Citrix App Protection helps secure remote workers

Issue 3 2022 Information Security, Infrastructure


Kurt Goodall.

While corporate-owned devices can be secured using anti-virus software, endpoint scans and MDM, many users don’t apply the same level of security to their personal endpoints. To deliver a best-in-class employee experience that keeps data secure in any scenario, business needs tools that balance business continuity planning, BYOD (bring your own device) and zero trust.

Troye technical director Kurt Goodall says App Protection is here for the Citrix Virtual Apps and Desktops service. “We’re excited to announce that App Protection is now generally available to our Citrix Virtual Apps and Desktops service customers.

“This adds a critical layer of defence against social engineering, phishing events, key logging and screenshot malware for end users accessing corporate resources through any Windows or Mac devices, whether personal, unmanaged or managed,” he explains.

IT and end users alike have seen the benefits of BYOD programmes, which have led to an increase of personal devices in the workplace. Additionally, many companies need gig workers and contractors to use their personal devices to get work done.

While IT takes measures to ensure that corporate-owned and managed devices are secure through policy administration, regular health checks, and web filtering, gig workers and contractors might not take the same measures on their personal devices.

“It’s unlikely that they are monitoring the health of their devices at all, despite the fact that they likely visit social media and other popular sites that are havens for malware. So, while IT invests in security solutions at double-digit growth rates, the risk of a data breach is still high because personal devices infected with malware can enter any corporate network,” he adds.

ATM cash-out attacks are on the rise and can be caused by silent keyloggers sitting on the computer. These attacks are carried out by inserting malware via phishing or social engineering methods into a financial institution or payment processor’s systems. Once infected, the system can transmit users’ personal data back to a third-party attacking system, causing huge financial liability.

Key logging and screen capture malware commonly affect unmanaged endpoints. When present on a device, key logging malware captures each key stroke entered by a user, creating a significant risk for an organisation. The malware captures all the information end users type into a device, including usernames and passwords.

Screen-capture malware periodically takes a snapshot of the user’s screen, saving it to a hidden folder on the device or directly uploading it to the attacker’s server. This also creates significant risk because the attacker can exfiltrate all the information on the user’s screen.

Even with managed devices, there is still the threat of social engineering. A common attack through social engineering is using screen sharing to steal data, money and more. In a screen share attack, the attacker will call and pretend they are tech support or IT and convince an unsuspecting target to screen share their device.

At this point, the attacker can infiltrate the device and take financial information, sensitive data and more. This is even riskier in businesses such as call centres, financial institutions, healthcare and any business handling sensitive customer and patient data.

Goodall says App Protection defends against accidental screen sharing by turning apps delivered through Citrix Virtual Apps and Desktops into black screens. “App Protection can complement your IT security strategy with a zero-trust security approach, assuming all Windows or Mac devices whether they are personal, unmanaged or managed are compromised and protecting from data exfiltration.”

To defend against key loggers, App Protection scrambles keystrokes entered in the device, sending the attacker undecipherable text. It also prevents screenshot malware by turning all screenshots into a blank picture.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Hytera supports communication upgrade for Joburg
News & Events Infrastructure Government and Parastatal (Industry)
By equipping Johannesburg’s metro police and emergency services with multimode radios which integrate TETRA and LTE networks, Hytera is bridging coverage gaps and improving response times across the city.

Read more...
Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Corporate and academic teams can register for Kaspersky contest
Kaspersky News & Events Information Security
Kaspersky has announced the registration opening for its new Kaspersky{CTF} (Capture the Flag) competition, inviting academic and corporate teams from around the globe to compete in a battle of skill, strategy and innovation.

Read more...
MDR: What you’re really paying for
Information Security
When businesses invest in managed detection and response (MDR), they’re buying more than a product, they’re securing access to an entire ecosystem of human expertise, global threat intelligence, and 24x7 incident response.

Read more...
Continuous security optimisation.
News & Events Information Security
Cymulate has announced its partnership with SentinelOne, a threat exposure validation and AI-powered cybersecurity platform. The collaboration delivers self-healing endpoint security that empowers businesses to increase protection for every endpoint on their network.

Read more...
Protect your smart home devices
Kaspersky IoT & Automation Information Security Smart Home Automation
Voice assistants, kitchen robots, smart lights and many other intelligent devices have become part of our everyday life. However, with the rise of smart technology comes the need for robust protection against potential vulnerabilities.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.