07:29 PM

End-User Security: SMBs Prefer Invisibility

Social media and mutating malware have changed the threat landscape, prompting smaller companies to list education and security users don't notice as top needs, Symantec found during the Endpoint Protection 12 public beta.

Strategic Security Survey: Global Threat, LocalPain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full slideshow)
IT pros at small and midsize businesses still want an antivirus program, but they don't want their end users to know it's there.

That was among the key takeaways from Symantec's public beta for Endpoint Protection 12, which ended Tuesday with input from roughly 5,500 businesses. Both the flagship and its corresponding Small Business Edition will be fully released on Wednesday. The client-side software platform currently counts around 175 million endpoints on its security watch.

The beta found and fixed some 500 unique defects, according to Hormazd Romer, Symantec's director of product marketing for infrastructure security. Romer said in an interview that performance feedback was paramount--not simply for the sake of speed, but because administrators don't want users complaining that their anti-malware program is bogging them down.

"[Administrators] definitely want to make sure they have the tools and the ability to do things that are transparent to the end user but increase their level of protection and security," Romer said. "[Users] shouldn't even know it's there until something potentially hazardous happens."

Part of that performance comes in the form of silence: Administrators have the option to install and manage SEP 12 in the background, without the user necessarily knowing it's even there. Scans can likewise run without any notifications or other interruptions. The program's latest version blends a mix of Insight reputation database and Sonar behavioral engine and marks a continued evolution from the traditional signature-based approach.

Symantec got a related--if somewhat unexpected--round of feedback from the beta that had nothing to do with feature sets or bugs: SMBs, in particular, asked for more help with educating employees about security risks.

"The SMB customers were often really surprised by how much the threat landscape has changed," Romer said. He listed social media risks and mutating malware as two security issues that aren't well-understood within the walls of some smaller businesses. "What we heard was: Do more with education."

According to Romer, Symantec will be investing more in user education--he wasn't able to offer details, but said such programs would be vendor-neutral.

The performance and education pieces speak to the human element of IT security, particularly as social media-borne attacks and other threats based on user error increase in frequency.

Romer said SMB beta users currently using a competing product also voiced concerns about the costs associated with switching vendors. Starting Wednesday, Symantec will knock 70% off the price tag of a three-year subscription for firms with fewer than 500 employees. Just over half of the beta testers indicated they used a security program from a different provider.

Existing customers should get a smoother upgrade ride than in the past. Romer acknowledged the transition between versions 10 and 11 was rocky for some companies, and the "silent" approach is applicable to the upgrade process as well.

"Quite frankly, four years ago it was a painful process," Romer said, adding that the move to SEP 12 should be much simpler. "The full version upgrade feels just like a maintenance update."

You can't afford to keep operating without redundancy for critical systems--but business units must prioritize before IT begins implementation. Also in the new, all-digital InformationWeek SMB supplement: Avoid the direct-attached storage trap. Download it now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
E-Commerce Security: What Every Enterprise Needs to Know
The mainstream use of EMV smartcards in the US has experts predicting an increase in online fraud. Organizations will need to look at new tools and processes for building better breach detection and response capabilities.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio