Product Overview | Shut Down Phishing Attacks with Device Posture Security

Product Overview | Shut Down Phishing Attacks with Device Posture Security

This product overview explains how Device Posture Security within Harmony SASE protects hybrid and remote workers by ensuring only secure devices can access corporate resources. Learn how it prevents phishing attacks by enforcing device compliance and integrates with Zero Trust and DNS filtering for enhanced network security. Download the product overview now.

Product Overview | Shut Down Phishing Attacks with Device Posture Security

SHUT DOWN PHISHING ATTACKS WITH DEVICE POSTURE SECURITY

2SHUT DOWN PHISHING AT TACKS WITH DE VICE POSTURE SECURIT Y

Protect Hybrid and Remote Workers With Device Posture Security Many employees work several days per week from home or outside of the office. This shift to hybrid work dramatically increases your organization’s attack surface and makes a breach more likely.

User credentials stored on devices that regularly access sensitive organizational data and resources are prime targets for phishing attacks. The 2023 Verizon Data Breach Investigations Report found that stolen credentials accounted for 49% of breaches, double the rate caused by ransomware (24%).

To address this growing threat and bolster the protection of network resources, mobile devices, and remote workers, organizations are now deploying device posture security. This enables IT administrators to allow only devices that comply with specific security policies to connect to the network.

When devices pass a security inspection - which checks for data/items installed on the device such as files, certificates, or registry keys - the corporate network is protected from phishing attacks that rely on stolen usernames and passwords. Even if an employee clicks on a phishing link in an email, compromised website, or elsewhere, hackers could not reuse the stolen credentials because their device would not meet the security requirements needed to access corporate resources.

When Does Your Organization Need Device Posture Security? • If you have remote or hybrid workers • If you want to see each device’s security status • If you want to ensure that all company devices are using up-to-date security software

Harmony SASE’s Device Posture Check Feature Enhances Network Security Device Posture Check (DPC) is a core feature of Harmony SASE Private Access, which enhances network security by ensuring that employees can only connect to network resources using devices that comply with security policies.

Prevents Malicious Access & Attacks It prevents malicious access and phishing attacks by automatically denying access to insecure or unknown devices at login and can continually verify device compliance at predetermined intervals.

3SHUT DOWN PHISHING AT TACKS WITH DE VICE POSTURE SECURIT Y

Complements ZTNA and DNS The rules or policies of DPC complement the other crucial security and networking features present in Harmony SASE Private Access, such as encrypted tunneling, multi-factor authentication (2FA), Zero Trust Network Access, and DNS filtering.

Eases Device Monitoring & Management Device Posture Check maintains an up-to-date inventory dashboard of devices, including access history and device details. The solution also provides detailed reports on employee connections to the network and changes to device health. In addition, a drill-down view provides detailed information regarding failed posture checks for follow-up.

Profiles Simplify Device Posture Management For faster administration of users and their devices, Device Posture Check supports profiles for groups or individuals. IT managers then apply device posture requirements in order to grant network access. For example, an administrator who wants to enforce proper device posture for salespeople who use macOS would create a Posture Check Profile for the sales team. They would then select macOS as the appropriate operating system and then specify the profile requirements such as endpoint protection software and a valid device certificate. If the user device meets the criteria, access will be granted. If not, they will be denied access, and the access failure will be logged for potential review.

4SHUT DOWN PHISHING AT TACKS WITH DE VICE POSTURE SECURIT Y

Applications

Mac / Windows Endpoint protection

Endpoint protection

Mac / Windows

Device Posture Check Rule

Infrastructure Database

Certificate: DNBA9773

Certificate: none Harmony SASE

IT teams can create profiles for groups of users on Windows, Mac, Linux, iOS, or Android and then enforce the presence of multiple security elements for granting access to the network resources. These include:

• Antivirus: Verify the presence of your organization’s preferred antivirus software. • File-Exists: Verify the presence of a specific file in a specific path. • Disk Encryption: Verify that the OS hard drive is encrypted. • Certificate: Verify that a specific certificate is installed on the device

(in the local Windows CA store or macOS Keychain). • Process Running: Verify that a specified process

(or antivirus program not in the antivirus dropdown) is running on the device. • Registry: Verify that a specific registry key exists in the Windows Registry. • Windows Security Center: Verify the status of the selected Firewall, Antivirus, or Windows Security

Center is showing as “Good”. • Active Directory Association: Verify that the user’s “logon domain” matches what is specified in

the rule (Windows only). • Operating System Version: Verify that the device is using an accepted version.

Device Posture Security: An Essential Part of Defense in Depth Device posture security—and Harmony SASE Device Posture Check—offer a critical layer of network security against cybercriminals. Even if a phishing attack results in the theft of an employee’s login information, Device Posture Check will prevent the use of stolen credentials to access corporate networking resources or to install ransomware.

5SHUT DOWN PHISHING AT TACKS WITH DE VICE POSTURE SECURIT Y

Meet Harmony SASE

The internet is the new corporate network, leading organizations to transition to SASE. However current solutions break the user experience with slow connections and complex management.

Harmony SASE is a game-changing alternative that delivers 2x faster internet security combined with full mesh Zero Trust Access and optimized SD-WAN performance—all with an emphasis on ease-of-use and streamlined management.

Harmony SASE enables any business to build a secure corporate network over a private global backbone in less than an hour. The service is managed from a unified console and is backed by an award-winning global support team that has you covered 24/7.

To learn more, visit https://www.checkpoint.com/harmony/sase/ or schedule a demo.

© 2024 Check Point Software Technologies Ltd. All rights reserved.

2x Faster Internet Security | Full Mesh Private Access | Secure SD-WAN

Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599

U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391

www.checkpoint.com

https://www.checkpoint.com/harmony/sase/ https://www.perimeter81.com/demo-cp?utm_source=p81&utm_content=WPR&utm_medium=PDF&utm_campaign=harmony_sase_healthcare


Item Type: pdf