ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

SpyCloud Compass Reduces Ransomware Risk with Post-Infection Remediation

Solution addresses malware infections on managed and unmanaged devices to identify compromised users, devices, and applications

SpyCloud, the leader in operationalizing Cybercrime Analytics (C2A), today announced the launch of Compass, a transformative solution to help enterprises detect and respond to the initial precursors to ransomware attacks. Compass provides definitive evidence that data siphoned by malware infections is in cybercriminals’ hands and provides a comprehensive approach to incident response for malware infected devices, known as Post-Infection Remediation™. Application credentials and stolen cookies from infected employee and contractor devices are often used by ransomware operators and Initial Access Brokers (IABs) to identify targets and infiltrate corporate networks undetected.

As remote workers and contractors increasingly blur the lines between managed and unmanaged device usage, malware infections on employee-owned systems enable cybercriminals to sidestep traditional ransomware protection solutions, including endpoint protection. Every time an employee logs into work on an infected device, bad actors have an easy path to workforce applications used for single-sign on (SSO) authentication, remote access portals, virtual private networks, code repositories, accounting applications, and other critical business systems.

In the 2022 SpyCloud Ransomware Defense Report, 87% of organizations surveyed showed concern about infostealer malware on unmonitored devices creating entry points for ransomware. Even with this concern, most businesses allow employees to access corporate applications on unmanaged, personal devices, and rely on vendors and contractors with BYOD policies or lax controls on managed devices, extending the attack surface for adversaries to capitalize on.

Security Operations Center (SOC) teams can use SpyCloud Compass to identify when devices, applications, and users are compromised by malware, even if the infected device or business application falls outside of corporate oversight. Incident responders can visualize the scope of each threat at-a-glance, seeing all the necessary details needed to quickly remediate. This reduces the legwork of investigating the potential impact of a compromised device, enabling them to move quickly from detection to response.

With Post-Infection Remediation™, a comprehensive malware infection remediation approach, security professionals now have a series of steps they can include in their traditional incident response playbooks to properly mitigate opportunities for ransomware and other cyberattacks by resetting the application credentials and invalidating session cookies siphoned by infostealer malware.

“Once a piece of data is compromised by malware, that data doesn’t just go away – but many companies fail to fully realize the long-term significance to their ransomware risk,” said Ted Ross, CEO & Co-Founder of SpyCloud. “Compass was designed to solve this problem. It reduces the enterprise's exposure by arming the security team with knowledge of the infected devices accessing critical workforce applications. Without addressing these exposures, the door is open for attackers to access, steal, encrypt, and even wipe corporate data.”

SpyCloud’s solution stands alone with the capability to support Post-Infection Remediation and prevent cybercriminals from launching a full-blown cyberattack. Acting on the information cybercriminals have gained from an infostealer malware infection, security teams can now properly remediate at-risk entry points – significantly shortening the ransomware exposure window.

“The Post-Infection Remediation process is frequently overlooked when it comes to addressing malware,” Ross said. “Wiping the infection off a device may sever the connection with the criminal, but it doesn’t address the authentication and access data they’ve already stolen. Post-Infection Remediation is now a requirement for organizations looking to address the gaps in their ransomware prevention framework.”

SpyCloud Compass enables organizations to:

  • Reduce their risk of ransomware by identifying hard-to-detect malware infections that provide bad actors with entry points
  • Identify threats outside of corporate control, such as employees’ and vendors’ malware-infected personal devices that have been used to access workforce applications
  • Shorten incident response times when investigating the potential impact of an infected device
  • Mitigate long-term malware risks by taking incident response beyond standard device remediation
  • Illuminate previously unseen compromised assets including credentials and cookies for third-party applications like SSO, VPN, CRM, etc.
  • Focus on high-priority threats based on definitive indicators of malware-infected devices and exposed applications on corporate networks

To learn more about Compass and how SpyCloud helps protect businesses from ransomware with Post-Infection Remediation, visit https://spycloud.com/products/compass/.

To download SpyCloud’s Guide to Post-Infection Remediation, visit https://spycloud.com/lp/post-infection-remediation-guide.

About SpyCloud

SpyCloud transforms recaptured darknet data to protect businesses from cyberattacks. Its products operationalize Cybercrime Analytics (C2A) to produce actionable insights that allow enterprises to proactively prevent ransomware and account takeover, protect their business from consumer fraud losses, and investigate cybercrime incidents. Its unique data from breaches, malware-infected devices, and other underground sources also powers many popular dark web monitoring and identity theft protection offerings. SpyCloud customers include half of the ten largest global enterprises, mid-size companies, and government agencies around the world. Headquartered in Austin, TX, SpyCloud is home to nearly 200 cybersecurity experts whose mission is to make the internet a safer place.

To learn more and see insights on your company’s exposed data, visit spycloud.com.

“Once a piece of data is compromised by malware, that data doesn’t just go away – but many companies fail to fully realize the long-term significance to their ransomware risk."

Contacts

Recent Quotes

View More
Symbol Price Change (%)
AMZN  222.54
+0.00 (0.00%)
AAPL  274.11
+0.00 (0.00%)
AMD  207.58
+0.00 (0.00%)
BAC  55.33
+0.00 (0.00%)
GOOG  309.32
+0.00 (0.00%)
META  647.51
+0.00 (0.00%)
MSFT  474.82
+0.00 (0.00%)
NVDA  176.29
+0.00 (0.00%)
ORCL  184.92
+0.00 (0.00%)
TSLA  475.31
+0.00 (0.00%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.