Stay tuned for the latest cybersecurity news and industry events.

In this section you will find all the news on technologies, regulations and must-attend appointments for LECS’ signature enterprise cybersecurity.

News, trends and technology events in cyber security.

We attend major national and international conferences to share strategic visions. This constant comparison with the market allows us to analyze emerging risks in real time and study new developments, ensuring proactive and cutting-edge protection solutions for companies.

Luigi Pelazza: From “Le Iene” Investigations to the Front Lines of Cybersecurity

Luigi Pelazza, Lecs Spokesperson

Since 2002, Luigi has been traveling the world with a microcamera and a notebook, reporting on investigations, scams, and news stories that have left a lasting impression on the Italian public. His work is driven by intuition, curiosity, and—above all—a focus on those at risk of falling victim to people who take advantage of others’ good faith. It’s no surprise that, a few years ago, he decided to put this same attention to work on a project of his own, founding Privacy S.r.l. in 2022, a company specializing in cybersecurity and new technologies.

It is in this spirit that today we are pleased to announce some news that makes us particularly happy: Luigi Pelazza is the new spokesperson for LECS®, the “Made in Italy” cybersecurity technology developed by Cyber Evolution. This was a natural choice, even before it was a business decision: someone who has spent a lifetime protecting people from scams is now doing the same in the digital realm.

That meeting soon led to a partnership: Luigi began bringing LECS to market, targeting primarily small and medium-sized businesses and large corporations through a network of partners, as well as public administration agencies.

It’s no coincidence that, out of all the possible projects, he was the one to take up this cause. “After 25 years spent hunting down scammers of all kinds, finding an ally like this black box—with technology made in Italy—lets me sleep more soundly, ” says Luigi, who sees in LECS the same mission he has pursued his entire life in front of the cameras: protecting those at risk of being exposed—whether it’s a family or a business.

LECS is a finalist in the Italian Security Awards for Best NDR 2026.

LECS tra i cinque finalisti degli Italian Security Awards 2026 nella categoria Infrastructure, Network Security e NDR
  • Go to the official voting page;
  • Fill in the required information and submit your vote.

LECS Among the Best Cybersecurity Solutions in Europe in 2026

Enterprise Security Magazine Europe has named Cyber Evolution | LECS among the best cybersecurity solutions in Europe for 2026 and highlights it as a top choice for organizations requiring network protection in enterprise and industrial environments.

Logo LECS con il riconoscimento Top Cyber Security Solutions in Europe 2026 assegnato da Enterprise Security Magazine Europe.

The editorial team’s assessment is based on a design principle shared by LECS: an NDR platform is useful when it detects activity on the network without interfering with protected systems. This capability becomes critical in manufacturing facilities, healthcare facilities, and mixed-use infrastructure, where medical devices, legacy machines, and IoT devices often do not support agents or frequent updates.

Certificate of Recognition awarded to Cyber Evolution | LECS as a Top Cyber Security Solutions Provider in Europe 2026 by Enterprise Security Magazine Europe.

Why LECS Is Among the Best Cybersecurity Solutions

In its in-depth technical analysis of Network Threat Detection, the international publication specializing in cybersecurity highlights LECS’s ability to transform observed traffic into actionable intelligence for analysts: the platform analyzes communications between assets, identifies lateral movement, and forwards contextualized events to SOCs and SIEMs.

By integrating with firewalls, antivirus software, and EDR, the platform extends the capabilities of the existing stack to internal traffic, interprets more than 300 protocols, and provides visibility into assets and network segments that are difficult to monitor using conventional tools.

This assessment is supported by Cyber Evolution’s operational data: LECS reduces false positives by an average of 87%, allowing analysts to focus on activities that require more in-depth investigation.

Co-founder and CTO Roberto Camerinesi also describes a customer deployment in which LECS detects lateral movement initiated by a compromised Wi-Fi host within an OT environment, isolates the affected system, and disrupts the attack chain.

Finally, the analysis highlights the balance between autonomous countermeasures and manual control.

These results contribute to LECS being recognized as one of the best European cybersecurity solutions for 2026 and reinforce its position as a European technology for cyber resilience.

NIS2: obligations, 2026 deadlines, penalties, and incentives for companies

NIS2 Deep Dive by LECS on 2026 obligations, deadlines, penalties and incentives for companies
cyber secuirty luxury e hospitality

From requirement to operational control.

LECS® helps turn monitoring, anomalies and response
into readable information for those who must oversee risk.

Several factors intervene in defining whether an organization falls under NIS2: sector, size, activity performed, role and services provided. Therefore, prior verification with technical and legal specialists is necessary before determining whether or not a company is subject to the regulations.

Govern the risk in your network.

When external vendors and services impact network and processes, you need visibility
into what impacts business continuity.

  • Reputational damage: incidents, deficiencies, or mandatory disclosures can reduce the trust of customers, partners, and stakeholders.
NIS2 infographic explaining the 10 areas where LECS® supports asset inventory, risk management, vulnerability, logs through continuous response and monitoring.
alt=""

Close the cybersecurity loop.

LECS® supports continuous, automated and auditable security,
helping to turn regulatory requirements into operational capabilities.

LECS arrives in OGR Turin: a new garrison in the Italian innovation ecosystem.

LECS presente in OGR Torino, hub italiano per innovazione e tecnologia

OGR Turin, a hub for technology and business growth.

OGR Turin is an innovation hub that combines culture, technology and business acceleration.

The Tech area is the space dedicated to scientific research, technological development and programs for the growth of innovative enterprises.

Its value also stems from its history. Built in the late 19th century as an industrial hub, the complex the complex accompanied the city’s growth for about a century. Today it has been redeveloped into a space dedicated to culture, technology and enterprise.

Today, OGR Turinhas activated collaborations with leading realities: from acceleration programs on smart mobility with partners such as Techstars, Fondazione CRT and Intesa Sanpaolo Innovation Center, to the Tech Revolution Factory set up with Microsoft on the topics of AI, Big Data, gaming and social entrepreneurship.

For LECS powered by Cyber Evolution, being present in OGR Turin means entering an environment that dialogues with national and international innovation protagonists. A step that strengthens LECS’ projection toward new markets and foreign interlocutors.

You can find us here: Corso Castelfidardo, 22, 10128 Turin, TO

Cyber Evolution – LECS honored for second consecutive year among Italy’s best innovative SMEs

Cyber Evolution - LECS Representative, Recipient of the 2026 America Innovation Award

An award that recognizes innovation and growth of Cyber Evolution – LECS

The award takes on even more weight considering that winners are selected on the basis of parameters related to competitiveness and innovative investment and that the process does not involve self-nominations. An aspect that helps solidify the institutional value of the award.

For us, this achievement is a concrete confirmation of our ability to transform expertise, research and technological vision into effective solutions for the market, capable of generating real value for businesses and organizations, through a path oriented toward growth, quality and applied innovation.

To be recognized once again among the country’s innovative excellences is a source of pride and, at the same time, an incentive to continue with even greater determination in investing in innovation, applied research and skill development, with the goal of continuing to offer the market reliable, advanced and high value-added solutions.

LECS at SMAU Paris April 14-16, 2026

LECS at SMAU Paris 2026 from April 14 to 16

Cyber Evolution – LECS honored as Innovative Vendor at Italian Channel Awards 2025

LECS honored as Innovative Vendor at Italian Channel Awards 2025

ACN QC1 strengthens LECS’s position in the Italian cybersecurity market

This achievement reinforces the credibility, reliability, and market value of the NDR technology developed by Cyber Evolution.

Black LECS logo on a light background, featuring the National Cybersecurity Agency logo and QC1 accreditation.

Cyber Evolution announces that LECS has achieved ACN QC1 accreditation related to cloud services, an achievement that further strengthens the solution’s positioning in terms of authority, reliability, and trust toward the market.

In the field of cybersecurity, QC1 accreditation is a formal recognition that certifies compliance with specific requirements within a scope defined by ACN—the National Cybersecurity Agency, Italy’s leading authority on cybersecurity—which lends significant institutional weight to the achievement.

This milestone is part of a development path that sees LECS evolve into a platform designed to offer more practical, automated, and sustainable cybersecurity, with a constant focus on proactive protection, ease of adoption, compatibility with IT/OT environments, compliance support, and business continuity. These elements align with the company’s strategic pillars.

For Cyber Evolution – LECS, the result also represents a strengthening of its position as an Italian company committed to the development of innovative, reliable and scalable cyber technologies.

ACN – QC1 accreditation takes on value not only for the brand, but also for the entire ecosystem of customers, partners, resellers and system integrators that revolves around LECS.

“This result confirms the validity of the path taken and further reinforces the value of LECS as a solution capable of combining innovation, reliability and operational concreteness,” says Roberto Camerinesi CTO of Cyber Evolution, “For us, it means continuing to invest in cybersecurity that truly protects organizations without adding complexity.”

With this milestone, Cyber Evolution continues its mission to develop Italian technologies for cybersecurity that are more transparent, more accessible and closer to the real needs of businesses.

Phishing: what to do after an attack and how to prevent it in the enterprise

Phishing is one of the most common and damaging threats to businesses, exploiting deception to obtain credentials, sensitive data and compromise corporate systems. In this article we will explore what to do after a phishing attack and how to prevent future incidents by integrating LECS solutions.

What to do immediately if someone in the company has clicked a phishing link

Isolate the device from the network and protect critical credentials

When an employee clicks on a suspected phishing link, immediate response is critical to reduce the damage. The first thing to do is to isolate the device from the corporate network to prevent the attacker from propagating his attack. This means disconnecting the device from both the wired and Wi-Fi networks. After isolating the compromised device, it is essential to prevent the user from entering new credentials and to immediately change passwords for critical accounts.

Enabling or strengthening multifactor authentication (MFA) on these accounts can significantly reduce risk.

The problem that companies face at this stage is the fear that a single click could compromise accounts and corporate data, with the difficulty of understanding whether the attack had an immediate effect or not. Cyber Evolution’s proposed solution helps monitor the network traffic generated by the compromised device by observing connections to suspicious IPs and domains. LECS flags any anomalies and helps the IT team distinguish between false alarms and real situations of compromise. This helps reduce the risk of chain compromise and contain the incident in a structured way.

With this immediate response, the enterprise gains more control over the attack surface, limiting the damage to only compromised devices and accounts. LECS helps to respond promptly and protect corporate data more effectively.

Activate IT/Security immediately and open a formal incident

If a user clicks on a phishing link, the IT team or SOC should be alerted immediately and a formal incident should be opened by creating an incident ticket. Management of the incident should not be left to the initiative of the individual employee, who may simply delete the email. A formal approach, following corporate guidelines for incident management, is essential for a timely and targeted response.

At this stage, the weakness concerns the delay with which incidents are reported, the incomplete information, and the difficulty in reconstructing the technical sequence of events. This results in an inability to respond promptly, increasing the risk of damage. The LECS solution solves this problem by providing immediate visibility into network events related to the compromised device. LECS provides a consolidated timeline and detailed view of the assets and connections involved, facilitating the Detect/Respond steps according to the NIST framework. This helps to document the incident with reliable technical evidence and enables rapid and efficient response to be initiated.

By quickly activating the incident response process, the incident exposure time can be reduced, ensuring that the company can deal with the attack in a structured and best-practice compliant manner.

Blocking links, sender and related domains at the enterprise level

To prevent phishing from spreading to other employees, links, senders, and domains used in the attack must be blocked immediately. This action must be performed on all levels of the enterprise, including e-mail gateways, Web filters, and network controls.

The problem at this stage is that phishing campaigns can hit multiple users in a very short time. In addition, enterprise security tools, such as email security systems, proxies, and firewalls, can be fragmented, making it difficult to know if other users have been affected by the same attack. The LECS solution helps identify recurring patterns in requests to suspicious domains and IPs from multiple hosts. LECS can trigger automatic actions via the Raises (Autonomous Response) engine to block phishing or C2 domains based on corporate policies. Alternatively, LECS can suggest targeted blocks on corporate firewalls and proxies to reduce further exposures.

This approach prevents a single attack from escalating into an extended campaign, quickly containing the incident and limiting the number of compromised devices and accounts.

Understanding the attack: technical analysis after a phishing incident

Classify the type of phishing and possible impacts (credentials, data, payments)

Phishing comes in several forms, including generic phishing, spear phishing, whaling, smishing and vishing, each of which has different objectives: credential theft, Business Email Compromise (BEC), ransomware and data exfiltration. Understanding the type of phishing helps determine the potential impact and actions to take.

Many times companies treat all malicious emails the same, without considering targeted campaigns, such as those targeting apex figures or critical business systems. The LECS solution allows the incident to be quickly classified using artificial intelligence engines (Specto, Tiresia, and Raises). LECS can detect lateral movement, data exfiltration and persistent connections, allowing it to distinguish a “limited” phishing attack from an evolving one. This helps prioritize corrective actions and determine whether authorities need to be involved or regulatory channels activated.

Analyze post-click network behavior (endpoint, server, cloud, OT/IoT)

Defense against phishing is not limited to checking email: it is critical to monitor post-click network communications. This means monitoring requests to malicious domains, payload downloads, attempted connections to C2, and lateral movement on the internal network.

The problem is that the logs are distributed across multiple systems (email, EDR, firewall) and it can be difficult to reconstruct an end-to-end view of the incident, risking missing important phases of the attack. The LECS solution provides a single source of truth about phishing-related network events by monitoring mirrored traffic and recording each network event in high-reliability logs. Critical logs can be notarized via DLT/blockchain, increasing the evidentiary value of collected evidence.

Decide on corrective actions and any formal communications

After analyzing the incident, it is critical to make quick decisions. Corrective actions may include resetting compromised credentials, isolating vulnerable systems, restoring from backup, and formally communicating to senior management, customers, or authorities as required by regulations such as NIS2.

Uncertainty at this stage relates to when to elevate the incident to management, DPO or CSIRT level, and how to justify the choice with hard data. The LECS solution offers structured network logs and reliable timelines that support documentation of the incident and provide the evidence needed for internal communications and regulatory notifications.

How to prevent the next phishing attack: people, processes, technology

Continuing education and phishing simulations for employees

Defense against phishing in the enterprise requires a structured ongoing training program. Training campaigns should include real-world examples, simple guidelines for recognizing suspicious emails, and periodic simulations to measure click-through rates on suspicious links.

The problem many companies face is message overload that confuses users and the difficulty of maintaining a high level of awareness. In addition, there is a lack of an effective way to measure improvements. The LECS solution is an essential support in this process. LECS collects data on network events and intercepted threats, fueling training campaigns and making them more relevant and targeted, as well as providing data for reporting to management.

Strengthening authentication and privilege: phishing-resistant MFA and least privilege

A crucial step in preventing phishing is theadoption of robust authentication solutions, such as multifactor authentication (MFA). In addition, the principle of least privilege should be adopted to limit access to corporate systems to only those who really need access.

The difficulty of properly managing privileges and protecting corporate credentials is real. The LECS solution is critical because it monitors network access and detects suspicious activity, such as abnormal access attempts and lateral movement. This allows it to limit the impact even when a phishing attack hits, protecting corporate systems from further damage.

Integrating an NDR such as LECS into the phishing defense strategy

In addition to email security and EDRs, integrating an NDR-IPS such as LECS into the phishing defense strategy is critical. LECS provides extensive visibility into network traffic, detecting communications to command and control (C2) servers, lateral movement, and other anomalies.

The problem here relates to poor visibility into internal traffic and the difficulty of monitoring the effects of phishing after the click. The LECS solution enables monitoring and responding to attacks along the entire attack surface, reducing risks from internal vulnerabilities and improving incident response.

In this scenario, LECS support is not limited to just being “a network sensor”-it is a plug-and-play, zero-config NDR-IPS Black Box that can be installed quickly and without having to design new architectures or manage complex configurations.

Once connected to the network, it protects IT, OT, and IoT devices and brings together three AI engines working in parallel: Specto (real-time automatic detection and management), Tiresia (threat forecast), and Raises (autonomous response), so as to move from observation to mitigation when the impact becomes critical.

From phishing as an emergency to phishing as a managed risk

Phishing should not be treated as an isolated emergency, but as an ongoing risk to be managed in a structured way. By adopting advanced technologies such as LECS, companies can integrate phishing into their cyber risk management model with measurable and auditable processes.

LECS becomes a central component for monitoring, detecting and documenting the effects of phishing on the corporate network. With visibility across the entire network surface, LECS enables more effective response and continuous updating of policies, training, and response plans, reducing the frequency and impact of phishing attacks.

For more information and to secure your business reality, learn about our technology.

Cyber Evolution partners with Nethesis at Digital Heroes Meeting 2025

The Digital Heroes 2025 Meeting, promoted by Nethesis, represents one of the main events in the Italian ICT landscape focused oninnovation, open-source solutions and community among technology partners.

This year, Cyber Evolution will take an active role in presenting advanced enterprise cybersecurity solutions, sharing concrete use cases and establishing new partnerships.

What is the Digital Heroes Meeting 2025

The event is organized by Nethesis, which brings together its community of Nethesis Partners to explore IT industry news.

It will take place on October 9 and 10, 2025 at the Rimini Palacongressi, with an agenda that includes workshops, technical sessions, success stories presented by partners, exhibition booths and high-value networking moments.

For those working in the industry, it will be an opportunity to learn more about tools for continuous monitoring, access management, response automation and regulatory compliance.

The Digital Heroes Meeting 2025 is more than a trade show: it is a laboratory of ideas, innovations and relationships. With LECS powered by Cyber Evolution present as an active partner, you can learn all about NDR cyber security solutions.

LECS at ICOSXperience 2025: must-attend event for enterprise cyber security

Cyber security is a strategic priority for businesses, especially in a rapidly changing technological and regulatory environment. LECS’ participation in the ICOSXperience 2025, which will take place Sept. 23 at the Hotel Parchi del Garda in Lazise, Verona, Italy, is a concrete opportunity for companies looking to strengthen their cyber security.

ICOSXperience 2025: what is it?

Organized by ICOS, the official distributor of LECS, ICOSXperience reaches its fifth edition this year and is one of the most relevant annual events for the cyber security industry in Italy. The event brings together business executives, technical and commercial managers, offering the chance to explore technological innovations, new market opportunities and emerging business models.

The program includes parallel breakout sessions, strategic networking moments and convivial opportunities to create synergies and new collaborations among participants.

Why meet Cyber Evolution at ICOSXperience 2025?

LECS powered by Cyber Evolution will participate as a Gold Partner in ICOSXperience 2025, with a dedicated exhibition space and an exclusive speech. During the presentation, it will be possible to participate in a special drawing and win a LECS NFR (Not For Resale), to directly test the benefits of our solution.

Meeting Cyber Evolution at ICOSXperience provides an opportunity to learn more about the most current and critical issues in cyber security and evaluate firsthand innovative technologies for protecting data and infrastructure. The LECS team will be available for customized meetings and technical demonstration sessions in the dedicated exhibit space.

Participants will learn about the LECS system, featuring patented technology that includes:

  • Specto, for continuous monitoring and intelligent threat classification, which is critical for preventing cyber attacks.
  • Raises, an advanced automatic incident response system with the ability to physically isolate compromised network segments via Air-Gap energy.
  • Tiresia, an artificial intelligence algorithm that constantly improves predictive ability and automates system response.

Networking and business opportunities

ICOSXperience provides an ideal platform for technical updates and the development of business relationships and strategic partnerships. In the previous edition, more than 300 participants from 120 companies, including business decision makers and technical specialists, attended the event. The presence of LECS powered by Cyber Evolution represents a concrete opportunity to explore possible partnerships with innovative companies seeking advanced cybersecurity solutions.

Details of the event

The appointment is set for Sept. 23 at the Hotel Parchi del Garda, in Lazise on Lake Garda. Here is the program for the day:

  • 8:30 am – 9:30 am: reception and welcome coffee
  • 9:30 a.m. – 12:55 p.m.: round of parallel sessions
  • 13:00 – 14:00: lunch
  • 2:00 p.m. – 4:00 p.m.: Expo
  • 14:20 – 16:00: 1-to1 Meetings
  • 14:20 – 16:00: Demo sessions
  • 4:00 – 4:30 p.m.: awards ceremony and cocktail reception

LECS powered by Cyber Evolution’s participation in ICOSXperience 2025 is a must-attend opportunity for companies engaged in cybersecurity. Delving into advanced technologies and engaging directly with experts in the field enables them to effectively improve corporate security.

Enhance the security of your customer portfolio with LECS’ invisible protection. See you on September 23.

For more information find out about our technology.

Corporate IT security: 7 steps to protect your business

Corporate IT security: 7 steps to protect your business

In today’s environment, where cybercrime is evolving at an unprecedented pace, enterprise cybersecurity is a competitive prerequisite and not just a regulatory obligation.

Companies of all sizes are continually exposed to sophisticated threats that can put data, business continuity, and reputation at risk. In this technical guide you will discover seven key guidelines for effectively protecting enterprise infrastructure and ensuring compliance with key industry standards.

For a general discussion of cybersecurity strategies and technologies, see also our Cyber Security – Cyber Protection for Business page.

1. Asset inventory and infrastructure mapping

Before implementing any defensive strategy, it is essential to fully understand the environment to be protected. This requires:

  • Hardware and Software Census: conducts a detailed inventory of every IT and OT component, including network devices, endpoints, cloud resources, and legacy equipment.
  • Risk mapping: associates each asset with a classification with respect to criticality, exposure, and potential impact if compromised.
  • Automation: leverage automated discovery platforms to monitor changes and anomalies in real time, which enables you to effectively manage resources and detect anomalies in a timely manner.

2. Identity and access management (IAM).

Proper identity management is crucial to prevent unwanted intrusions.

It is essential to strictly enforce the principle of least privilege and separation of roles, thus limiting access to only those resources necessary for each user.

Implementation of Multi-Factor Authentication (MFA), especially for privileged accounts and remote access, is an additional layer of protection. In heterogeneous contexts, the use of identity federation and single sign-on systems can further mitigate the risk associated with credential management.

3. Hardening, patch management and vulnerability management

An effective security strategy must include proactive hardening and vulnerability management measures.

  • Choose technologies that incorporate the principles of “Secure by Design” and “Secure by Default,” meaning security built in already at the design stage, and secure by default, with optimal security configurations already preset.
  • Automates update cycles and verifies correct application, even for custom or embedded operating systems (patch management).
  • Complete the process with periodic audits, vulnerability assessments and penetration tests certified to ISO/NIST standards to identify new risk surfaces.

4. Continuous Monitoring, Log Management and SIEM.

Continuous and effective protection requires constant monitoring of network traffic and system activities through Network Detection and Response (NDR) and SIEM solutions, following GDPR and ISO 27001 best practices.

It also stores logs in a certified and unalterable manner to ensure traceability and accountability in case of incident response, complying with regulatory requirements.

5. Layered defense: firewall, IDS/IPS, honeypot and segmentation

A robust defense relies on multiple layers of protection:

  • Advanced firewalls: uses next-generation firewall(NGFW) devices with deep packet inspection, application control and threat intelligence capabilities.
  • IDS/IPS and honeypot: integrates AI-based Intrusion Detection & Prevention systems, and dynamic honeypots for active threat deception, monitoring real attack patterns on decoy assets.
  • Network segmentation: isolates critical networks through VLANs, DMZs and segmented access policies, preventing lateral movement.

6. Staff training and safety culture

Staff training is one of the best defenses against cyber threats and prevent cyber crime.

Periodic awareness programs and attack simulations allow the company’s technical and organizational responsiveness to be tested and continuously improved.

A safety-oriented corporate culture also fosters collaboration and communication between departments, accelerating incident management.

7. Data security, backup, encryption, and regulatory compliance

Enterprise data security also comes through regular, tested and possibly air-gap backups for rapid recovery in the event of ransomware or other threats.

End-to-end encryption and adoption of tokenization protect sensitive data in compliance with GDPR and ISO 27001.

Finally, continuous regulatory updates (NIS2, Privacy Code, GDPR) are essential to ensure long-term compliance and security.

How to Build “Plug & Play” Security

LECS, with its proprietary architecture and cybersecurity blackbox patent, embodies the secure by design and secure by default paradigm: each device is self-determining, works in stealth mode, includes built-in honeypot, AI for real-time detection and response, user-friendly dashboard control, and advanced log certification.

The plug & play solution dramatically reduces the adoption curve and provides maximum protection without blocking business productivity.

Best practices for the future

  • Regular audit: documents each activity and updates the security plan at least annually or after any major changes in IT/OT infrastructure.
  • Supply Chain Security: require “secure by design” and “secure by default” guarantees from vendors, verifying third-party resilience over the entire data lifecycle. Contact us to find out who already offers this service.

Investing in IT security for SMEs and large companies can no longer be postponed: adopting a structured, up-to-date and technically evolved approach can protect the company from existential risks, ensuring competitiveness, operations and reputation in the long run.

Network detection and response (NDR): the new frontier of network security

In today’s cybersecurity landscape, threats are moving faster and with greater sophistication. Traditional defense tools are no longer sufficient to provide complete visibility, especially when the attack leaves no obvious traces on endpoints or exploits fileless techniques. In this context, the concept of Network Detection and Response (NDR) is emerging: a technology designed to detect anomalous behavior within network traffic and activate intelligent countermeasures.

But what exactly is an NDR? How does it work? And why is it an increasingly crucial component of corporate security strategy?

What is Network Detection and Response

Network Detection and Response is an advanced network traffic monitoring and analysis system that can detect, in real time, suspicious or malicious activity that escapes traditional signature- or agent-based controls.

Unlike traditional perimeter tools, the NDR observes internal network behavior ( east-west traffic) and outflows(north-south) to identify anomalies indicative of compromise: data exfiltration, lateral movement, beaconing to control servers(Command & Control), and more.

The goal is clear: detect attacks in progress even in the absence of obvious signs, and respond before they cause damage.

How an NDR works

An NDR system is based on three technological pillars:

  1. Deep packet Inspection (DPI)Deeply analyzes network packets, extracting detailed information about protocols, payloads, and communication patterns.
  2. Machine Learning and Behavioural AnalyticsCreatesa model of “normal” behavior within the network, automatically detecting suspicious deviations that could indicate a threat.
  3. Threat Intelligence and Compromise Indicators (IOC)Compares IP addresses, URLs, certificates, and other metadata with known blacklists, OSINT sources, and up-to-date intelligence feeds.

The result is constant, unseen surveillance, capable of recognizing weak signals that could foreshadow a complex attack.

Why adopt an NDR

The NDR is not just an audit tool-it is a strategic resource for any company that wants to proactively protect its digital assets.

Here’s why:

  • Extended visibility: monitors all flows, even between unmanaged or agentless devices;
  • Real-time detection: detects sophisticated threats before they cause damage;
  • dwell-time reduction: shortens the average time the attacker stays in the network;
  • Complementarity with EDR/SIEM: provides a unique perspective that can be integrated into existing architectures;
  • Adaptability: applies to classic IT contexts, OT environments, cloud and hybrid networks.

In particular, NDR is crucial for highly critical contexts (healthcare, manufacturing, OT infrastructure) where devices that cannot be monitored directly-such as PLCs, HMIs, SCADA-are a weak point.

LECS Specto: the evolved, invisible, adaptive NDR

In the landscape of NDR solutions, LECS offers a radically innovative approach with its proprietary Specto module.

Designed for continuous, non-intrusive surveillance, Specto analyzes all traffic in transit, employing proprietary Hidden Analysis techniques and an advanced AI engine integrated with the Tiresia platform.

The distinguishing features of Specto:

  • Full-packet analysis with adaptive behavioral models
  • Monitoring extended to IT, OT and cloud-based networks
  • Native integration with LECS artificial intelligence
  • Immediate reaction through the Raises engine, which triggers automatic isolation of compromised assets (up to theEnergy Air-Gap)
  • Direct connectivity with the XDR LECS system for cross-layer viewing

In addition, Specto is available both as an integrated component in LECS Business devices and as an advanced module in LECS Enterprise 2.0 and Core platforms, providing flexibility and scalability.

Read more: LECS Enterprise 2.0

When is an NDR really needed?

An NDR is especially useful when:

  • Manage mixed networks with hard-to-secure IoT/OT devices
  • Fileless or APT attacks themes that escape traditional antivirus
  • you want to identify lateral postbreach movements
  • you need forensic visibility into traffic for rapid investigations

Today, the absence of an NDR is a vulnerability. The attacker who enters your network without leaving a trace on the endpoint could remain undetected for weeks. With LECS, you can intercept it before it’s too late.

Conclusion

Network Detection and Response is the most practical and intelligent response to threats that move under the radar of traditional solutions. LECS, with Specto, Tiresia and Raises, integrates a next-generation NDR into a plug-and-play ecosystem that combines visibility, automation and rapid response.

Don’t leave your network blind. Put Specto on watch.

Discover the invisible protection of LECS: lecs.io

LECS at RHC Conference 2025: Roberto Camerinesi talks about the new frontier of satellite hacking

LECS will be among the protagonists of the RHC Conference 2025, the benchmark event for the world of cybersecurity in Italy, organized by Red Hot Cyber and scheduled in Rome on May 9 and 10. Official speakers include our CTO Roberto Camerinesi, inventor of the LECS technology and a point of reference in digital security research, who will take the stage on Friday, May 9 at 6 p.m. with a speech entitled:

“Houston, we have a problem! Satellite hacking: the next frontier.”

lecs rhc speach

At a time when space infrastructure is becoming increasingly central to daily life and global security, Roberto will bring a practical and technical reflection on the vulnerabilities of satellite systems and the new challenges that the cyber ecosystem will face in the coming years.

His talk will offer a visionary yet pragmatic insight into the future of cyber defense, in line with our mission: to transform innovation into real protection for companies, infrastructure and territories.

See the full event program

RHC Conference: where innovation meets challenge

The RHC Conference is much more than an event: it is a point of convergence for those of us who want to redefine cybersecurity standards, fearlessly tackling the new frontiers of digital risk.

To be on the stage alongside top experts in the field is to carry the LECS vision forward with determination, credibility and pioneering spirit.

An appointment worth marking in the diary

It will be a crucial moment to engage with professionals, decision makers and innovators from across the national landscape. An opportunity to share ideas, build new synergies and strongly reiterate that Italian cybersecurity can-and must- aspire to a leading role in the global scenario.

See you in Rome on May 9 to tackle the next cybersecurity challenge together. And if you can’t be there with us, follow us on our social channels to experience first-hand the story of the speech, the highlights of the event, and the new frontiers we are exploring.

The cybersecurity revolution is underway.

And we are on the front line.

Overfunding in underwriting: exceeded 1.5 mln in crowdfunding

After launching a major round and reaching the maximum 1.5 million euro underwriting target, LECS technology now accelerates and tries to make the international climb.

Cyber Evolution - LECS Mamacrowd Campaign Raises Over 1.5 Million Euros

We are excited to announce that Cyber Evolution, our innovative cybersecurity SME based in Ascoli Piceno, has recently successfully completed a funding round with a maximum funding target of €1.5 million.

This financial transaction closed brilliantly, thanks to the participation of institutional and industrial investors and our community, who believed in our vision through the crowdfunding campaign launched on MamaCrowd from December 19, 2024 to January 21, 2025. This milestone is a key step in strengthening the scalability of LECS technology and accelerating its expansion both domestically and internationally.

LECS is much more than a cybersecurity solution-it is a technological revolution. We have developed a unique device designed to provide effective, automated protection against increasingly sophisticated cyber threats. With our proprietary patent, we position ourselves as a key player in the digital security industry, offering plug-and-play technology with proprietary artificial intelligence algorithms and all-in-one capabilities covering prediction, detection, response and management.

Our technology is in full compliance with international regulations, fully integrates with other IT and OT security systems, and is scalable for SMEs, large corporations and critical infrastructure.

Our growth path has been supported by important strategic partners, including Forward Factory of the CdP network, Industrio Ventures and NanaBianca, and several international awards that have confirmed the validity of our solution. Thanks to continuous commercial expansion, today LECS is installed in 12 countries and distributed through an established partner network, serving large corporations, multinationals and public administrations.

As we look to the future, our goal is clear: to become an international benchmark in cybersecurity. With our indirect B2B model, we want to make cybersecurity accessible to the widest possible number of companies and institutions, providing protection, innovation and reliability without compromise.

Screenshot of the Cyber Evolution - LECS Mamacrowd campaign, which raised over 1.5 million euros

Tonino Celani: Pride in crowdfunding success and international ambitions

“I am really pleased with the great work done by our team over the past few years, and the success achieved by exceeding the maximum target set for crowdfunding is for us on the one hand a source of pride and on the other hand a great responsibility to those who have put their trust in us by believing in our project and our potential for growth in the short term. This is an incentive for us and I feel like thanking on behalf of our society all those who have invested in us. Now, we aim to continue to improve our products by making them more and more performant, to strengthen the team and to develop targeted activities to expand the network and to generate significant business development thus going on to improve our positioning in the cyber security industry. We firmly want to achieve the goal of taking our LECS to an international dimension; we have the potential to do so, considering that our technology is currently considered among the most cutting-edge cyber security solutions in the world .”; these are the words of our Board President and CEO, Tonino Celani.

Pio Paoloni: Crowdfunding as a step toward new growth goals

Pio Paoloni, Vice Chairman BoD and CFO, adds, “The capital increase achieved through Crowdfunding is undoubtedly an important step in our growth, but it is certainly not a point of arrival, rather it is a stage, I see it as a “bridge round” toward new goals, without setting limits for ourselves. Indeed, our bplan envisions significant growth supported by excellent ebtida values and profitability margins. We would like to thank all the investors who participated in the round, and in particular the accelerators Industrio Ventures and Forward Factory of the CDP network, who were the first to put their trust in us back in 2022. The choice in this round to inclusively involve institutional and industrial investors and the community through crowdfunding is a strategic factor for us to create shared value and build a strong and innovative ecosystem, in line with our mission.”

Roberto Camerinesi: Continuous innovation and the opening of a research center in Ascoli Piceno.

“We are excited about this growth opportunity that will allow us to take LECS toward new patentable models and capabilities, which we are already working on, to position ourselves among the leading cyber defense companies with a new OEM NDR-DPI multispectrum technology for 4.0 and 5.0. Our development program, also includes that in the first half of 2025 we will open our own cyber threat research center in Ascoli Piceno, with an expansion of our headquarters, and this will be a feather in the cap for both our company and the area. We will strengthen the development and research team and will partner with prestigious universities, also attracting young talent who can contribute to a safer digital future. LECS, definitely aims to redefine current cybersecurity standards, responding to the needs of an increasingly connected, complex and “exposed” world said Roberto Camerinesi – CTO and Inventor of the LECS technology.

Marco Camerinesi: Accelerating strategic expansion in key markets.

“With the new resources from the round concluded a few days ago, we have a great opportunity to accelerate the strategic expansion operations that we have already started in several key markets such as Italy, which is obviously the most proximate one, and abroad, in high-potential areas in Europe and South America, where by the way we are already present with several clients. The cyber security market is certainly among those with the highest growth trends with annual CAGRs of about 15 percent and a potential global market of €240Bn estimated to 2027. The wide market validation of our LECS technology, supported by a very large application scalability on IT/OT environments, I am sure that it will allow us to realize a strong expansion of our network of technical business partners in a short time and to acquire important market shares,” said Marco Camerinesi – COO of Cyber Evolution.

The new European NIS2 regulation: what changes for cybersecurity in Italy

As of Oct. 16, 2024, the Network and Information Security (NIS) decree, which aims to strengthen the cybersecurity of companies and public administrations throughout Europe, came into effect.

Let’s find out together what the main changes are, who is involved, and what obligations arise for Italian companies.

What is the NIS2 Directive and why it is an evolution of cyber security

NIS legislation has a clear goal: to raise cybersecurity standards by promoting effective cooperation among member states and ensuring that digital infrastructures are ready to deal with increasingly sophisticated threats.

Compared to the past, the new version broadens the scope to include more sectors and categories of companies considered essential or strategic.

Now, the enterprises and administrations involved must adopt security measures that cover all dimensions of cyber security: confidentiality, integrity and availability of data.

In addition, the legislation introduces a more timely notification system for reporting incidents so as to facilitate a rapid and coordinated response.

A new element is also the coordinated disclosure of vulnerabilities, which allows emerging threats to be addressed in a shared way.

Which companies need to adapt: the critical and highly critical sectors

The new NIS regulation expands its scope. now encompassing 18 total sectors from the previous 8 and distinguishing between highly critical and critical sectors, greatly expanding its scope:

  • Highly critical sectors (already in place and updated): energy, transportation, banking, financial market infrastructure, health sector, drinking water, wastewater, digital infrastructure.
  • Highly critical new sectors: space, ICT service management (b2b), waste management
  • New critical sectors: postal and courier services, manufacturing, chemical production and distribution, food production, industrial manufacturing, digital service providers, research.

This expansion reflects the need for more extensive cybersecurity, covering more than 80 types of public and private entities.

The new obligations for the security of computer systems and networks

As of Dec. 1, 2024, all stakeholders must register on the portal of the National Cybersecurity Agency (NCA), which serves as the lead enforcement authority. This registration phase is only the first step in a security strengthening journey that will continue in the months to come.

Obligations on incident reporting and safety measures will be phased in and defined through the decisions of the Director General of ACN, based on sector consultations. Full regulations are expected by the first quarter of 2025.

There will also be a differentiated implementation period: companies will have 9 months to comply with notification requirements and 18 months to adopt security measures, starting from the date when the list of NIS subjects is consolidated, set for April 2025. From that time, a coordinated path to strengthen cybersecurity at the national level will begin.

Risk management and impact analysis

Risk management is one of the central elements of the new regulations, which focus on the adoption of a proactive approach: not only protection of networks, but also the ability to react quickly in the event of a crisis.

Another key aspect is corporate responsibility, which becomes even more stringent. Companies must meet clear reporting requirements and adopt security measures for the entire supply chain.

Failure to comply can result in significant penalties, while ACN oversight ensures constant monitoring for compliance.

Is your company among those involved?

Contact us for a free consultation and find out how we can support you to be compliant with the regulations.

GDPR: how to ensure your company’s regulatory compliance and information security

International regulations, such as the GDPR (General Data Protection Regulation) and ISO (International Organization for Standardization) standards, have become an essential part of the cybersecurity landscape.

Ensuring compliance with these regulations not only improves overall data security, but is also critical to avoiding heavy penalties and maintaining customer trust. But how can you ensure that your company’s infrastructure is secure and compliant with these regulations?

The Importance of Regulatory Compliance for Cybersecurity

As cyber attacks and data breaches increase, many organizations are forced to improve their security systems. However, in addition to the adoption of advanced technologies, regulatory compliance has become a key requirement. Regulations such as the GDPR in Europe, the CCPA (California Consumer Privacy Act) in the United States, and ISO standards for cybersecurity (eg, ISO/IEC 27001) are designed to ensure that companies take appropriate protective measures for personal and sensitive data.

The GDPR, which went into effect in May 2018, requires companies operating in Europe, or processing personal data of European citizens, to take strict measures to protect sensitive information and ensure users’ rights. Failure to comply with the GDPR can result in penalties of up to €20 million or 4 percent of the company’s global annual turnover, whichever is greater. This shows how crucial it is for businesses to ensure data security to avoid legal and financial consequences.

Moreover, being compliant involves not only protection against external attacks, but also internal data management, governance and transparency in the collection, storage and use of personal information.

ISO 27001: the standard for information security management

The ISO/IEC 27001 standard establishes the requirements for an information security management system (ISMS). This international standard provides a solid framework for organizations to identify, manage and mitigate information security risks. Adhering to ISO 27001 is particularly useful for companies that want to demonstrate their commitment to data protection and responsible information management.

  1. Advanced data protection: this includes encryption, anonymization and access control.
  2. Reduced risk of penalties: allows the company to operate in a more legally secure environment.
  3. Increased customer trust: when customers know that a company protects their data and complies with applicable regulations, trust in the organization increases, leading to improved reputation and loyalty.
  4. Competitive advantage: demonstrating regulatory compliance can provide a competitive advantage, distinguishing the company from its competitors.

Implementing compliant solutions in the enterprise can be a very complex task, but with the support of patented technologies it is possible to be 100 percent compliant realities.

This is why LECS (Logical Endpoint Cyber Security) was designed: to protect corporate data while ensuring compliance with international regulations.

LECS’s architecture, based on artificial intelligence and machine learning technologies, enables companies to continuously monitor their IT infrastructure and proactively respond to threats in real time. But how can LECS specifically help companies comply with data protection regulations?

Data confidentiality protection and continuous monitoring

One of the main areas of regulatory compliance is the protection of data confidentiality. LECS uses advanced encryption technologies to ensure that sensitive data is always protected. End-to-end encryption ensures that only authorized users can access information, reducing the risk of unauthorized access and data breaches.

Another critical requirement imposed by regulations, particularly ISO 27001, is the continuous monitoring of IT infrastructure to detect and prevent any security breaches or incidents. LECS, with its artificial intelligence-based architecture, constantly monitors all network activity and identifies suspicious behavior in real time. This proactive monitoring helps prevent data breaches before they can cause significant damage.

If threats are detected, LECS takes immediate action with automatic response actions.

Data integrity and prevention of information loss

LECS also offers advanced backup and recovery capabilities. Companies are required to maintain secure copies of data and regularly test recovery procedures to ensure that information can be recovered quickly in the event of a loss or breach. LECS performs regular, automated backups of critical data, enabling companies to restore information quickly and efficiently, which is crucial for compliance with both GDPR and ISO standards.

Audit and reporting for regulatory compliance

In addition to protecting data, companies must be able to demonstrate compliance during internal and external audits. LECS provides advanced reporting tools, enabling companies to generate detailed reports on security activities, access attempts and incidents detected. These reports are essential for demonstrating compliance to regulators and responding promptly to audit requests.

Regulatory compliance is not just a legal issue; it is an essential pillar of cybersecurity. Regulations such as GDPR and ISO/IEC 27001 standards require companies to take stringent measures to protect sensitive data and ensure information security. LECS represents a comprehensive solution that enables companies to comply with these regulations while effectively protecting their data. From advanced encryption to continuous monitoring, from incident management to reporting, LECS helps organizations improve their security and demonstrate their compliance every step of the way.

For more information on how LECS can help your company implement a robust and secure regulatory compliance strategy, learn more about all LECS technologies and request your demo.

The 3 pillars of cybersecurity: the CIA triad

In today’s cybersecurity landscape, there are fundamental pillars that are essential to understand in order to protect organizations’ and companies’ digital assets from cyber threats.

To ensure proper management of cyber data security, in the context of Cyber Security, there are three principles, commonly known as the CIA triad, which are: confidentiality, integrity and availability.

They relate to the 3 main goals of cryptography and secure systems, and guide not only safeguard policies and practices, but also serve as evaluation criteria for any security system.

The CIA triad concept then guides cybersecurity strategies, ensuring that information is protected against possible data breach threats.

Let’s look at them in detail.

Confidentiality

Confidentiality is about protecting information against non-legitimate access. Ensuring confidentiality means making sure that only authorized people have access to sensitive data, protecting the privacy of users.

For a company, a breach of confidentiality can result in serious legal consequences and reputational damage, as well as significant financial losses.

Specific techniques such as using advanced encryption, access control, and monitoring to quickly detect and block unauthorized access must be adopted to ensure confidentiality.

Integrity (Integrity)

Integrity refers to the accuracy and completeness of information: ensuring integrity means making sure that data is not altered or damaged in an unauthorized way, ensuring accurate and reliable information.

Business decisionsare based on correct data, so any compromise of integrity can lead to incorrect and harmful decisions. In addition, maintaining data integrity is crucial to comply with regulations and security standards.

Techniques to ensure integrity includehashing (i.e., checking hashes, a unique representation of data generated by algorithms), version control to track all changes made to the data, and the use of checksums, to detect and correct any errors in the data during transmission.

Maintaining data integrity is an ongoing task and requires constant vigilance and updating of security measures. This is the only way to ensure that corporate information is protected and reliable.

Availability

Availability is about reliable and timely access to information and systems when needed, to ensure that systems and data are accessible to authorized users at all times, but not only that, availability is critical to business operations.

Any disruptions can lead to significant losses in productivity and income, as well as undermine customer confidence.

To ensure availability, it is useful to implement redundancy and failover solutions to ensure business continuity, perform regular backups , and use DDoS attack mitigation solutions to protect systems from disruptions caused by malicious traffic.

The concepts of data confidentiality, integrity, and availability are closely linked, and the design of a data security system requires that they be considered in an integrated way.

By integrating these principles into security policies and practices, companies can effectively protect access to their data against a wide range of cyber threats.

Some of the solutions may include the use of firewalls, antivirus, data encryption, two-factor authentication systems and other security measures.

If you would like more information on how to protect your company’s data and work worry-free, please contact us. Our cybersecurity experts will be happy to provide you with personalized advice and identify the right solutions for your company’s needs.

Don’t let your business data be exposed to risk, contact us today to protect your business.

Best Practice: 5 key activities for cybersecurity

In an era of evolving and increasingly sophisticated cyber threats, cybersecurity has become a top priority for companies of all sizes. Cyber attacks can cause devastating damage, compromising sensitive data, disrupting business operations and damaging an organization’s reputation. To effectively address these challenges, it is essential to take a proactive and systematic approach to cybersecurity.

In this article, we will explore five key activities to improve your company’s cybersecurity. From identifying threats to implementing advanced security measures, these best practices will help you protect your digital assets and ensure business continuity.

Let’s find out together how to put in place a robust and effective security strategy.

Threat identification

The first step is to identify the type of threats against the cybersecurity and integrity of your business data. Some of the most common threats include:

  • Malware: malicious software designed to damage, disrupt or gain unauthorized access to computer systems. Practical examples include viruses, Trojan horses, and ransomware, such as the infamous WannaCry, which has encrypted the data of numerous organizations by demanding a ransom for decryption.
  • Phishing: a social engineering technique that aims to trick users into obtaining sensitive information, such as login credentials and financial data. An example is a fraudulent email that appears to be from a bank and asks users to update their security information.
  • Denial of Service (DoS) attacks: attacks that aim to make a service or network inaccessible by overloading the system with fake traffic. The 2016 Mirai botnet attack affected large websites such as Twitter and Reddit, disrupting services for millions of users.
  • Insider Threats: threats from within the organization, such as current or former employees abusing their access to harm the company. A well-known example is the case of Edward Snowden, who leaked confidential NSA information.

lecs malware the core activities for cybersecurity


Threat detection tools and techniques

To detect threats, companies can use a combination of software tools and analytical techniques, including:

  • IDS (Intrusion Detection Systems): Systems that monitor network traffic for suspicious or abnormal activity.
  • Log analysis: Review of log files generated by systems and applications to identify suspicious patterns.
  • SIEM (Security Information and Event Management): Systems that collect and analyze security data from multiple sources to provide a centralized view of security activities.

Vulnerability assessment

Vulnerability assessments are essential to identify and correct security holes before they can be exploited by attackers. This process includes:

  • Vulnerability scans: use of automated tools to scan networks and identify known vulnerabilities.
  • Patch management: regular updating of software to correct discovered vulnerabilities.
  • Manual assessments: involvement of security experts to perform detailed assessments and targeted penetration tests.

Staff training: an often underestimated aspect

Ongoing staff training is crucial for recognizing and reporting potential threats. Activities that can be undertaken are security training programs designed to educate employees on cyber threats and security best practices.

In addition, having clear procedures for reporting suspicious activity or security incidents helps create a corporate culture that encourages supervision of all employees. Doing so increases the speed of response to threats.

The implementation of effective security measures

To build a strong cyber defense, companies must start with basic security measures, which include:

  • Strong passwords: this may seem trivial, but you often find yourself on the receiving end of cyber attacks because of very weak passwords. You need to use complex combinations of letters, numbers and symbols, and change them regularly. Obviously, a password such as “P@ssw0rd!2024” is much more secure than “password123.”
  • Multi-factor authentication (MFA): Implementing a second level of verification, such as authentication via SMS or authentication app, significantly reduces the risk of unauthorized access.
  • Regular software updates: keep all systems and applications up-to-date to protect them from known vulnerabilities. Automating updates can ensure that they are not overlooked.

In addition to these basic measures, companies will need to adopt advanced technology solutions to proactively protect their assets, such as next-generation firewalls and end-to-end encryption, complemented in recent years by sophisticated intelligent monitoring and response systems that are crucial for automatically responding to threats.

Today, the use of advanced artificial intelligence and machine learning algorithms are able to support enterprises extremely effectively in detecting network behavior in real time. Not only that: technological innovation has led to the creation of tools that can perform automatic mitigation actions in response to detected threats, such as isolating a compromised device from the network. LECS is the quintessential example of this: designed to respond quickly to attacks without human intervention.

Cyber attacks are the order of the day: in fact, while AI is helping to manage attacks, they are becoming even more complex and could put a strain on even the most compact infrastructure.

Being resilient is the antidote

Good rule of thumb dictates that regular tests and mock attacks be carried out . These tests include:

  • Penetration Testing: engage security experts to attempt to penetrate corporate defenses using hacker-like techniques. This helps identify weaknesses that could be exploited.
  • Attack simulations: running simulated attack scenarios to assess the readiness of the company’s response. For example, simulate a phishing attack to test staff awareness and response procedures.

By adopting these best practices, companies can not only improve their cybersecurity, but also gain a competitive advantage, reduce operational costs and protect their reputation.

Cybersecurity is not an option, but a fundamental necessity for success and sustainability in the modern digital landscape.

Don’t leave your company’s security to chance: if you have any doubts, contact us.

Phishing alert: how to recognize the attack, is Meta not writing to you!

In recent weeks, we have seen an increasing number of targeted phishing attacks. One particular aspect of this threat is the deception of malicious attackers posing as the well-known Meta group, which includes platforms such as Facebook, WhatsApp, and Instagram.

The Modus Operandi of the Strikers

The scammers behind these phishing attacks are cleverly exploiting the trust associated with the Meta brand to trick victims into providing sensitive information. Victims receive emails ostensibly from disguised Meta addresses containing malicious links. Once clicked, these links lead to counterfeit web pages with a form requesting sensitive data.

lecs phising alert

How to Recognize and Protect Yourself

  • Careful Verification of E-mail Address: Carefully review senders’ e-mail addresses. Attackers often use addresses similar to official ones, but with slight variations.
  • Urgent Messages and Requests for Sensitive Data: Be skeptical of panic-inducing e-mails threatening account suspension or asking for personal data. Legitimate institutions rarely request sensitive information via e-mail.
  • Beware of Links: Avoid clicking on links in suspicious e-mails. Hover over them to check the full URL before clicking.
  • Report Suspicious E-mails: Forward any suspicious e-mails to your security team or IT administrator. Early reporting can prevent further damage.
  • Staff Awareness: Informs all members of the organization about the current phishing threat and reinforces security measures.

Each of us must do our part to protect sensitive information and ensure the security of humanitarian institutions. Collaboration and awareness are key to countering these threats.

Computer Fraud in the World: The 10 Most Devastating Cases

Cyber fraud is one of the most serious and pervasive threats of the digital age.

In fact, these crimes, ranging from the interception of sensitive data to the alteration of computer systems, have had a profound impact globally.

Governments, companies of all sizes, and individuals have been affected, testifying to the vast scope and destructive potential of such attacks. These incidents not only cause huge financial losses, but also undermine confidence in digital security, forcing continuous updating of defense strategies to protect data and critical infrastructure.

lecs computer fraud the most devastating cases

What is Computer Fraud?

A computer fraud is a crime in which the perpetrator uses the computer as the main tool to commit fraud. Fraud can range from intercepting financial transactions to usurping identities.

Increase in Computer Fraud

The latest data from the Italian Postal Police indicate a significant increase in computer fraud in recent years. From 2018 to 2022, cases of computer fraud almost doubled from 3,476 to 5,908 incidents.

In addition, the number of people investigated for computer fraud increased from 331 in 2018 to 725 in 2022.

In parallel, online fraudsters have become more adept at embezzling larger sums of money, rising from 5.5 million stolen in 2018 to 36.5 million in 2022.

These data highlight the urgent need to strengthen cybersecurity measures and further raise awareness of the risks of online fraud. (Source: www.tg24.sky.it)

The 10 Most Devastating Cases of Computer Fraud

Cyber fraud, ranging from data breaches to ransomware attacks, has left an indelible imprint on the world’s digital security.

Ten of the most notable and devastating cyber fraud attacks are analyzed below:

  1. Attack on Sony Pictures (2014): This attack, attributed to North Korea, involved the disclosure of internal data, emails, and unreleased films. It was a major blow to the company’s reputation and security.
  2. WannaCry Ransomware (2017): A ransomware attack that affected hospitals, businesses, and governments, causing large-scale outages and requiring Bitcoin payments to unlock systems.
  3. Bangladesh Bank Fraud (2016): Hackers exploited weaknesses in the SWIFT system to divert millions of dollars from Bangladesh to the Federal Reserve Bank of New York.
  4. Attack on Yahoo (2013-2014): Considered one of the largest data breaches, it exposed the names, emails, birthdates, and encrypted passwords of billions of users.
  5. NotPetya (2017): Originally targeted at Ukraine, this malware has spread globally, affecting multinational companies and causing extensive damage.
  6. Equifax Data Breach (2017): Important personal information, including Social Security numbers, was stolen in this breach, putting the identities of millions of people at risk.
  7. Target Data Breach (2013): This attack hit Target’s payment systems during the holiday season, compromising the credit card information of millions of customers.
  8. Attack on Marriott International (2018): Hackers gained access to Marriott’s reservation database, stealing guests’ personal information.
  9. SolarWinds Cyberattack (2020): A complex cyberattack that allowed hackers to spy on government agencies and companies by exploiting a vulnerability in SolarWinds network management software.
  10. Attack on JPMorgan Chase (2014): Theft of personal data and contact information of millions of customers, one of the largest attacks on a financial institution.

Conclusions

These cases of cyber fraud demonstrate the increasing sophistication and danger of digital attacks.

They stress the importance of robust cybersecurity and constant awareness of digital threats.

As technology continues to evolve, so must our defense strategies to protect ourselves from these increasingly complex threats.

Lecs dispostitives make use of sophisticated military technology, applicable to any type of network and need, while maintaining affordability for any budget.

Chank for advice and secure your business: don’t wait to become a statistic.

Protecting Yourself from Computer Fraud: Security Tools and Tips

In the digital age, computer fraud has become one of the most significant threats to individuals and businesses. Characterized by the misuse or illegal use of information technology to deceive or steal resources, computer fraud can take many forms.

From phishing emails that aim to steal login credentials, to installing malware to control computer systems, these attacks are constantly evolving.

The effects of such fraud can be devastating, causing financial loss, reputational damage, and compromise of sensitive data.

Protection against cyber fraud is critical for both businesses and individual users.

For businesses, a security breach can lead to loss of sensitive customer data, operational disruptions, and serious financial and legal implications. For individuals, protecting their personal data is essential to safeguard privacy and prevent financial loss.

In this context, awareness and adoption of appropriate security measures become crucial to defend against the increasingly sophisticated strategies of cyber criminals.

The following article aims to provide a detailed understanding of what cyber fraud involves, how to recognize it, and the most effective strategies to protect against it.

lecs fronds computing

Types of Computer Fraud

Computer fraud can manifest itself in various forms, each with specific characteristics and methods. Here are some of the most common types:

  1. Phishing: This technique involves sending fraudulent emails that appear to come from trusted sources. The goal is to trick recipients into revealing personal information, such as passwords or bank details. In 2022, 79% of companies in Italy experienced at least one phishing attack
  2. Man-in-the-Middle (MitM) Attacks: In these attacks, criminals intercept communication between two parties (e.g., between a user and a website) to steal or manipulate data.
  3. Malware: This term encompasses various types of malicious software, such as viruses, Trojans and ransomware, that are secretly installed on the victim’s device to damage it, steal data or block access to files until a ransom is paid.
  4. Social Engineering Attacks: These attacks rely on deception and psychological manipulation to induce victims to reveal confidential information or perform actions that compromise their security.
  5. Credit and ATM Card Fraud: Criminals use several techniques to steal credit card information, such as installing skimmers on ATMs or creating fake web pages to collect card data.
  6. Cryptojacking: This fraud involves the unauthorized use of others’ devices to mine cryptocurrencies.
  7. Identity Theft: Criminals collect personal information to impersonate the victim, access their bank accounts or commit fraud.

Recent and Relevant Examples of Computer Fraud

Let us now look together at some significant examples of computer fraud:

  • Widescale Phishing Attacks: Recently, there have been reports of phishing campaigns targeting customers of major banking institutions, using emails that mimic official communications to induce victims to enter sensitive data on fake web pages.
  • Ransomware in Businesses and Public Entities: Numerous public entities and private companies have been affected by ransomware attacks, with ransom demands for the recovery of encrypted data. Notable examples include attacks on hospitals, schools, and critical infrastructure. A 2022 report by CrowdStrike revealed a significant annual increase of 82 percent in data leaks related to ransomware attacks, with an average cost of 1.72 million per affected company
  • Data Breaches of Large Corporations: Some of the largest companies globally have suffered data breaches where sensitive information of millions of users has been exposed or stolen.
  • Cryptojacking on Popular Websites: Websites with high traffic have been compromised to secretly use visitors’ processing resources to mine cryptocurrencies, often without users noticing.

Discover our products for your cybersecurity

Tools Used by Fraudsters

Cybercriminals use a wide range of tools and techniques to commit fraud. Understanding these methods is critical to developing effective prevention strategies.

Common Software and Techniques

  1. Phishing: Attackers use spoofed emails, text messages or websites to trick victims into revealing personal information. These messages are often designed to appear to come from legitimate sources, such as banks or service providers.
  2. Malware: Includes a variety of malicious software such as viruses, worms, Trojans, and ransomware. These software can be distributed through email, downloads from compromised websites, or through infected USB storage devices.
  3. Social Engineering: This technique relies more on psychological manipulation than on technology. Attackers trick people into revealing confidential information or performing actions that jeopardize security.
  4. Keylogging: These software programs record keystrokes made by the user, allowing hackers to intercept passwords and other sensitive information.
  5. Exploit Kit: These are tools that exploit known vulnerabilities in software to install malware or perform other malicious actions.

How to Protect Yourself from Scammers

Digital Security Tools

Protecting one’s data and information systems requires a multilayered approach that includes various digital security tools. These tools are designed to defend against a wide range of threats, from prevention to identification and response to attacks.

  1. Firewall: Acts as a barrier between the protected internal network and the Internet. A firewall can be either hardware or software and is used to filter network traffic, blocking unauthorized access.
  2. Antivirus and Anti-Malware: These software programs are essential for detecting and removing viruses, worms, Trojans, and other types of malware. It is important to keep these programs up-to-date to protect against the latest threats.
  3. Intrusion Prevention Systems (IPS): They monitor network and data traffic to detect and block suspicious activities, such as hacking attempts and network attacks.
  4. Patch and Update Management: Keeping software up-to-date is crucial to protect against known vulnerabilities that can be exploited by attackers.
  5. Multi-Factor Access Control and Authentication (MFA): Restricting access to systems and data and using MFA adds an additional layer of security by requiring multiple forms of verification to access critical systems.
  6. Data Backup: Having regular and reliable data backups is critical to recovering information in case of ransomware attacks or other security incidents.
  7. Encryption: Protects data by making it unreadable without a decryption key. It is used to protect sensitive data both in transit (during transmission) and on-site (archived).
  8. Employee Training and Awareness: Training on security risks and best practices is critical, as human error is often the weak point in security defenses.

Importance of Cyber Security Devices

The importance of these safety devices cannot be underestimated.

In today’s digital landscape, where threats are constantly evolving and becoming more sophisticated, having a robust security system is essential.

These tools not only protect against financial loss and reputational damage, but also ensure the continuity of business operations. Moreover, for companies, ensuring the security of customer data is a legal and moral obligation that contributes to the company’s trust and credibility.

Conclusions

In this article, we explored several key aspects of cyber fraud, a growing threat in the digital age: Keeping systems up-to-date, using advanced security tools, and fostering a culture of cybersecurity are essential to protect both individuals and businesses from digital threats. In an increasingly connected world, cybersecurity is not just a matter of technology, but a crucial component of our daily lives.

Contact us for a free consultation

Cyber Security for Children: Educating on Data Protection

In the modern digital world, it is important not to neglect the online safety of our children.

Cyber security for children has become a daily priority, even considering the widespread use of technological devices from an early age.

Therefore, it is the duty of the ‘grown-ups’ to ensure that our little digital explorers are protected as they navigate the vast world of the Internet in search of they don’t even know quite what.

In this guide, we will explore essential strategies and tips for protecting children online.

lecs computer safety in children

Children’s Digital Safety is a Priority

Children’s digital safety has become a key priority in an age when digital devices and Internet access are an integral part of young children’s daily lives. There are several key reasons for this priority:

  1. Early Exposure : Children begin using digital devices and surfing the Internet at an increasingly young age. This early exposure exposes them to a range of potential online risks and threats.
  2. Complex Online World : The Internet is a vast and complex world with a range of content, social media, and online services. Children can easily end up on age-inappropriate websites or platforms, and may be exposed to inappropriate content or interact with unsafe people, making cyber security actions for children essential on everyone’s part.
  3. Emerging Threats : Online threats are constantly evolving. Cyberbullying, online grooming, and identity theft are just some of the negative aspects that can affect children.
  4. Privacy and Personal Data : Children often do not fully understand the importance of online privacy and may share personal information carelessly. This makes them vulnerable to abuse and scams.
  5. Impact on mental health : Excessive or inappropriate use of technology can have a negative impact on children’s mental health, contributing to problems such as anxiety and addiction to digital devices.
  6. Parental Responsibility : Parents have a responsibility to educate their children on how to safely navigate the digital world and to provide clear guidelines for responsible online behavior.
  7. Digital Education : Digital education is essential to prepare children for the challenges and opportunities of modern technology. Children should be taught how to recognize and manage online risks.
  8. Family communication : Open and honest communication within the family is crucial in addressing digital safety issues. Children should feel comfortable talking to their parents about any online issues.

Read also: What to do after a cyber attack: security guide

Cyber Security for children: install parental control software

One of the most effective ways to protect children online is through the installation of parental control software. These tools allow parents to monitor their children’s online activities, restrict access to inappropriate websites, and set device usage times.

To better understand its importance, imagine a family in which a 12-year-old child has unlimited access to the Internet and various devices.

One day, while innocently surfing the Web, a child comes across a site that seems harmless but actually has inappropriate and harmful content. Without parental control software installed, parents have no way to learn of this exposure.

However, if parents had installed parental control software on the child’s devices, they could have:

  1. Filter content: the software would automatically block access to the inappropriate Web site, protecting the child from exposure to harmful content.
  2. Monitor activities: parents would receive alerts or reports on their child’s online activity, allowing them to converse with their child about Internet safety.
  3. Managing time: they could have set limits on the time spent in front of the screen, ensuring that the child does not spend too many hours online, which could have a negative impact on his or her studies and health.
  4. Safe searches: the software can apply safe search settings on search engines, further reducing the chances of your child coming across inappropriate content.

Read also: PCI DSS: ensuring the security of credit card transactions

Teaching Privacy Online

Online privacy education is a critical aspect of cyber security for children. In an increasingly connected world, children need to learn from a young age the importance of protecting their personal information and not sharing it indiscriminately on the Internet. This is why teaching online privacy is critical:

  1. Awareness: Children need to be aware that information shared online can be easily accessed by strangers. They must learn to distinguish between what is safe to share and what is private.
  2. Consequences: It is important to explain to them the possible negative consequences of sharing sensitive data online. This may include the risk of fraud, identity theft or cyberbullying.
  3. Learning to protect themselves: Children should learn how to protect their personal information, such as using strong passwords and not sharing it with strangers. They should also be taught the importance of not posting sensitive information such as addresses, phone numbers or school details on social media or other online platforms.
  4. Open communication: Parents should encourage open communication with their children so that they can feel comfortable talking about any online situation that makes them feel unsafe. This may include receiving inappropriate messages or interacting with unfamiliar people.
  5. Model Behavior: Parents and educators should serve as role models of responsible online behavior. Children often learn by watching adults, so by seeing their parents adopt safe online practices, they are more likely to follow suit.

Read also: Ongoing cyber attack: how to prevent snake bite

Social media knowledge

Knowledge about social media is a crucial aspect of educating children about digital safety. It is important that young people understand both the benefits and risks associated with using social media. That is why it is essential to explore this aspect in greater depth

Family Social Media

Social media have become an integral part of daily life, and children often start using them at a young age. Popular social media include Facebook, Instagram, Twitter, TikTok, and many others. These platforms provide a place for communication, sharing content and connecting with other people.

Associated Risks

however, the use of social media poses significant risks to children’s privacy and safety. Hacker fraud is increasingly a community on social media, with hackers trying to steal personal data or gain access to others’ accounts. For example, statistics show that millions of social accounts can be compromised each year due to weak passwords or other vulnerabilities.

Online privacy

children need to understand the importance of protecting their privacy online in social media. This means using appropriate privacy settings, not sharing sensitive information, and not accepting friend requests or interacting with unknown people.

Online Fraud

Online fraud is common on social media platforms. Children should be taught to recognize signs of potential scams or fake accounts and to report suspicious behavior.

Awareness raising

Raising children’s awareness of the risks of social media and teaching them how to recognize and deal with problematic situations online is crucial. Statistics show that a good proportion of young people have experienced unpleasant situations on social media at least once, which underscores the importance of this awareness.

Conclusions

Children’s cyber security is a shared responsibility. Cyber security should be an integral part of our little ones’ digital education. By following these guidelines and staying involved in your children’s online activities, you can help create a safe online environment for them. Always keep your children’s safety at the center of your digital concerns.

Request a free consultation to protect your business data

lecs news and useful events on cyber security

Learn more about our documentation.

White papers, technical guides and exclusive reports to deepen your defense strategy.