Open post
laptop and mug with link22 logo

Productnews – link22 Offline Update

Productnews – link22 Offline Update

Ellen Brunnström and Martin Steen-Holmberg

link22 can now offer a product solution to ensure and automate downloads to physically separated environments. The solution ensures that downloads are inspected and managed over unidirectional data flows.

The process is fully automated, information is fetched, reviewed, and then distributed to different locations in the target system. Files are inspected by link22 Data Guard, where a thorough inspection of each file takes place. The file is broken down into its components to detect vulnerabilities. Inspection can be done with traditional antivirus software, but we also support "Content Disarm and Reconstruction" (CDR), where each file is checked in detail to detect and remove unwanted information. For example, with CDR, we can remove embedded code in Office files. (CDR requires a separate license.) link22 Data Guard has an open architecture that allows for the addition of further customer-specific filters. Extending with additional filters is easy with our development kit.

Read more about link22 Offline Update.

Så funkar link22 offline-update

Our efficient architecture saves time and energy. Files are only inspected once before being distributed to multiple end domains/target environments.

For example, we can handle the following files from the Internet today;

  • Linux updates (Ubuntu, Rocky, CentOS, Epel, Raspbian, and more)
  • Antivirus software updates (Defender ClamAV, and more)
  • Docker
  • Python repositories
  • Emacs Packages
  • CRL lists and CA

Access to downloaded files is done either via HTTPS or file sharing. This means that, for example, Linux computers believe they are online and can easily be patched regularly.

We are especially pleased to announce that we are extending our system license for link22 Secure Transfer with our new functionality. Existing customers can contact us to start using link22 Secure Offline Update. More information is available on our website.

Contact sales@link22.se if you are interested in learning more about how this could be implemented in your context.

Open post
säkerhetsprodukt link22

Three government security challenges solved with data diodes

Three government security challenges solved with data diodes

Appropriate data security

As government authorities are becoming more vulnerable to various types of cyberattacks, it is crucial to prioritize cybersecurity and implement systematic measures to protect against these threats. An important aspect of cybersecurity is selecting the appropriate solutions, such as data diodes, which are designed to withstand attacks and provide a high level of security for sensitive information. By utilizing data diodes, government authorities can effectively address a range of IT security issues and ensure the protection of data security.

The data Diode

A data diode is a cybersecurity solution that utilizes one-way-communication to exchange information. This hardware product provides high assurance in maintaining the integrity of networks by preventing intrusions, while also protecting sensitive information through maintaining network confidentiality. Data diodes are an important part of any comprehensive cybersecurity strategy.

säkerhetsprodukt link22

Data diode or Firewall?

When it comes to protecting sensitive or classified information from leakage or manipulation, one common solution is to completely disconnect it from other networks. However, there may be times when data needs to be transferred to or from the protected network. In these cases, a firewall may not be sufficient for improving cybersecurity. While a firewall can help protect the network by only allowing certain traffic through, a high assurance supplement in the form of a Cross Domain Solution (CDS) may also be necessary. A CDS, like a data diode, helps to maintain secure information exchange between domains with different security or protection needs. Data diodes, specifically, are a type of CDS that facilitate communication, sharing, or movement of information between domains while also applying validation, transformation, or filtering to the exchange.

Secure File Transfer

One use of data diodes for government authorities is secure file transfer. When transferring important information from a high-security system to a lower-security administrative office network, there is a risk of security breaches. However, by using a data diode to send the data from the high-security network to the lower-security network, the information can be transmitted safely while maintaining the integrity of the high-security network. The data diode ensures that no one can use the same connection to access the sensitive network and potentially manipulate it while also protecting the sending domain.

Learn more about the functions of data diodes here.

Using data diodes for traceability and logging in security-sensitive operations

Centralized log collection in security-sensitive systems can increase the risk of attacks. To mitigate these risks, a solution is needed that protects both log information and all connected systems.

Many IT systems generate logs that allow for troubleshooting and traceability. To maximize the usefulness of these logs, it is important to collect logs from as many systems as possible into a central system for storage and analysis.

If you have security-sensitive or zoned systems and want to implement centralized log collection, you must consider the inherent goal conflict. Logging benefits from having a common system for all zones/subsystems, but a common system increases the risk of various types of attack and the risk of information leakage between the supervised systems.

Data diodes can provide powerful protection for centralized log collection. Each zone that delivers log information is protected with a data diode. The data flow is unidirectional towards the log system. This allows for the use of a common log system, regardless of the number of zones that deliver data to it. 

Read more about logging and CDS here.

Welcome Henrik Nilsson!

Secure Updates

As the use of Windows and/or Linux based systems within ICS/SCADA has grown, the need to update these systems has become more pressing. This is because complex software often contains bugs that need to be fixed in order to maintain system stability and security.

However, if not done properly, the process of updating can itself pose a security risk. The integrity and availability of the systems must be maintained, and most system updates are not adequately evaluated in the environment in which they are used or in combination with the applications that are running.

One way to securely perform updates is by using a data diode to ensure one-way communication. The data diode is connected in such a way that information can be imported into the system, but since no traffic can be transmitted in the opposite direction, information leakage is prevented.

We know the in and outs of data diodes from a cybersecurity point of view. Please do not hesitate to ask us anything.

Book a demo or a meeting here.

Welcome Henrik Nilsson!
Open post

A national safety discussion secured by Shield

A national safety discussion secured by Shield

A meeting between military Officers and the ministry of defense is held with security support from Shield

Mobile phones are relatively easy to use for eavesdropping on meetings. Phones are therefore an attractive target for foregin powers who want to conduct espionage. They can be hacked through downloaded apps that have access to the microphone and by physically getting a hold of the phone to install malicious software. This means that a phone should never be left out of sight and that a phone never should be laying around during a meeting where sensitive information is discussed. An obvious cyber security conundrum.

Safety meeting

Shield is our solution to this problem, a noise-box especially developed to make phones less of a security risk. Here is an example of how Shield can be useful in a meeting between politicians and national defense.

Two high ranked officers have a meeting with the defense ministry and two politicians from the ruling party. None of the participants want to leave their phone out of sight as it is a security risk for them. They enter the meeting room and put their phones in Shield. One of the politicians has a smartwatch that she puts in the Shield. The meeting is held at full discretion.

Read more about Shield here.

Welcome Henrik Nilsson!
Open post

Cyber security for the toughest security requirements.

Cyber security for the toughest security requirements

More of everything

We feed more people with fewer resources, we educate more humans faster and more people live in luxury. All thanks to the printing press, the agricultural revolution and the industrial revolution. It's now clear that digitalization is taking over in order to optimize and improve society further. Products are being connected, information is being created and shared in real-time, people are meeting, value is being saved on blockchain networks, and the list goes on. Society is changing fundamentally and everyone is affected.

Cybersecurity

What was once protected by guards, locks, and long distances need new types of defense in our digital world. Cybersecurity is essential to maintain function and security in society. Our product portfolio is the result of 16 years of helping organizations and businesses meet the highest security requirements. We offer the market-leading off-the-grid laptop Outpost, which is used by hundreds of customers. Outpost is the best in the industry and ensures compliance with the highest security requirements in Sweden.

Full control

Government agencies, businesses, municipalities, defense forces, infrastructure, and individuals are all interconnected. The economies of scale are obvious and the challenges are many.

How do we protect critical infrastructure? How can we digitize government agencies without jeopardizing the integrity of the citizen? How can we link domains with different security classifications? How do we give people access to data without making them targets for extortion? How do we make it easy for citizens to administer their personal data without enabling manipulation from anyone else?

Welcome Henrik Nilsson!

Take back control

To have full control, meet data security requirements and privacy guidelines, the solution in many cases is a so-called on-premises solution. We are specialists in this area. A number of cases have taught us how a government agency or company can maintain its effectiveness without having servers, data storage or processor power outsourced to a third party. Full control without compromise.

Adaptability

The digital landscape is constantly changing, so adaptability is key. We deliver ongoing modular solutions to help our customers who constantly face new needs, requirements, and threats. We are a long-term and reliable partner in an ever-changing world of cybersecurity.

Contact us for a free initial consultation on how we can work together to address your cybersecurity needs.

Welcome Henrik Nilsson!
Open post

Shield preventing insider trading within big pharma

Shield preventing insider trading within big pharma

Shield helps to safely reveal test results from cancer medicine research within a pharmaceutical company

Mobile phones are relatively easy to use for eavesdropping on meetings. Phones are therefore an attractive target for competing companies and insider traders who can benefit from conducting espionage. They can be hacked through downloaded apps that have access to the microphone and by physically getting a hold of the phone to install malicious software. This means that a phone should never be left out of sight and that a phone never should be laying around during a meeting where sensitive information is discussed. An obvious cyber security conundrum.

Shield is our solution to this problem, a noise-box especially developed to make phones less of a security risk. Here is an example of how Shield can be useful when sensitive information is to be discussed at a big pharmaceutical company.

Insider trading prevention

A publicly traded pharmaceutical company that is a lucrative target for insider traders has an internal meeting to go through test results for a new cancer medicine. The information of discussion will heavily affect the stock price. None of the participants can leave their phone out of sight since an unattended phone is at risk of being manipulated. All phones and smartwatches are put inside Shield before anything regarding the tests results are discussed. Shield is placed inside the meeting room.

Read more about Shield here.

Welcome Henrik Nilsson!
Open post
sections consulting services

The NIS2 Directive

What is the NIS and NIS2 directive?

The article is an introduction to the NIS directive and the NIS2 directive, aiming to strengthen the EU's protection of critical infrastructure. We briefly go through what the directive means in practice and who is affected. We help businesses manage security challenges with tailored solutions. Book a demo to discuss how NIS affects you and what measures you may need to take.

Secure cloud system with link22

About the NIS directive

(The Directive on security of network and information systems) The purpose of the NIS directive is to heighten the security levels for critical infrastructure in the European Union.

link22 and the NIS Directive

The NIS Directive affects each company and organization differently, there is no one-size-fits-all solution to meet the requirements and stay efficient. It can be hard to assess whether or not the NIS Directive affects your company at all. We have helped governments, organizations and companies with challenges like this for 16 years and can be of use in many ways. It can seem complicated to determine what this means for you; what are you obliged to do or not to do? If you are unsure about this we suggest that you book a demo with us where we make an assessment together. Based on your situation we reason together and specify what you need to do to meet the new requirements and most importantly to secure what's valuable in your possession.

What does the term “directive” mean in this context?

It means that it can be incorporated differently in every member state to functionally harmonize with local legislation. In Sweden, the NIS-directive came into force on august the first in 2018 though The information security law.

Why does the NIS directive exist?

The NIS-directive was created to protect european citizens by heightening security around critical infrastructure within the member states. Specifically by improving information security related to critical infrastructure.

Digitalization gave rise to NIS and NIS2

The number of hacker attacks from criminal organizations and nation states has increased significantly. Attacks are more sophisticated and so are the motifs. Hackers are not just in it for money, elections and national security is also at stake. Cyberwar is a fact. There is good reason to prevent and prepare for attacks to keep critical infrastructure intact. The NIS and NIS2 directive is ultimately meant to serve european citizens.

The NIS directive affects certain industries

Energy, health care, transport, finance, water supply and digital infrastructure are considered critical according to the NIS directive. Companies and organizations within these sectors are obligated to secure their information according to the NIS directive.

The NIS directive in reality

The NIS directive means generally stricter security requirements around information security. Concerned entities must consider people, process and technology when securing information. They need to classify information and systems. These entities must also prepare for the eventualities that an attack may lead to and specify action plans to increase resilience. Continuous knowledge gathering by incident reporting is mandatory with the purpose of always becoming more prepared. Companies and organizations are expected to direct their NIS-related actions towards network and information-systems.

The NIS2 Directive

To oblige- and benefit by the NIS-directive

The NIS directive is a useful place from which to start making valuable cybersecurity improvements. Best practice in this case may be to first create an overview of the organization as a whole and then extract potential and useful changes in order to improve information security. Some processes are crucial for core functionality, some individuals have access and responsibilities that make them targets for extortion and some parts of the technical infrastructure are more vulnerable than others. This is properly complemented by an external assessment of the external cybersecurity landscape, specifically what kind of attacks that are common and what kind of attacks that may become common in the future. Information transfer between security domains and/or networks are, for example, one of the most exposed and vulnerable situations in cybersecurity today. Implementation of data diodes, countersign and encryption are three actions that will make a significant difference for many organizations in the coming years. Separate domains for different security levels is a good idea that can be implemented when one has specified what information is more important than the other. A clear information hierarchy is necessary to maintain efficiency and security.

The NIS-2 directive to improve the NIS directive

The NIS directive includes continuous review to ensure incremental improvements and adaptations to meet the change rate of the digital world. This has resulted in NIS 2.

Identified weaknesses

  • European companies do not have sufficient ability to defend themselves against cyber attacks
  • European companies do not have sufficient ability to stay operational during a cyberattack
  • European companies do not have sufficient ability to return to normal functionality after a cyberattack
  • Some sectors and states are significantly stronger than others, the European digital landscape has obvious weaknesses
  • The cyber threat awareness among EU member states is low
  • There are no common crisis management practices regarding cyberattacks within the EU

Improvements through the NIS 2 Directive

The NIS directive has been extended to further enhance security. Here are some of the most important add ons:

  • New sectors have been added
  • Increased minimum security and reporting requirements
  • Stricter supervisory measures for nation authorities
  • Stricter compliance requirements for nation authorities
  • Administrative fines has been made possible
  • Increased cooperation and increased information sharing between Member States' authorities

The NIS2 Directive affects more entities

NIS2 covers more sectors and more companies and organizations within each sector. The original NIS-directive considers energy, healthcare, transport, finance, water supply and digital infrastructure as critical for a functional society. With NIS2, public administration, pharmaceutical production, critical medicine technology and space has been added to the list.

The NIS2-directive also affects sectors in the periphery of critical infrastructure, these include; waste disposal, chemicals, post service, food, motor vehicles, production of medical machines, computers and electronics, machine equipment and digital suppliers

The majority of affected entities are medium and large enterprises within the above mentioned sectors but some small companies may also be affected depending on their profile.

link22 and the NIS Directive

The NIS Directive affects each company and organization differently, there is no one-size-fits-all solution to meet the requirements and stay efficient. It can be hard to assess whether or not the NIS Directive affects your company at all. We have helped governments, organizations and companies with challenges like this for 16 years and can be of use in many ways. It can seem complicated to determine what this means for you; what are you obliged to do or not to do? If you are unsure about this we suggest that you book a demo with us where we make an assessment together. Based on your situation we reason together and specify what you need to do to meet the new requirements and most importantly to secure what's valuable in your possession.

Read more

Read more

Was the article valuable?

Sign up for our newsletter!


    Do you want to know more?

    Niklas Amnebratt
    sales@link22.se
    +46 13-13 24 00

    Niklas Amnebratt
    Open post

    Shield preventing insider trading at a municipality

    Shield preventing insider trading at a municipality

    Discussing a stock price-affecting construction permit at a municipality

    Mobile phones are relatively easy to use for eavesdropping on meetings. They are therefore an attractive target for people who seek to steal information of value. Phones can be hacked through downloaded apps that have access to the microphone and by physically getting a hold of the phone to install malicious software. This means that a phone should never be left out of sight and that a phone never should be laying around during a meeting where sensitive information is discussed. An obvious cyber security conundrum.

    Stop insider trading crimes

    To enable free conversations around classified information, we created Shield, a noise-box especially developed to make phones less of a security risk. Here is an example of how Shield secures a construction permit meeting.

    A large construction permit is to be approved or denied. The decision affects stock prices, housing prices and more prices that are subject to potential insider trading crimes. To minimize the risk of eavesdropping the municipality has a meeting room especially designed for meetings around sensitive information. The meeting room is equipped with a Shield in which all phones and smartwatches are put whenever a meeting is hosted.

    Read more about Shield here.

    Welcome Henrik Nilsson!
    Open post

    Shield safeguarding a M&A-process

    Shield safeguarding a M&A-process

    A possible merger is discussed between two large industrial companies under the protection of Shield

    Mobile phones are relatively easy to use for eavesdropping on private conversations. They are therefore an attractive target for hackers who aim to sell or use valuable information during an M&A-process that have significant impact on the stock market. Phones can be hacked through downloaded apps that have access to the microphone and by physically getting a hold of the phone to install malicious software. This means that a phone should never be left out of sight and that a phone never should be laying around during a meeting where sensitive information is discussed. An obvious cyber security conundrum.

    Shield safeguarding

    Shield is our solution to this problem, a noise-box especially developed to make phones less of a security risk. Here is an example of how Shield can play an important role for safeguarding and information security during a M&A-process.

    During a six months long merger process between two large corporations, meetings are held biweekly. Whether done intentionally or accidentally, any information leakage may be the end of the merger and could also be used to conduct insider trading. Before all meetings the participants are expected to put their phones and smartwatches in Shield.

    Read more about Shield here.

    Welcome Henrik Nilsson!
    Open post

    Integrity and personal information safeguarded by Shield

    Integrity and personal information safeguarded by Shield

    A family with secret identities meets with social services and speaks freely thanks to Shield

    Mobile phones are a security risk for people in vulnerable situations. A hacked phone can reveal a secret identity or location. A perpetrator can, by placing malicious software in a phone or using a regular app with microphone access, threaten and hurt his victim. This means that a phone should never be left out of sight and that a phone never should be laying around during a meeting where sensitive information is discussed. An obvious cyber security conundrum.

    Integrity and privacy

    To help people in vulnerable situations safely share information we have created Shield, a noise-box especially developed to make phones less of a security risk. Here is an example of how Shield can be an important piece of a truthful conversation between social security and a family living under protected identities.

    A mother and her child living under protected identities have a meeting at social services. They have been living under threat for a long time and are extremely cautious not to be found. To respect the family's integrity and privacy the social services have a Shield in the meeting room where all phones are put in sensitive meetings. This also gives the mother a well needed sense of safety.

    Read more about Shield here.

    Welcome Henrik Nilsson!
    Open post

    Shield protecting client information at a law firm

    Shield protecting client information at a law firm

    Earn trust with superior meeting room security through Shield

    Mobile phones are relatively easy to use for eavesdropping on meetings. They are therefore an attractive target for hackers who aim to sell or use valuable information. Phones can be hacked through downloaded apps that have access to the microphone and by physically getting a hold of the phone to install malicious software. This means that a phone should never be left out of sight and that a phone never should be laying around during a meeting where sensitive information is discussed. An obvious cyber security conundrum.

    Shield protecting client

    Shield is our solution to this problem, a noise-box especially developed to make phones less of a security risk. Here is an example of how Shield protection can help a law firm win the trust of an important client.

    A large corporation is about to sign a partnership agreement with a law firm to handle everything from patents to M&As. The law firm explains to their guests that phones are a major security risk and their security policy requires everyone to put their phones in Shield before any business is discussed. The potential client is impressed by the seriousness of the law firm and decides that they are by far the most reliable long term partner.

    Read more about Shield here.

    Welcome Henrik Nilsson!

    Posts navigation

    1 2
    Scroll to top