Hornetsecurity GmbH - Experts & Thought Leaders

Latest Hornetsecurity GmbH news & announcements

Develop A Comprehensive Ransomware Action Plan

Let's be honest, without a well-thought-out plan, Kevin McCallister would have been powerless against the break-in at his home. Like Kevin, users too must proactively prepare for the possibility that a few lousy burglars might sneak into the business and cause trouble. Developing and regularly reviewing a well-thought-out ransomware response plan helps the company proactively combat ransomware attacks. Adequate preparation can significantly reduce the impact of a ransomware incident and increase the chances of data recovery. Addressing potential ransomware attacks Developing a ransomware action plan is a critical step for companies to proactively address potential ransomware attacks. An action plan helps to limit the impact of an attack. This allows for preventative measures to be taken, employees to know their responsibilities, and regular system backups to be performed. It makes it easier to quickly detect, contain, and mitigate an attack, and to recover from it. A post-incident analysis helps identify weaknesses and implement improvements to prevent future attacks. It's about testing the plan in practice and focusing on what has been learned from past incidents. In most cases, companies create a broader response plan that considers not only ransomware but also other cyber incidents. However, due to the immense impact a successful ransomware attack can have on business operations, the plan should primarily focus on such an attack. Ransomware response plan The most important components of a ransomware response plan Preparation - Preventive measures should be implemented, such as EDR, SOC teams, vulnerability scanners, and regular software/operating system updates. In addition to these preventive measures, a Roles and Responsibilities (RACI) matrix should be implemented so that all team members are aware of their role in a ransomware attack. The key to mitigating risks is to combine this plan with regular backups, employee training, and ensuring up-to-date security software. Detection and analysis - This step focuses on detecting a ransomware attack as quickly as possible. This includes monitoring systems for unusual activity, analyzing the ransomware, and understanding its potential impact on the business. A thorough endpoint and metrics analysis, either part of an EDR solution or conducted by a Security Operations Center (SOC) , not only helps recover from an attack but also reduces the risk of an incident occurring in the first place.  Isolating affected systems Limitation - Once an attack has been detected, the next step is to prevent the ransomware from spreading. This can be achieved by isolating affected systems, taking them off the network, and stopping the spread to other parts of the organization. An EDR solution can help identify suspicious behaviour on endpoints and isolate the affected device before it can spread to other systems.  Control - This step involves removing the ransomware from the affected systems. This includes cleaning the infected systems, restoring data from backups, decrypting encrypted data, and ensuring that the ransomware has been completely removed. Users should also determine how the attackers gained access. Urgently seek established maintenance mechanisms, as simply removing the ransomware is insufficient. There are numerous cases where organizations were attacked again shortly after an initial attack because the attackers still had access. Resuming normal operations Restoration - Once the ransomware has been dealt with, the focus shifts to resuming normal operations. Data can be restored from backups to verify the integrity of the restored systems and ensure that all systems are operational.   The final step involves analyzing the incident to understand how the ransomware attack occurred and how such attacks can be prevented in the future. This should include reviewing the action plan to identify weaknesses and implement improvements. The plan should be printed out and stored in different locations; in the event of a complete ransomware compromise, file servers or SharePoint sites may become inaccessible. Ransomware incident response plan Following ransomware prevention, these best practices are crucial for organizations to strengthen their cybersecurity defences and mitigate vulnerabilities. The following section describes best practices for creating a ransomware incident response plan and for responding to an incident. This is particularly relevant in the event of a ransomware emergency. It is crucial to define and assign roles within the ransomware incident team. Each team member should know their responsibilities, from initial detection to recovery. Roles such as Incident Manager, Security Analyst, and Communications Officer must be clearly defined to optimize the response. This is typically represented in a Roles and Responsibilities (RACI) matrix, where each role is assigned a name and title. Managing large environments Training is just as important. If every team member is adequately prepared to perform their tasks even under pressure, it increases the efficiency of the response. Regular drills and scenario-based training sessions are the key to an efficient and ready-to-deploy team. Practice, practice, practice. Creating a comprehensive inventory of all hardware and software resources within the company is essential for an effective incident response. An inventory helps to quickly identify affected systems, assess the scope of a ransomware attack, and thus accelerate containment and remediation efforts. The inventory should list device types, operating systems, software applications, data storage, and network configurations. Regular updates ensure that the response team has accurate and up-to-date information during an attack. Using an inventory system like Microsoft Intune, in combination with a vulnerability scanner, can significantly reduce the complexity of managing large environments. Efficient resource allocation Listing and prioritising critical business functions and their assets facilitates efficient resource allocation during a ransomware attack. It helps the response team decide which systems need to be restored first to minimize business disruption. This prioritisation should align with the business continuity plan and the organizational impact analysis. Some organizations use a bronze, silver, and gold classification, or simply use levels like 0, 1, and 2. Furthermore, backups should be tested regularly to ensure they are functional and accessible when needed. Part of this should also include creating off-site or cloud backups that are not connected to the network to protect them from encryption or destruction by ransomware. Use immutable storage to ensure that backups cannot be easily deleted or manipulated, even if the cloud administrators' accounts are compromised. Evolving ransomware tactics Creating backups is useless if users can't restore the data. Regularly test the restore process and ensure that backups have completed successfully. Practice restoring entire systems, not just individual servers or files—in a real, network-wide recovery scenario, users will encounter many interactions that can hinder the process.   To improve the ransomware response plan, it's crucial to document all findings. Post-incident reviews should highlight what worked, what failed, and how the plan can be improved for future incidents. These insights help users to adapt their response to new and evolving ransomware tactics. Documenting each incident also provides a historical record that can help identify trends and improve training simulations. Continuously improving the ransomware response plan ensures that the company is prepared against ransomware threats. Ransomware response plan lifecycle   The lifecycle of the response plan is the process and sequence in which the procedure is followed in the event of an incident. The main reason for this is to ensure that we continuously review, test, and improve their plan to incorporate changes in the industry or company. Phase 1: Recognising the incident - Generally, the incident detection process begins with monitoring and alerting tools/teams. In some cases, an incident is reported by an employee. Since alerts can originate from various sources, it is important to use a solution that integrates multiple alerting and reporting tools. Utilising a SIEM solution in conjunction with a SOC team significantly improves environmental monitoring capabilities and incident analysis. This integration can transform a fragmented response into a coherent, collaborative effort. Platforms like Microsoft Sentinel allow teams to personalize and filter alerts, extracting actionable insights from diverse data sources. This integration ensures that incident response is both rapid and coordinated. Centralize team communication Phase 2: Cadence - Establishing communication channels for the emergency response team is crucial at this stage. The goal is to centralize team communication in easily accessible locations, such as dedicated Teams channels and video conferencing bridges. Regular phone calls with all involved parties to monitor progress and share new information ensure transparent communication. Also, plan for the possibility that users entire Entra ID tenant is compromised and users can no longer rely on email or Teams for communication—and switch to a smartphone messaging service instead. Phase 3: Impact Assessment - In the next phase, the impact of the incident is assessed to determine who else needs to be informed and what information should be shared with stakeholders. Using the Criticality Matrix helps determine the extent of the incident and lays the foundation for solution plans and external communication.   Tailored communication methods Phase 4: Communication - Timely and clear communication with internal and external stakeholders strengthens trust in leadership. Tailored communication methods enable teams to work effectively, leading to faster solutions. Individual customization also allows teams to control the message and the timing of its delivery.   Phase 5: Reaction - The initially responsible team members may need to involve additional teams or external parties for support in identifying and resolving the problem. By grouping related tickets and identifying relevant parties, the responsible employees are directed straight to the incident ticket. This ensures coordinated notifications and comprehensive context for everyone involved in the ransomware emergency plan. Ransomware emergency plan Phase 6: Responsibilities - As additional team members join, the incident manager assigns roles. A well-developed incident response plan with clearly defined roles and responsibilities is key to success. Every member who takes on a task in the response plan knows their role and responsibilities during an incident. Phase 7: Solution & Review - An incident is considered resolved when its current or imminent impact on the business has been eliminated. At this point, the emergency response is complete, and the team moves on to cleanup and postmortem analysis. Effective incident management includes a detailed timeline of events. Employees who handled the incident should be able to access critical incident data at a later date. This allows them to generate reports that uncover root causes and help prevent future incidents. Postmortems also serve as valuable resources should a similar situation arise again. Effective incident management As users can see, a well-thought-out response plan can make all the difference in a ransomware attack – comparable to Kevin McCallister's clever home defense or the scenario in which the bandits escape with the family treasures. By implementing the strategies and best practices described in this document, the organization can significantly increase its resilience against ransomware attacks. A proactive and well-prepared approach can minimize the impact of ransomware incidents and ensure a fast and effective recovery.

Proofpoint Acquires Hornetsecurity For AI Protection

Proofpoint, Inc., a cybersecurity and compliance company, announces the completion of its acquisition of Hornetsecurity Group. Hornetsecurity is a pan-European provider of AI-powered Microsoft 365 security, data protection, compliance, and security awareness solutions for managed service providers (MSPs). With this acquisition, Proofpoint reaches a significant milestone in its strategic path to protecting employees, data, and AI-powered digital assistants. Leveraging Hornetsecurity's strong market presence in Europe and a partner network of over 12,000 MSPs and resellers serving more than 125,000 customers, Proofpoint significantly expands its reach and capabilities. AI-powered workplace “We are thrilled to officially welcome Hornetsecurity to Proofpoint and to advance our mission to protect the emerging AI-powered workplace for businesses of all sizes,” said Sumit Dhawan, CEO of Proofpoint. “Together, we will further develop our leading security strategy to protect people, AI assistants, and data alike. At the same time, we will expand our reach in the channel and MSP markets through Hornetsecurity’s proven, scalable platform. As threats become increasingly rapid and targeted, our combined expertise will set new standards for innovation and resilience, helping customers and partners worldwide protect what matters most.” Comprehensive cloud security platform Hornetsecurity's flagship solution, 365 Total Protection, is the most comprehensive cloud security platform for M365 environments. With services ranging from email security and backup to compliance, awareness training, and access control, the platform provides MSPs with a multi-tenant control panel to manage and scale their customers' protection – without the complexity of combining multiple standalone solutions. “The merger with Proofpoint marks a new chapter in our journey,” said Daniel Hofmann, founder and CEO of Hornetsecurity. “Together, we are ideally positioned to deliver the most effective M365 security and data protection to MSPs worldwide. Building on our proven, channel-centric approach, our threat intelligence technologies and shared vision will enable a new level of innovation and added value for our partners and customers globally.” Driving product innovation As part of the transaction, Hornetsecurity will operate as a business unit focused on the channel and MSPs worldwide. Daniel Hofmann will lead the business unit as Executive Vice President and General Manager within Proofpoint. His leadership team will remain in place and continue to drive product innovation, go-to-market strategy, and partner success through the Hornetsecurity platform. Customers and partners can expect seamless continuity of products, services, and support—enhanced by additional benefits from Proofpoint's global resources, research, and threat intelligence. Proofpoint acquires Hornetsecurity for a total purchase price of $1.8 billion. Hornetsecurity generates nearly $200 million in annual recurring revenue (ARR) , representing 20% ​​year-over-year growth. This acquisition underscores Proofpoint's commitment to the European market and its strategy to deliver differentiated, AI-powered security to organizations of all sizes worldwide.

Hornetsecurity Joins Proofpoint For Global MSP Innovation

Today is a pivotal moment in Hornetsecurity's history. They are now officially part of Proofpoint, opening the door to an extraordinary future that we will shape together. As CEO of Hornetsecurity and now EVP & GM of the MSP Platform Business Unit at Proofpoint, I am very excited – not only about what they have achieved so far, but especially about the opportunities that this next chapter will open up for the customers, partners and teams. Global partner network Hornetsecurity has grown over the years – through the collective strength of its employees, the unwavering trust of its customers, and the commitment of the global partner network. Proofpoint's foundation is built on the same cornerstones: innovation, resilience, and a relentless dedication to protecting businesses worldwide. Now these two stories become one. What inspires them most at this moment is the great opportunity that arises for their partners, their customers, and the employees. Together with Proofpoint, they will: Build the global MSP hub for the entire organization based on Hornetsecurity's proven 365 Total Protection platform. Accelerate innovation and bring new product developments and features to market faster than ever before. Offering the most comprehensive portfolio on the market for defending against cyberattacks, thus providing global protection against global threats. Implementing powerful innovations – from enhanced threat intelligence capabilities to advanced detection technologies that will redefine the possibilities of cybersecurity. Expanding the global reach by leveraging Hornetsecurity's success in Europe and Proofpoint's strong market presence in the US to become even more visible worldwide. To further expand their position in the OEM/ISP sector, with pooled resources and their commitment to modular, high-performance solutions. Proofpoint Essentials business This is not simply an expansion of their capabilities, but the beginning of a new era of innovation. Hornetsecurity will continue to operate as a business unit and expand Proofpoint's MSP offering. The business unit will be responsible for both the Hornetsecurity product lines and the Proofpoint Essentials business. Their strong European foundation continues to grow – supported by the combined expertise of both organizations. The people and relationships that shape their collaboration remain firmly in place. Their teams and trusted contacts will continue to walk this path together with users, their valued partners and customers. Data protection and privacy remain central to their identity. All data hosted in Europe continues to be subject to the GDPR, the UK DPA 2018, ISO 27001, and the respective regulatory frameworks in Europe and the United Kingdom. This stability gives them the opportunity to grow together courageously and confidently. Outstanding product portfolio Proofpoint has built an outstanding product portfolio that has proven successful in the enterprise sector and grown into a dominant player in the US. They will leverage this strength to further accelerate their expansion into the MSP market – with an expanded, channel-focused product portfolio and significant investments in this market segment. Their all-in-one platform 365 Total Protection combines the most comprehensive suite of solutions that enables MSPs to offer stronger security, simplified management, and scalable growth. For customers, this means even more powerful protection and faster deployment of new features. For partners, this means new opportunities, larger markets and a strengthened global ecosystem. Strengthened global ecosystem For the employees of both companies, it means working together with colleagues who are equally passionate about shaping the future of cybersecurity. By combining the strengths, expertise, and energy of both organizations, they can achieve things that neither organization can accomplish alone. They thank their customers for their trust, their partners for their belief in the vision, and the employees for their dedication and passion. The next era of Hornetsecurity begins now – brighter, bolder, and more promising than ever.