Tuesday, 13 March 2012

Accellion Unveils kitedrive - Dropbox for the Enterprise

Accellion today announced Secure Mobile File Sharing solutions for enterprises, businesses and individuals that include kitedrive™ file synchronization capabilities to enable business users to be securely connected to their files anytime, anywhere. Accellion is filling an important business need by addressing security concerns related to BYOD, and the use of free consumer file sharing applications within enterprise organizations. Included within the Accellion Secure Mobile File Sharing solutions is kitedrive sync, a new file sharing capability from Accellion, that enables business users to synchronize files across devices, including iPad, iPhone, Android and BlackBerry, for secure anytime, anywhere access to information, while at the same time providing IT and Security teams management over mobile access to content.
“There are real security concerns with the use of free mobile file-sharing and synchronization platforms by business users who need anytime access to enterprise data,” said Chris Hazelton, Research Director, Mobile and Wireless at 451 Research. “In place of consumer-based offerings, IT needs to provide alternatives that offer control and management capabilities to protect confidential information. Providing these enterprise-grade services to government and business users, especially those in regulated industries, will ensure much-needed awareness and control of corporate data that moves across the multiple devices that employees use today.”
As a welcome enterprise-class alternative to free consumer-grade file sharing and syncing solutions such as Dropbox, Accellion provides enterprise, business and individual users with ease of use and simplicity in addition to increased security features, including most importantly IT and Security controls and management of users and privileges to address mobile security.
“The influx of personal smartphones and tablets into enterprise organizations is threatening information security as IT and Security teams scramble to address BYOD and Mobile Security,” said Yorgen Edholm, CEO of Accellion. “Balancing employee demand for increased mobile access while ensuring enterprise-class security and control is now possible with Accellion Secure Mobile File Sharing Solutions.”
“Everything we do is based on a collaborative, team-based approach, so we needed a solution that supported this philosophy,” said Noman Ahmed of Halsall Associates. “Now, we don’t have to think twice about how to share documents. Accellion is the go-to source for all external interactions. We are looking forward to implementing Accellion's new sync features especially with mobile devices."
The Accellion Mobile File Sharing solutions all include Accellion Mobile Apps and the new Accellion kitedrive sync capability that provides secure cloud storage, file sharing and sync for business users. In addition, the Accellion Mobile File Sharing Solution for Business provides secure collaboration features including secure workspaces, commenting, notifications, versioning, and secure uploads and downloads. Accellion Mobile File Sharing for Business can be seamlessly upgraded to the Enterprise solution allowing deployment of more advanced enterprise file sharing features including private, hybrid cloud deployment, LDAP/AD integration, SAML/SSO, DLP integration and Archiving.
• Accellion Mobile File Sharing for Individuals: Single user with 2GB cloud storage free
• Accellion Mobile File Sharing for Business: 5-500 users with 1,000GB cloud storage
• Accellion Mobile File Sharing for Enterprise: 500+ users with unlimited cloud storage (public, private, hybrid cloud) enterprise options include: Archiving, DLP Integration, SFTP, LDAP/AD integration

Monday, 5 March 2012

A New Angle on Content Control


American companies with 1000+ employees each hold more data than the U.S. Library of Congress; approximately 293 billion emails are exchanged globally every day while Facebook users share 30 billion pieces of content every month.
No one said information management and protection was easy. It’s human nature to want to break things down into more manageable pieces, but reducing data control and protection to an inbound threat issue is a classic case of shooting alligators when what you’re really there to do is drain the swamp.
Managing information in today’s business environment has become increasingly complex: Data leakage is a critical issue for CIOs. Companies are hitting the headlines for all the wrong reasons, and human error is one of the biggest culprits. With many organisations focusing on in-bound threats, there’s a genuine risk that vulnerability inside company walls will be overlooked. As Deloitte’s 2011 Global Security Survey has pointed out, ‘external attacks get most of the headlines, but internal security risks are just as onerous.”
It’s time for a new angle on content control.
Communications tools like email and social media have become an almost reflexive thing for end users – combined with easy access to sensitive information, it’s a heady mix that can spell trouble for those charged with preserving the integrity and security of data. Stopping and blocking might seem like the easiest route to take, but this doesn’t reflect the realities of the way we communicate and do business today. To really protect organisational IP and other high-value information assets, monitoring the data leaving the network is just as important as watching what’s coming in.
There’s no patch for irresponsible or careless behaviour, but you can control the consequences. Technology that recognises the difference between an innocent Tweet and potentially damaging data sharing can be automated to prevent users from engaging in risky behaviours without cramping their style as ambassadors for the company brand online. Similarly, context-aware content controls can help guard against accidental data leakage via email – either through automating the decision to encrypt any data that meets specific organisational requirements or inserting an extra “Are you sure you want to send that?” step into the email process when certain kinds of information are being shared.
As companies increasingly understand that inside risk is as serious a concern as outside threats, context-aware content management plays a key role in ensuring that threat doesn’t impede your capacity to communicate and get on with business. Tackling the obvious risks – i.e. shooting alligators – without addressing the broader issues of information explosion and human error (the swamp) is setting yourself up for failure. Sooner or later, you’re going to run out of bullets. And the swamp will still be there.
by Alyn Hockey

Don’t let BYOD turn into “BYOR” in your network


BYOD (Bring Your Own Device) seems to be the dominant theme for 2012 in the Wi-Fi infrastructure and security space. As people increasingly bring in personal smartphone devices on the enterprise premises, the network/security administrators are grappling with the security implications. Given how engaging the new smartphone and tablet apps are, conflict arises between the users’ desire and the network/security administrators’ intentions. You need to ensure that this conflict does not turn BYOD into BYOR (Bring Your Own Rogue AP)!
Peep into history
This is similar to what happened 5 years ago when laptops started to embed Wi-Fi radios, but organizations had deployed only spotty Wi-Fi coverage, often of the experimental type. Employees would often not get adequate Wi-Fi signal in their offices and they would be prompted to bring in Wi-Fi access points of their own and connect them into the enterprise LAN jacks, often with unencrypted wireless links and with default wireless configurations. That is how the rogue AP threat of the unassuming user type came into being. Administrators became concerned that some open AP showing up on the Wardriving maps of their area could in fact be connected in the corporate networks that they manage. This history can repeat itself with BYOD!
Employees can install rogue APs for unrestricted smartphone use
The BYOD user, frustrated with the smartphone usage controls on the managed Wi-Fi access points, may bring in a personal access point and plug it into the enterprise LAN jack to be able use the smart mobile device in the office without restrictions. Not only will this result in the violation of the corporate smartphone use policy, but as a side effect, will expose corporate network to outsiders through the rogue access point. The urge to connect rogue access point can be even more in the no-Wi-Fi environments.
Visitors can install rogue APs for high-speed, free Internet for their smart mobile devices
Another trigger to install rogue APs could come from visitors, contractors, maintenance personnel, etc. on the enterprise premises, who may want to connect their smartphone devices to the Internet and may install their own APs on the enterprise network without administrator knowledge or permission. Of course, the smartphones can work on the 3G/4G network, but the user experience is way too good with Wi-Fi and it is free. Apple even sells a product called AirPort Express which is 802.11n Wi-Fi access point not larger than size of a power plug, designed for plug and play portability, and use with iPhones, iPods and iPads. Anything Apple sells, does get used a lot; I don’t think there can be any debate about that.
Retail networks
Highly distributed nature of retail networks makes security monitoring difficult. The local staff at the store locations will invariably carry smartphone devices on them (iPhones, gaming consoles, etc.) and thus will be incented to use them despite the corporate policy. Such staff can install rogue APs in stores on retail networks, thereby violating corporate policy and also adversely affecting PCI (Payment Card Industry) compliance which has explicit requirements for the rogue AP prevention.
BYOD security as a whole has many aspect to it, ranging from installing security agents on the IT assigned smartphone devices to deploying access controls in the Wi-Fi infrastructure to prevent personal mobile devices from connecting to the managed Wi-Fi network assests. However, the more difficult you make it to use smartphone device on the enterprise facility through the managed Wi-Fi network, the bigger catalyst it is for rogue APs to be installed on the network. Hence, effective rogue AP detection and containment also becomes an important component of the comprehensive BYOD security.
by Hemant Chaskar

Wednesday, 22 February 2012

Accellion, BoxTone, in a “Healthy” Partnership


Until recently, the thought of doctors using a mobile device to remotely monitor the health condition of a patient sounded like a work of science fiction. In fact, the potential benefits that mobile devices could provide the healthcare community have been discussed since the late 90s. With the recent innovation of powerful and easy to use mobile devices and innovative apps it was only a matter of time until the medical community joined the mobile revolution.
The uses of mobile technology in the healthcare sector seem limitless. The ability for medical professionals to access apps that provide up-to-date information about medical news, tools, procedures, and trends across multiple specialties keeps medical pros well informed. The ability for a doctor to send patient x-rays to a specialist for diagnosis using a mobile device or writing and then sending a prescription to the patient’s pharmacist is remarkable.
Currently, there are 17,000 healthcare applications available in the major app stores. Unfortunately, as more and more traditional healthcare providers join the mobile revolution they are using unmanaged, untracked, free file storage and file sharing apps, in direct violation of federal mandates such as HIPAA. The increased use of mobile devices, file sharing, and collaboration across multiple devices, tablets, and applications has healthcare IT professionals searching for secure solutions.
The idea of securing patient data anywhere, anytime is one of the reasons why Accellion announced a partnership  with BoxTone today. Linking the BoxTone EMM solution with Accellion’s secure file sharing solution ensures healthcare IT can instantly secure, manage and support thousands of mobile employee devices and apps, while retaining complete control over access and security of confidential document- and file-based patient information.
Healthcare professionals can learn more about the secure mobility solution offered by BoxTone and Accellion in Las Vegas at HIMSS 2012 Booth 12928 Kiosk #13 on February 20-22 in the Mobile Health Knowledge Center.
by Ryan Swindall

Tuesday, 21 February 2012

BYOD and WPA2 – not made for each other


As the BYOD (Bring Your Own Device) tide rises, the  network and security admins wonder if their existing Wi-Fi infrastructure security will hold on. In particular, will WPA2 with PEAP, which is pretty much the norm for the Wi-Fi infrastructure security in the enterprise networks today, continue to be adequate? WPA2 with PEAP is simple enough, still strong enough, and has served the enterprise Wi-Fi security needs very well in the past several years. The forthcoming BYOD revolution however pops a new challenge for WPA2 and will require additional thinking on part of the network and security admins about how to complement PEAP to address some of the BYOD security issue. This new challenge comes from the ease with which people can bring in personal mobile devices on the enterprise premises and connect them to the WPA2 enterprise Wi-Fi network without administrator knowledge or help.
Quick rundown on how WPA2 with PEAP works
In WPA2 with PEAP, the security handshake starts with the authentication server sending the server certificate to the client. The client is “supposed” to check the validity of the certificate to ensure that it is connecting to the legitimate network. If you check your Windows laptop PEAP configuration, the certificate check is ensured by selecting the “validate server certificate” checkbox. After the server certificate check passes, the client and the server establish an encrypted TLS tunnel between them. Once the encrypted tunnel is up, the client sends username and password to the server to get entry into the network.




PEAP certificate check is no requirement for personal mobile devices

With respect to the description above, if you did not check the “validate server certificate” option in the Windows PEAP configuration, the server certificate check is ignored. Then, it is also not essential to put in the server CA certificate in the client for the certificate checking. With the smart mobile devices also, the certificate check option is off by default. In Android, the default value for the certificate is ”unspecified” (and the device does not even throw any warning about it) and in iOS you have to simply accept a warning indicating that the certificate verification has not been done (who looks at the warnings anyway, particularly those which one doesn’t understand). The result? Users can simply put in their WPA2 usernames and passwords (which they know from their laptops) in any personal Android, iPhone, or any other device for that matter, and connect that device to the enterprise Wi-Fi. No need to call help desk! It is not a good idea to allow indiscriminate connections of personal mobile devices to the corporate networks assets, there can’t be much disagreement about that.
WPA2 can be complemented with “device identification” to solve the above problem
WPA2 can give good user authentication capability, but does not give device identification capability. Hence, when the users log in using their credentials on different devices (including the personal mobile devices), WPA2 can’t stop them from connecting. You will need ability for the device identification in addition to the user authentication to solve this problem. With the device identification capability in place, administrators can then set up policies on what devices the users can connect from and block personal mobile devices from connecting to the WPA2 network, even if users copy credentials from the IT assigned authorized devices to the personal devices.
Device identification in AirTight WIPS and AirTight Wi-Fi access points
AirTight Networks WIPS and Wi-Fi access points both provide the ”device identification” capability. They can fingerprint the device behavior attempting connection to the enterprise Wi-Fi and identify the type of the device. Now administrator can set up policy rules on what devices to allow and what devices to block. On any blocked device, administrator can do drill down including location tracking and then decide to leave it blocked or put in the allow list. This facilitates monitoring and controlling personal mobile devices attempting connection to the enterprise Wi-Fi network and nicely complement WPA2.

by Hemant Chaskar



Monday, 20 February 2012

The information management payoff


If Metcalfe’s Law shows that the value of any communications network increases in direct proportion to the number of connected users, Murphy’s Law suggests it’s only a matter of time before one of those connected users does something to compromise the integrity of the information being exchanged.
One significant lesson to be learned from any data breach incident is the high cost of human error. In too many cases, failure to comply with information privacy legislation or the leaking of sensitive data boils down to any organisation’s capacity to get a firm grip on exactly who is handling their data – and why.
Incredible as it may seem, many organisations seem to have tighter control over the processes for re-stocking their global stationery cupboards than they do for how, when, why and by whom sensitive information should be used and shared. Small wonder, then, that CompTIA’s IT Security in the Workforce study found that one in five organisations say they ‘definitely’ experienced sensitive data loss in 2011, with 32 per cent saying it was ‘likely’ that they had done so.
Nailing down all your company’s information seems like an onerous task. But there are simple steps any organisation can take to reduce the risk of human error without shutting down communications. In the case of misdirected email – a leading cause of data leakage - organisations can use deep content inspection and true file type analysis to establish the sensitivity or integrity of any information before allowing it to be exchanged. Based on company-defined policies and settings, certain types of information can be encrypted automatically, without requiring any intervention by the user.
Organisations can take the extreme approach of configuring email gateways to quarantine all outbound email, forcing users to think twice before and after they’ve hit the send button. Or they can inject flexible controls into the equation and only quarantine mails that match specific criteria, such as those with attachments, messages containing credit card numbers or going to certain addresses. By diverting potentially sensitive content to a personal message manager portal, senders can review messages, releasing them only when they’re absolutely certain it’s appropriate.
These approaches do add an extra step to the email sending process, but it’s a short one and the payoffs in terms of data protection are significant. As the UK’s Information Commissioner’s (ICO) head of enforcement, Stephen Eckersley, has said, “One of the most basic rules when disclosing highly sensitive information is to check and then double check that it is going to the right recipient.”
Just this week, it was revealed that the ICO has issued over £1m in fines for data breaches since April 2010. New EU directives on data privacy will see penalties of up to 2 per cent of global annual turnover for organisations that breach data regulations. Globally, some of the world’s most respected brands have found themselves in the spotlight for all the wrong reasons; financial penalties aside, the reputational damage that follows in the wake of a data breach can linger long after any fine has been paid.
That’s a heavy price to pay for an errant click of the ‘attach file’ or ‘send’ button.
by Nick Peart


Friday, 17 February 2012

Customer Spotlight: Pepperdine University Gives Accellion Top Marks

Accellion In Action: Pepperdine Secures Copier Files
When Pepperdine decided to implement a university-wide copier replacement program, the mission was to make staff and students’ lives easier. With 90 copiers across four campuses, individuals could scan documents as needed, convert files to PDFs, and send them to an email account. Sounds great, right? But, the big question facing IT was – just how secure is the process?
For Pepperdine, all documents needed to be properly encrypted, keeping financial and other personal information out of the wrong hands and enabling the university’s clinics and counseling centers to comply with HIPAA regulations. But, the encryption needed to happen behind the scenes, as the university recognized that if the new copiers weren’t easy to use, they simply wouldn’t be used by students.
With Pepperdine already using Accellion Secure File Transfer to send and receive large documents – powering much of the university’s communications – the university decided to also use Accellion to support its copier rollout. How? Users simply scan desired documents, the Accellion SMTP Satellite forwards the file attachments to the Accellion appliance, and once users return to their PCs, they’ll have a secure link waiting with the scanned items. Users don’t have to do anything new – a huge perk. Plus, with all documents sent through the appliance, the built-in security aligns with the university’s HIPAA compliance practices.
“When you have an IT solution in place that can be used to support and secure other key business operations, it’s a huge win,” said Michael Lucas, CTO with Pepperdine University. “Our users know – and like – Accellion Secure File Transfer, so extending the product to our new copiers was a no brainer.”
Click here to read the full case study
by Ryan Swindall