sized companies in the U.S. and Canada, who are responsible for IT security and are aware of both virtual private networks (VPN) and ZTNA. The key findings from this study include:

Over half (54%) of VPN owners stated that secure remote access is a priority at this time.
VPN usage is still prevalent among a majority (90%) of security teams who have highlighted cost, time, and difficulty as reasons to not move forward with ZTNA adoption.
Almost all organizations (97%) say that adopting a zero trust model is a priority, with 93% of organizations having committed a budget to enhance their VPN or move toward ZTNA within the next year or two.
More than half (53%) of respondents have already started rolling out zero trust solutions.

Personal Devices and VPNs Do Not Mix
The last two years have shifted how we work, producing a new remote workforce that was essentially created overnight. As highlighted in this study, this has resulted in most workers – in this case 51% of respondents – using a combination of corporate and personal devices to connect to business applications and resources. Personal devices often used by less security-conscious family members. This creates a very risky environment as personal devices are easy targets for threat actors especially since IT teams cannot fully monitor activity on these devices. Additionally, personal devices are often used by other family members – particularly children – which make them even more susceptible to malware and other viruses.

Despite known security issues, VPN usage continues to thrive, with 90% of respondents currently using a VPN in some capacity for secure remote access. When access is permitted on a personal device, it creates a risky situation for not only the user, but the entire organization. VPNs lack many of the application-level access controls and integrated security that are common in ZTNA solutions. As a result, cybercriminals will often target VPNs because a single set of compromised credentials can provide all of the access needed to carry out a data breach, ransomware incident, or other attacks.

“As this study shows, VPN usage continues to be prevalent, often viewed as ‘good enough’ for remote access among organizations simply because that is what they have always used, What this doesn’t account for is the poor administrative and end user experience, not to mention that on-premises access must be handled with separate, siloed tools. We have plenty of evidence to show that legacy VPNs no longer adequately protect nor provide consistent and easy access to corporate resources for today’s ‘work from anywhere’ workforce.”

Jayanth Gummaraju, CEO & Co-Founder of Banyan Security

Key Drivers for ZTNA
A majority of the respondents (97%) stated that adopting a zero trust model is a priority for their organization, where 44% said they have plans to roll out zero trust but are in the early stages, while 53% said they have already begun to roll out zero trust solutions. For organizations who have begun to roll out ZTNA solutions, the survey revealed that secure remote access (48%), improving the end user experience (34%) and eliminating exposure to VPN vulnerabilities (34%) were the top three drivers in their decision to choose ZTNA. Unlike VPNs, ZTNA provides access on a case-by-case basis, which is decided based on user, device, and application-level access and security controls.

What’s Holding VPN Users Back from Making the Switch?
Over two thirds of organizations (69%) believe implementing a ZTNA strategy would require a large undertaking. Aside from the general familiarity and comfortable usage of their traditional VPN solution, organizations stated that cost/budget constraints are the biggest barriers (62%) for VPN users to adopt ZTNA. Thirty percent of VPN owners said that it would be difficult to implement ZTNA infrastructure in their current security environment; however, 82% of respondents stated they would likely implement ZTNA if there was an easily deployable, inexpensive option. Apathy also appears to be one of the biggest barriers preventing VPN owners from adopting ZTNA solutions with 46% of respondents stating that modern, secure remote access is not a priority at this time.

“While it is good to see that awareness of ZTNA solutions amongst IT security professionals continues to grow, the actual implementation of a ZTNA architecture is still considerably low, with just over 17% of respondents having truly begun to roll out a ZTNA strategy,” continued Gummaraju. “As we look toward a future where remote and hybrid work are the standard for most organizations, it’s encouraging to see that IT teams are looking beyond VPNs at more comprehensive zero trust network access solutions.”

Research Methodology
The survey was conducted among 410 Senior Decision Makers from mid- to large-sized companies in the U.S. and Canada, who are responsible for IT security and are aware of both VPN and ZTNA. The interviews were conducted online by Sapio Research in April 2022 using an email invitation and an online survey, with results accurate to ± 4.8% at 95% confidence limits.

About Banyan Security
Banyan Security provides secure, zero trust “work from anywhere” access to infrastructure and applications for employees, developers, and third parties without relying on network-centric legacy VPNs. Deep visibility provides actionable insight while continuous authorization with device trust scoring and least privilege access deliver the highest level of protection with a great end user experience. Banyan Security protects tens of thousands of employees across multiple industries, including finance, healthcare, manufacturing, and technology.

Spotlight

Lenovo is a GOLD sponsor at #VMwareExplore 2023 Singapore! Uma Thana Balasingam and Sumir Bhatia sat down to discuss VMware and Lenovo’s long-standing partnership and their excitement of helping customers transform from the edge to the cloud!


Other News
Virtual Desktop Strategies, Virtual Server Management

LogicMonitor Expands Observability Intelligence to New Environments

businesswire | August 18, 2023

LogicMonitor, a leading SaaS-based unified observability platform for hybrid IT infrastructure, today announced expanded integrations, insights and workflows to the LM Envision Platform. LogicMonitor is also introducing Dexda, an event management solution that filters through the noise of thousands of daily alerts by using advanced machine learning (ML) techniques, contextual enrichment capabilities and deduplication efforts. Together, these additions allow customers to reach a significantly lower mean time to resolution and lower risks to the business. “Every business is under tremendous pressure to seamlessly deliver exceptional digital performance,” states Christina Kosmowski, CEO, LogicMonitor. “To efficiently do that, our customers look to us to contextualize the overwhelming amount of data within their complex IT environments.“ The core of LogicMonitor’s platform has been built with advanced machine learning, intelligence and automation, combined to abstract complexity and deliver business impact through IT data collaboration. The company has focused its product roadmap in the areas of intelligence, experience and extensibility. Intelligence and Automation Dexda is the next evolution of AI Ops. It is built on top of LogicMonitor’s extensive data set and integrated into its platform, so users can effortlessly move from alerting to automating actions. Key attributes of Dexda include: Adaptive Correlation- Alerts are automatically re-clustered when a more optimal option is detected. ServiceNow Ready- Automatically enriches Dexda alerts with ServiceNow CMDB data to drive additional context for ML correlations. User-defined Correlation- Dexda admins can now fine-tune the ML models to meet their unique needs or build new ML models. In addition to Dexda, LogicMonitor has also delivered: Event-Driven Ansible Integration- This jointly developed solution with Red Hat assists with auto-remediation and auto-troubleshooting. This integration lets customers trigger remediation workflows in Ansible and act in accordance with predefined rules. Datapoint Analysis- Leverages machine learning techniques to find related metrics and patterns across different resources, which in turn reduces MTTR and increases productivity. Unified Platform Experience A unified platform experience is critical for consistency, adaptability and scalability while reducing tool sprawl and data complexity. Troubleshooting in hybrid modern environments requires a contextual and intuitive UX across devices, services and networks. This modernization and unification effort is the key to continually delivering new capabilities to users and keeping time to value short for new customers. UI Modernization- Optimized to present information in complex hybrid environments. Components for all parts of the LM Envision platform now include bulk actions, better search and filtering and new editors for LogicModules. Expanded Cloud Support- 20 new out-of-the-box dashboards for AWS and Azure, accelerating time to value while providing service-specific views for more insight into health, performance and availability. Log Ingest and Filter Simplification- Introduced declarative UI to simplify log collection and configuration. Users can also add custom LM Properties to the logs which allows for more flexible searching and potentially faster MTTR. Digital Experience Monitoring- Synthetic tests now support multi-factor authentication (MFA) and automated alerts for latency and error conditions. Extensibility As a trusted partner in the advancement of monitoring across on-prem, hybrid and cloud environments, LogicMonitor continues to invest in new ways to manage and monitor network equipment through integrations woven tightly into its overall platform experience. Improved VMware vSphere Support- Support for vSphere 8 and automation for the discovery and monitoring of new ESXi Hosts and mission-critical Virtual Machines, eliminating manual processes – reducing the time, resources and risk involved in repeatable remediation processes. Cisco Meraki and Catalyst SD-WAN- These new integrations make it easier than ever to monitor Cisco environments in the broader context of one's heterogenous hybrid infrastructure. Customers can now get alerted about anomalous events, visualize network traffic usage and see how Cisco vEdge/cEdge (formerly Viptela), SD-WAN Controllers, Meraki Security Appliances, Switches, Wireless Access Points and Smart Cameras connect to their network and where alert conditions exist. Improved Kubernetes Monitoring- Greater coverage and deeper visibility into frequently changing cloud environments with new support and coverage for Amazon Elastic Kubernetes Service (Amazon EKS) Anywhere and enhanced Kubernetes helm and scheduler monitoring. SaaS Monitoring-M365 and Okta logs allow users to clearly understand why problems happen, pinpoint the root cause and quickly troubleshoot alongside alerts. By advancing many key features of its platform, LogicMonitor customers can harness the full potential of their data to make informed decisions with confidence and efficiency. This approach not only streamlines operations, but also provides clarity and precision to the complexities of their IT landscape. About LogicMonitor LogicMonitor’s SaaS-based observability intelligence platform, LM Envision, helps ITOps, CloudOps, DevOps, CIOs, and business leaders gain operational visibility into and predictability across the technologies that modern organizations depend on to deliver extraordinary employee and customer experiences. LogicMonitor seamlessly enables unified observability across infrastructure, networks, clouds, containers and applications, empowering companies to focus less on troubleshooting and more on innovation.

Read More

Virtual Desktop Tools, Server Hypervisors

ZEDEDA Launches Industry-First Application Services Suite, Revolutionizing Edge Computing

businesswire | July 28, 2023

ZEDEDA, the leader in edge infrastructure orchestration, today introduced ZEDEDA Edge Application Services, making it easier for customers to instantly gain granular control across all of their edge applications, including their modern AI-based applications. The number of edge devices, along with the data they produce, is growing exponentially. Gartner® predicts that “by 2025, 75% of data will be generated outside these centralized [data centers or cloud regions] facilities.”1 Edge computing is required to manage and process that data, but the complexity of distributed environments can make it difficult for customers to get started quickly. Enabling access to core services can provide an on-ramp for organizations to benefit from an initial edge use case while also establishing a foundation for future growth, just as was seen previously with cloud adoption. “Just as we saw occur with the cloud providers in the early days, it is time for the edge market to evolve beyond just infrastructure and begin to offer value-added services in addition,” said Said Ouissal, founder and CEO of ZEDEDA. “Now, with ZEDEDA Edge Application Services, we are able to offer our customers the ability to manage, configure and control their edge applications simply by leveraging the ZEDEDA ecosystem.” ZEDEDA Edge Application Services are delivered using ZEDEDA’s market-leading edge orchestration solution, which reduces cost while increasing visibility, security and control. The new industry-leading suite of services provides remote access, inventory and configuration management, and Kubernetes management services tailored to the individual needs of each deployment and customer. ZEDEDA Edge Access: A Simple and Secure Remote Access Solution The first service in the suite, ZEDEDA Edge Access, enables IT administrators and platform operations teams to instantly access any remote device from any location at any time. It is a simple solution that provides secure access, control and audit tracing for edge deployments. ZEDEDA Edge Access is secure out of the box, with built-in access controls that provide full encryption of user sessions, and requires no backend configuration or specialized skills. ZEDEDA Edge Access Service eliminates the overhead associated with conventional methods of remote access, providing a streamlined and efficient alternative. ZEDEDA Edge Access Service also provides granular user control and access, enabling customers to provide third parties secure access to their edge infrastructure. For example, if there is a problem with a specific application, the software vendor or developer can securely access, audit and troubleshoot if needed. This service, and others like it, will ultimately enable ZEDEDA partners and OEMs to generate new revenue streams. ZEDEDA’s open, distributed, cloud-native edge management and orchestration solution has attracted strategic OEM and customer relationships with Global 500 companies, including Emerson, Rockwell Automation, and VMware. The company continues to quadruple the number of edge nodes it has under management annually, scaling toward a hundred thousand edge nodes and has raised more than $55 million in capital from investors, including Coast Range Capital, Lux Capital, Energize Ventures, Porsche Ventures, Chevron Technology Ventures, Emerson Ventures, Juniper Networks, Rockwell Automation, Samsung Next and EDF North America Ventures. About ZEDEDA ZEDEDA makes edge computing effortless, open, and intrinsically secure — extending the cloud experience to the edge. ZEDEDA reduces the cost of managing and orchestrating distributed edge infrastructure and applications while increasing visibility, security and control. ZEDEDA delivers a distributed, cloud-native edge management and orchestration solution, simplifying the security and remote management of edge infrastructure and applications at scale.

Read More

Security, Hyper-V

Cradlepoint Partners with Los Angeles County to Modernize Election Network Infrastructure with 5G-Optimized Hybrid WAN

Cradlepoint | August 02, 2023

Cradlepoint, the global leader in cloud-delivered LTE and 5G wireless network edge solutions, today announced that Los Angeles County Registrar-Recorder/County Clerk (RR/CC) has leveraged Cradlepoint to modernize the network infrastructure of one of the largest and most diverse counties in the United States, creating a new paradigm to enhance accessible voting capabilities to eligible voters. Before 2020, the voting infrastructure and registration processes across Los Angeles County remained widely unchanged from the 1960s. The county recognized the need for a complete voting overhaul — technological and procedural — to address the significant demographic changes impacting equitable voting access. On the technological front, the RR/CC sought innovative, pop-up networking solutions capable of reliably and securely connecting voting technology across widespread and remote locations, while enabling centralized, real-time monitoring and management capabilities. In November 2020, RR/CC approached their existing connectivity vendor Cradlepoint to test and deploy Cradlepoint’s 5G-optimized Wireless Wide Area Network (WWAN) solutions, in the form of NetCloud Manager and E3000 routers, which enabled highly scalable, reliable, and secure pop-up networks across approximately one thousand voting centers during the presidential election. Key solution capabilities and outcomes include: Centralized network management:With NetCloud Manager, RR/CC’s in-house IT team successfully managed the deployment, configuration, and troubleshooting of each network device from centralized locations, reducing unnecessary complexity and on-site visits to quickly scale networks ad hoc for future election-related initiatives. Consistent enforcement of security policies:NetCloud Manager and E3000 routers enabled the team to take a multi-layered approach to security with policy-based VPN tunneling and certificate-based authentication, keeping sensitive voting data secure to remain compliant with state and federal laws and maintaining the integrity of the democratic electoral process. Continuous, flexible network connectivity:E3000 routers utilize ethernet, Wi-Fi, and 5G/LTE connectivity to enable multiple transport layers, which keeps voting technology operational across locations, despite any primary network disruptions or failures. “Los Angeles County recognized the pressing need to modernize our network infrastructure to enhance the accessibility, transparency, and security in the electoral process, but limited IT resources impacted our ability to deploy and manage distributed networks at scale,” said Aman Bhullar, CIO at LA County Registrar-Recorder/County Clerk. “Our partnership with Cradlepoint enabled this transformation, helping us to not only accomplish our mission with innovative solutions, but also to set a new standard for widely accessible voting capabilities.” “In today’s digital world, pop-up connectivity services have become vital to operate in new places and ways, and the Los Angeles County Registrar-Recorder/County Clerk is a great example of how LTE/5G connectivity and Cradlepoint’s 5G-optimized solutions seamlessly work together to help the office adapt to the modern needs of its constituents,” said Bryan Wood, Sr vice president of sales, North America for Cradlepoint. “We are honored to partner with the Los Angeles County Registrar-Recorder/County Clerk office to ensure eligible voters have access to polling locations, no matter their whereabouts in the county during an election period.” About Cradlepoint Cradlepoint enables the freedom to connect people, places, and things that drive more experiences, more ways to work, and better business results — anywhere. The company is a pioneer in Wireless WAN, offering advanced 4G and 5G routers and adapters — controlled through Cradlepoint NetCloudTM. Enterprise businesses and public sector agencies rely on Cradlepoint and its Cellular Intelligence to build a reliable, secure network wherever they need it, connecting fixed and temporary sites, vehicles, IoT devices, and remote employees. Headquartered in Boise, Idaho, Cradlepoint is a wholly owned subsidiary of Ericsson (NASDAQ: ERIC) and part of their Business Area Enterprise Wireless Solutions.

Read More

Virtual Server Management

EMA and Auvik Research Reveals Hybrid and Remote Work Has Increased Workloads, Posed Challenges to Remote Network Experiences

businesswire | September 28, 2023

New research by Enterprise Management Associates (EMA) and Auvik, an award-winning provider of cloud-based network management software, revealed that the ongoing shift to hybrid and remote work environments has resulted in key changes to the roles and priorities of network administrators in order to address new connectivity challenges and prioritize and preserve a secure, productive end-user experience. The report examined the remote and hybrid work paradigm through the lens of network operations teams – 73% of which reported an increase in workloads, either slightly or significantly, following the shift from traditional to hybrid work environments. Results from the report demonstrated that the top challenges associated with the remote work experience are poor home Wi-Fi setups, distance from applications, and poor ISP quality. To combat these obstacles, 72% of surveyed organizations have deployed network hardware to the homes of remote workers, including network security devices (62.7%) and Wi-Fi access points (54.1%). Additionally, 90% of organizations with hybrid workers shared that they had to upgrade Wi-Fi networks to address increased office mobility requirements. “These results reinforce that although people are beginning to return to the office, hybrid work is here to stay and is resulting in significant changes for network administrators,” said Alex Hoff, co-founder and Chief Strategy Officer for Auvik. “Although IT teams no longer own all the assets utilized daily by employees, they are still responsible for these operations. And despite not being able to directly exert control over employees’ home networks, they can have visibility over these environments with network monitoring tools. Implementing network visibility software helps IT professionals overcome these new obstacles by providing the ability to maintain visibility and control amid changing work circumstances. The data provided in this report reinforces Auvik’s place in the market and demonstrates that our recent acquisitions, integrations, and expanded product offerings that were designed to help IT teams adapt to these new norms are well-suited for the challenges that are being identified within the industry.” Additional findings from the report include Nearly 49% of network operations teams started working with a new tool vendor to help them manage the network experience of remote workers. 76% of organizations need to unify how they manage network access policies across on-premises networks and remote users. Remote desktop access tools (deployed by 81% of companies) remain the go-to solution for troubleshooting remote users’ problems, but endpoint monitoring tools are increasingly popular (79%). Although 87% have allocated funds in their budget to update network operation tools for remote and hybrid user support, only 32% of organizations shared that they have been successful in doing so. The top issues employees most often report when they are working from home are VPN access issues, followed by performance issues with SaaS applications. “96% of IT organizations said they are supporting hybrid workers, and 30% of all employees who work remotely are hybrid workers,” said Shamus McGillicuddy, VP of Research, EMA. “With employees working both at home and in the office, it is important to have the assets and software necessary to support them in both locations. This means enterprises must invest in more secure remote access solutions that offer integrated network security automation, centralized management, and network optimization or network enhancement, as well as network observability tools that are able to monitor performance across disparate locations.” Methodology Auvik commissioned an independent research firm to survey 354 IT professionals directly involved in supporting the networking requirements of employees who work from home. About Auvik Auvik’s mission is to simplify how IT teams work and live by providing cloud-based IT monitoring and management with simplicity and speed. It lets IT professionals visualize IT infrastructure, SaaS applications, and shadow IT in minutes. As a result teams can identify and resolve issues in seconds, saving valuable time. Auvik is one of the fastest-growing North American technology companies, and is winner of the Deloitte Technology Fast 50 and Deloitte Fast 500. Visit www.auvik.com for more details. Auvik is a registered trademark of Auvik Networks Inc. About EMA Founded in 1996, EMA is a leading industry analyst firm that specializes in providing deep insight across the full spectrum of IT and data management technologies. EMA analysts leverage a unique combination of practical experience, insight into industry best practices, and in-depth knowledge of current and planned vendor solutions to help their clients achieve their goals.

Read More