WatchGuard Security News Q3 2023

Multifaceted Benefits of WatchGuardONE Certification

11 August, 2023 by Adisa Hairlahovic

Blog WatchGuardone Certifications WatchGuard

The WatchGuardONE certification program goes beyond just a badge of recognition; it empowers partners with a profound understanding of cybersecurity intricacies. Certification stands as a powerful endorsement for partners, equipping them with comprehensive knowledge and tools to deliver top-tier cybersecurity solutions and elevate their competitive edge. This knowledge translates into several significant advantages:

Revenue Growth

The correlation between partner revenue and the completion of additional WatchGuardONE product specializations is strong. This upward trajectory in revenue isn’t solely due to cross-selling opportunities. It’s an inherent characteristic of the WatchGuardONE program. The intentional design of WatchGuardONE Specializations contributes to this performance by providing partners with the tools and expertise needed to excel in various product lines. As partners increase their Specializations count, they position themselves to tap into new revenue streams and into the full potential of the WatchGuard portfolio.

Faster Sales Cycles

Sales certifications for WatchGuard products translate into efficient selling processes. A certified partner is better equipped to not only communicate the value of products effectively but also to identify cross-selling opportunities seamlessly. This heightened competence leads to quicker deal closures and a more streamlined sales cycle.

Operational Efficiency

A technically certified partner can dramatically impact operational efficiency. The ability of certified technicians to swiftly onboard new customers is a key driver in enhancing customer satisfaction and loyalty. What’s more, with a solid technical foundation, these technicians can resolve issues more promptly and tackle a larger number of customer accounts per person. This operational agility can significantly lower response times, increase client satisfaction, and reduce resource strain.

Discounts, Benefits, and Higher Margins

As WatchGuardONE specializations accumulate, partners unlock an array of discounts, rebates, and other sales and marketing benefits. Elevated program tiers come with substantial advantages that extend beyond financial incentives. Higher margins, combined with the suite of marketing resources offered, provide partners with a strategic advantage in the market. Armed with these resources, partners can confidently expand their market reach, promote their expertise, and compete more effectively.

The benefits of engaging with WatchGuardONE and obtaining certifications span multiple dimensions of business growth and operational excellence. The program not only enhances partner revenue and sales cycle efficiency but also amplifies operational effectiveness and equips partners with the resources required to succeed in a competitive landscape.

Certification equips partners with expertise across product lines, allowing them to tap into new revenue streams by increasing their specialization count. For further information regarding WatchGuardONE certifications, and details about technical certification exams, please visit the WatchGuard Learning Center.

WatchGuard Fireware v12.10 and v12.5.12 Releases

15 September, 2023 by Joseph Tavano

Firebox Software Updates

WatchGuard Technologies has released two new versions of its Fireware operating system: v12.10 and v12.5.12. In addition to several key capabilities, these releases include maintenance updates to the Fireware OS, such as fixes for reported issues and updates of software components to the latest versions.

What is new with version 12.5.12?

This Fireware release applies only to the T15 and T35 models and does not include the new features of v12.10. This release updates the engine used for intrusion prevention service (IPS) and application control. As a result, you will see a change in signature IDs used by the engine to identify and classify malicious traffic.

What is new with version 12.10?

This Fireware release applies to FireboxV, Firebox Cloud, the newer T25, T45, T85, M290, M390, M590, M690, M4800, and M5800 models, as well as the older T20, T40, T55, T70, T80, M270, M370, M440, M470, M570, M670, M4600, and M5600 models. This release offers the following new capabilities:

  1. Pre-defined alias for Microsoft 365
    The alias setup process is complicated since Microsoft continuously updates its IP addresses and domains. This forces you to continually check with Microsoft to ensure you have the latest URLs and IP address ranges. Built using Microsoft’s API, you can now take advantage of our simple alias setup. For example, using this alias, you can easily define priority for Microsoft application traffic in SD-WAN.
  2. Expanded cryptography options
    We now support Diffie-Hellman 21. Diffie-Hellman is a widely used protocol for secure communication in various applications, including VPNs, email encryption, and file sharing. Ensure your solution supports the larger key sizes and, thus, offers the highest level of security available.
  3. Proxy updates for WebSocket
    WebSocket connections allow bidirectional communication between a client and server over a single TCP connection, which enables faster and more efficient data transfer. It is commonly used in real-time web, games, and chat applications. Disabled by default for all HTTP proxy actions, you can now specify whether HTTP proxy actions allow WebSocket protocol connections. One example of using WebSocket is our LiveStatus communication between a Firebox and WatchGuard Cloud.
  4. Support for Authority Information Access (AIA) fetching in HTTPS
    AIA is an extension to the X.509 certificate standard that allows clients to obtain information about the issuer of a certificate. This information can be used to verify the certificate’s validity and determine the trust anchor for the certificate chain. A common cause of certificate errors with HTTPS proxy is that web servers are not correctly configured and either provide the wrong intermediate certificate or no certificate. AIA fetching provides a method for clients to find the necessary information about the certificate chain and work around a poorly configured server.

 

Next Steps to Update Software

It is important to keep your Firebox software up to date to ensure you get the most out of your investment and protect your network from security threats. You can upgrade the version of Fireware OS on your Firebox from Fireware Web UI, Policy Manager, or WatchGuard Cloud.

Got a question for us? 

Contact your Security Account Manager today! We are here to help!

How MSPs are Improving Business Models with Unified Security Services

12 September, 2023 by Diana Harter

MSP Imrpove Business Model with WatchGuard

MSPs are transforming their businesses by moving from a resale model to a subscription model. What are the keys to a successful transition?

Historically, MSPs have offered a broad portfolio of outsourced IT products and services, but not cybersecurity. Demand for security services from companies of all types and sizes is rising significantly now due to the steady rise in cyberattacks.

According to a recent survey, 52% of MSPs state that cybersecurity is the most requested offering by customers. Adding security services to their portfolios gives MSPs the opportunity to reinvent themselves and access a broader customer base. But which steps do they need to take to move from a reseller model to a subscription model?

Transformation to a new business model

The shift to a subscription model for MSPs entails a significant transformation in terms of knowledge, skills, infrastructure and services offered. It is important to dedicate adequate time and resources to ensure a successful transition and provide quality security services to customers.

  • Acquisition of cybersecurity expertise: It is essential to have a deep understanding of threats, vulnerabilities, security technologies, regulatory compliance and best practices. Investment in staff training and upskilling is required to develop the necessary expertise.
  • Infrastructure upgrade: Moving from a resale model to a pay-per-use managed services model requires a robust and up-to-date infrastructure capable of delivering advanced cybersecurity services. This may involve investment in tools, management platforms, intrusion detection and prevention systems, log analysis and other solutions.
  • Developing a service strategy: It is essential for the MSP to define a clear strategy for the pay-per-use services they want to offer. This includes determining the scope of services, such as event monitoring, vulnerability management, security analysis, incident response and consulting services. It is also important to establish appropriate service level agreements and policies.
  • Regulatory compliance and security frameworks: It is imperative to understand and comply with relevant regulatory requirements and frameworks. This may include regulations such as the General Data Protection Regulation (GDPR) or standards such as ISO 27001. Adherence to these frameworks gives customers confidence in the quality and robustness of services.
  • Evaluation and continuous improvement: As an MSP with a subscription-based service model, it is essential to perform regular assessments on the effectiveness of the security services provided and to look for opportunities for improvement. This entails collecting and analyzing metrics, reviewing and learning from past incidents, and keeping abreast of the latest trends and threats in this area.

recent study estimates that global MSP revenues will increase by an additional 25% in 2023 compared to 2022. This growth is driven by the incorporation of additional security services.

To make the leap to a pay-as-you-go model simply and efficiently, the best option is to integrate a holistic security solution that covers the areas needed to protect customers in a unified approach. Holistic solutions provide the flexibility and scalability that enable MSPs to choose the most appropriate functions and technology solutions for different service levels. WatchGuard’s Unified Security Platform® architecture provides a unified and simplified approach that helps deliver a powerful service for each threat angle with greater scale and speed while supporting operational efficiencies and generating greater profitability.

It’s time to UPGRADE from TDR Host Sensor to EDR Core

31 August, 2023 by Carlos Arnal

Partner Blog EDR Core

Last March, WatchGuard released WatchGuard EDR Core to replace WatchGuard’s Threat Detection and Response (TDR) Host Sensor. Their goal is to continually improve services and security offerings for their valued partners and clients. As part of this process, they have recently announced the deprecation of some product features, including WatchGuard TDR Host Sensors. The deadline to replace TDR Host Sensor with WatchGuard EDR Core is September 30th, 2023.

What is EDR Core?

WatchGuard EDR Core is included as part of the Total Security Suite license. It complements other next-gen antivirus solutions, protecting against APTs, fileless and malwareless attacks, and advanced ransomware that traditional solutions cannot detect. WatchGuard EDR Core is fully integrated into ThreatSync, providing complete visibility to any malicious activity that bypasses traditional security solutions. EDR Core installs on top of existing endpoint security solutions to add EDR capabilities, as well as ThreatSync (XDR) correlation and remediation features.

Why is it important to upgrade as soon as possible?

Upgrading to WatchGuard EDR Core offers several benefits for you, enhancing capabilities in delivering cybersecurity solutions and services to your clients. Here are some of the main benefits:

  • Enhanced Security: WatchGuard EDR Core adds a layer of advanced threat detection and response to your network security portfolio. This upgrade allows partners to provide their clients with a more comprehensive security solution, addressing sophisticated threats that other antivirus solutions might miss.
  • Competitive Advantage: By offering WatchGuard EDR Core, partners can differentiate themselves in the market. There are no competitors that include EDR protection and XDR capabilities as part of a network security bundle. This solution can help to position you as a cutting-edge security technology provider.
  • First step into XDR: Extending visibility across your network and endpoints is now possible with EDR Core. As a component of WatchGuard’s Total Security Suite, EDR Core brings EDR capabilities to the network portfolio, equipping customers with cross-product Detection and Response features to build up an XDR-based security posture via ThreatSync.

What should you do?

They have released a WatchGuard Cloud feature that enables you to upgrade TDR Host Sensors to WatchGuard EDR Core or to any other WatchGuard Endpoint Security product.

The addition of EDR Core licenses and the upgrade wizard provide a path for TDR users to upgrade to WatchGuard Endpoint Security before September 30th, 2023. The upgrade wizard is not recommended for all customers. Carefully review the Host Sensor upgrade to Endpoint Security to determine the best upgrade path and schedule your upgrade accordingly.

Please, take into account that if you do not upgrade to EDR Core, your existing TDR service will no longer perform detections and responses, and ransomware hash lists will not update for new threats.

Threat Detection and Response (TDR) end-of-life timeline:

  • 30 September 2023 – The TDR user interface in WatchGuard Cloud will no longer be available and therefore the Threat Detection options in the Monitor or Configure menus are not visible. The Host Sensor License pages are also not visible on the Inventory menu. TDR Host Sensors will continue to function, but you will no longer be able to view or remediate indicators or generate reports. Your ability to upgrade Host Sensors to WatchGuard Endpoint Security from WatchGuard Cloud remains enabled.
  • 28 October 2023 – WatchGuard will automatically uninstall heart beating Host Sensors that have not upgraded to WatchGuard Endpoint Security.
  • 1 December 2023 – The TDR service ceases to function, and any remaining Host Sensors must be uninstalled manually.

Need more info?

If you have any questions about this upgrade, please get in touch with your Security Account Manager Today.

Multifaceted Benefits of WatchGuardONE Certification

11 August, 2023 by Adisa Hairlahovic

Blog WatchGuardone Certifications WatchGuard

The WatchGuardONE certification program goes beyond just a badge of recognition; it empowers partners with a profound understanding of cybersecurity intricacies. Certification stands as a powerful endorsement for partners, equipping them with comprehensive knowledge and tools to deliver top-tier cybersecurity solutions and elevate their competitive edge. This knowledge translates into several significant advantages:

Revenue Growth

The correlation between partner revenue and the completion of additional WatchGuardONE product specializations is strong. This upward trajectory in revenue isn’t solely due to cross-selling opportunities. It’s an inherent characteristic of the WatchGuardONE program. The intentional design of WatchGuardONE Specializations contributes to this performance by providing partners with the tools and expertise needed to excel in various product lines. As partners increase their Specializations count, they position themselves to tap into new revenue streams and into the full potential of the WatchGuard portfolio.

Faster Sales Cycles

Sales certifications for WatchGuard products translate into efficient selling processes. A certified partner is better equipped to not only communicate the value of products effectively but also to identify cross-selling opportunities seamlessly. This heightened competence leads to quicker deal closures and a more streamlined sales cycle.

Operational Efficiency

A technically certified partner can dramatically impact operational efficiency. The ability of certified technicians to swiftly onboard new customers is a key driver in enhancing customer satisfaction and loyalty. What’s more, with a solid technical foundation, these technicians can resolve issues more promptly and tackle a larger number of customer accounts per person. This operational agility can significantly lower response times, increase client satisfaction, and reduce resource strain.

Discounts, Benefits, and Higher Margins

As WatchGuardONE specializations accumulate, partners unlock an array of discounts, rebates, and other sales and marketing benefits. Elevated program tiers come with substantial advantages that extend beyond financial incentives. Higher margins, combined with the suite of marketing resources offered, provide partners with a strategic advantage in the market. Armed with these resources, partners can confidently expand their market reach, promote their expertise, and compete more effectively.

The benefits of engaging with WatchGuardONE and obtaining certifications span multiple dimensions of business growth and operational excellence. The program not only enhances partner revenue and sales cycle efficiency but also amplifies operational effectiveness and equips partners with the resources required to succeed in a competitive landscape.

Certification equips partners with expertise across product lines, allowing them to tap into new revenue streams by increasing their specialization count. For further information regarding WatchGuardONE certifications, and details about technical certification exams, please visit the WatchGuard Learning Center.

The Dark Web: What Threats Does This Pose To Your Company

04 August, 2023 by Sam Manjarres

WatchGuard AuthPoint Total Identity Security for DarkWeb Threats

There is a welter of websites that are not indexed by search engines on the dark web, making it an ideal space to exchange all kinds of illegal content or products. This dark part of the web actually represents just 0.1% of the deep web. So how come something so small can be so dangerous for organisations and users?

For starters, there is a significant amount of information available on the dark web. According to Statista data, the current volume of data on the Internet is reached 64.2 zettabytes in 2020 and expected to reach 180 zettabytes by 2025. Although the dark web may seem a tiny percentage of the network, if we do the calculations, we are talking about more than 88 million TB of data. Moreover, as this is sensitive information, a multitude of vulnerabilities can be exploited or attacks perpetrated. The dark web has major forums, used mostly to trade and sell stolen data. One example was the RaidForums, a major forum that Europol and the FBI took down last April. RaidForums started in 2015, created and maintained by a Portuguese teenager who was arrested in the UK last January.

Inside the dark web, there is a huge demand for data, not only for data obtained through ransomware attacks but also for information and services needed to orchestrate one, such as obtaining data to launch a multiphase attack. These include passwords, personal IDs, driver’s licenses, social media accounts and other platforms, email addresses, and phone numbers, as well as other personal data.

It is possible to monitor the dark web

What is clear is that if a company has its data exposed on the dark web, it is unknowingly at the mercy of cybercriminals who are willing to pay large sums of money for the opportunity to infiltrate a corporate network. The good news is that there are ways to know if an organization’s data has been exposed, enabling companies to react and make the necessary password changes before they can be used to access systems and breach data.

The new AuthPoint Total Identity Security solution adds a new layer of protection by monitoring for credential exposure. It also protects the user against potential theft or reuse of credentials. So how does it work?

With the addition of WatchGuard’s Dark Web Monitor, administrators, as well as users involved in data exfiltration, are notified if compromised credentials from monitored domains are found. This enables them to take the necessary actions to mitigate an attack such as the one suffered by Bangkok Airlines when the LockBit ransomware group was able to gain access to the airline’s customers’ data thanks to an initial access broker.

Passwords: gateway or armour to protect your company

Despite the fact that there is interest in promoting “passwordless authentication” as an answer to protecting identity, the fact is that passwords will continue to be used and it is common for organizations to be exposed by employees not managing passwords properly. It has been proven that most incidents happen due to human error – in fact, Verizon’s 2023 Data Breach Investigations Report says that 74% of 2022 investigated breaches involved the human element – and there are common mistakes that function as the gateway for attackers, including:

  • Password sharing
  • Reusing a corporate password for personal use
  • Using the same password for everything
  • Passwords that are easy to crack
  • Shared administration password
  • Password exposure for accounts managed by an MSP

But all is not lost and there is no need to panic. Tools such as a corporate password manager help organizations gain greater control over password quality, reducing the need for password resets and mitigating problems related to weak or stolen passwords. This manager is included in the new AuthPoint Total Identity Security which, in addition to promoting the correct use of passwords within a company, also makes them virtually impossible to crack, even if a hashed password database is stolen.

Being fully protected against malicious cyber actors is essential nowadays and, as the Bangkok Airways incident shows, being equipped with the necessary tools to prevent cyberattacks can protect the company from being hit hard.

How Not-For-Resale Promos and Trials Can Help You Sell Total Identity Security

03 August, 2023 by Sam Manjarres

WatchGuard Nfr Tips Total Identity Security

Managed service providers (MSPs) are constantly on the lookout for effective sales tactics that can promote and sell their products and services. One of the best ways to offer potential customers a taste of what your product can offer is through not-for-resale (NFR) promotions and trials. With credential-related threats being a hot topic among consumers, this is the perfect time to leverage NFRs and trials to see the newly launched AuthPoint Total Identity Security!

Not-For Resale (NFR) Promo Available

AuthPoint Total Identity Security Not-For-Resale (NFR) SKU for one year (1 YR) is now available on the DISTI price list for just $.01

Description:     WatchGuard AuthPoint Total Identity Security – NFR – 1 Year

SKU #:             WGTIS365

Promo Price:    $0.01 per user/per month

Term:               1 Year

Minimum:        5 Users

Easily Enable Trials in WatchGuard Cloud

Trials offer an opportunity to test our corporate password manager and dark web monitoring service. Simply activate the trial in WatchGuard Cloud and allow your clients to experience the benefits of Total Identity Security in real time.

Also included in AuthPoint Total Identity Security trial:

  • Auto-fill credentials with browser extensions for Chrome, Edge, Safari, and Firefox
  • Corporate password manager
  • Dark web credential monitoring
  • Web application portal enabled with single sign-on access
  • Zero trust risk policies based on location, time, and device DNA

Contact your Account Manager today to find out more about WatchGuard AuthPoint Total Identity Security

Resources And Tips To Get Started With AuthPoint Password Manager

27 July, 2023 by Sam Manjarres

WatchGuard AuthPoint Corporate Password Manager

Since the launch of AuthPoint Total Identity Security – the ultimate package for robust password management and dark web monitoring – our latest release has already generated a buzz, with new trial activations and pipeline deals pouring in.

To ensure a seamless setup of our password manager, we’re equipping you and your admins with comprehensive resources. Get ready to fortify your security like never before.

The AuthPoint Password Manager gives your customers better control with built-in advanced password generation and visibility into weak, reused, duplicate, and shared passwords.

With password manager, users set a single, complex password that is used to store and protect all their other credentials. No need to create or remember unique passwords ‒ the only password you have to remember is the password to your vault!

How to Access and Install AuthPoint Password Manager

You can use the AuthPoint Password Manager on your mobile device or from a web browser.

  • The AuthPoint Mobile App is available for iOS and Android.
  • AuthPoint browser extensions are available for Chrome, Edge, Firefox, and Safari.

Watch this video tutorial to learn how to get started with password management.

WEBINAR: Expand Your Managed Security With XDR

26 July, 2023 by Adisa Hairlahovic

WatchGuard Webinar XDR Security

Don’t miss the opportunity to equip yourself with the knowledge and insights needed to expand your current managed security delivery with WatchGuard by leveraging the power of eXtended Detection and Response (XDR). Join us in this webinar to explore how WatchGuard ThreatSync will elevate your security offering by providing real-time threat visibility and automated response capabilities, thereby strengthening your clients’ overall security posture.

We’ll cover the following:

• Cybersecurity landscape updates
• Stay competitive with WatchGuard in the MSP industry
• Unifying security under XDR
• Enhancing managed security

August 9 at 8am PDT (3pm GMT): Leveraging XDR to Expand Your Managed Security Delivery – Business Track

August 10 at 8am PDT (3pm GMT): Leveraging XDR to Expand Your Managed Security Delivery – Technical Track

WATCH NOW

Explore the ONE Security Platform MSPs

17 July, 2023 by acogswell

Watchguard One for MSPs

As cyberattacks and the overall threat landscape grow more complex, managed service providers (MSPs) need to evolve. As an MSP, you must be capable of protecting customers from attacks targeting networks, devices, and users. Finding ways to protect your customers’ expanding threat surface is one thing, but doing so without compromising on operational efficiency or profitability is another. At times this can feel like an insurmountable task.

A 100% channel-driven company, WatchGuard understands this unique set of challenges and has built our Unified Security Platform® architecture to help MSPs overcome them. Our platform streamlines every aspect of modern security delivery and makes comprehensive, simplified, and profitable protection possible for security service providers.

With WatchGuard, you get the products and services you need to secure IT environments, endpoints, and identities, and a centralized management interface from which to manage them. Moreover, you get the speed and efficiency of cross-product threat intelligence and platform-wide automation, opening up endless possibilities for managed security offerings and profitable, recurring revenue streams. Simply put, we offer the only advanced security platform tailor-made for MSPs like you.

New Product Alert – AuthPoint Total Identity Security

12 July, 2023 by Sam Manjarres

WatchGuard AuthPoint MFA Total Identity Security

AuthPoint Total Identity Security is a new product bundle with AuthPoint MFA and credentials management products, including corporate password management and dark web monitoring. With this product, you can now add new identity security services to your offering that reduce credential management costs, increase user adoption of identity protection, and mitigate risk from potential phishing and social engineering attacks related to credential theft.

Passwords are not going anywhere anytime soon. Early adopters of passwordless authentication find themselves in countless situations where passwords are required, and passwords are one of the factors in multi-factor authentication. The password needs to be protected to keep authentication strong.

AuthPoint Total Identity Security includes all the following products and is purchased using any FlexPay option, such as pre-paid licenses, pay-as-you-go WatchGuard Points, and monthly subscriptions (where available). AuthPoint MFA service is also available for purchase separately.

  • AuthPoint MFA – Deploy a complete multi-factor authentication solution with single sign-on (SSO) and risk-based authentication that’s easy to manage and use.
  • Dark Web Monitor  Get notified when compromised credentials from monitored domains are found on the dark web and published to credentials databases.
  • Corporate Password Manager  Improve password quality, reduce resets, and mitigate risk from shared or stolen passwords. Our Corporate Password Manager creates strong, complex passwords and provides the enforcement controls and shared vaults that businesses need.

Existing AuthPoint MFA customers can upgrade to Total Identity Security with a co-termed new license purchase. As a WatchGuard partner, you will continue to have some customers with AuthPoint MFA and some with AuthPoint Total Identity Security, but each customer’s (tenant) account in WatchGuard Cloud may only have either AuthPoint MFA or AuthPoint Total Identity Security licenses applied to it.

Try AuthPoint Total Identity Security today! You can start a trial directly from WatchGuard Cloud, and you can start a trial for yourself or any client, even if they have a valid AuthPoint MFA license. In fact, this is a great way to upsell to your existing customers.