Schließen
Schließen
Ihr Netzwerk von morgen
Ihr Netzwerk von morgen
Planen Sie Ihren Weg zu einem schnelleren, sichereren und widerstandsfähigeren Netzwerk, das auf die von Ihnen unterstützten Anwendungen und Benutzer zugeschnitten ist.
          Erleben Sie Netskope
          Get Hands-on With the Netskope Platform
          Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
            Ein führendes Unternehmen im Bereich SSE. Jetzt ein führender Anbieter von SASE.
            Ein führendes Unternehmen im Bereich SSE. Jetzt ein führender Anbieter von SASE.
            Netskope debütiert als Leader im Gartner ® Magic Quadrant ™ für Single-Vendor SASE
              Generative KI für Dummies sichern
              Generative KI für Dummies sichern
              Learn how your organization can balance the innovative potential of generative AI with robust data security practices.
                Modern data loss prevention (DLP) for Dummies eBook
                Moderne Data Loss Prevention (DLP) für Dummies
                Get tips and tricks for transitioning to a cloud-delivered DLP.
                  Modernes SD-WAN für SASE Dummies-Buch
                  Modern SD-WAN for SASE Dummies
                  Hören Sie auf, mit Ihrer Netzwerkarchitektur Schritt zu halten
                    Verstehen, wo die Risiken liegen
                    Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
                        Die 6 überzeugendsten Anwendungsfälle für den vollständigen Ersatz älterer VPNs
                        Die 6 überzeugendsten Anwendungsfälle für den vollständigen Ersatz älterer VPNs
                        Netskope One Private Access is the only solution that allows you to retire your VPN for good.
                          Colgate-Palmolive schützt sein "geistiges Eigentum" mit intelligentem und anpassungsfähigem Datenschutz
                          Colgate-Palmolive schützt sein "geistiges Eigentum" mit intelligentem und anpassungsfähigem Datenschutz
                            Netskope GovCloud
                            Netskope erhält die FedRAMP High Authorization
                            Wählen Sie Netskope GovCloud, um die Transformation Ihrer Agentur zu beschleunigen.
                              Let's Do Great Things Together
                              Die partnerorientierte Markteinführungsstrategie von Netskope ermöglicht es unseren Partnern, ihr Wachstum und ihre Rentabilität zu maximieren und gleichzeitig die Unternehmenssicherheit an neue Anforderungen anzupassen.
                                Netskope solutions
                                Netskope Cloud Exchange
                                Netskope Cloud Exchange (CE) provides customers with powerful integration tools to leverage investments across their security posture.
                                  Technischer Support von Netskope
                                  Technischer Support von Netskope
                                  Überall auf der Welt sorgen unsere qualifizierten Support-Ingenieure mit verschiedensten Erfahrungen in den Bereichen Cloud-Sicherheit, Netzwerke, Virtualisierung, Content Delivery und Software-Entwicklung für zeitnahen und qualitativ hochwertigen technischen Support.
                                    Netskope-Video
                                    Netskope-Schulung
                                    Netskope-Schulungen helfen Ihnen, ein Experte für Cloud-Sicherheit zu werden. Wir sind hier, um Ihnen zu helfen, Ihre digitale Transformation abzusichern und das Beste aus Ihrer Cloud, dem Web und Ihren privaten Anwendungen zu machen.

                                      The Winter Wonderland of Cyber Threats

                                      Dec 12 2023

                                      It’s the season for mince pies, tinsel and, of course, holiday shopping. I am in the Middle East so temperatures are quite pleasant for a mall stroll while shopping for family gifts, but it’s certainly odd hearing Mariah Carey being played and seeing fake snow on Christmas trees when it’s 25 degrees outside. While I prefer to do my shopping in person, around the world the majority of festive shopping happens on mobiles and laptops. In fact, over the five-day holiday weekend from Thanksgiving Day through Cyber Monday this year, two-thirds of US shoppers did some retail spending online, according to the National Retail Federation. With this flurry of consumer spending comes a tidal wave of emails and messages offering holiday discounts and updates on package deliveries. 

                                      Unfortunately, cyber criminals anticipate this surge of on-line activity, and every year they seize on the opportunities to dupe unassuming victims with phishing tactics, using the promise of one-off time-bound discounts. Vigilance is crucial in this period as threat actors push forward with attacks using well known brands as cover. But it isn’t just the shoppers who need to be alert. With every online purchase, retailers receive new data over which they have to apply stringent protections. Payment data, personally identifiable data… the holiday shopping period creates a honey pot within retail businesses and threat actors swarm around it like bees, desperate to steal the sugar.

                                      Netskope’s recent Threat Labs Report took a deep dive into the retail sector. Using the report’s key learnings, here are the top threats impacting retail businesses this festive season.

                                      1. It’s no surprise that cloud apps are a top target for cyber criminals. On average, professionals in the retail sector engage with around twenty cloud apps every month, with the top 1% of those using a staggering 85 apps monthly. 
                                      1. Retail is unique compared to other industries, where often Microsoft OneDrive is both the most popular app used and the most popular app for malware downloads. Instead Google Drive, Google Gmail, and WhatsApp are among the top spots for malware in retail (while OneDrive continues to be the most popular app used in general). 
                                      1. Using these channels, Trojans are the primary attack mechanism. Google Drive, for example, can be used by attackers to host malware and share it with victims, or occasionally, a user may accidently upload an infected file to a shared location that will spread quickly to everyone with access. Often, Trojans are used as the initial tool to trick the workforce in retail businesses into downloading other malware payloads, such as infostealers, backdoors, and ransomware, that will then do the real damage. Popular malware families—such as Guloader and Remcos—often aim to steal banking information, credentials, as well as personal and credit card information. 

                                      So what can retail businesses do to protect themselves?

                                      1. Over the winter holidays, the best advice is to always maintain vigilance. This means security teams should ensure they are inspecting all downloads from the web and trusted cloud apps, to prevent malware infiltrating networks, so use solutions such as our Netskope NG-SWG with a Threat Protection policy to seamlessly analyse the web and cloud traffic for you. 
                                      1. When it’s necessary for employees to visit high-risk websites (such as new domains or cloud apps with no or low trust scores), make use of Remote Browser Isolation to give users access to a site via a remote browsers session instead of a user’s usual endpoint device for added protection. 
                                      1. For damage mitigation, Intrusion Prevention Systems can be set up in advance of a breach to capture and block common traffic patterns for malicious activity, such as command and control traffic associated with popular malware. By disallowing this communication, attackers are limited in their ability to perform additional actions after a successful violation.
                                      1. Finally, take the opportunity to reinforce your workforce’s cyber education, highlighting the importance of scrutinising emails and messages, and thinking before clicking attractive, yet deadly, links. Similarly, remind users of policies around personal use instances on company devices. It is well worth making a New Year’s resolution to stop relying on annual security training and instead make use of technology (like Netskope) that can enable just-in-time user coaching, helping the workforce navigate appropriate behaviours in the moment that threats occur, rather than relying on them to retain best practice methods over 12 months between mandatory courses. 

                                      Unfortunately, all industries are subject to cyber threat, and retail is no exception. Throughout the busiest period in the retail industry’s year (holiday shopping, then well into the New Year sales), it’s now more important than ever to stay informed about the latest threats and protect ourselves against them wherever possible.

                                      author image
                                      Steve Foster
                                      Steve Foster has spent his career working to bridge the gap between business need and technical solution. Steve comes from networking, with 20 years of experience.
                                      Steve Foster has spent his career working to bridge the gap between business need and technical solution. Steve comes from networking, with 20 years of experience.

                                      Bleiben Sie informiert!

                                      Abonnieren Sie den Netskope-Blog