eBook | The Modern Network Security Challenge: How to Secure Today's Perimeter-Free Enterprise

eBook | The Modern Network Security Challenge: How to Secure Today's Perimeter-Free Enterprise

Explore the rapid evolution of network security in the perimeter-free enterprise. Learn how to secure your hybrid network with zero-trust models, cloud-native security tools, and best practices for mitigating risks from legacy networks to cloud environments. Download this eBook for expert insights!

eBook | The Modern Network Security Challenge: How to Secure Today's Perimeter-Free Enterprise

© 2024 CyberRisk Alliance

The modern network security challenge How to secure today's perimeter-free enterprise

SPONSORED BY

https://www.scmagazine.com/ https://www.cyberriskalliance.com/ https://www.checkpoint.com

The modern network security challenge: How to secure today's perimeter-free enterprise

2© 2024 CyberRisk Alliance

The perimeter is being erased and replaced by zero trust and identity management. Some data centers, workplace applications and firewalls have been moved to the cloud, while others remain on-premises, and modern network- security tools must protect them all.

Where does that leave an organization with a legacy network infrastructure that, to be kind, might have a little catching up to do? How does that organization begin to understand all the fundamental changes that have taken place in network security in the past few years? And how can that organization efficiently, affordably, and securely modernize its network security to be ready not just for the present day, but for years to come?

Here's what has changed in network security, and how to update your network-security architecture so that it can be flexible, scalable, and manageable for today's hybrid world.

The enterprise perimeter is vanishing. This is driving rapid changes in network security, including adopting zero-trust elements. Paul Wagenseil explains how to update your network-security architecture so that it can be flexible, scalable, and manageable enough for today's hybrid world.

Can you catch up with the future?

"All you needed was the edge perimeter firewall, and that was your network security because everything was just a flat network.”

— Julian Mihai | Chief Information Security Officer, Penn Medicine

OUR EXPERTS:

Aviv Abramovich

Robert Lowry

Head of Security Services Product Management, Check Point

VP of Security, The Lifetime Value Co.

John Isch Director of Infrastructure Solutions – Americas, Orange Business

Julian Mihai CISO, Penn Medicine

https://www.scmagazine.com/ https://www.cyberriskalliance.com/ https://www.scmagazine.com/zero-trust https://www.scmagazine.com/identity-and-access https://www.scmagazine.com/topic/cloud-migration https://protect.checkpoint.com/v2/___https:/www.scmagazine.com/topic/network-security___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2OjllYzY6MmRkZDg4NGY2ODBhNWJjNzVjMTZhYzk3NmFjM2MwMTk3MWE3NGU3YmM5MjFjZDAyMGJiNWUzYjJjZDE0Mzk2ZTpwOlQ https://protect.checkpoint.com/v2/___https:/www.scmagazine.com/topic/network-security___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2OjllYzY6MmRkZDg4NGY2ODBhNWJjNzVjMTZhYzk3NmFjM2MwMTk3MWE3NGU3YmM5MjFjZDAyMGJiNWUzYjJjZDE0Mzk2ZTpwOlQ

What's new, and what's old, in network security

The most significant change to network security has been the gradual disappearance of the perimeter. Up until recently, organizational networks had a physical limit. Enter the building and flip on your PC, and you were on the network. Leave the office, and you could no longer reach the network. Network security was similarly simple.

"All you needed was the edge perimeter firewall, and that was your network security because everything was just a flat network," says Julian Mihai, CISO at Penn Medicine in Philadelphia.

That began to change with the wide deployment of broadband internet access and enterprise VPNs. But even when a remote worker was logging in, the network still had an "inside" and an "outside," although logically instead of physically. Once "inside," the worker had mostly unfettered access throughout the network, save for a few protected areas restricted to special staffers.

That's no longer the case. For many companies, the network is everywhere, and anything can join the network if it presents the right credentials. This works well for organizations that have offices scattered over a vast area and many employees working remotely.

"You need to think of security holistically," says Aviv Abramovich, head of security services product management at Check Point. "Your network actually extends to the employee that sits at home in their slippers, reading their email on their bring-your-own-computer connected to their personal Wi-Fi router at home."

The paradigm to secure a network that has no physical boundaries is the zero-trust model, which uses identity rather than location to grant access to individual users. More importantly, it does not give users free range through the network.

Instead, users are challenged to authenticate themselves again when accessing new areas and resources, even if they have already logged in. The zero-trust model also works well for legacy, on-premises networks.

"Ask yourself, 'What is my risk before and after, and which one of these products will help me mitigate the risk better?”

— Aviv Abramovich | Head of Security Services Product Management, Check Point

The modern network security challenge: How to secure today's perimeter-free enterprise

3© 2024 CyberRisk Alliance

https://protect.checkpoint.com/v2/___https://www.scmagazine.com/resource/foundational-pillars-of-an-effective-zero-trust-solution___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2OjY2NGI6ZjBiMGRkNGQwNGQ4NGYzYTViYmE1Nzg5ODFkZWExNmE5MWIyMWZkZWIyOWUwY2U3NWYyMTE5ODVjMTAwYTNhMzpwOlQ https://www.scmagazine.com/ https://www.cyberriskalliance.com/

Cloud-native security tools

Moving assets to the cloud involves a radically different concept of network topology and security and requires retraining of security personnel. It also may lead to security and application-development teams becoming more integrated, as cloud "infrastructure" is mainly software that can be developed in-house.

Misconfigurations of cloud assets are a leading problem. Check Point's 2022 Cloud Security Report found that, "for 33% of organizations, the complexity of their cloud environments makes it challenging to rapidly identify and correct misconfigurations before they can be exploited by an attacker."

Legacy network-security tools based on the perimeter-defense model are not well positioned to protect cloud assets, which means that "cloud-native" tools and models must be implemented instead. IT managers looking to license these tools may find themselves wading in acronym soup.

There are off-the-shelf products such as cloud security-posture management (CSPM), a cloud access security broker (CASB), a cloud workload protection platform (CWPP), the more encompassing cloud-native application protection platform (CNAPP) and zero-trust network access (ZTNA), which despite its name is not a turnkey implementation of the zero-trust model.

These cloud-based tools have tremendous advantages over legacy tools in terms of speed and flexibility.

"By definition, a cloud environment is a lot more dynamic. You click a button, you have 10 new servers, so you need your security to also be very dynamic and adjust to it," says Check Point's Abramovich. "Network security can read information, if you will, from the cloud and automatically and dynamically adapt the policy and the access to the changes in the cloud."

To the cloud!

The second most important change has been the rapid adoption of cloud computing. In a 2024 survey of 202 IT and security managers and decision-makers conducted by CyberRisk Alliance, a whopping 96% of respondents said their organizations had at least some workloads in the cloud. Cloud computing is no longer the future — it's very much here and now.

"The cloud gives us scalability," said one respondent to the CRA survey. "If we need a new server, we can spin that up in minutes rather than waiting on equipment purchase for on-prem. It lets us focus more on application support rather than focusing on worrying about infrastructure."

Network security for the cloud requires a whole new set of software and techniques that may not be familiar to security practitioners accustomed to on-prem networks, creating a new sub-industry of "cloud-native" security tools that can follow each asset, each set of data and each user and create protections around them individually. However, the old ways also still apply. In the CRA survey, only 16% of respondents said that more than three-quarters of their workloads were cloud-based, meaning that almost all respondents were running networks that were hybrids of cloud and legacy elements.

"The vast majority [of organizations] have traditional networks [that] are being augmented by cloud and other types of new technologies," says Check Point's Abramovich. "Perimeter defense is still very relevant for all of those organizations."

The modern network security challenge: How to secure today's perimeter-free enterprise

4© 2024 CyberRisk Alliance

https://www.checkpoint.com/cyber-hub/cloud-security/what-is-cloud-security/the-biggest-cloud-security-challenges-in-2022/ https://protect.checkpoint.com/v2/___https:/www.scmagazine.com/topic/cloud-security___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2OjY2NWQ6NWQxZDZkOGZiOGQwMDU5YjZiNmFkNzFjMGI4M2FjN2YyMzFjMWQzZTgzMGUzMzU4NDk0NDhmNWQ3NjYwOGFkNTpwOlQ https://www.checkpoint.com/resources/ciso-corner/2024-cloud-security-report?w=d39ff https://www.scmagazine.com/ https://www.cyberriskalliance.com/

Personal mobile phones and rogue IoT devices

Two other factors must be mentioned: The proliferation of powerful, modern smartphones means that millions of pocket-sized, privately owned personal computers join enterprise wireless networks every day.

This "bring your own device" phenomenon implores network-security practitioners to secure and sanitize inputs from these unsupervised devices. This adds another reason to implement zero-trust models that assume every device on the network is potentially hostile.

Embedded or IoT devices are less powerful than smartphones, but the addition of a smart TV, smart refrigerator, or "rogue" device to the workplace network creates another avenue of attack — one that likewise can be mitigated by a zero-trust network-security model.

Fortunately, or perhaps not, many of the adversarial tactics used against enterprise networks are somewhat similar, but they have become highly sophisticated and evasive. Detecting and blocking these new variants requires the use of advanced AI/ML security. Phishing and social engineering, whether through email, voice calls or instant messaging, remains a top attack vector, alongside the credential compromise that is often a result of these attacks.

Endpoint compromise is still a threat. Network penetration remains a top attacker goal — and network segmentation combined with Intrusion Detection/Prevention remain top defenses for network penetration.

Several solutions have been developed to secure remote work, cloud computing, BYOD and IoT devices. We'll focus on just a few: zero trust, identity and access management (IAM), secure access service edge (SASE) and other "cloud- native" security tools, and finally automation, which includes AI and machine learning.

Zero trust and the erosion of the perimeter

The zero-trust security model may be the most important development in information security of the past two decades. It's not a terribly new idea — the concept and the name were proposed separately in 1994 — but it was more fully realized when Google implemented, then evangelized, its BeyondCorp zero-trust model around 2010.

In that same year, Forrester Research matched the name with the concept in a now-famous paper called "No More Chewy Centers: Introducing the Zero Trust Model of Information Security."

Zero trust took some time to catch on, but it really took off in early 2020 when the COVID-19 pandemic sent home hundreds of millions of workers worldwide, all of whom suddenly needed to work remotely.

"[COVID] definitely accelerated something that already started before: the need to work from my phone, work from my computer, work from home, work from a cafe, work when I travel, and so on," says Check Point's Abramovich.

Zero trust offers more flexibility to staffers, as an employee logging in from home is treated exactly the same as a user on a company-owned machine in the office.

The modern network security challenge: How to secure today's perimeter-free enterprise

5© 2024 CyberRisk Alliance

https://www.scmagazine.com/ https://www.cyberriskalliance.com/

The zero-trust concept is simple: No network user, whether human, device, or algorithm, should get permanent access or be extended implicit trust, but instead should be forced to continuously verify their identity.

No user should be given more system privileges than necessary to carry out their assigned role, a concept known as "least-privilege access." Access to assets should be based mainly upon identity, not location.

"The reality is you're going to have a threat actor on a trusted asset on your network," says Penn Medicine's Mihai. "Without having the zero-trust approach, on the network, on the applications, you're not going to be able to contain that threat effectively."

Those tenets also solve some of the headaches associated with cloud computing, which removed assets and workloads from the cocoon of perimeter defenses. Adopting a zero-trust model centered around identity rather than geography makes it somewhat easier to protect cloud assets.

Least-privilege access We asked Abramovich what he considers to be the three "pillars" of the zero-trust model. The first, he said, is least-privilege access and its corollary of no implicit trust.

"You only get access to what you need, and it's not because you're in the right location," Abramovich explained.

Continuous user verification The second is continuous user verification, challenging users to constantly authenticate themselves, often through the use of context- aware multi-factor authentication (MFA) that takes into account a user's location, device and time zone.

"The fact that I trusted you two minutes ago doesn't mean I trust you now," Abramovich said. "Maybe you, in those two minutes, managed to get malware on your laptop, or wherever you're accessing, and now I have to take that trust away."

Visibility and monitoring of everything Finally, he said, the third pillar is the visibility and monitoring of everything: being able to understand who has access, who has trust, to where, what, where did they log on to and how they logged on to it.

Visibility and analytics are essential to zero trust because the system needs to know exactly where each user goes and what they do, and to be able to log it all. Or, as a common infosec adage goes, "You can't protect what you can't see."

The Three Pillars of Zero Trust

The modern network security challenge: How to secure today's perimeter-free enterprise

6© 2024 CyberRisk Alliance

https://www.scmagazine.com/ https://www.cyberriskalliance.com/

Securing the modern workforce

There are cloud-based secure-access models such as secure access service edge (SASE) and security service edge (SSE). These models, which can be assembled internally or bought as a service bundle from a single vendor, are generally comprised of a secure web gateway (SWG), a firewall as a service (FWaaS), and ZTNA. SASE also includes a software-defined wide area network (SD-WAN).

Some SASE/SSE implementations also throw in a web application firewall (WAP) and data-loss-prevention (DLP) and intrusion-prevention or intrusion-detection systems (IPS/IDS).

SASE and SSE are best suited for organizations with many remote workers and branch offices. They extend network protections to regionally dispersed points of presence (POPs), to which users can connect locally rather than a far-off data center.

"There are customers that secured [their] cloud and they are not using SASE," says Abramovich. "SASE can be more of an architecture where you have SD-WAN on the branch and firewall as a service in the cloud. A good SASE solution doesn't need to be expensive or require training — for example, if purchased as-a-service."

Naturally, licensing and implementing these cloud-native tools, and training your staff to run them, is expensive. Some organizations may expand their security staffs to keep up with the expansion of their cloud assets.

But as noted earlier, most organizations run hybrid networks, with some assets in the cloud and others still on-prem. Don't throw out those legacy network security tools just yet.

IAM: Who do you think you are?

Abramovich's first two pillars both concern identity and verification, and strong identity and access management (IAM) is central to the zero-trust security model.

As Abramovich points out, an organization that doesn't claim to use zero trust may be implementing it anyway if it's using a modern IAM solution that continuously challenges, verifies, and monitors its users, even within a perimeter- based network.

"If you've implemented security in the sense that you require authentication before access, you do validation, and you monitor the application," Abramovich says, "maybe without even knowing or meaning to do it, you've kind of already implemented some of the zero-trust principles."

Network segmentation isn't unique to zero trust but is essential to modern information security. Many organizations implement "micro-segmentation," chopping up the network into bite-sized pieces that will slow down all but the most determined attackers.

The modern network security challenge: How to secure today's perimeter-free enterprise

7© 2024 CyberRisk Alliance

https://www.scmagazine.com/ https://www.cyberriskalliance.com/

Robert Lowry, vice president of security at The Lifetime Value Co., agrees with that observation.

"When we start thinking about what zero trust means, it's almost the same as where we have a more complex application with lots of microservices and lots of different things going on," Lowry says. "If you're really following modern best practices these days, it'll become what we call zero trust without naming it zero trust."

IAM solutions, especially cloud-based ones, are excellent modern network-security tools regardless of whether an organization has implemented a zero-trust model. A robust IAM solution will authenticate and monitor users, provision and deprovision employees joining and leaving an organization, and log user activity so that other tools, such as an SIEM, can review it.

IAM solutions also work with other authentication schemes such as single-sign-on (SSO) or MFA. The most up-to-date ones can avoid using passwords altogether, replacing them with hardware keys or device-specific biometric-based passkeys.

Most importantly, identity has replaced the perimeter as the first line of defense. That's why MFA and password-less solutions have become so important, as credential compromise continues to be a crisis.

The devastating Change Healthcare ransomware attack of early 2024, for example, which cost medical providers hundreds of millions of dollars in lost billing revenue, has been linked to a remote-access portal that did not have MFA.

"A cloud environment is a lot more dynamic. You click a button, you have 10 new servers, so you need your security to also be very dynamic and adjust to it”

— Aviv Abramovich | Head of Security Services Product Management, Check Point

Automation, AI and machine learning

The wider world became aware of AI only in late 2022 with the public debut of ChatGPT, but information-security practitioners have been using automation, machine learning and AI for years in the forms of security orchestration, automation and response (SOAR) and static and dynamic application security testing (SAST and DAST) tools.

Automation is especially useful when it comes to cloud-based assets and cloud-based security tools. New virtual servers can be spun up in a minute, and virtual firewalls can be reconfigured just as quickly. In the cloud, you no longer need to install patches — you can just install an upgrade.

"If you need to make a change, you don't actually log on to the servers," says The Lifetime Value Co.'s Lowry. "You just deploy the new change. Tear down and replace. Same thing with patching. Don't patch, replace — you spin up something fresh."

The modern network security challenge: How to secure today's perimeter-free enterprise

8© 2024 CyberRisk Alliance

https://protect.checkpoint.com/v2/___https://www.scmagazine.com/topic/siem___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2Ojc1ZTU6YTU5ZWRmMDAxMTQzZmY5ZGI0MjlmMmYzYzM2MWY0MzZhOWVkNzg3NDg0MjRkNzkwYzY1YzhlZmY5N2VmN2RkNDpwOlQ https://protect.checkpoint.com/v2/___https://www.scmagazine.com/analysis/tech-giants-encouraging-adoption-of-hardware-based-auth-keys___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2OmRjYTg6NTg0YjZjZTE3ZTk3ODRhNzU2ODI4MWRmZmNmZGU4NThkMDVkZGQxNzk4ZDdkMzhlMzY0MzlkYzkxZjBjZmQ5NDpwOlQ https://protect.checkpoint.com/v2/___https://www.scmagazine.com/resource/how-passkeys-pave-the-way-for-passwordless-authentication___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2OmM2NDQ6NjE3YzM5MmEwNjZlZWI4YzUwY2JhNDM5OWQwODkxMmRkMTBjYTU1YTg5MTc2Mzk5NWNmN2IwMzBhMmUwZTJiMDpwOlQ https://www.scmagazine.com/news/change-healthcare-incident-caused-by-compromised-citrix-credentials https://www.scmagazine.com/resource/from-the-headlines-chatgpt-and-other-ai-text-generating-risks https://protect.checkpoint.com/v2/___https:/www.scmagazine.com/resource/what-is-dast-and-how-it-can-improve-web-application-security___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2OmI2MzA6MTgyY2U1NzIwZTJhMGM0MWE4ZDBiZmVkM2NlY2YwZDIxZTg0Njg2MTFjYjM5OWQ0M2U1NjkzNjc5NGE5MWI5MzpwOlQ https://www.scmagazine.com/ https://www.cyberriskalliance.com/

Automation is also tremendously useful when sifting through mounds of logs and other data looking for anomalies and threats. AI will only speed up those efforts, as it can learn as it goes and constantly incorporate new data into its training model.

"Using machine learning and deep learning, we were able to increase our accuracy in detecting and preventing new threats and reducing false positives considerably," says Check Point's Abramovich. "We had 90% less false positives and detected 40 to 50% more malicious activity."

The question is really whether AI will generate anything new, or just speed up what humans already do — for both good and bad.

John Isch, director of infrastructure solutions – Americas at Orange Business, thinks that AI might drive organizations to use fewer vendors.

"Each [security] vendor is developing AI within the confines of their product set, so the challenge faced by organizations who have disparate security infrastructure is in unifying the various AI instances," Isch points out. "This may end up to be THE reason enterprises migrate to a single-vendor SASE solution."

"Within our customer base, the process of modernizing security infrastructure is done with careful consideration over a long period of time.”

— John Isch | Director of Infrastructure Solutions – Americas, Orange Business

The modern network security challenge: How to secure today's perimeter-free enterprise

9© 2024 CyberRisk Alliance

https://www.scmagazine.com/ https://www.cyberriskalliance.com/

1 Inventory and evaluate your existing assets This involves workloads, databases, servers, cloud instances, endpoints and networking gear, obviously, but don't forget that employees are also assets — you'll need to determine which ones get which privileges.

5 Segment your network and implement robust monitoring and logging tools Segment your network if it hasn't been already and implement robust monitoring and logging tools if you don't already have them. "Number one [in network-security modernization] is to put in place some level of segmentation and monitoring," says Mihai. "At a minimum, segmenting some of the highest, most critical assets, particularly security technology for crown-jewel applications or critical applications."

Assess your security tools Are there any that can be repurposed for, say, a zero-trust model? Can you get rid of some? Do you have long-term service contracts that cannot be broken?

2

How to modernize your network security

As with most new deployments of information-security tools and models, modernizing your network security involves a fair amount of self-discovery, followed by due diligence on potential vendors and, finally, implementation. Here are the steps to follow:

Investigate potential vendors Ask them about the total cost of ownership, including training; about scalability and ease of use; about their tool's ability to work with your existing tools; and if they might offer bundles of different security tools. Use third-party reviews and assessments, such as Miercom's Zero Trust Platform Assessment. And not least, determine how these tools can help you.

4

Make a plan What do you need? What do you want? And what can you afford? Medium-sized and large organizations would benefit from implementing a zero-trust model, but for small companies, the cost of migration and retraining might not be worth it. Likewise, organizations that deal mostly with outside consumers might not benefit from a SASE/SSE model. Whatever you decide on, make sure that the company leadership is fully committed to the plan. And remember — no matter what their marketing may claim, no company offers a full off-the-shelf zero-trust implementation. "I think everybody who would say that they do, I would challenge that claim," says Check Point's Abramovich. Instead, see if what you already have can be put toward implementing zero trust.

3

The modern network security challenge: How to secure today's perimeter-free enterprise

10© 2024 CyberRisk Alliance

https://www.checkpoint.com/resources/report-3854/miercom-zero-trust-platform-assessment-2024?w=c778b https://www.checkpoint.com/resources/report-3854/miercom-zero-trust-platform-assessment-2024?w=c778b https://www.scmagazine.com/ https://www.cyberriskalliance.com/

Consider SASE or SSE if applicable For more on this, check out our guide to determining your SASE needs.

8

Begin the migration to zero trust You may want to implement a zero-trust pilot program in which only one part of the organization moves over. Once the lessons from that have been hammered out, migrate other parts of the organization one at a time. Go slowly and accept that a large organization might take years to complete a zero-trust migration.

9

Implement an IAM solution Cloud-based solutions offer the most flexibility and ability to work with legacy on-prem tools as well as cloud workloads. You cannot have zero trust without an IAM solution. "There are compa- nies that are very good at managing identities," says Abramovich. "You would use them as an identity [provider]. And you would use, let's say, Check Point for network security. You might use a third-party SIEM tool for consolidating and monitoring everything. "

7

Implement SOAR and AI-or machine-learning-based anomaly detection "[Make] some investment in anomaly detection at the network level," says Mihai. "Without having the ability to detect what's going on a network, somebody could presumably be there forever and take advantage once they gain access and be undetected for years."

6

Conclusion

For many organizations, it's difficult and complicated to gather and meld various vendor solutions into a harmonious whole. Fortunately, you can now find effective consolidated platforms that provide more modern, more secure, more flexible network-security architectures. The solution you choose may or may not be in the cloud, and it may or may not use SASE or AI, but it will certainly involve a zero-trust security model, whether you call it that or not.

"It's a philosophical question of what is the definition of zero trust, really," Abramovich said. "As long as you put security in place to mitigate risk, that's the core foundation of zero trust — mitigate your risk."

11

The modern network security challenge: How to secure today's perimeter-free enterprise

© 2024 CyberRisk Alliance

https://protect.checkpoint.com/v2/___https://www.scmagazine.com/resource/how-to-determine-sase-needs-specific-to-your-it-environment___.YzJlOmNwYWxsOmM6bzpiN2YwNGVmMTM5OGExZWE5YThjZmViNTVjMTM5OWJkZTo2OjgwZjA6ZjUyZDJlNWNlMzE5ZTgyMjE0ZDNhMjM3NTYyNDZjN2U0MTYzZjY0M2FjNjBkZTkxMTIxMGJlYjI3MmJhODA4NjpwOlQ https://www.scmagazine.com/ https://www.cyberriskalliance.com/

The state of identity: Resolving the tug of war between security and user experience

12© 2024 CyberRisk Alliance

MASTHEAD

EDITORIAL SVP OF AUDIENCE CONTENT STRATEGY

Bill Brenner | bill.brenner@cyberriskalliance.com

SALES CHIEF REVENUE OFFICER

Dave Kaye | dave.kaye@cyberriskalliance.com

DIRECTOR, STRATEGIC ACCOUNTS

Michele Guido | michele.guido@cyberriskalliance.com

SPONSORED BY

CyberRisk Alliance (CRA) is a business intelligence company serving the high growth, rapidly evolving cybersecurity community with a diversified portfolio of services that inform, educate, build community, and inspire an efficient marketplace. Our trusted information leverages a unique network of journalists, analysts and influencers, policymakers, and practitioners. CRA’s brands include SC Media, Security Weekly, ChannelE2E, MSSP Alert, InfoSec World, Identiverse, Cybersecurity Collaboration Forum, its research unit CRA Business Intelligence, the peer-to-peer CISO membership network, Cybersecurity Collaborative, the Official Cyber Security Summit, TECHEXPO Top Secret, and now LaunchTech Communications. To learn more, visit CyberRiskAlliance.com.

Check Point Software Technologies is a global leader in cyber security solutions, dedicated to protecting corporate enterprises and governments worldwide. For over 30 years, our mission has been to secure the digital world for everyone, everywhere. From pioneering stateful firewalls to our AI-powered, cloud-delivered security solutions, we are committed to safeguarding organizations with an industry-leading 99.8% prevention rate. Through our Check Point Infinity Platform, we provide cutting-edge solutions to defend against the most sophisticated cyber attacks. Our portfolio includes Check Point Harmony to secure the workforce, CloudGuard to secure the cloud, and Quantum to secure the network.

https://www.scmagazine.com/ https://www.cyberriskalliance.com/ https://www.checkpoint.com https://www.cyberriskalliance.com/ https://www.cyberriskalliance.com/

PREVENT THE NEXT CYBER ATTACK

ASSESS YOUR SECURITY POSTURE WITH A COMMITMENT-FREE ENTERPRISE SECURITY CHECKUP*

AI-powered and cloud-delivered security platform defends your network, cloud, and workspace. Protect what matters most.

SCHEDULE CHECKUP

LEARN MORE ABOUT OUR SECURITY SOLUTIONS

LEARN MORE

• Industry’s highest block rates against zero-day attacks1

• Top-rated zero trust security platform2

• Unified management for consistent network security and regulatory compliance across your enterprise

*View sample report

1Miercom Next Generation Firewall Security Benchmark 2024 2Miercom Zero Trust Platform Assessment 2024

SC-MEDIA-prevent-ad-FINAL.indd 1SC-MEDIA-prevent-ad-FINAL.indd 1 6/12/2024 1:17:12 PM6/12/2024 1:17:12 PM

https://pages.checkpoint.com/security-checkup.html?utm_source=cra-pr&utm_medium=advertising&utm_campaign=cm_onm_24q2_ww_all_corp-force-digital-aw_en-cra&utm_term=ebook&utm_content=checkup https://www.checkpoint.com/downloads/products/check-point-security-checkup-sample-threat-analysis-report.pdf https://www.checkpoint.com/quantum/next-generation-firewall/?utm_source=cra-pr&utm_medium=advertising&utm_campaign=cm_onm_24q2_ww_all_corp-force-digital-aw_en-cra&utm_term=ebook&utm_content=ngfw https://www.checkpoint.com/resources/items/miercom-2024-security-benchmark-infographic?w=1b737 https://www.checkpoint.com/resources/items/miercom-zero-trust-platform-assessment-2024?w=1b737 https://www.checkpoint.com/


Item Type: pdf