{"id":413974,"date":"2021-09-14T13:23:23","date_gmt":"2021-09-14T11:23:23","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=413974"},"modified":"2021-09-14T13:28:51","modified_gmt":"2021-09-14T11:28:51","slug":"microsofts-expensive-security-add-ons-for-office-365-are-basically-ransomware-software-ceo","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/413974-microsofts-expensive-security-add-ons-for-office-365-are-basically-ransomware-software-ceo.html","title":{"rendered":"Microsoft&#8217;s expensive security add-ons for Office 365 are basically ransomware \u2014 software company CEO"},"content":{"rendered":"<p>Microsoft is ripping businesses off with expensive premiums on its most secure enterprise solutions, effectively holding them to ransom in exchange for getting the best possible protection, which isn\u2019t always guaranteed.<\/p>\n<p>This is the view of Richard Firth, CEO of software development firm MIP Holdings, who labelled Microsoft\u2019s products as the largest vulnerability for cybercrime attacks on businesses.<\/p>\n<p>\u201cThe vulnerabilities in various Microsoft products are the biggest source of cyberattacks worldwide,\u201d Firth stated.<\/p>\n<p>\u201cApproximately 1.5 billion people use Windows operating systems every day, and the number of reported Microsoft vulnerabilities has risen a whopping 181% in the last five years.\u201d<\/p>\n<p>\u201cIn 2020 alone, 1,268 Microsoft vulnerabilities were discovered,\u201d he added.<\/p>\n<p>Firth said that many companies believe if they kept their Windows versions updated, they would be fully secure.<\/p>\n<p>However, this was not the case, as many Windows security flaws don\u2019t get patched.<\/p>\n<p>\u201cSeveral Microsoft issues may or may not receive a patch, and some are configuration issues that can\u2019t be patched,\u201d Firth stated.<\/p>\n<p>Firth said that Microsoft offers a &#8220;secure version&#8221; of its products at an additional cost \u2014 likely referring to <strong><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/enterprise\/office-365-e5?activetab=pivot:overviewtab\" target=\"_blank\" rel=\"noopener\">Office 365 E5<\/a><\/strong> and <strong><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/compare-microsoft-365-enterprise-plans\" target=\"_blank\" rel=\"noopener\">Microsoft 365 E5,<\/a><\/strong> both of which include advanced security features with the subscription.<\/p>\n<p>In MIP Holdings&#8217; case, upgrading to the version of the Microsoft product they need with advanced security features would take the costs per employee from $20 to $57 per month.<\/p>\n<p>\u201cWhile many companies might see this as an investment in security, the fact that the secure version costs almost three times as much as the \u2018normal\u2019 version raises questions,&#8221; Firth stated.<\/p>\n<div id=\"attachment_413978\" style=\"width: 650px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-413978\" class=\"wp-image-413978\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/09\/Richard-Firth.jpg\" alt=\"\" width=\"640\" height=\"441\" \/><p id=\"caption-attachment-413978\" class=\"wp-caption-text\">Richard Firth, chairman and CEO of MIP Holdings<\/p><\/div>\n<p>On top of this, Firth said there was no guarantee that this version could keep out attackers.<\/p>\n<p>\u201cThere isn\u2019t a single product on the market that can do that \u2014 so additional tools will still be required,\u201d he said.<\/p>\n<p>\u201cOn GitHub, there is an entire <a href=\"https:\/\/github.com\/cfalta\/MicrosoftWontFixList\/blob\/main\/README.md\" target=\"_blank\" rel=\"noopener\"><strong>\u2018won\u2019t fix\u2019\u00a0list<\/strong><\/a> of security issues that Microsoft has either not yet patched, won\u2019t patch, or are issues that need manual adjustment to fix.\u201d<\/p>\n<p>CSO Online recently also published an article with a list of<a href=\"https:\/\/www.csoonline.com\/article\/3627403\/6-vulnerabilities-microsoft-hasnt-patched-or-cant.html\" target=\"_blank\" rel=\"noopener\"><strong> six security vulnerabilities<\/strong><\/a> that Microsoft hasn&#8217;t or cant&#8217;t fix, including the now-infamous &#8220;<strong><a href=\"https:\/\/mybroadband.co.za\/news\/software\/405101-windows-emergency-patch-fixes-critical-security-flaw-update-now.html\">PrintNightmare<\/a><\/strong>&#8221; exploit.<\/p>\n<p>Firth said these factors led him to question whether Microsoft\u2019s own secure solutions was any different from ransomware.<\/p>\n<p>\u201cMicrosoft is charging almost triple for a product that will still require additional investment to secure, effectively taking advantage of their poor networking tooling to make extra money,\u201d he stated.<\/p>\n<p>Firth explained the problem was exacerbated by many businesses adopting a \u201cMicrosoft everything\u201d strategy, with the company\u2019s software being used throughout their architecture.<\/p>\n<p>\u201cThink about the ease by which a vulnerability can be spread throughout the organisation,\u201d he said.<\/p>\n<p>\u201cThis will increase the scope of a cyber-attack in the future, as cybercriminals continue to focus on the most widely used platform in the world.\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-413992\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/09\/Microsoft-office-programs-640x426.jpg\" alt=\"\" width=\"640\" height=\"426\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/09\/Microsoft-office-programs-640x426.jpg 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/09\/Microsoft-office-programs-600x400.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/09\/Microsoft-office-programs-768x512.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/09\/Microsoft-office-programs.jpg 800w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Firth explained that most vulnerabilities were found in Microsoft Exchange Servers, although all of the company\u2019s products are being targeted by attackers.<\/p>\n<p>\u201cCheckpoint Research, for example, recently found four security vulnerabilities that affect products in the Microsoft Office suite, including Excel and Office online.\u201d<\/p>\n<p>\u201cRooted from legacy code, the vulnerabilities create the potential for an attacker to execute code on targets via malicious Office documents, such as Word, Excel and Outlook.\u201d<\/p>\n<p>Firth warned that cyberattacks would have a bigger impact on businesses and their customers in the future, highlighting the long-tail costs of a data breach that can extend for months to years.<\/p>\n<p>\u201cThese costs include lost data, business disruption, revenue losses from system downtime, notification costs, fines associated with government regulations designed to deal with breaches of \u2019Protection of Personal Information\u2019 or even damage to a brand\u2019s reputation,\u201d he explained.<\/p>\n<p>He said companies that hold sensitive data or personally identifiable information are common targets for hackers and already invest heavily in security.<\/p>\n<p>\u201cWhy should they pay extra for a secure version of the tools that their businesses use daily? Shouldn\u2019t the secure version be the standard version?\u201d Firth asked.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/413912-apple-releases-critical-security-fixes-update-your-iphone-now.html\" rel=\"bookmark\">Apple releases critical security fixes \u2014 update your iPhone now<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>One software firm&#8217;s CEO says Microsoft is ripping businesses off with expensive premiums on its most secure enterprise solutions, effectively holding them to ransom in exchange for getting the best possible protection, which doesn&#8217;t cover all threats. <\/p>\n","protected":false},"author":23,"featured_media":413990,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[72252,123,72250,72248,30150,72246,49767],"class_list":["post-413974","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyberattacks","tag-microsoft","tag-microsoft-security","tag-mip-holdings","tag-ransomware","tag-richard-firth","tag-security-vulnerabilities"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/413974"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=413974"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/413974\/revisions"}],"predecessor-version":[{"id":414044,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/413974\/revisions\/414044"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/413990"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=413974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=413974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=413974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}