All Posts By

Ofer Amitai

What Kind of WiFi Protected Access Should You Use to Secure Your Enterprise?

By | Network Security | No Comments

When examining WiFi security, the first layer of defense is the method being used to authenticate to the network. The most widely used methods of authentication are Open authentication, WPA2-PSK (Pre-Shared Key) and WPA2-Enterprise (read more about WPA protocols below).

authenication typesOther authentication methods such as WEP (Wired Equivalent Privacy) and WPA-PSK (without the 2, also referred to as WPA-Personal) are used as well, but they are relatively easy to hack, and therefore are not really worth mentioning, besides making a general note here – to utterly avoid them.

Open Authentication

As the name implies, an open authentication network allows access to all, and users are not required to authenticate at the association level. It is important to know that open networks are not encrypted, and so everything transmitted can be seen by anyone in its vicinity.

The best security practice is to completely avoid connecting to open networks. If there is an immediate need to connect, it is best not to allow devices to connect automatically but rather to select the network manually in the device settings. Open networks are easily forged, and hacking tools such as Pineapple use the fact that mobile devices are constantly searching to connect automatically to an open network. These tools perform Man-in-the-middle attacks to steal data such as passwords, credit cards, etc.

wifi networks

WPA / WPA2 / WPA3

WPA stands for WiFi Protected Access. This authentication method uses different encryption algorithms to encrypt the transport. Therefore, this type of network cannot be forged easily, unlike open networks, and users get privacy. Today, WPA2 is probably the most commonly used method to secure WiFi networks.

Sadly, WPA and WPA2 protocols have been hacked and are considered to be less secure. Performing a WPA2 hack requires a lot of time and is somewhat theoretical. Slowly, we are noticing a move to the WPA3 method, but for that to happen, different infrastructure is needed to support that protocol.

WPA2-PSK

WPA2-PSK (and WPA3-PSK) is WiFi Protected Access (WPA) with a Pre-Shared Key. In simple terms, it is a shared password to access the WiFi network. This method is commonly used for home and small office WiFi networks. Even in a small office setting, using this method is problematic, because each time an employee leaves the company, the password must be replaced; otherwise, the former employee could still connect to the company WiFi.

Furthermore, employees tend to share the password with guests, visitors and contractors in the building, and you shouldn’t have the whole building connecting to the internet at your expense, risking the security of your data and assets in the process.

WPA2-Enterprise

This method, also referred to as WPA-802.1X mode, authenticates to WiFi by using different identities instead of a single password. An identity can be credentials (user + password) or it can be a digital certificate.

This authentication method is better suited for enterprise networks and provides much better security for wireless networks. It typically requires a RADIUS authentication server as well as a configuration process to different repositories, enabling the organization to authenticate different types of endpoints.

The underlying protocols to secure the authentication vary between different Extensible Authentication Protocols such as EAP-TTLS / EAP-TLS, EAP-PEAP, each one representing a different type of authentication method and level of security.

With WPA2-Enterprise one can use advanced features such as assigning each endpoint after authentication to a specific VLAN or assigning ACLs (Access Control Lists) to specific sections. Additionally, enterprises can audit the connection with additional details. These features are important as they allow enterprises to properly secure their wireless networks and to make sure that they are compliant with security best practices.

Portnox CLEAR

CLEAR is a SaaS, cloud-delivered, WiFi access control solution that allows you to secure your WiFi based on WPA2/3-Enterprise, using personal identities or digital certificates. CLEAR supports a wide range of authentication providers, from on-premises AD through cloud providers such as GSuite and Azure AD. CLEAR comes with a cloud-RADIUS, therefore there is no overhead, as there is no equipment to install or maintain. It requires no training or skilled personal to deploy and operate. In less than 10 minutes, large and small companies are deploying CLEAR’s enterprise-grade Wi-Fi security.

See a Demo of CLEAR – Please fill out this form:



Secure WiFi

Securing Your WiFi Network: The Case for Implementing Enterprise-Grade WiFi Security Now, and Why Shared Passkeys Should Be a Historical Bygone

By | Network Security | No Comments

Are you using a pre-shared passkey to allow access to the organization’s WiFi?

Securing WiFi access in businesses has been historically weak. Oftentimes, companies protect their Wi-Fi access with a pre-shared password, sometimes posting it on whiteboards within the company or placing it for all to use at the reception desk to enable easy access. This is primarily for modern convenience purposes, as businesses would like to enable productivity and collaboration with contractors and guests, as well as allow for staff mobility within the premises of the enterprise.

What’s the problem? And why should I care?

The problem with this practice is that this is a “home style” level of security that places the company’s data and assets (whether intellectual or physical) at risk of being damaged or stolen. If an outsider successfully connects to the company’s WiFi, they could bypass the Firewall and all traditional cyber security mechanisms applied by most companies today. Once inside, they could damage the organization’s reputation by accessing illegal web sites, or company data, whether it resides on premises or in the cloud. Accessing these items is easy, and there are many automated network tools that can enable “non-techies” to do the work. Additionally, this type of hack could easily be achieved via simple social engineering. Another reason to be worried about the use of passkeys is that WiFi hacks and damages do not require being physically present at the organization. These simple actions could be taken from a nearby public space such as the parking lot and would leave no trace. Trying to track who accessed the enterprise WiFi by using a shared password is almost impossible.

Click here to watch a video demonstrating CLEAR’s easy set up

Internal players – disgruntled and former employees

One of the scariest scenarios are the hacks performed by disgruntled employees that can use their remaining access to perform nefarious activities, including damaging, sabotaging or stealing company data, resources and assets. Roughly one out of five organizations has experienced a data breach by a former employee. The Gartner analysis of criminal insiders found that 29 percent of employees stole information after quitting or being fired for future gains, while 9 percent were motivated by simple sabotage.

Attacks by disgruntled employees who commit deliberate sabotage or intellectual property theft are considered to be among the costliest risks to an organization. For example, one of our customers, a food manufacturer in the United States, fired an employee. The disgruntled employee decided to get even. Using the organization’s Wi-Fi password, he connected to the network from the parking lot and changed the temperature setting for the refrigerators. The result was the destruction of food inventory to the tune of hundreds of thousands of dollars.

Bottom line?  Former employees, even those who left amicably, should no longer have access to any part of the network.

Removing employees’ access to all accounts immediately after leaving the company is the best practice to use; however, typically it is not possible to revoke all access due to shared passwords for certain systems and services. In some cases, these systems do not require a password at all, such as printers and Point of Sale devices. For certain organizations, such as law firms and medical facilities, these represent the crown jewels in terms of company data and therefore should be highly secured.

Do I have important assets on the network that I should be protecting?

With the growing numbers of Wi-Fi connected IoT devices (IP cameras, printers, etc.) in the enterprise, each network has a lot of devices that could be compromised and thereby causing data leaks, denial of service attacks or severe damage to the organization. Therefore, ensuring that IoT endpoints are segmented into separate sections of the network and cannot be accessed by outsiders is crucial.

What is the alternative to PSK?

Using enterprise-grade authentication & access services is a good idea.
The best security practice would be to have digital certificates, but at the very least, it is recommended to establish a personal identity-based authentication solution. It would enforce network access via unique user credentials, thereby dramatically reducing the chances of unauthorized access to the organization’s Wi-Fi network, and it would ensure a much better security standard over the shared password practice. Traditionally, this was difficult, as setting up such services required high levels of technological knowledge, as well as extensive maintenance and long and complicated deployments.

This is exactly where Portnox CLEAR can help.

Portnox CLEAR

CLEAR is a cloud-delivered, WiFi access control solution that among other benefits provides a cloud-RADIUS, therefore requiring no training or skilled personal to deploy and operate. There is no overhead, as there is no equipment to install or maintain, and the service is inexpensive and based on the number of devices in the enterprise. Additionally, there is no need to manage a WiFi password as authentication is based on user accounts or digital certificates (customer’s choice), and therefore all passwords are unique. In less than 10 minutes, companies are deploying CLEAR’s enterprise-grade Wi-Fi security, providing the highest level of security to any enterprise, large or small.

See a Demo of CLEAR – Please fill out this form:



portnox pr logo

Portnox CLEAR’s Secure WiFi Access, Powered by Microsoft Azure, Delivers Enterprise-Grade WiFi Security to Businesses of All Sizes, as a Service.

By | press releases | No Comments

Mid-market and enterprise customers can now authenticate to their wireless network, based on identities, with Portnox CLEAR’s 802.1X seamless solution, delivered from the cloud

NEW YORK–Portnox, a market leader for network visibility, access control and device risk management solutions, today announced that its cloud-based solution Portnox CLEAR, powered by Microsoft Azure, is now available for Microsoft sales teams, enabling organizations to protect their network infrastructures with the Portnox CLEAR platform.

Enterprises and SMBs are facing a growing challenge protecting their networks from different cybersecurity threats, specifically their wireless infrastructure. More than 60% of all data breaches target small and medium businesses and yet, most are still using a pre-shared passkey to enable employee access to their organization’s Wi-Fi. This is particularly troubling as 40% of those attacks, involve the compromise of employee passwords.

To address these challenges and risks, Portnox CLEAR, a cloud-delivered, enterprise-grade network access control solution, provides individual authentication and access policy enforcement. With its built-in Azure Active Directory or Windows Server Active Directory plug-ins, Portnox CLEAR provides 802.1X network authentication services to the mid-market and enterprise customers within minutes. Additionally, CLEAR offers organizations visibility, control and pervasive risk assessment capabilities to better protect their networks in real time. Users can automate network access, certificate enrollments and onboarding scenarios for employees, contractors, guests and non-corporate machines, on or off premises. Key features include 802.1X based authentication and authorization, expanded threat management, breach remediation, dynamic network access control policies, and automated implementation of compliance protocols.

“Microsoft customers are a strategic business avenue for Portnox,” said Ofer Amitai, CEO, Portnox. “Portnox CLEAR allows organizations to secure their Wi-Fi in a matter of minutes by applying the highest security standards with a simple method, anywhere in the world. As a SaaS solution, CLEAR is pre-setup, always running the latest version, latest security and latest features with seamless upgrades, while requiring close to zero maintenance from IT and security teams.”

Portnox CLEAR is a cloud-delivered NAC-as-a-service solution that enables organizations to secure their entire network, including their Wi-Fi. Ultimately, the organization can control all network access by using continuous risk-scoring for each endpoint, including mobile, BYOD, and IoT, connecting from anywhere in the world. Built to simplify the complexities associated with implementing NAC, CLEAR delivers the necessary network visibility and access control mechanisms to protect against non-compliant and rogue devices that introduce security threats.

CLEAR is built as a multi-tenant and geo-distributed service due to the fact that it runs on top of Azure as a PaaS service. It utilizes many Azure cloud components and therefore CLEAR customers benefit from the conveniences of a SaaS solution while implementing the highest standards in information security.

“In today’s environment where BYOD, IoT and mobile workforces are the norm, our mutual customers rely on our solution to help monitor and secure all their devices, regardless of location,” said Avi Binya, VP One Commercial Partner at Microsoft. “The integration of Portnox CLEAR with Microsoft Azure Active Directory brings visibility and network access control to customers, allowing them to embrace the new market trends in a simple way.”

Support & Professional Services Engineer

By | Careers | No Comments

Portnox Security is looking for a Support & Professional Services Engineer to join our office in Ra’anana.

Do you like working with people?

Do you enjoy solving puzzles and have technical curiosity?

Are you familiar with network topology and configuration?

Interested in growing within the cyber security business world?

Then this role is for you!

Who are we looking for?

We are seeking a highly motivated and creative individual who likes to work with customers, and who consistently sees many options for solutions rather than problems.

 

Responsibilities

  • Provide customer support and technical issues resolution via phone, E-mail and web sessions
  • Respond in a timely manner (within documented SLA) to support customer issues and inquiries
  • Resolve problems independently and understand the correct escalation procedures
  • Use IT and networking skills to perform troubleshooting to isolate and diagnose common network problems
  • Responsible for customer satisfaction and overall success of the PS Team
  • Be a trusted advisor for our prospects and customers

Requirements

  • Highly motivated
  • Self-managed and team-oriented
  • Technical Bachelor’s degree- an advantage
  • Minimum 2 years’ of experience in product support / professional services for an international hi-tech company
  • Excellent customer service skills
  • Detail oriented
  • Advanced analytical thinking and problem-solving skills
  • Strong oral (phone) and written (e-mail) communication skills in English
  • Expert level knowledge and hands-on experience with Layer 2/Layer 3 Switching/Routing, TCP/IP, Layer 4/Layer 7 switching, firewalls, IDS/IPS, VPN, security consulting, SSL, IPSec
  • DevOps experience – advantage
  • Project management experience- advantage

Interested? Send us an email: apply@portnox.com

Senior C# developer

By | Careers | No Comments

Senior C# developer with proven experience in the area of Enterprise Software Development

  • 8+ years of experience in C# development
  • Deep knowledge and a strong background in .NET / OOP / OOD / multi-threading
  • Experience in Web Services / MS SQL / Web applications development – Must
  • Experience with network management protocols (SNMP, RADIUS, NetFlow) – Advantage
  • Experience with Scrum/Agile methodology – Advantage
  • Leadership and collaboration skills
  • Ability to work independently and mentor other developers
  • Innovative and out-of- the-box thinker

Interested? Send us an email: apply@portnox.com

Junior C# Developer – Ra’anana

By | Careers | No Comments

Looking to hire a Junior C# Developer to join our engineering team. Portnox provides awarding winning solutions for Network Access Control, which is today a must have solution for most all enterprises.

Requirements

  • 2+ years of experience in C# development
  • Excellent C# and .NET skills – Must
  • Knowledge of relational databases and SQL – Advantage
  • Knowledge in web development concepts (REST, JSON, AJAX) – Advantage
  • Innovative and out-of-the-box thinker
  • BA/B.Sc. in Computer Science

Interested? Send us an email with your CV: apply@portnox.com

Inside Sales Specialist – North America

By | Careers | No Comments

Looking to hire an inside sales specialist to join our growing sales team. Portnox provides awarding winning solutions for Network Access Control (NAC), which today is a must have solution for most of the organizations.

Your job will be in the front line, facing potential customers and be responsible for creating and converting leads into business opportunities. You’ll develop a deep understanding in our industry and reach out to top decision makers in the IT space.

You will be a part of the marketing team, reporting into the company CMO and working alongside with the sales team, supporting both marketing and sales.

Responsibilities

  • Phone and email follow-up to daily inbound & outbound leads
  • Scheduling on-line product demonstrations and/or sales follow up meetings
  • Tradeshow lead follow-up
  • Cold calling
  • Sales coordination activities
  • List building/enhancement

Requirements

  • Self-motivated individual with “can do” attitude
  • Strong communication skills
  • Experience using/working with Salesforce
  • A general understanding of networks and network security is a plus

Interested? Send us an email with your CV: apply@portnox.com

Channel Manager – Israel

By | Careers | No Comments

Looking to hire a Channel Manager to join our sales team in Israel.

Position Overview

In this key role, you will:

      1. manage and drive sales within Israel via Portnox strategic partnerships. Your focus will be to create and implement strategic account plans. These initiatives will ultimately lead to enterprise-wide deployments of Portnox products and services.
      2. Develop great business relationships with key buyers and influencers, and leverage these throughout the sales process.
      3. Coordinate with the appropriate internal groups to generate and deliver winning contract bids, proposals, RFI/RFP responses, and statements of work.
      4. Negotiate terms of business with partners (and clients) to achieve win-win results that provide the basis for strong ongoing relationships.

Responsibilities

  • Generating business opportunities and managing the entire sales process from the beginning to the closure of the sale.
  • Achievement of agreed quarterly sales goals and quotas.
  • Create a sales pipeline, qualify opportunities, and accurately forecast the pipeline.

Required Skills

      • A proven track record of quota achievement and demonstrated career stability.
      • Experience in closing large deals.
      • Excellent presentation skills to executives & individual contributors.
      • Excellent written and verbal communication skills both Hebrew and English.
      • Self-motivated, independent thinker that can move deals through the sales cycle.
      • Minimum 5 years of sales experience.
      • Minimum 3 years selling enterprise network security products and services.
      • Candidate must thrive in a fast-paced, ever-changing environment.
      • Competitive, self-starter, hunter-type mentality.

Education

      • • BS or equivalent experience, graduate degree – preferred.
    • Seniority Level – Middle management.
      Industry – Cyber SME-ENT
      Employment Type – Full-time
      Job Functions – Sales & Business Development
    • Interested? Send us an email with your CV: apply@portnox.com

     

Customer Support Engineer – North America

By | Careers | No Comments

Looking to hire a professional services and technical support engineer to join our team. Portnox offers both on-premise and cloud based technologies. Supporting Portnox’s Network Access Control products requires a rich understanding of networks, IT infrastructure and web applications. The ideal candidate is familiar with network switch topology and configuration.

Our Support Engineers interact extensively with customers and partners in the highest professional manner.

Responsibilities

  • Provide excellent technical support to global customers
  • Use IT and networking skills to perform troubleshooting to isolate and diagnose common network problems
  • Take responsibility for customer satisfaction and overall success of the PS Team
  • Respond in a timely manner (within documented SLA) to support customer issues and inquiries
  • Resolve problems independently and understand the correct escalation procedures

Requirements

  • Minimum of 4 years of experience in full-time product support / professional services for an international hi-tech company
  • Excellent customer service skills
  • Highly motivated
  • Advanced analytical thinking and problem-solving skills
  • Strong oral (phone) and written (e-mail) communication skills in English
  • Self-managed and team-oriented
  • Deadline and detail-oriented
  • Expert level knowledge and hands-on experience with Layer 2/Layer 3 Switching/Routing, TCP/IP, IPv4, Layer 4/Layer 7 switching, firewalls, IDS/IPS, VPN, security consulting, SSL, IPSec
  • DevOps experience – advantage

Interested? Send us an email with your CV: apply@portnox.com