Nozomi Networks automates cybersecurity defences for critical infrastructure

by Varun Godinho
0 comment

Nozomi Networks has announced a new cybersecurity solution that automates threat responses in operational environments. 

That new capability is built into the latest version of Nozomi Arc which, it first launched in 2023. 

Nozomi Arc can now operate in three modes depending on the organisation’s environment and risk tolerance. Detection Mode offers non‑disruptive monitoring for audits and compliance. Quarantine Mode will block malicious files while preserving them for forensic analysis and Delete Mode instantly removes malicious files to prevent further damage. 

“Industrial networks are under escalating attack, and traditional IT cybersecurity automation tools aren’t safe or viable in OT environments,” Nozomi Networks co-founder and chief product officer Andrea Carcano says. 

“With Nozomi Arc threat prevention, we are empowering customers to – at their discretion – safely and automatically block and contain threats directly at the endpoint. We intend to extend automated threat prevention capabilities across the Nozomi Platform in the future.”

Nozomi Arc’s prevention engine is supported by Nozomi Networks Threat Intelligence and its Threat Intelligence Expansion Pack, powered by Mandiant Threat Intelligence. 

Indicators of compromise are delivered in Yet Another Recursive Acronym (YARA), Structured Threat Information Expression (STIX) and Signature-based Intrusion Detection (SIGMA) formats to enable effective local behavioral analysis. 

The automated offering from Nozomi comes a few months after the company’s bi-annual Nozomi Networks Labs OT & IoT Security Report showed that Australia is now the fourth most targeted country of cyberattacks behind Japan, Germany and Brazil. 

In Australia, the top threats include default credentials and valid accounts attacks, which accounted for 45.6 percent of all the alerts raised. 

Adversary-in-the-Middle technique – where attackers insert themselves between two communicating parties in an attempt to compromise the confidentiality or integrity of the data – followed as the third most popular threat tactic. 

In the previous six-month period, Network Denial of Service was a prevalent technique observed in Australia, taking fourth place. 

The country’s manufacturing sector was the most targeted industry during this period, followed by minerals and mining.

Read more: Mitsubishi Electric acquires Nozomi Networks for $1.5 billion

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More