Opens in a new tab
vmblog logo 2024 wht (updated)

Black Hat USA 2024 Q&A: Menlo Security Will Showcase Its Cloud-Browser Security Platform

Share: 

David Marshall | Published: August 1, 2024

 

Are you getting ready for the upcoming Black Hat USA 2024 event, an internationally recognized cybersecurity event providing the most technical and relevant information security research, now in its 27th year.  The event is quickly approaching, taking place August 3-8, 2024, returning to the Mandalay Bay Convention Center in Las Vegas, NV with a 6-day program. 

Ahead of the show, VMblog received an exclusive interview with Andrew Harding, Vice President of Security Strategy, Menlo Security, a pioneer in browser security.  Make sure to add them to your MUST SEE list.

Menlo Security Logo 

VMblog:  Before we get into it, can you give us a quick overview of the company? What should folks know?

Andrew Harding:  Menlo Security protects organizations from cyber threats that attack web browsers. Menlo Security’s patented Cloud-Browser Security Platform scales to provide comprehensive protection across enterprises of any size, without requiring endpoint software or impacting the end user-experience. Menlo Security is trusted by major global businesses, including Fortune 500 companies, eight of the ten largest global financial services institutions, and large governmental institutions.

VMblog:  Today’s cyberattacks are highly sophisticated and evasive, oftentimes weaving past traditional endpoint security solutions. How does Menlo Security address this gap?

Harding:  If you’re a cybercriminal looking for an easy and lucrative pathway to launch successful attacks, web browsers are the hotspot. Traditional security tools have fallen behind in detecting the sophisticated attacks today’s cybercriminals are launching. These cyberattacks are evasive, slipping past what many consider to be the most comprehensive security stacks. Also known as Highly Evasive and Adaptive Threats, HEAT, they are well-crafted, thought out, and have high success rates. Earlier in 2024, the threat research team at Menlo Security detected a 200% increase in browser-based phishing and evasive attacks during the second half of 2023. Menlo Security addresses this gap by adding the browser to a defense-in-depth architecture. Layering multiple security measures to secure enterprises doesn’t work if care is not taken to defend browsers and the user working within them. The Menlo Security Enterprise Browser solution, powered by the Secure Cloud Browser, protects millions of enterprise users globally. It blocks zero-hour phishing, malware, and ransomware attacks directly inside browser sessions and provides unparalleled protection against even the most advanced and evasive cyber-attacks. All of this is done in any browser users may choose, avoiding hefty costs and the inconveniences that come with deploying and using a replacement browser.

VMblog:  What is your message to Black Hat attendees coming out to the show this year? If they take back one message about your company, what should it be? 

Harding:  Security practitioners are in the business of managing risk and stopping criminals. We need new tools to expose the hidden danger lurking behind some clicks. And we need to manage the risk of Internet connected workplaces while gaining the speed advantages of our hyperconnected, hybrid, and mobile workplace. The struggle we face together: an increasing attack surface and smarter adversaries requires us to rethink fundamental assumptions. The security architecture for the 2000s doesn’t manage browsers or protects users effectively. Secure application access and governance of enterprise data needs attention. And we have to address these changing requirements in a budget constrained environment. Solutions powered by the Menlo Security Secure Cloud Browser can meet them right where they are in their security journey and change the game on adversaries while making zero trust access much simpler. Menlo can help enterprises achieve progress in a “secure by design” journey as they rethink remote access, legacy VDI, or look to make SOC teams more efficient.

VMblog:  Black Hat attendees are known for being security professionals at the forefront of the industry. What specific challenges do you anticipate they’ll be facing, and how will your solutions help them overcome those challenges?

Harding:  Security leaders and practitioners need to accept the reality that evasive, browser-based cyberattacks are the new normal. Browsing security needs attention. Employee training is not enough, and the solution must allow users the flexibility to use the browser they know and prefer. The browser is where the majority of employee and user work happens – whether email, communication, document sharing, collaboration. Employees spend at least 75% of their workday in a browser. During 2023, 175 CVEs classified as high or critical were issued and over 125 new features were added to Chromium, the open-source web browser serving as the foundation for over 95% of browsers. Menlo Security helps security practitioners address these challenges by enabling the workspace of tomorrow within the browser, delivering browser security to desktops and mobile work, and protecting users, applications, and data from today’s most evasive, destructive cyber-attacks.

VMblog:  The market is a crowded space. What is it about your company and technology that sets you apart from the competition? What are your differentiators?

Harding:  Menlo Security enables the world to connect, communicate, and collaborate securely without compromise. It’s imperative that we close the gap in cybersecurity left by legacy defenses while enabling zero-trust access that is easy to deploy. Businesses need to consider threats that target enterprise browsers specifically. The Menlo Enterprise Browser solution has emerged as a platform that turns every browser into a secure enterprise browser. Blocking zero-hour phishing, malware, and ransomware attacks are just the start. The Menlo Security Secure Cloud Browser provides a secure browsing experience for users and enables enterprises to make more of hybrid work and mobility without taking on more risk and complexity

VMblog:  What are some of the top priorities security leaders should be considering for 2024?

Harding:  Security leaders need to be looking at their arsenal of security tooling to see if each one is detecting – and responding to – the level of sophistication of today’s threats. Threats get through legacy tools. And the complexity and expense of legacy zero trust systems or out of date remote access VPNs makes things harder, not better. Browser-based threats are often neglected because some endpoint protection agents are running on autopilot, and folks don’t notice that they are missing threats until it’s too late.  Phishing attacks may originate in email-but they lead to browsers. Having a defense that covers the browser must be a priority. Cybercriminal playbooks are constantly changing, oftentimes faster than IT and security teams can keep up. This means last year’s priorities cannot remain the same as this year’s.

VMblog:  Looking ahead, what excites you most about the future of cybersecurity, and how do you see your company playing a role in shaping it?

Harding:  Although threats are becoming more evasive and sophisticated, we do believe it is prompting organizations to respond sooner rather than later. We see the role of the browser being taken more seriously. Menlo Security has been collaboration with organizations to evolve from legacy tools or generation-one RBI and quickly adopt a secure enterprise browser solution. Protecting employees from growing browser-based threats reduces risk. By taking this browser-centric, defense-in-depth approach, organizations can effectively protect their workforce against the evolving landscape of browser-based attacks.

Menlo Security recently uncovered three novel nation-state campaigns employing highly evasive and adaptive threat (HEAT) attack techniques. In a recent 90-day period, Menlo Labs uncovered a trifecta of sophisticated HEAT campaigns-LegalQloud, Eqooqp, and Boomer-compromising at least 40,000 high-value users. And we have upcoming research that will reveal the evolution of these attacks. Such research helps to focus our product R&D, so we can stay ahead of browser oriented threats and help enterprise security teams ensure a safer environment in which to do business.

##