Risk
7/5/2011
07:29 PM
50%
50%

End-User Security: SMBs Prefer Invisibility

Social media and mutating malware have changed the threat landscape, prompting smaller companies to list education and security users don't notice as top needs, Symantec found during the Endpoint Protection 12 public beta.

Strategic Security Survey: Global Threat, LocalPain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full slideshow)
IT pros at small and midsize businesses still want an antivirus program, but they don't want their end users to know it's there.

That was among the key takeaways from Symantec's public beta for Endpoint Protection 12, which ended Tuesday with input from roughly 5,500 businesses. Both the flagship and its corresponding Small Business Edition will be fully released on Wednesday. The client-side software platform currently counts around 175 million endpoints on its security watch.

The beta found and fixed some 500 unique defects, according to Hormazd Romer, Symantec's director of product marketing for infrastructure security. Romer said in an interview that performance feedback was paramount--not simply for the sake of speed, but because administrators don't want users complaining that their anti-malware program is bogging them down.

"[Administrators] definitely want to make sure they have the tools and the ability to do things that are transparent to the end user but increase their level of protection and security," Romer said. "[Users] shouldn't even know it's there until something potentially hazardous happens."

Part of that performance comes in the form of silence: Administrators have the option to install and manage SEP 12 in the background, without the user necessarily knowing it's even there. Scans can likewise run without any notifications or other interruptions. The program's latest version blends a mix of Insight reputation database and Sonar behavioral engine and marks a continued evolution from the traditional signature-based approach.

Symantec got a related--if somewhat unexpected--round of feedback from the beta that had nothing to do with feature sets or bugs: SMBs, in particular, asked for more help with educating employees about security risks.

"The SMB customers were often really surprised by how much the threat landscape has changed," Romer said. He listed social media risks and mutating malware as two security issues that aren't well-understood within the walls of some smaller businesses. "What we heard was: Do more with education."

According to Romer, Symantec will be investing more in user education--he wasn't able to offer details, but said such programs would be vendor-neutral.

The performance and education pieces speak to the human element of IT security, particularly as social media-borne attacks and other threats based on user error increase in frequency.

Romer said SMB beta users currently using a competing product also voiced concerns about the costs associated with switching vendors. Starting Wednesday, Symantec will knock 70% off the price tag of a three-year subscription for firms with fewer than 500 employees. Just over half of the beta testers indicated they used a security program from a different provider.

Existing customers should get a smoother upgrade ride than in the past. Romer acknowledged the transition between versions 10 and 11 was rocky for some companies, and the "silent" approach is applicable to the upgrade process as well.

"Quite frankly, four years ago it was a painful process," Romer said, adding that the move to SEP 12 should be much simpler. "The full version upgrade feels just like a maintenance update."

You can't afford to keep operating without redundancy for critical systems--but business units must prioritize before IT begins implementation. Also in the new, all-digital InformationWeek SMB supplement: Avoid the direct-attached storage trap. Download it now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.