×

Empower Your Business with Innovation

  • Shop By Category
  • Deploy endpoint security everywhere

    Posted by HSSL Technologies on Aug 17th 2021

    This article is part of a series that aims to educate cyber security professionals on the lessons learned by breach victims. Each lesson will include simple recommendations, many of which do not require organizations to purchase any tools.

    There is a thinking in parts of the IT world that there are some systems that simply don’t need endpoint security. Maybe they are air-gapped or have no internet access. Maybe they are development systems or have nothing important running on them. I’ve even come across organizations that were happy to let their endpoint security subscriptions lapse – they didn’t think it was adding any value.

    The mindset comes from a long history (in the InfoTech world anyway) of endpoint security being designed to stop a piece of malware, should it somehow land on that system. So, if the system was isolated, easily restored, unimportant or “we’re always really careful” then protection wasn’t required.

    Some consider user workstations/laptops as less important than servers, so only protect servers. In reality, according to the Sophos 2021 Active Adversary Playbook, 54% of attacks involved unprotected systems.

    Both endpoint security and the way attacks work have changed dramatically in recent times. Threat actors have developed sophisticated ‘living off the land’ tactics where they use your own administration tools (e.g. PowerShell), scripting environments (e.g. JavaScript), system settings (e.g. Scheduled Tasks and Group Policy), network services (e.g. SMB and Admin Shares and WMI) and valid applications (like TeamViewer, AnyDesk or ScreenConnect) to avoid having to use actual malware to achieve their goals. What were considered Nation State and Advanced Persistent Threat (APT) techniques are now used by even the most unsophisticated threat actors.

    The adversaries’ goal, however, is still largely the same: to make money. This could be by deploying ransomware (often following data exfiltration and backup deletion to make paying the ransom more compelling), cryptocurrency mining, obtaining personally identifiable information (PII) to sell, or industrial espionage.

    In response, endpoint security has evolved and now detects and prevents malicious behaviors while providing detailed visibility, context and threat hunting tools. This evolution of protection is wasted if not deployed. Unprotected systems are blind spots.

    Top

    Don't Miss Out

    Sign up now to receive exclusive perks and unique promotions directly to your inbox.

    Culver Drive, 340 Irvine, CA 92604

    Tel 888.988.5472

    Copyright © HSSL Technologies. All Rights Reserved. HSSL Technologies are registered trademarks of HSSL Technologies. All other trademarks and registered trademarks brands are the sole property of their respective owners.

    HSSL Technologies (US) © 2026. All Rights Reserved.
    american expressdiners clubdiscovermaestromasterpaypalvisa